Privacy Policy · Effective September 5, 2026
Privacy Policy
This policy explains what WITNESS collects when you use witnessstandard.com, the WITNESS application at chat.witnessstandard.com, and the WITNESS API (together, the “Service”), why WITNESS collects it, how long it is kept, and the choices you have. WITNESS is operated by Witness, Lewisville, Texas, United States (“WITNESS”, “we”, “us”).
1
Who WITNESS is for and the principle behind this policy
WITNESS is an evidence-backed creator intelligence service. A creator, artist, or ministry connects the platforms where their work is published, and WITNESS observes those sources, reconciles what they report, explains what changed, and executes only actions the creator has authorized. The creator is the protected principal. WITNESS does not sell personal data, does not build advertising profiles, and does not use connected data to train models. Our design principles are described in plain language at Privacy & Creator Control; this page is the binding policy.
2
Information we collect
Information you give us
- Account information. Your email address and the authentication identifiers issued when you sign in. Sign-in is handled through our authentication provider (see Section 6); WITNESS never sees or stores your password.
- Workspace content. Questions you ask WITNESS, findings you save, watches you set, approvals you grant or deny, and files or exports you choose to upload.
- Billing information. If you purchase a plan, our payment processor collects payment details. WITNESS receives only a customer reference, plan, and payment status — never full card numbers.
- Support correspondence. Messages you send us.
Information from platforms you connect
When you authorize a provider connection, WITNESS receives only the data covered by the permissions you grant, and only for as long as the authorization remains valid. Depending on the provider this includes:
- TikTok (via TikTok Login Kit and the Display API, scopes
user.info.basic,user.info.stats,video.list): your open ID, display name, avatar, profile counts (followers, following, likes, video count) and the public metadata and counters of your own videos (title, cover, view, like, comment and share counts). WITNESS does not receive your TikTok password, private messages, drafts, or the data of other TikTok users. - Spotify, Apple Music, YouTube and similar platforms: artist profile identifiers and the audience, streaming, and catalog metrics those platforms expose for your own account or your public artist pages.
- Distributors, publishers and royalty portals (for example UnitedMasters or a performing rights organization) when you connect them: statements, per-track earnings, and usage reports for your own catalog.
Provider access tokens and, where you explicitly choose to hold a browser session with WITNESS, the session cookies for that provider are stored encrypted (AES-256-GCM) and are used solely to fetch your data on your behalf on the schedule you approved. They are never shown to WITNESS staff, never shared, and are deleted when you disconnect.
Public information
WITNESS also records publicly published figures about your own work (for example the monthly-listener count on a public Spotify artist page or the public view count of a YouTube channel) so that it can compare public signals with what your connected platforms report. WITNESS does not collect public data about other people’s accounts on your behalf.
Information collected automatically
- Service logs. Request identifiers, timestamps, HTTP status codes, the API route called, and error classes. Logs are used for security, reliability, and abuse prevention. We do not use third-party advertising or analytics trackers on the Service.
- Evidence receipts. For every observation WITNESS makes, it retains a receipt (what was fetched, when, from where, and a content hash) and, for authenticated pages, a copy of the page body so that every figure WITNESS reports can be traced back to its source. These records belong to your workspace.
3
How we use information
- To operate the Service: observe your connected sources, reconcile conflicting reports, explain changes, and surface findings to you.
- To execute actions you have explicitly approved, and to record the outcome of those actions so WITNESS can learn what worked for you.
- To authenticate you, secure the Service, prevent abuse, and debug faults.
- To bill you for a paid plan and send transactional messages about your account (for example, a provider session that needs to be re-authorized).
- To comply with law and enforce our Terms of Service.
WITNESS does not use your data for advertising, does not sell or rent it, does not share it with data brokers, and does not use connected platform data or your workspace content to train machine-learning models. Where WITNESS uses an AI model to draft an explanation, the model receives only the evidence needed for that explanation and its output is labelled as model output, kept distinct from source evidence.
4
Platform data terms
Data received from TikTok is used only to provide the features you requested inside WITNESS, is not used to build or augment user profiles, is not transferred to any third party except the infrastructure processors in Section 6, and is deleted or refreshed in accordance with TikTok’s Developer Terms of Service and platform policies. Data received from other platforms is handled in accordance with that platform’s developer terms. If a platform requires deletion of its data when you disconnect, WITNESS performs that deletion.
5
Legal bases (EEA, UK, and similar jurisdictions)
We process account and connected data to perform our contract with you; service logs and security records under our legitimate interest in keeping the Service safe and reliable; billing records to meet legal obligations; and any optional processing (such as holding a browser session) on the basis of your consent, which you may withdraw at any time by disconnecting.
6
Who processes data on our behalf
WITNESS runs on a small set of infrastructure providers, each bound by a data-processing agreement and used only to deliver the Service:
- Cloudflare, Inc. — application hosting (Workers), databases (D1), object storage for evidence receipts (R2), browser rendering for pages you authorized WITNESS to observe, and AI inference (Workers AI). Cloudflare also provides our network security and TLS.
- Supabase, Inc. — sign-in and session management, and the encrypted vault that stores provider credentials.
- Polar Software, Inc. — subscription billing and payment processing.
- The platforms you connect (TikTok, Spotify, Apple, Google, UnitedMasters, and others) receive the API calls WITNESS makes on your behalf using the authorization you granted.
We may also disclose information if required by law, to protect the rights and safety of WITNESS or others, or as part of a merger or acquisition (in which case this policy continues to apply to your data until you are told otherwise).
7
Retention
- Account data: for the life of your account and up to 30 days after deletion.
- Provider tokens and held sessions: until you disconnect, the provider revokes them, or they expire — whichever comes first. Revoked material is deleted immediately.
- Observations, findings, and evidence receipts: for the life of your workspace, because their value is the ability to trace a claim back to its source. You can delete your workspace at any time.
- Service logs: 30 days, unless retained longer for an active security investigation.
- Billing records: as long as tax and accounting law requires.
8
Your choices and rights
- Disconnect a platform at any time from Connections inside WITNESS. Disconnecting revokes WITNESS’s authorization, deletes the stored token or held session, and stops further observation of that source. You can also revoke WITNESS from the platform’s own settings (for example, TikTok → Settings and privacy → Security → Manage app permissions).
- Export your findings, observations, and receipts from Records inside WITNESS.
- Delete your account from Settings, or by emailing us. Deletion removes your account, workspace content, connected-platform data, provider credentials, and evidence receipts within 30 days, except for records we must keep by law.
- Access, correct, restrict, object, or port your data by contacting us. We will respond within 30 days. You may also lodge a complaint with your local data-protection authority.
WITNESS does not sell personal information and does not engage in “sharing” for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act.
9
Security
All traffic is encrypted in transit (TLS 1.2 or later, HSTS). Provider credentials and held sessions are encrypted at rest with keys held separately from the data they protect. Access is scoped per workspace and fails closed: an authority WITNESS cannot verify is treated as no authority. WITNESS never escalates its own permissions and never signs in as you — if a provider session expires, WITNESS stops, records the boundary, and asks you to re-authorize.
10
Children
The Service is not directed to anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
11
International transfers
WITNESS is operated from the United States and our processors may store data in the United States or other countries. Where required, transfers rely on standard contractual clauses or equivalent safeguards.
12
Changes to this policy
When we change this policy we will update the effective date above and, for material changes, notify you inside the Service or by email before the change takes effect. Prior versions are available on request.
13
Contact
Witness · Lewisville, Texas, United States
Privacy and data requests: support@witnessstandard.com