API Privacy Addendum
Last updated: September 16, 2026
Shinra Metrics is the product name of the SaaS service operated by Ciberdime GmbH. In this document, “Ciberdime GmbH”, “we”, “us”, and “our” refer to the legal entity operating Shinra Metrics; “Shinra Metrics” refers to the product or service.
1. How this policy fits
This API Privacy Addendum supplements our Privacy Policy (GDPR Notice). It focuses on data received through social platform APIs, including Meta / Instagram / Facebook / Threads, Google / YouTube, TikTok, Twitch, Kick, X, LinkedIn, Pinterest and Bluesky. If a topic is not covered here, the main Privacy Policy applies. If this addendum and the main Privacy Policy conflict for platform API data, this addendum controls for that API data.
2. API data we access
- Account identifiers, profile information, connected pages or channels, scopes, permissions and revocable access tokens.
- Social content and metadata such as posts, videos, livestream metadata, captions, thumbnails, URLs, comments, engagement metrics, impressions, reach, demographics and analytics made available by the relevant platform. Audience demographics are processed only in aggregated form where the platform provides them and are not used to identify individual audience members.
- Platform-specific content: X posts you own with public and, where entitled, non-public metrics and recent replies; Bluesky public posts, engagement and reply threads; LinkedIn member profile and administered Page analytics plus known posts and their statistics; Threads posts, insights, follower demographics and replies; Pinterest boards, Pins, analytics and business audience insights.
- Copies of post images, thumbnails and videos kept with campaign reports so that they stay verifiable, text extracted from images (OCR) and video transcripts used for campaign mention detection.
- Campaign-related outputs such as tracked content, livestream mentions, transcripts, AI-assisted clip evaluations, review status and reports when those features are enabled.
3. How we use API data
- To authenticate accounts and provide dashboards and reports.
- To track campaign deliverables, links, livestream mentions, clips and creator-approved media.
- To let creators approve, remove or revoke access to shared campaign data.
- To monitor security, troubleshoot errors, maintain API reliability and improve product functionality using service diagnostics and aggregated usage patterns. We do not use platform API data to train general-purpose AI models or to build advertising profiles.
We do not sell API data and do not use Google, YouTube, TikTok, Meta, Twitch, Kick, X, LinkedIn, Pinterest or Bluesky user data for advertising, for targeting advertising or for building audiences outside the service. We do not combine a person's platform data with data from other services except as needed to provide the requested features, and we do not associate X accounts with other identities without express consent.
The legal bases are described in section 3 of our main Privacy Policy. In short, we process API data to perform the requested service (Art. 6(1)(b) GDPR), based on creator or platform authorization where applicable (Art. 6(1)(a) GDPR), for security, fraud prevention, diagnostics and limited B2B communications (Art. 6(1)(f) GDPR), and where needed for legal obligations (Art. 6(1)(c) GDPR).
4. Sharing API data
We share API data only as needed to provide the service: with a team or campaign when a creator authorizes access, with service providers listed on our sub-processors page, with the relevant platform provider, or where required by law. Platform-specific restrictions on recipients and uses apply to all such disclosures, including workspace access and processing by service providers. Listing a recipient here does not authorize a transfer prohibited by a platform. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. Platform-specific notices
- YouTube / Google: Features that rely on YouTube API Services are subject to the YouTube Terms of Service and the Google Privacy Policy. You can revoke Shinra Metrics access via Google security settings.
- Meta / Instagram / Facebook:Facebook Login and Graph API access can be revoked in Facebook settings. We also expose Meta's data deletion callback at https://www.shinra-metrics.com/api/meta/data-deletion and a deletion status page at https://www.shinra-metrics.com/data-deletion-status. Meta receives a status URL with a confirmation code when a platform-required deletion request is processed.
- TikTok:TikTok API access is used only for the features you request, such as creator analytics, campaign tracking and content metadata. You can revoke app access in TikTok's app permission settings. TikTok's own processing is described in the TikTok Privacy Policy. For TikTok-specific deletion requests, disconnect the TikTok account in Shinra Metrics or contact us at info@ciberdime.com; we will revoke stored tokens and delete or anonymize related account-level data according to this addendum and the main Privacy Policy.
- Twitch: Twitch API access is used for requested Twitch features such as livestream tracking, channel analytics, campaign mentions and clips. You can disconnect Shinra Metrics in Twitch connection settings. Twitch's own processing is described in the Twitch Privacy Notice.
