Privacy Policy
Last Updated: August 15, 2026
1. Introduction
Oskkee (trade name of Indslav Joog Private Limited, CIN: U62099HR2025PTC129498) is a service owned and operated by Indslav Joog Private Limited ("we", "our", or "us"), a company incorporated in India. The website oskkee.com and the Oskkee brand are owned by Indslav Joog Private Limited. We operate a creator discovery platform that helps brands, agencies, and businesses find relevant content creators and influencers for marketing collaborations. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services.
By using Oskkee, you agree to the collection and use of information in accordance with this policy.
1A. About Our Service and Payment Model
Oskkee is an AI-powered creator discovery platform. We help brands, marketers, and agencies find content creators and influencers across major social media platforms (Instagram, YouTube, Twitter/X, TikTok, LinkedIn, Pinterest, and more) through a simple conversational interface available on Web Chat, WhatsApp, and other messaging channels.
Token-based payment model: Access to our AI creator discovery service operates on a token (search credit) system. Users purchase tokens by subscribing to one of our plans. Each search or AI-powered query consumes a certain number of tokens from the user's balance. All payments for token purchases are collected by Indslav Joog Private Limited (the operator of Oskkee) through our payment processor. We process personal data collected during the payment (name, email, phone number, transaction ID) solely for the purpose of fulfilling the token purchase, providing the service, and complying with applicable financial and legal obligations.
Available plans range from Free (100 tokens) to Agency (50,000 tokens/month). Prices are in Indian Rupees (₹) and are inclusive of applicable taxes. For details on eligibility and refund conditions, please see our Refund Policy.
2. Information We Collect
2.1 Information You Provide
- Account Information: Phone number (for WhatsApp communication), name, business type, and preferences
- Search Queries: Your search requests for finding creators
- Communication Data: Messages exchanged through our WhatsApp chatbot
- Payment Information: Transaction details processed through our payment partners
2.2 Information from Social Media Platforms
We access publicly available information from social media platforms to provide our creator discovery services:
- Public Profile Data: Usernames, display names, profile pictures, bios, follower counts, and public account metrics
- Public Content: Posts, pins, tweets, reels, and other publicly shared content
- Engagement Metrics: Likes, comments, shares, and other public engagement data
We only access information that creators have made publicly available on their social media profiles. We do not scrape the platforms ourselves — this data reaches us through the search and data providers named in section 3.1, and your search terms are sent to those providers in order to run the lookup.
2.3 Automatically Collected Information
- Device information and browser type
- IP address and approximate location
- Usage data and interaction patterns
- Cookies and similar tracking technologies
3. How We Use Your Information
We use the collected information for:
- Service Delivery: To provide creator discovery, brand-pulse audits, outreach drafting and recommendation services across WhatsApp, web chat, email, Instagram DM, Facebook Page messages, Twitter/X DM and Discord.
- Communication: To respond to your queries, send service updates and proactive nudges on the channel you have opted into.
- Improvement: To analyze usage patterns, run nightly self-reflection and A/B experiments that improve the agent.
- Personalization: To tailor search results, persona detection and proactive messaging based on your preferences and history.
- Security: To detect and prevent fraud, abuse, and security incidents.
- Legal Compliance: To comply with applicable laws and regulations including India's DPDP Act, GST and consumer-protection rules.
3.1 Where your data lives (current data flows)
So you know exactly what touches your data:
- Conversations & identity: stored in our managed PostgreSQL database (Neon, provisioned through Replit) hosted in the EU/US, with row-level isolation per user. Your conversation history is held here and nowhere else.
- Vector search: creator/post embeddings live in Qdrant Cloud.
- LLM calls: routed through OpenRouter, which forwards each request to a model provider on our behalf. We do not send your data to a fixed vendor: the model is chosen per request by task complexity, and the current pins are open-weight models (Z.ai GLM, MiniMax, Qwen, Google Gemma, DeepSeek). Anthropic models remain configured for specific internal tasks but are not on the default path. On Pro and above you can opt into BYOK and your own keys are used end-to-end (encrypted at rest with AES-256-CBC).
- Embeddings: text is converted to vectors by a single embedding model (currently Qwen3 Embedding) through the same OpenRouter route. One model is used for every vector we store, so no embedding of your data is sent to a second vendor.
