Privacy policy
Last updated 10 Sep 2026
This notice explains what personal data Rundown processes, why, and what you can do about it. It is written for the two kinds of people who sign in — the members of a talent agency, and the creators that agency represents — and it follows the Swiss Federal Act on Data Protection (FADP) as revised on 1 September 2023.
1. Who is responsible
Jakob Baranowski, sole proprietor, Wintergasse 10, 4056 Basel, Switzerland, operates Rundown and is the controller for sign-in and service data. For the platform statistics an agency’s creators connect, the agency decides whom it adds and what it does with the numbers, and we process those on the agency’s behalf. Contact: privacy@rundown.ch.
2. What Rundown is
Rundown shows a talent agency the performance numbers of the creators it represents — followers, views, engagement and audience make-up — read from the official interfaces of YouTube, Instagram, TikTok and Twitch after a creator connects their own accounts. Creators sign in only to connect or disconnect a platform; they never share a password with the agency or with us.
3. What data we process
For agency members:
- Your email address and, if you set one, your display name.
- The way you sign in (email link, password, or Google), and the profile photo Google provides if you use it.
- What you do in the product that changes something — invitations, role changes, creators added or removed — kept as an activity record so the agency can see who did what.
For creators:
- Your name and email address, entered by your agency.
- For each platform you connect: the account identifier and handle, an access token that lets us read your statistics, and the statistics themselves — follower counts, views, likes, comments, shares, watch time, live-stream viewer counts, and the aggregated audience breakdowns the platform provides (countries, age groups, gender shares). We never receive your platform password, your messages, or anything a platform does not offer through its official reporting interface.
For everyone:
- Technical records of requests to the service (IP address, browser type, time) in the logs of our hosting provider, kept for 30 days for security and troubleshooting.
4. Why we process it
To provide the service to the agency you belong to (a contract with the agency); for creators, because you chose to connect a platform and can disconnect it at any time; and to keep the service secure and working. We do not profile anyone, we do not sell data, and we do not use it for advertising.
5. Who processes data for us
| Processor | What for | Where |
|---|---|---|
| Google Cloud / Firebase (Google Ireland Ltd.) | Hosting, database, background jobs and sign-in | Database and jobs in Belgium (europe-west1); sign-in infrastructure may process data in the USA |
| Resend, Inc. | Sending sign-in links, invitations and notifications by email | Sent from the European Union; account records in the USA |
Transfers to the USA rest on the Swiss-U.S. Data Privacy Framework or on standard contractual clauses. The platforms you connect (Google, Meta, TikTok, Twitch) process your data under their own terms; we only read from them.
6. Platform data and how to revoke access
YouTube. Rundown uses YouTube API Services. By connecting a YouTube channel you also agree to the YouTube Terms of Service; the Google Privacy Policy applies to Google’s side of that exchange. Rundown’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We refresh YouTube data nightly and keep the daily totals while the channel stays connected. You can revoke our access at any time at Google account permissions.
Instagram. Data comes from the Instagram API with Instagram Login and covers professional (creator or business) accounts only. Revoke under Instagram → Settings → Apps and websites.
TikTok. Data comes from the TikTok API for Business. Revoke under TikTok → Settings and privacy → Security and permissions → Manage app permissions.
Twitch. Data comes from the Twitch API. Revoke under Twitch → Settings → Connections.
Disconnecting a platform inside Rundown deletes our access token for it immediately; revoking at the platform has the same effect the next time we try to read.
7. How long we keep data
| Record | Kept until |
|---|---|
| Platform access tokens | You disconnect the platform, or the platform revokes access |
| Platform statistics of a creator | The creator is removed from the roster or deletes their account |
| Handshake records for connecting a platform | Used once; unused ones expire after ten minutes |
| Invitations | Accepted, withdrawn, or expired after seven days |
| Agency activity records | The agency’s account ends |
| Request logs | 30 days |
| Backups | 14 days after the daily backup is taken |
8. How we protect data
Every connection to Rundown uses TLS. Platform access tokens are encrypted before they are stored, with AES-256-GCM under a key kept in Google Secret Manager, on top of the database’s own encryption at rest. Every platform scope we request is read-only, and database rules limit an agency’s numbers to that agency’s members; no one can read a token through the product.
9. Your rights
You can ask us which data we hold about you, have it corrected, have it deleted, receive a copy in a common format, and object to a processing. Creators can disconnect any platform themselves on their connect page; how to delete an account is described on the data deletion page. For anything else, write to privacy@rundown.ch. You can also contact the Swiss Federal Data Protection and Information Commissioner (FDPIC).
10. Cookies and local storage
Rundown sets no tracking cookies and uses no analytics service. Your browser keeps: your sign-in session (Firebase Authentication, in the browser’s IndexedDB), whether the sidebar is collapsed (a first-party cookie), your light-or-dark preference, and — until the link is used — the email address you asked a sign-in link for. All of these exist to make the product work and are not read by anyone else.
11. Changes
We change this notice when the service changes. The date at the top says when; the current version is always at this address.