1. Scope and operator
This policy applies to the CaughtUp Chrome extension, website, and related backend services. CaughtUp is the service name used by its owner and operator. This policy is effective August 10, 2026.
2. Data we receive
| Source | Data | Why it is needed |
|---|---|---|
| Google and Gmail | Google account identity; authorized Gmail message and thread content, metadata, labels, drafts, and attachment information required by the connected workflow. | Authenticate the creator, triage eligible inbox mail, prepare and update reviewable drafts, apply labels, and show the inbox timeline. |
| TikTok Shop Creator | Creator authorization tokens and data returned by app-approved Creator APIs, such as eligible open-collaboration product and commission information. | Connect the creator’s TikTok Shop account separately and retrieve approved opportunity information. This connection is not yet generally available. |
| You | Profile and communication preferences, contact preferences, media kits, matching rules, availability, product interests, draft edits, chat messages, and actions taken in the extension. | Configure CaughtUp, personalize bounded assistance, match owned media kits, and remember creator-controlled settings. |
| Service operation | Authentication events, run status, error details, delivery state, and limited diagnostic metadata. | Secure, operate, troubleshoot, and improve reliability. |
3. How we use data
We use data only to provide, secure, maintain, and improve the CaughtUp features a user chooses to use. This includes classification, draft preparation, media-kit selection, inbox display, negotiation visibility, account connection, and eligible opportunity matching.
CaughtUp does not sell personal data. CaughtUp does not use connected Gmail or TikTok Shop data for targeted advertising. Product recommendations do not guarantee acceptance, sales, commissions, or earnings.
4. Infrastructure and service providers
CaughtUp uses Supabase Edge Functions, Postgres, private Storage, authentication services, and Vault-backed configuration for its backend. For bounded email classification and drafting tasks, relevant content may be sent to the configured language-model provider. That provider is used as a processor for the requested task, not as an independent advertising service.
Google and TikTok process data under their own terms and privacy policies when you authorize their services.
5. Tokens and security
OAuth credentials and sensitive integration configuration are kept server-side under the established encrypted secret-storage design. The extension does not persist TikTok or Gmail refresh tokens in browser storage. Access to CaughtUp data is scoped to the owning account, and service-only database tables use row-level security.
No online service can promise absolute security. We use reasonable technical and organizational safeguards and review access boundaries as the product changes.
6. Retention and deletion
Account settings, media kits, processed-email records, drafts and edits, chat or style history, connection records, and related product data are retained while the account remains active and as needed to provide the service. Operational logs may be retained for security, troubleshooting, and reliability. We do not keep personal data longer than reasonably necessary for those purposes.
When an account is disconnected, CaughtUp stops using that connection for new work. Revoking access at Google or TikTok does not by itself delete records already stored by CaughtUp. A user may request deletion of the account and stored CaughtUp data. After a verified deletion request is completed, data is removed from active systems except where limited retention is reasonably necessary for security, legal compliance, fraud prevention, or backup recovery cycles.
7. Your choices and rights
Depending on location, users may have rights to access, correct, export, restrict, object to, or delete personal data. Users can revoke Google access through their Google Account, disconnect supported connections in CaughtUp, and request deletion of CaughtUp-held data.
8. Children
CaughtUp is intended for creators who are legally able to authorize business-account connections and enter contracts. It is not directed to children under 13.
9. Changes
We may update this policy as the product and its integrations change. The published policy will identify its effective date, and material changes will be communicated through an appropriate product or account notice.
10. Contact
Privacy and deletion requests: support@getcaughtup.io.