- Data connected from Google (YouTube/Google account): any request that carries data you connected from Google is pinned to zero-data-retention endpoints only — providers that do not log, retain, or train on the request. This applies to the vector calls as well as the text calls, because a vector derived from your data is still your data. If no zero-retention provider is available the request fails rather than falling back.
- Creator discovery: to answer a search we send your search terms to the data providers that perform the lookup — Apify, SearchAPI.io, Serper, SearchCans, Exa, Jina, Google Programmable Search, the YouTube Data API and the Twitter/X API. Each returns publicly available profile and post data, which we then rank and show you.
- Messaging: WhatsApp messages are delivered via Twilio; email via Resend; Instagram and Facebook messages via Meta's Graph API; Discord and Twitter/X messages via their respective platform APIs.
- Payments: processed by Cashfree. We never see or store full card details.
- Analytics, advertising & observability: anonymised event metrics via Google Analytics 4 (GTM-T8VD4Z56); the Meta Pixel, which loads on our public pages and reports your visit to Meta for advertising measurement and retargeting; error and performance monitoring via Sentry; and LLM tracing via Langfuse, which receives the text of the requests we send to the models and the responses they return.
- Search-engine indexing: when we publish a public creator or brand page we submit its URL through IndexNow, which shares it with participating search engines including Microsoft Bing and Yandex. This carries the page address only.
- Browser notifications: if you turn these on, delivery is handled by your browser vendor's push service (Google, Mozilla or Apple). We sign each message with our own key; the vendor sees the delivery endpoint.
4. Social Media Platform Compliance
We access social media data in compliance with each platform's terms of service and developer policies:
4.1 Instagram & Facebook (Meta)
A creator connects their own Instagram professional account, or a Facebook Page they manage, through Meta's official login. Everything below applies only to the account or Page that person chooses to connect, and only for as long as they stay connected. We request the following permissions, each tied to a specific product feature:
- instagram_business_basic: We read the connected account's ID, username, name, profile picture and follower and media counts. We display these back to the creator so they can confirm the correct account connected, and use them to build the media kit they choose to share. We read only the account the creator connects.
- instagram_business_manage_insights: We read the connected account's own audience insights — reach, and follower demographics by country and by age and gender — to build that creator's audience report and media kit. We read only the connected account's own insights.
- instagram_business_manage_comments: On the connected account's own posts, we receive comment events and read the public comment text and ID to match them against automation rules the account owner configured, and we may post a short public reply on that comment thread telling the commenter a message has been sent. We never delete or hide comments, and we act only on the connected account's own posts.
- instagram_business_manage_messages: We send and receive direct messages on connected Instagram professional accounts. Every message we send is a direct response to a comment or a message that person initiated: either a one-time Private Reply to someone who commented on the creator's post, or a reply in an existing conversation with our own account. We do not send unsolicited or bulk messages, and we do not message people who have not contacted the account first. Message content is retained so the account owner can review their own conversations, and is deleted on disconnection or on request.
- pages_show_list: We read the list of Facebook Pages a person manages, so they can choose which of their own Pages to connect, and to verify they manage it.
- pages_read_engagement: We read the connected Page's own follower count (fan_count) to display it on the creator's account and in their media kit.
- pages_messaging: We send and receive Messenger messages on a connected Page, on the same strictly user-initiated basis described for Instagram messages above.
- pages_manage_metadata: We subscribe the connected Page to its feed webhook at connect time so we receive the comment events that drive the automation the Page owner configured. We do not change Page settings and we do not post.
We comply with Meta's Platform Terms and Developer Policies. We do not store Instagram or Facebook login credentials. We do not post content on behalf of users without explicit consent. We do not use Meta data to search for, profile, or contact people who have not connected their own account to Oskkee. Users can request deletion of their Instagram-related data at any time via our data deletion page. When a user deauthorizes Oskkee from their Instagram settings, we automatically delete all stored Instagram data within 30 days. We do not sell or share this data with third parties for advertising purposes.
4.2 X (Twitter)
- We comply with X's Developer Agreement and Policy
- We access only public tweet data and profile information
- We respect rate limits and data retention requirements
- We do not perform automated actions (tweeting, following, etc.)
4.3 Pinterest
- We comply with Pinterest's Developer Terms and API Terms of Service
- We access only public pins and profile information
- We do not store Pinterest user credentials
- We respect Pinterest's data usage policies
4.4 YouTube & Google user data
Oskkee uses YouTube API Services. By connecting your YouTube channel you agree to the YouTube Terms of Service; Google's handling of your data is described in the Google Privacy Policy.
