Last updated October 2, 2026

Privacy policy

What BOOMIN collects when you use it as a brand or a creator, why, who processes it, and what you can ask us to do with it.

Who is responsible

BOOMIN (boomin.app) decides what is collected and why, so it is the data controller for everything in this policy. Reach the team at hi@boomin.app for anything about your data.

We don’t sell your data, we don’t show ads, and we don’t run advertising or analytics trackers.

What we collect

Your account
Your email address, the name from your sign-in, how you sign in (email link or code, or Google), and whether you are a brand or a creator.
Brands
Your company’s name, website, description, audience and category, what a model read from your website’s public page, and the people you shortlist.
Creators
Your X handle, name and bio, your topics, rates, country, the past collaborations you list, and payout details you choose to save. From an X Analytics screenshot we keep only the age and country shares it shows, not the image.
From X
Public data about a creator’s account: profile and bio, follower count, recent posts and their views and engagement, and the posts published for a deal.
On BOOMIN
Launches, offers, counter-offers, messages, drafts, post links, publishing times, notifications, applications, and feedback you send.
Technical
Sign-in cookies and tokens, and your IP address in hashed form to stop sign-in abuse. No device fingerprinting.

Why, and on what basis

  • To run your account and your deals — signing you in, showing offers and conversations, scheduling, reminders, results. This is needed to provide the service you asked for.
  • To match brands and creators — reading a brand’s website and a creator’s public X activity, scoring how well they fit, and showing approved creators to brands. Our legitimate interest in running the marketplace, and part of the service.
  • To review creator applications — the team reads each profile before it is approved. Part of the service.
  • To email you — about your sign-in, your application, your deals and reminders. Part of the service; we send no marketing email.
  • To keep BOOMIN safe — rate limits, abuse prevention, and keeping records of what was agreed. Our legitimate interest.
  • To answer you — feedback and support. Our legitimate interest.

Reading an X Analytics screenshot happens only when you upload one, and you can skip it.

Who sees what

  • Brands see approved creators’ profiles: handle, name, bio, topics, rates, country, audience shares, X statistics, recent posts and past collaborations.
  • Creators see the brand’s name and the brief of each offer they receive.
  • The two sides of a deal see their conversation, the agreed terms and the post’s results.
  • The BOOMIN team sees applications and, when needed for support, your account and deals.
  • Nobody on BOOMIN sees your email address but us.

Services that process it

These providers help run BOOMIN. Each receives only what its job needs and may not use it for anything else.

  • Google Cloud and Firebase — sign-in and our database, stored in Frankfurt, Germany.
  • Google Vertex AI (Gemini) — reads a brand’s public webpage, a creator’s recent posts and an uploaded screenshot.
  • KIE — a fallback for the same readings when Vertex AI can’t answer.
  • TypeSafe — scores how well a brand and a creator fit, from the brand’s profile and creators’ public profiles. No email addresses.
  • TwitterAPI.io — reads public X data.
  • Resend — sends our emails.
  • unavatar.io — serves creators’ X profile pictures, which your browser loads from it.

Our application runs on our own server. Some of these providers are in the United States; where data leaves the EU, it is covered by their standard contractual clauses or an adequacy decision.

Cookies and your browser

We set one sign-in cookie that keeps you signed in, and short-lived cookies while you sign in. Your browser also keeps a few small notes of its own: the email address a sign-in link was sent to, the handle you typed when joining, and a tab or filter you last used. Nothing in them tracks you, and there are no advertising cookies.

How long we keep it

  • Your data stays while your account is open.
  • Sign-in records and codes expire on their own, within days.
  • A screenshot is read and then discarded; only the shares it showed are kept with your profile.
  • When you ask us to delete your account, we delete your data within 30 days, except what we must keep by law or to settle a dispute, and copies in backups, which expire on their own.

How we protect it

Everything travels over HTTPS. Sign-in tokens are stored hashed, as are IP addresses. Access to the database is limited to the service and to the people who run it. No system is perfectly secure; if something goes wrong with your data, we tell you and, where required, the authorities.

Your rights

You can ask us to show, correct, export or delete your data, or to stop using it in a certain way, at any time: write to hi@boomin.app. We answer within a month.

If you are in the EU or the UK, the GDPR gives you these rights and the right to complain to your data protection authority. Wherever you are, the same email reaches us.

Age

BOOMIN is for people aged 18 and over. We don’t knowingly collect data from anyone younger; if we learn we have, we delete it.

Changes to this policy

When we change this policy in a way that matters, we tell you by email or in the app before the change applies. The current version is always at boomin.app/privacy.

Questions about this? Write to hi@boomin.app.

Terms of Use · boomin.app