Privacy Policy

Last updated: May 13, 2026

1. About This App

MVP Affiliate ("the App", "we", "us") is a SaaS tool used by individual content creators (bloggers, YouTubers, affiliate marketers) to generate, publish, and distribute product review content to their own websites and social accounts. The App is operated by Gominplanet Holdings Ltd, an exempted company incorporated in Anguilla, British West Indies under the Business Companies Act, 2022 (company no. A000003427), registered office: The Hansa Bank Building, 1st Floor, PO Box 886, Landsome Road, The Valley, AI-2640, Anguilla, BWI (us@gominplanet.com).

2. Data We Collect From You

  • Account email address and name (provided at signup)
  • Brand profile information you enter (brand name, bio, logo, social URLs, contact email)
  • YouTube channel ID (provided by you)
  • WordPress site URL and Application Password (provided by you, stored encrypted)
  • Generated blog content and publishing history
  • Analytics on content the App has produced for you (post counts, publishing dates)

3. Pinterest Data

When you connect your Pinterest business account to MVP Affiliate, we use Pinterest's OAuth flow and request the minimum scopes needed for the features you use. Specifically:

  • boards:read — to list the boards on your own Pinterest account so you can choose where new Pins are saved.
  • boards:write — to create a new board on your behalf, only when you explicitly request one inside the App.
  • pins:read — to retrieve metrics (impressions, saves, outbound clicks) for Pins the App has helped you publish, shown back to you inside the App.
  • pins:write — to create new Pins linking to review articles you have published through MVP Affiliate. Pins are only created when you explicitly click a publish action; no Pin is ever created in the background.
  • user_accounts:read — to identify which Pinterest account you have connected so the App can display "Connected as @yourhandle" in the settings UI.

We do not:

  • Sell, rent, share, or transfer your Pinterest data to any third party.
  • Use your Pinterest data for advertising or to train AI models.
  • Read, follow, save, or interact with content on Pinterest accounts other than your own.
  • Bulk-create, automate engagement on, or schedule Pins outside of explicit user actions.
  • Store your Pinterest password — we use OAuth tokens only, encrypted at rest.

Pinterest access tokens are stored encrypted in our database. You can disconnect Pinterest at any time from the Settings page in the App, which immediately revokes and deletes the stored token. You can also revoke MVP Affiliate's access directly from your Pinterest account settings under "Apps".

4. Facebook Data

If you connect a Facebook Page, we request only the scopes needed to list your Pages (pages_show_list) and publish a post when you explicitly click the "Post to Facebook" button (pages_manage_posts). We do not post in the background, do not read personal profile data, and do not use Facebook data for advertising. You can disconnect at any time from the Settings page; we delete the stored access token on disconnection.

5. Google / YouTube Data

If you connect your YouTube channel, MVP Affiliate uses YouTube API Services. We request only the scopes needed to read your own channel and videos and, only when you explicitly click an action (such as "Apply" or "Save as draft"), to update the title, description, tags, thumbnail, privacy or schedule on your own videos:

  • https://www.googleapis.com/auth/youtube — read your channel/videos and update your own video metadata, thumbnail, privacy and schedule.
  • https://www.googleapis.com/auth/youtube.force-ssl — perform those same read/update operations over a secure connection, as required by the YouTube Data API.

We never access channels other than the authenticated user's own, never post or change anything in the background, and never use YouTube data for advertising or to train AI/ML models. You can revoke access at any time from the App's Settings page (we delete the stored tokens on disconnection) and via your Google Account at myaccount.google.com/permissions.

MVP Affiliate's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Your use of YouTube features is also subject to the YouTube Terms of Service and the Google Privacy Policy.

6. TikTok Data

When you connect your TikTok account to MVP Affiliate, we use TikTok's OAuth flow and request the minimum scopes needed for the features you use. Specifically:

  • user.info.basic — to identify which TikTok account you have connected and display "Connected as @yourhandle" in the App's Settings page. Provides open_id, display name and avatar only.
  • user.info.profile — to display your TikTok profile link, bio, and verified status in the App's Settings page.
  • video.upload — to upload a video to your authorized TikTok account as a draft for you to finalize from the TikTok app, only when you explicitly click a publish action in MVP Affiliate.
  • video.publish — to publish a video directly to your authorized TikTok feed, only when you explicitly click a publish action in MVP Affiliate. The caption, privacy setting, and audience are chosen by you inside MVP Affiliate before the request is sent.

