Who is responsible
BOOMIN (boomin.app) decides what is collected and why, so it is the data controller for everything in this policy. Reach the team at hi@boomin.app for anything about your data.
We don’t sell your data, we don’t show ads, and we don’t run advertising or analytics trackers.
What we collect
- Your account
- Your email address, the name from your sign-in, how you sign in (email link or code, or Google), and whether you are a brand or a creator.
- Brands
- Your company’s name, website, description, audience and category, what a model read from your website’s public page, and the people you shortlist.
- Creators
- Your X handle, name and bio, your topics, rates, country, the past collaborations you list, and payout details you choose to save. From an X Analytics screenshot we keep only the age and country shares it shows, not the image.
- From X
- Public data about a creator’s account: profile and bio, follower count, recent posts and their views and engagement, and the posts published for a deal.
- On BOOMIN
- Launches, offers, counter-offers, messages, drafts, post links, publishing times, notifications, applications, and feedback you send.
- Technical
- Sign-in cookies and tokens, and your IP address in hashed form to stop sign-in abuse. No device fingerprinting.
Why, and on what basis
- To run your account and your deals — signing you in, showing offers and conversations, scheduling, reminders, results. This is needed to provide the service you asked for.
- To match brands and creators — reading a brand’s website and a creator’s public X activity, scoring how well they fit, and showing approved creators to brands. Our legitimate interest in running the marketplace, and part of the service.
- To review creator applications — the team reads each profile before it is approved. Part of the service.
- To email you — about your sign-in, your application, your deals and reminders. Part of the service; we send no marketing email.
- To keep BOOMIN safe — rate limits, abuse prevention, and keeping records of what was agreed. Our legitimate interest.
- To answer you — feedback and support. Our legitimate interest.
Reading an X Analytics screenshot happens only when you upload one, and you can skip it.
Who sees what
- Brands see approved creators’ profiles: handle, name, bio, topics, rates, country, audience shares, X statistics, recent posts and past collaborations.
- Creators see the brand’s name and the brief of each offer they receive.
- The two sides of a deal see their conversation, the agreed terms and the post’s results.
- The BOOMIN team sees applications and, when needed for support, your account and deals.
- Nobody on BOOMIN sees your email address but us.
Services that process it
These providers help run BOOMIN. Each receives only what its job needs and may not use it for anything else.
- Google Cloud and Firebase — sign-in and our database, stored in Frankfurt, Germany.
- Google Vertex AI (Gemini) — reads a brand’s public webpage, a creator’s recent posts and an uploaded screenshot.
- KIE — a fallback for the same readings when Vertex AI can’t answer.
- TypeSafe — scores how well a brand and a creator fit, from the brand’s profile and creators’ public profiles. No email addresses.
- TwitterAPI.io — reads public X data.
- Resend — sends our emails.
- unavatar.io — serves creators’ X profile pictures, which your browser loads from it.
Our application runs on our own server. Some of these providers are in the United States; where data leaves the EU, it is covered by their standard contractual clauses or an adequacy decision.
How long we keep it
- Your data stays while your account is open.
- Sign-in records and codes expire on their own, within days.
- A screenshot is read and then discarded; only the shares it showed are kept with your profile.
- When you ask us to delete your account, we delete your data within 30 days, except what we must keep by law or to settle a dispute, and copies in backups, which expire on their own.
How we protect it
Everything travels over HTTPS. Sign-in tokens are stored hashed, as are IP addresses. Access to the database is limited to the service and to the people who run it. No system is perfectly secure; if something goes wrong with your data, we tell you and, where required, the authorities.
Your rights
You can ask us to show, correct, export or delete your data, or to stop using it in a certain way, at any time: write to hi@boomin.app. We answer within a month.
If you are in the EU or the UK, the GDPR gives you these rights and the right to complain to your data protection authority. Wherever you are, the same email reaches us.
Age
BOOMIN is for people aged 18 and over. We don’t knowingly collect data from anyone younger; if we learn we have, we delete it.
Changes to this policy
When we change this policy in a way that matters, we tell you by email or in the app before the change applies. The current version is always at boomin.app/privacy.





