Last updated: 11 July 2026
CAD (“Creator Analytics Dashboard”, “we”, “us”) is an invite-only analytics and content management platform for social media creator teams, available at https://getcad.app. This policy explains what information we collect, how we use it, and the choices you have. Questions about this policy or your data can be sent to info@getcad.app.
We use only essential cookies: a session cookie to keep you signed in and a CSRF token to protect forms. We do not use advertising or cross-site tracking cookies.
A workspace administrator may connect a Google account so that CAD can work with Google Drive. When you connect Google Drive, CAD accesses it strictly to provide user-facing features you initiate:
We store the OAuth tokens Google issues (encrypted at rest) and the file metadata needed for these features (file IDs, names, sizes). We do not use Google user data for advertising, we do not sell it, and no humans read it except with your explicit permission for support, for security purposes, or where required by law.
CAD’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect Google Drive at any time from Settings inside CAD, or revoke CAD’s access from your Google account permissions page. Disconnecting deletes the stored tokens.
We do not sell personal information and we do not use it for advertising.
We rely on a small number of infrastructure providers to run the service: cloud hosting for the application and database, Cloudflare (media storage and optional bot protection on the login form), Resend (transactional email), social media data providers used to retrieve public profile and post information, and optional integrations a workspace may enable (such as GetMySocial link analytics or Telegram notifications). Each provider receives only the data needed to perform its function.
We keep your information while your account is active. Media files are subject to workspace retention settings and may be deleted automatically. When an account or workspace is deleted, or on request to the contact address above, we delete the associated personal data within 30 days, except where a legal obligation requires longer retention.
All traffic is encrypted in transit (HTTPS). Passwords are hashed, and sensitive credentials such as OAuth tokens and API keys are encrypted at rest. Access to production systems is restricted to the operator.
Depending on where you live (including under UK and EU GDPR), you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Contact us at the address above and we will respond within a reasonable timeframe.
If we make material changes we will update this page and revise the “last updated” date. Continued use of the service after changes take effect constitutes acceptance of the revised policy.