We do not:

  • Sell, rent, share, or transfer your TikTok data to any third party.
  • Use your TikTok data for advertising or to train AI/ML models.
  • Read, follow, like, comment on, or interact with TikTok content from accounts other than your own.
  • Post, schedule, or bulk-create content on your TikTok account outside of explicit user actions.
  • Store your TikTok password — we use OAuth tokens only, encrypted at rest.

TikTok access tokens are stored encrypted in our database. You can disconnect TikTok at any time from the Settings page in the App, which immediately deletes the stored token. You can also revoke MVP Affiliate's access directly from your TikTok account settings under "Manage app permissions". Your use of TikTok features is also subject to the TikTok Terms of Service and the TikTok Privacy Policy.

7. How We Use Your Data

  • To generate blog posts from your inputs (product URLs, YouTube videos, etc.)
  • To publish posts to your WordPress site
  • To create Pins or social posts on platforms you have explicitly connected, only when you trigger a publish action
  • To display your content history and analytics inside the App
  • To send transactional account emails (login confirmations, billing receipts)

We never publish anything on your behalf without a direct, explicit user action. There is no background scheduling, no automated bulk distribution, and no "set and forget" posting.

8. Data Storage and Security

Account data, content, and integration credentials are stored in Supabase (PostgreSQL) on servers in the United States. OAuth access tokens and other secrets are stored encrypted at rest. Access to production data is restricted to authorized personnel and protected by multi-factor authentication.

9. Data Retention and Deletion

We retain your data for as long as your account is active. To delete your account and all associated data, email us@gominplanet.com from the address registered to the account. We will delete your account and all associated data within 30 days of receiving the request, including any Pinterest, Facebook, and other third-party tokens we hold for you.

10. Third-Party Services

MVP Affiliate integrates with the following services on your behalf:

  • Pinterest (Pin creation and analytics — only the connected business account)
  • Facebook / Meta (Page posting — only Pages you authorize)
  • TikTok (video posting — only the connected account, only on explicit user action)
  • YouTube Data API (channel and video data)
  • WordPress REST API (publishing to your own self-hosted WordPress site)
  • Large-language-model providers used to power our AI agent pipeline (content generation)
  • Supabase (data storage)
  • Stripe (billing and subscription management)
  • Vercel (web hosting)

Each service's own privacy policy governs their handling of your data.

11. Children

MVP Affiliate is not directed to anyone under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

12. Browser Extension (CC Scout)

The optional "MVP Affiliate — CC Scout" Chrome extension has a single purpose: to help you find Amazon Creator Connections campaigns and queue the ones you choose into your own MVP Affiliate account. It is not required to use MVP Affiliate.

What it accesses, and only when you open it on the relevant page:

  • It reads campaign listing data (product ASINs, commission/EPC, budget, available slots) from the Amazon Creator Connections page you are already viewing in your own logged-in Amazon session. It runs only on affiliate-program.amazon.com and amazon.com/creatorconnections pages, plus mvpaffiliate.io.
  • It stores a single MVP Affiliate link token locally in your browser (chrome.storage) so the extension can attach campaigns to your account. The token stays on your device and is only sent to mvpaffiliate.io.
  • When you click to push campaigns, it transmits only the campaign identifiers/metadata you selected to your own MVP Affiliate account.

The extension does not read other tabs, browsing history, your Amazon credentials, or payment data; does not run in the background; does not use analytics or advertising; and does not sell or share data with third parties. Its permissions (activeTab, scripting, storage, and the host permissions above) are the minimum needed for this single purpose. Use of the extension is consistent with the Chrome Web Store User Data policy, including its Limited Use requirements. You can remove the extension at any time from Chrome; doing so deletes its locally stored token.

13. Changes to This Policy

We may update this Privacy Policy. The "Last updated" date at the top reflects the most recent revision. Material changes will be announced via an in-app notice or email.

14. Contact

For privacy questions, deletion requests, or any other concerns, contact us at us@gominplanet.com.