Northstar
Privacy Policy
Last updated: July 31, 2026
NorthStar Creator is a creator analytics and planning platform. Depending on the feature, NorthStar may process data in the user's browser or through approved server-side systems and managed infrastructure providers. NorthStar does not access a connected service unless the user intentionally connects or authorizes it.
Information Northstar May Process
NorthStar may process creator business data such as connected-account identifiers, products, videos, performance metrics, sample records, creator-attributed sales and commission records, notes, hooks, generated plans, settings, session records, connection metadata, and backup metadata. Depending on the feature, this information may be stored in local browser storage, user-controlled exports, or approved server-side systems.
NorthStar does not intentionally request or durably store direct messages, phone numbers, physical addresses, login IP histories, payment details, searches, watch history, customer-service conversations, or shopper activity for its creator analytics features. Managed infrastructure providers may temporarily process IP addresses, device details, request headers, and related request metadata for security, fraud prevention, reliability, logging, and ordinary service operations under their applicable terms and retention practices.
How Data Is Used
User data is used only to provide creator dashboards, analytics, planning tools, and product features. NorthStar does not sell, rent, or share creator data with third parties for advertising or marketing purposes.
Third-Party Connections
When TikTok authentication is enabled, OAuth access and refresh tokens are handled through a secure server-side connector and are not stored in browser localStorage. The current active integration is TikTok for Developers Login Kit and Display API, and its connector encrypts token payloads before durable storage. The TikTok Shop Affiliate Creator integration currently performs no token exchange or token storage and will remain unavailable until the required implementation, security review, configuration, and TikTok approval are complete. NorthStar will only access TikTok data after a user explicitly authorizes the applicable connection through TikTok's official authorization flow.
Managed Service Providers
NorthStar uses managed infrastructure providers, including Vercel for application hosting, Neon for database services, and Upstash for Redis-compatible session and state storage. These providers may process data on NorthStar's behalf to deliver, secure, monitor, and maintain the service. NorthStar configures its application to limit processing to the information needed for approved features.
TikTok Data
When a user chooses to connect a TikTok account, NorthStar accesses only the data authorized through TikTok's official OAuth process and only the permissions approved by the user. This information is used solely to provide creator dashboard features, analytics, organization tools, and planning insights within NorthStar.
TikTok for Developers Login Kit and Display API, TikTok Shop Affiliate Creator, and any optional TikTok Shop Seller integration are treated as separate connections with separate credentials, identities, permissions, and data boundaries. For the Affiliate Creator integration, NorthStar will not invoke affiliate-link generation operations or LIVE User Portrait endpoints. Selection of a bundled scope does not authorize NorthStar to use every operation available under that scope.
Backups and Exports
Users may export backups from Northstar. Exported files are controlled by the user and should be stored carefully.
Data Deletion
Users may disconnect their TikTok account at any time. Users may also request deletion of imported data by contacting northstar-creator@northstar-creator.com. Upon a valid request, NorthStar will disconnect applicable provider access, delete applicable stored token material and active account-scoped NorthStar application records, and, where supported by the provider, revoke or invalidate the associated authorization. NorthStar will complete the request within all applicable legal and platform deadlines; otherwise NorthStar targets completion within 30 days.
Data removed from active systems may remain temporarily in managed-provider backups until those backups expire through the provider's normal retention and rotation cycle, unless earlier deletion is supported and required.
Contact
Users may request deletion or contact support through the Contact page or by emailing northstar-creator@northstar-creator.com.