What Google user data we access. Without sign-in we access only public video and channel information. If you explicitly connect your own YouTube channel via Google sign-in, we additionally access — with your consent — your basic Google account identity (name, email), your own channel's title, description, thumbnail and public counts, and your own private YouTube Analytics (views, watch time, retention, subscriber changes, and aggregated audience age/gender/geography). We request read-only access: we never post, edit or delete anything on your YouTube channel, and we never use your authorisation to reach any channel other than the one you connect.
How we use it. This data is used solely to provide your own user-facing features: your creator health check, your shareable media kit, and your private taste/persona profile. Raw and aggregated Google user data is never used for advertising, credit or lending decisions, or any purpose unrelated to these features.
What we share. We do not sell or transfer Google user data to data brokers, advertisers, or other third parties. Your media kit becomes publicly visible only if you choose to share it. Where AI models help generate your summaries, Google user data is processed only under terms that prohibit the provider from using it to train their models, and it is never transferred to any third party for model training.
How it is protected. OAuth tokens are encrypted at rest (AES-256-GCM) and all data moves over TLS. Access is limited to what the features above require.
Retention and deletion. We keep this data only while your channel stays connected. Disconnecting (from your Oskkee account page) revokes our access and purges the stored tokens and Google-derived data we hold for that connection. You can also request export or deletion of all your data at any time (see Section 9 and our Data Deletion page), and you can revoke Oskkee's access from your Google account security settings.
Limited Use disclosure. Oskkee's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4.5 TikTok
- We comply with TikTok's Developer Terms of Service
- We access only publicly available content and metrics
- We do not access private user data
4.6 LinkedIn
- We comply with LinkedIn's API Terms of Use
- We access only public professional profile information
- We do not scrape or store private LinkedIn data
4.7 Threads
- We comply with Meta's Threads API Terms and Policies
- We access only public thread content and profile data
- We respect all data retention and usage limitations
5. WhatsApp Business Platform
Our primary communication channel is WhatsApp. We comply with:
- WhatsApp Business Terms of Service
- WhatsApp Business Policy and Commerce Policy
- Meta's data processing requirements
Messages are processed to provide our services and may be stored for service improvement and compliance purposes. We do not share your WhatsApp conversations with third parties except as required by law.
5A. Oskkee Browser Extension (Chrome)
We publish an optional Chrome extension, Oskkee – Social Scout. It is a separate piece of software from the oskkee.com website, it is installed only if you choose to install it, and this section describes it specifically. Everything else in this policy — retention, your rights, security, contact — applies to it as well.
5A.1 What it is for
The extension has a single purpose: researching a creator you are already looking at. When you are on a creator's profile, post or reel, it adds one button. On Instagram and YouTube that button runs an authenticity check on the account and shows the result in the page. On TikTok, LinkedIn and X it opens a pre-filled search on oskkee.com. The toolbar popup lets you search for a creator from any page.
5A.2 What it reads, and when
The extension runs only on instagram.com, youtube.com, tiktok.com, linkedin.com, twitter.com, x.com and oskkee.com. It does not run on any other site.
- Automatically, on those sites only: the page URL, the page title, and the creator handle shown on it. This is used to remember which creators you have looked at, and it is stored on your own device (see 5A.4). It is not transmitted to us.
- Only when you click the button: the extension asks the platform, from your browser and using your existing logged-in session, for that creator's public profile and recent public posts. This is the same data the platform would show you in the page; the extension requests it in a structured form so it can be scored.
The extension does not read your direct messages, your inbox, your notifications, your follower or following lists, your drafts, your account settings, or anything behind your account's private surfaces. It does not read pages of any site outside the seven listed above. It does not modify what you post, follow, like or send.
5A.3 What leaves your browser
When — and only when — you click the check button on Instagram or YouTube, the following is sent to oskkee.com and nowhere else:
- The creator's public profile: handle, display name, bio, external link, profile picture URL, follower and following counts, post count, and whether the account carries a platform verification badge.
- The creator's recent public posts: post URL, caption, like count, comment count, view count, publish date, and whether it is a video.
- The extension version and a random request ID, so we can debug failures.
