Privacy Policy
1. Summary
- Rolifin shows content creators their social media statistics in one dashboard. We collect only what is needed to do that.
- You choose which platforms to connect. We get read-only access, and we can never post, message or change anything on your accounts.
- We do not sell your data, and we do not use it for advertising.
- You can disconnect a platform at any time. Its data is deleted straight away.
- We use one essential sign-in cookie and no advertising or analytics trackers.
2. Who we are
Rolifin (“Rolifin”, “we”, “us”) is operated by RolIfIn, Baneshwor, Kathmandu. This policy explains how we handle personal information when you use the Rolifin website and apps at https://www.rolifin.com (the “Service”).
Questions or requests about your data: suraj.rolifin@gmail.com.
3. Information we collect
Information you give us
- Account details: your name, email address and password. We store only a salted, one-way hash of your password (scrypt), never the password itself.
- Creator profile (optional): your handle, city and content category.
- Messages you send us, for example support or privacy requests.
Information from platforms you connect
When you connect a platform, you sign in on that platform's own page and approve read-only access. Rolifin never sees your platform password. Depending on the platform, we receive:
| Platform | What we read |
|---|---|
| YouTube (Google) | Channel name, handle, picture and subscriber count; your recent videos and Shorts with their views, likes and comments; daily channel analytics (views, likes, comments, shares, watch time, subscribers gained and lost); estimated revenue if your channel is monetised. |
| The list of Pages you manage, directly or through your Meta Business portfolio (we read only which Pages it holds, not other business assets), so you can pick one; for the Page you choose: name, picture, follower count, daily follows and unfollows, daily content views and viewers, recent posts and reels with reactions, comments, shares, plays and views, Page stories, and estimated content-monetization earnings if the Page is monetised. | |
| Your professional account's username, name, picture, follower, following and post counts; daily reach; recent posts and reels with likes, comments, views, reach, saves and shares; currently live stories with views, reach, replies and shares. | |
| TikTok | Display name, username, avatar, follower, following, like and video counts; your recent public videos with their views, likes, comments and shares. |
We also receive the access tokens that let us fetch these statistics. We store them encrypted (AES-256-GCM).
We do not read your private messages, your followers' personal profiles, or the content of anything you haven't published. We do not post on your behalf.
Information collected automatically
- Sign-in session: an essential cookie (
rolifin_session) that keeps you signed in. It is httpOnly, and on our servers we store only a hash of it, together with the IP address and browser type used to sign in. - Security log: sign-ins, failed sign-in attempts, account creation, platform connections and administrator actions, with the IP address involved. We use it to protect accounts and investigate abuse.
- Preferences on your device: display choices such as theme and currency are saved in your browser's local storage. They are not sent to us.
We do not use advertising cookies, cross-site tracking or third-party analytics.
4. How we use information
- To create and secure your account and keep you signed in.
- To show you your statistics, for one platform at a time or combined, including trends, top content, stories and revenue.
- To refresh your statistics automatically (about every six hours) and to renew platform access tokens before they expire.
- For Rolifin administrators to support creators, check that connections are working, and review aggregate statistics across the Service.
- To detect and prevent fraud, abuse and security incidents, and to meet legal obligations.
We do not use your data to train AI models, build advertising profiles, or make automated decisions that have legal or similarly significant effects on you.
6. Platform-specific terms
YouTube and Google
Rolifin uses YouTube API Services. By connecting YouTube you also agree to the YouTube Terms of Service, and Google's handling of your data is described in the Google Privacy Policy. You can remove Rolifin's access at any time from your Google Account connections page, or by disconnecting in Rolifin.
Rolifin's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. While YouTube stays connected, we refresh your data from YouTube about every six hours. If you revoke Rolifin's access in your Google Account, we can no longer refresh it, and all data we obtained through YouTube API Services is deleted within 30 days. Disconnecting in Rolifin deletes it immediately.
Facebook and Instagram (Meta)
Data from Facebook and Instagram is handled under the Meta Platform Terms. You can remove Rolifin under Facebook Settings › Apps and websites or Instagram Settings › Apps and websites. When you do, Meta notifies us and we revoke the connection automatically. See Deleting your data for data-deletion requests.
TikTok
Data from TikTok is handled under the TikTok Terms of Service. You can remove Rolifin's access from TikTok's Settings and privacy › Security › Manage app permissions, or by disconnecting in Rolifin.
7. How we protect information
- All traffic to the Service is encrypted in transit (HTTPS).
- Platform access tokens are encrypted at rest (AES-256-GCM). Passwords are stored only as salted scrypt hashes, and session tokens only as SHA-256 hashes.
- Access is role-based: creators see only their own data, and administrator access is separate and logged.
- Sign-in attempts are rate-limited to slow down password guessing.
No system is perfectly secure. If a breach affects your personal information, we will notify you and the relevant authorities as required by law.
8. Retention
| Data | How long we keep it |
|---|---|
| Account and profile | While your account is open. Deleted within 30 days of a verified deletion request. |
| Connected-platform statistics and tokens | While the platform stays connected. Deleted immediately when you disconnect it, or when the platform tells us you removed Rolifin and asked for deletion. If our access stops working (for example, you revoked it on the platform), the data is deleted automatically after 30 days. |
| Sign-in sessions | Up to 7 days, or until you sign out. Expired sessions are deleted daily. |
| Security log | 12 months, then deleted automatically. |
| Backups | Removed from backups as they are replaced on their normal cycle. |
9. Your choices and rights
You can:
- Disconnect any platform in Creator Studio at any time. We revoke our access at the platform where the platform supports it, then delete that platform's data.
- Access or correct your information. Most of it is visible in Creator Studio; for anything else, contact us.
- Delete your account and all associated data by emailing suraj.rolifin@gmail.com from your account's email address.
- Object to or restrict certain uses, or ask for a copy of your data in a portable format.
These rights apply under Nepal's Individual Privacy Act, 2075 (2018) and, where relevant, other data-protection laws such as the GDPR. We respond within 30 days. We may need to verify your identity first.
10. Deleting your data
- One platform: in Creator Studio, open the platform's card and click Disconnect. Its statistics and tokens are deleted immediately.
- Through Facebook or Instagram: remove Rolifin under Settings › Apps and websites and choose to delete the data. We delete it automatically and give you a confirmation code with a status page you can check.
- Your whole account: email suraj.rolifin@gmail.com from your account's email address with the subject “Delete my account”. We delete your account, profile, all connected-platform data and tokens within 30 days, and confirm by email.
11. Children
The Service is intended for people aged 18 and over. We do not knowingly collect information from anyone under 18. If you believe a child has created an account, contact us and we will delete it.
12. International transfers
Our servers and service providers may be located outside Nepal. Wherever your data is processed, we protect it as described in this policy and as required by applicable law.
13. Changes to this policy
We will post any changes on this page and update the effective date. If a change materially affects how we use data you have already shared, we will tell you in Creator Studio or by email before it takes effect.
14. Contact us
RolIfIn
Baneshwor, Kathmandu
Email: suraj.rolifin@gmail.com