This Privacy Policy explains how the BrandPlay browser extension ("BrandPlay", "the extension", "we", "us") handles information. BrandPlay is published by BrandPlay.id (published at https://brandplay.id/extension/privacy) and is used together with KOL Portal at https://vibe.brandplay.id to help teams review KOL (Key Opinion Leader) prospects.
BrandPlay is local-first: it captures and calculates creator analytics inside your browser and only transmits data to KOL Portal for the specific actions described below. The extension runs no advertising, sends no analytics telemetry, and does not sell data.
1. Who this policy applies to
This policy applies to users who install and use the BrandPlay Chrome extension as part of the BrandPlay.id / KOL Portal workflow. Use of KOL Portal itself (the web application at vibe.brandplay.id) is additionally governed by BrandPlay.id's main service terms and privacy notice.
2. What data BrandPlay accesses and collects
| Data type | Accessed | Sent off your device? | Purpose |
|---|---|---|---|
| Public creator profile data (handle, display name, avatar URL, bio, profile/website URL) | Yes, from the Instagram/TikTok page you are viewing | Only when you click Save as Prospect, or during a duplicate check (handle + platform only) | Build the prospect review payload you choose to send to KOL Portal |
| Public post metrics (views, likes, comments, shares, saves, captions, post/media cover URLs, pinned and sponsored signals) | Yes, from the page you are viewing | Only when you click Save as Prospect | Engagement analysis and prospect review |
| KOL Portal authentication cookies (better-auth session cookie for the configured portal origin) | Yes | Yes — sent only to KOL Portal endpoints | Confirm you are logged in and authorized before enabling import |
| Local UI settings (aggregation mode, include-pinned, include-sponsored, Posts To Capture) | Yes | No — stored locally only | Remember your HUD preferences |
| Browsing history | No | No | Not collected. BrandPlay only runs on Instagram and TikTok creator pages |
| Analytics / telemetry about you | No | No | BrandPlay sends no usage telemetry of any kind |
BrandPlay only reads data that is already visible on the public Instagram or TikTok creator page you are actively viewing. It does not access private accounts' protected data beyond what the platform itself renders to your logged-in browser session, and it does not crawl or background-scrape other pages.
3. How and where data is sent
Data leaves your device only in these cases, and only to KOL Portal (https://vibe.brandplay.id, or the portal origin configured in your build):
- Session validation —
GET /api/extension/session: your KOL Portal session cookie is forwarded so the portal can confirm you are logged in and authorized to use the extension. - Duplicate check —
POST /api/prospect-import/check: the visible creator's platform and handle are sent so the portal can tell you whether that creator already exists, before you spend effort importing. - Save as Prospect —
POST /api/prospect-import: triggered only by your explicit click. The captured creator profile and post metrics are sent to KOL Portal, which returns a review link that opens in a new tab. No database change is made automatically — you review the payload inside KOL Portal.
No data is sent to any third party, advertising network, data broker, or analytics provider.
4. Permissions and why they are needed
| Permission | Why BrandPlay needs it |
|---|---|
cookies |
Read the KOL Portal session cookie for the configured portal origin to confirm you are logged in. |
storage |
Save your local HUD settings (aggregation mode, pinned/sponsored toggles, Posts To Capture). |
scripting |
Inject BrandPlay's own bundled, local interceptor scripts into Instagram/TikTok pages to read the metrics shown on the creator page. No remote code is loaded or executed. |
tabs |
Open the KOL Portal import review tab and support the messaging required by the Save as Prospect flow. |
Host access to instagram.com and tiktok.com |
Run the content script and local interceptor on creator pages to capture the metrics you see. |
Host access to vibe.brandplay.id |
Validate your session, run duplicate checks, and open the import review page. |
5. Data storage and retention
- On your device: Only UI settings are stored, in Chrome's local extension storage (
chrome.storage.local). They never leave your browser. - Captured creator data: Held only transiently in memory while you view a creator page. It is not persisted by the extension and is discarded when you navigate away or close the tab — unless you click Save as Prospect, in which case it is sent to KOL Portal as described above.
- On KOL Portal: Any prospect you save is retained by KOL Portal under BrandPlay.id's service data practices.
6. Data sharing and sale
- BrandPlay does not sell your data or any captured data.
- BrandPlay does not use data for advertising, retargeting, or creditworthiness/lending purposes.
- BrandPlay does not run third-party analytics or send telemetry.
- Captured data is shared only with KOL Portal (BrandPlay.id) to provide the prospect review workflow you initiate.
7. Your choices and controls
- Duplicate checks and saving are tied to your actions; the extension does not auto-submit prospects.
- Remove local settings: uninstall the extension, or clear extension storage via
chrome://extensions. - Stop all data transmission: log out of KOL Portal, disable, or uninstall the extension.
- Portal data: to access or delete prospect data already stored in KOL Portal, contact us at the address below.
8. Children
BrandPlay is a professional tool intended for business users and is not directed to children under 13. We do not knowingly collect data from children.
9. Changes to this policy
We may update this policy as the extension evolves. Material changes will be reflected by updating the "Last updated" date above and the published version at https://brandplay.id/extension/privacy.
10. Contact
Questions or requests regarding this policy or your data:
BrandPlay.id — ceo.herbabumi@gmail.com