If you are signed in to Oskkee, your Oskkee session token is attached so the resulting report is saved to your account. If you are not signed in, no identifier of yours is attached. We use this data to produce the authenticity report and to build the creator record described in section 2.2. Nothing else is transmitted: the extension sends no browsing history, no page content from other tabs, no cookies, and no analytics. It contains no third-party trackers, advertising SDKs, or remotely-loaded code.
5A.4 What stays on your device
Stored in the browser's own extension storage, on your machine, and never uploaded by us:
- Recently viewed creators — the last 100 creator pages you visited on the supported sites (URL, title, handle, inferred topic, timestamp), used to make search suggestions more relevant.
- Your Oskkee sign-in token, if you have signed in.
- A request-signing key and the random install identifier it belongs to, which the extension requests from us the first time our server asks for signed requests. The identifier is generated at random per installation, is not derived from you or your device, and is used only to verify that a report request came from the extension.
Removing the extension from Chrome deletes all of it.
5A.5 About the creators you check
An authenticity check is run on a third party — the creator — not on you. We process only information that creator has made public on their own profile, and we do so on the legitimate-interest basis described in section 2.2, for the purpose of helping brands and agencies assess whether an account's audience is genuine. We do not attempt to identify, contact, or profile that creator's followers, and we do not collect lists of who follows, likes, or views them.
If you are a creator and you want the record we hold about your account corrected or erased, email info@oskkee.com with "Privacy Request" in the subject line, from an address or account you can show control of. The rights in section 9 and the retention limits in section 7 apply to you whether or not you have ever used Oskkee.
5A.6 Why the extension asks for each permission
- Access to the seven sites listed above — to place the button on a creator's page and, on your click, to read that creator's public profile and posts. Each site is listed separately so the extension cannot run anywhere else.
- Storage — to keep the three items in 5A.4 on your device.
- Active tab — so the toolbar popup knows which creator page you are on when you open it.
- Notifications — to tell you a check has finished, since checks continue after you scroll away or switch tabs.
We do not sell, rent, or transfer extension data to third parties; we do not use it for advertising, credit assessment, or any purpose unrelated to creator research; and we do not use it to build profiles of individuals other than the public creator accounts being checked.
6. Data Sharing and Disclosure
We may share your information with:
- Service Providers: Third-party vendors who assist in operating our platform (hosting, analytics, payment processing)
- Legal Requirements: When required by law, court order, or government request
- Business Transfers: In connection with a merger, acquisition, or sale of assets
- With Your Consent: When you explicitly authorize us to share information
We do not sell your personal information to third parties.
7. Data Retention
- Account Data: Retained while your account is active and for up to 2 years after deletion
- Search History: Retained for 1 year to improve recommendations
- Social Media Profile Data: Creator profiles and engagement metrics are cached for up to 90 days and refreshed periodically; we do not retain raw data beyond 90 days unless aggregated into anonymized metrics
- Instagram Comment and Hashtag Data: Processed in real time during the search session and not stored beyond the session unless aggregated into anonymized metrics
- Instagram Direct Messages: Message content and delivery status are retained for up to 90 days for service quality and compliance, then automatically deleted
- WhatsApp Communication Logs: Retained for 1 year for service improvement and compliance
You can request deletion of your data at any time by contacting us.
8. Data Security
We implement appropriate technical and organizational measures to protect your information:
- Encryption of data in transit (TLS/SSL) and at rest
- Access controls and authentication mechanisms
- Regular security assessments and monitoring
- Secure cloud infrastructure with reputable providers
While we strive to protect your data, no method of transmission or storage is 100% secure.
9. Your Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of your personal data
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your data
- Portability: Request transfer of your data
- Objection: Object to certain processing activities
- Withdraw Consent: Withdraw consent where processing is based on consent
To exercise these rights, contact us at the email below.
10. Children's Privacy
Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a minor, please contact us immediately.
11. International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for such transfers in compliance with applicable data protection laws.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the "Last Updated" date. Your continued use of our services after changes constitutes acceptance of the updated policy.
13. Contact Us
Indslav Joog Private Limited
D73 Oakwood Estate, DLF Phase 2
Gurgaon, Haryana 122002
India
Email: info@oskkee.com
Website: https://oskkee.com
WhatsApp: +91 96670 87507
For data protection inquiries or to exercise your rights, please email info@oskkee.com with "Privacy Request" in the subject line.