- Meta / Threads:Threads API access is subject to the Meta Platform Terms and used only for your own Threads posts, insights, follower demographics and replies. You can revoke access in the Threads app under Settings, Account, Website permissions; removing the app triggers Meta's data deletion callback listed above, and the status page shows the result.
- X: X API access is used only for posts you own, their metrics and recent replies, with the scopes tweet.read, users.read and offline.access. X requires stored content to be updated or removed to reflect deletions, edits and changes in availability on X, including protected, suspended or withheld content. Changes must be addressed as soon as reasonably possible; requests from X or the account owner must be acted on within 24 hours. Campaign reporting does not create an exception. Automated checks during beta do not yet cover every availability change or content from disconnected accounts. Disconnecting stops these checks and does not automatically erase stored content. Send deletion requests to info@ciberdime.com.We never associate an X account with other identities without your express consent. You can revoke access in your X settings under Security and account access, Apps and sessions. X's own processing is described in the X Privacy Policy.
- LinkedIn: LinkedIn API access is used for member profile analytics, analytics of Pages you administer and known posts with their statistics, subject to approved access. Collection, refresh and storage must follow the limits for the relevant data category; this is not authorization to refresh every field on an automated schedule. We do not use this data for advertising. LinkedIn connections are currently disabled. Before activation, the following requirements apply: campaign reports may retain only data that LinkedIn permits us to store for the approved API access, purpose and duration. Media and other content must be removed when no longer needed or when their permitted storage period ends. API-derived metrics and aggregated analytics are not automatically exempt from these limits. On your deletion request or closure of your Shinra Metrics account, LinkedIn API data collected on your behalf, including derived data and tokens, must be deleted immediately unless a legal or governmental obligation prevents deletion. Use in campaign reporting alone does not justify continued retention. Independent contracts, invoices and data you supply separately without obtaining it from the LinkedIn API follow the general retention rules.You can withdraw consent in LinkedIn under Settings, Data privacy, Permitted services. LinkedIn's own processing is described in the LinkedIn Privacy Policy.
- Pinterest:Pinterest API access is used for your own boards, Pins, analytics and, for business accounts, aggregated audience insights. We do not combine this data with other people's account data or use it to target advertising outside Pinterest. Pinterest API data is provided to the account holder. We do not sell this data. Disclosure to other recipients is permitted only where Pinterest allows the recipient and use, or where legally required. The general recipient disclosures and a workspace authorization alone do not extend that permission.You can revoke access in Pinterest under Settings, Security, Connected apps. Pinterest's own processing is described in the Pinterest Privacy Policy.
- Bluesky:Bluesky connections use AT Protocol OAuth; we read your public posts, engagement and reply threads and honour content deletions on the network. You can revoke access in your Bluesky account settings. Reports about content processed through our Bluesky integration can be sent to info@ciberdime.com. Bluesky's own processing is described in the Bluesky Privacy Policy.
- Kick:Kick API access is used for livestream tracking, channel analytics, campaign mentions and chat analysis. We delete Kick data when you revoke or reduce the authorization, on your request, or when our developer agreement with Kick ends. Kick's own processing is described in the Kick Privacy Policy.
6. Retention and deletion
Disconnecting an account stops future API access and revokes or deletes stored tokens. Campaign reporting data may remain only while needed for an authorized report and permitted by the platform. Media and other content are not exempt from deletion merely because a campaign references them. You can request deletion of content collected on your behalf at any time. When you close your account, all connected social accounts are disconnected immediately. The general deletion period is at most 30 days; the platform-specific rules in section 5, including LinkedIn's immediate-deletion requirement and X's content rules and beta limitations, take precedence. Shorter storage periods and stricter platform deletion, use or access restrictions take precedence over the general periods and campaign reporting exceptions. Anonymization or aggregation does not replace required deletion. Independent business records, such as contracts and invoices not obtained through a platform API, may be retained where necessary and lawful for billing, legal obligations or claims. More detailed retention periods for logs, billing records, campaign analytics and website analytics are listed in section 6 of our main Privacy Policy.
7. Contact and rights
To exercise privacy rights or request deletion, contact info@ciberdime.com. More detail on GDPR rights, legal bases, cookies, transfers and security is available in our main Privacy Policy.
8. Updates to this addendum
We update the “Last updated” date when API-related privacy terms change. Material API privacy changes will be communicated through the website, platform or email where appropriate, especially where a platform review or user-facing permission change requires clearer notice.