LEGAL · PRIVACY

Privacy Policy

Effective May 13, 2026

KOLens (“we”, “us”) provides a TikTok creator-discovery service. This policy explains what information we collect when you use kolens.xyz, why we collect it, and the choices you have. If anything here is unclear, email hello@kolens.xyz.

1. What we collect

Account information

When you create an account we store your email address, a hashed password (or your Google account identifier if you sign in with Google), and the date your account was created. We do not store your raw password.

Search activity and billing

We log every keyword search you run, the parameters you choose, the number of creators returned, and the number of credits charged. This is required to operate the credit system, show you your search history, and answer billing questions.

Workspace data

Watchlists, KOL lists, exports, and other items you create inside the app are stored against your account so you can return to them later.

Cookies and similar technologies

We use a small number of first-party cookies, all strictly necessary to provide the service:

  • Authentication. Supabase auth cookies keep you signed in across requests.
  • Preferences. Your theme choice (light/dark inside the app) is stored in localStorage on your device.
  • OAuth callback state. Short-lived cookies used during Google sign-in to round-trip the PKCE challenge.

We do not run third-party advertising trackers or session-replay tools on the marketing site or inside the app.

Server logs

Our hosting provider (Vercel) records standard request metadata — IP address, user agent, request path, response status, and timestamp — for up to 30 days for security and abuse-prevention purposes. We do not link these logs to your account except when investigating a specific issue.

2. What we do not collect

KOLens does not collect data from private TikTok accounts. All creator data shown in search results is information that is publicly visible on TikTok at the time of the search. KOLens itself does not log into TikTok with anyone’s personal credentials.

We do not sell your data, and we do not share it with third parties for advertising or marketing.

3. How we use your information

  • To operate, secure, and improve the KOLens service.
  • To bill credits accurately and prevent abuse.
  • To send transactional emails — account confirmation, password reset, billing receipts, and important service notices. We do not send marketing emails without separate opt-in consent.
  • To respond to support requests and legal obligations.

4. Third-party processors

We rely on the following services to deliver KOLens. Each is bound by its own privacy policy; we share with them only the data necessary for that function.

  • Supabase — authentication, database hosting.
  • Vercel — web hosting, edge network, server logs.
  • Apify — TikTok scraping infrastructure. Only the keyword and search parameters are passed; your account identity is not.
  • Google — optional sign-in and (when you enable export) writing to your own Google Sheets / Drive. We never read content from your Drive that you didn’t create through KOLens.
  • Anthropic — only if you use the KOLens Claude plugin. In that case your search queries are passed to Claude via the Anthropic API to generate the response you see in the chat.

5. Data retention

We keep your account and workspace data for as long as your account is active. If you delete your account, we delete the account record, your saved lists, watchlists, and search history within 30 days. Anonymous aggregate metrics (e.g. “X searches were run last week”) may be retained indefinitely.

Server logs are retained for up to 30 days as described above.

6. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete personal information we hold about you, and to object to or restrict certain uses of it. You can exercise any of these by emailing hello@kolens.xyz. We will respond within 30 days.

7. Children

KOLens is not intended for children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, email us and we will delete it.

8. International transfers

Our infrastructure runs in multiple regions, including the European Union and the United States. By using KOLens you understand that your information may be processed outside your country of residence.

9. Security

We use industry-standard security practices — TLS everywhere, password hashing via Supabase Auth, scoped API keys for third-party processors, and per-user authorization checks on every data access. No system is perfect; if you believe you have found a security issue please report it to hello@kolens.xyz and we will investigate.

10. Changes to this policy

We may update this policy from time to time. When we make material changes we will update the “Effective” date at the top of this page and, where appropriate, notify you by email or in-app banner.

11. Contact

Questions about this policy or how we handle your data? Email hello@kolens.xyz.

See also: Terms of Service.