Zaaz
Sign inGet started

Legal

Privacy Policy

Super Zaaz Collective Inc. · zaaz.co · Effective date: July 23, 2026

Super Zaaz Collective Inc.(“Zaaz,” “we,” “us”) helps content creators understand and prove the value of their work. This policy explains what data we collect, why we collect it, and the controls you have. It covers zaaz.co, app.zaaz.co, and our platform integrations, including our Instagram integration via Meta’s official API and account connections made through our data partner Phyllo.

1. Data we collect, only with your consent

We only collect data from social accounts that you connect to Zaaz, and only after you authorize access through each platform’s official consent screen. You choose what to share and can decline any optional permission.

Instagram (via Meta’s API)

When you connect your Instagram professional account to Zaaz, you authorize us, through Meta’s official API and an explicit consent screen, to read:

  • Profile basics: username, name, account type, profile picture, and follower / following / media counts.
  • Content metadata:your posts’ captions, media type, timestamps, permalinks, and public engagement counts.
  • Performance insights: views, reach, likes, comments, saves, shares, watch time, and similar metrics for your account and posts.
  • Audience demographics: aggregated distributions only (age ranges, gender, top cities and countries). We never receive lists of your followers, only aggregates.
  • Comments on your media (optional permission):comment content is processed solely to help you understand your own content, performance, and audience sentiment. When you view comments, commenters’ public usernames are displayed as provided by the API, exactly as they appear on the platform. Commenter usernames are retained only as needed to display your comments to you, and are deleted upon your deletion request, and at the latest within 30 days of disconnection. We do not build commenter profiles. Purchase-intent signals are aggregate measurements only, the percentage of comments that express purchase intent or product questions, and are never profiles of individual buyers or commenters.

Personal (non-professional) Instagram accounts are not supported and are never accessed.

Accounts connected via Phyllo (YouTube, TikTok)

Phyllo is an approved data partner operating on the official developer APIs of Meta, YouTube, and TikTok. Where you connect an account through Phyllo, you complete the same style of platform-native authorization, and we receive the equivalent categories of data listed above for that platform: profile basics, content metadata, performance insights, and aggregated audience demographics. The same rules in this policy apply identically to data received via Phyllo:

  • Access is read-only and consent-based.
  • We never receive or store your passwords. Authentication is handled through secure tokens managed under each platform’s official authorization process.
  • You can revoke access at any time through the platform’s settings or your Zaaz account settings, and revocation ends our access.

Phyllo acts as a data processor on our behalf. Phyllo’s own privacy practices are described in its privacy policy at getphyllo.com/privacy-policy.

2. What we never do

  • We never post, comment, like, message, or change anything on your accounts. Our access is read-only.
  • We never sell your personal data.
  • We never access non-public data from any account other than the accounts you connect.

3. How we use your data

We use your data to provide the service to you: analytics about your content and audience, growth and engagement indicators, earned-media-value estimates, benchmarking, personalized recommendations, and insights and materials that help you identify, win, and fairly price brand partnerships. Aggregated, de-identified statistics may be used to generate benchmarks across the Zaaz member base and to improve the product. Benchmarks are always anonymized and will never identify you personally.

4. Storage and security

Data is encrypted in transit, stored with access controls in our analytics infrastructure (cloud providers acting as processors, for example Amazon Web Services and ClickHouse Cloud), and personal identifiers are masked by default for internal analytical access. Access tokens are stored as managed secrets and are never shared.

5. Retention

We retain your data only for as long as it is needed to provide the service to you, in practice for as long as your account remains connected. When you ask us to delete your data or delete your Zaaz account, we delete the associated personal data, including our internal analytics copies, within 30 days, and at the latest within 30 days of disconnection. Aggregated, de-identified statistics that cannot be linked back to you may be retained.

6. Disconnecting and deleting your data

  • Disconnect Instagram at any time:Instagram → Settings → Apps and Websites → remove “Zaaz.” Our access ends immediately.
  • Disconnect Phyllo-linked accounts:through the relevant platform’s connected-apps settings or your Zaaz account settings.
  • Request deletion: email privacy@zaaz.co from the email associated with your account, or include your platform @username. We will confirm and complete the deletion of your personal data within 30 days. You may also delete your account directly in account settings, which triggers the same deletion.

Full deletion instructions are maintained at zaaz.co/data-deletion.

7. Your rights

Depending on where you live, applicable data protection laws (including the GDPR and U.S. state privacy laws) may give you rights to access, correct, export, or delete your personal data, and to withdraw consent at any time. Use the contact below to exercise them. We honor these rights for all users regardless of location.

8. Changes

We will post any material changes to this page and update the effective date.

9. Contact

Super Zaaz Collective Inc. · privacy@zaaz.co
1424 11th Ave, Seattle, WA 98122-4269, United States

Zaaz

Transforming audience signals into revenue.

© 2026 Zaaz. All rights reserved.

Privacy PolicyTerms of ServiceData Deletion