Last updated 9 September 2026.
This policy is for the Instagram creators in India who use Who's Paying, and for anyone who turns up in a report without asking. Data Sources covers every external source we read; Data Removal covers getting your data deleted.
Who we are
Who's Paying is operated by Abscissa AI LLP, a limited liability partnership registered in India.
- LLPIN: ACS-9875
- GSTIN: 07ACMFA2280L1Z5
- Registered address: 130, 3rd Floor, Right Side, Kirti Nagar, New Delhi, West Delhi, Delhi, India – 110015
- Website: creators.ostryaai.com
- Contact: raghav@ostryaai.com
Under the Digital Personal Data Protection Act, 2023 (DPDP), Abscissa AI LLP is the Data Fiduciary for the personal data described here. If you run a scan, you are a Data Principal.
What personal data we collect, and from where
Two very different groups appear in this product, and it matters which one you are.
(a) Data about you — the creator who ran a scan
You can start a scan without an account. A private browser cookie lets you follow that scan and preview its report; it expires after 24 hours. After a short preview, you need to sign in to save and use the report. Signing in attaches only the scans you started or were explicitly given access to. One account can save reports for multiple Instagram handles. Sign-in is run for us by Clerk, our identity provider: you give Clerk an email address, and a password or a Google sign-in. We never see or store your password. From Clerk we hold your user ID and the email address on the account, so we know whose credits, whose unlocks and whose reports are whose.
You never log in to Instagram through us — no Instagram login, no OAuth, no Instagram password.
When you subscribe or buy a credit pack or a top-up, Razorpay takes the payment. Card, bank and UPI mandate details go to Razorpay and never reach us; we store the order and subscription references, which plan or top-up it was, the amount, the state of the recurring mandate, and whether the charge succeeded.
What you actively give us about your creator work is the Instagram handle you type in and, if you build a media kit, what you add to it: an about line, rates, past collabs, contact details (email, WhatsApp number), Insights screenshots, any photos you upload, and any videos or video links you add to your UGC deck.
From the handle we read your public profile and recent public posts through a third-party provider (Monid; an alternate route uses Apify), storing your handle, your public display name, follower count, post count, and per post the shortcode, post type, play, like and comment counts, caption text, tagged brand names, paid-partnership flag and posted-at timestamp.
For a few of your public reels we download the audio and produce a text transcript using one configured provider, Deepgram or Groq, kept as a working artifact. We also record operational data: scan ID, timestamps, job status, error messages, and provider spend and LLM call metadata for cost control.
We do not collect your password, login session, OAuth token, direct messages, private posts, close-friends content, contacts or location.
(b) Data about third parties who appear in public sources
A report also needs data about people who never used Who's Paying.
- Advertisers and their ads from the Meta Ad Library (public, India, active ads) — page names, ad creatives, and the search terms we used.
- Creators named or shown in those ads, because a brand's public ad may feature someone else's handle or face.
- Business contact emails at a brand's company domain, via Hunter.io, for up to five matched brands. This is personal data about someone who works at a brand — a work address, not a personal inbox — shown to you so you can write to them. Who's Paying never emails a brand.
All of it comes from public sources; Data Sources sets out what is read at each step.
Why we process it (purpose limitation)
One purpose: to run the scan you asked for and give you the report — working out your vertical and topics, matching you to brands advertising in that space, showing the evidence for each match, producing an indicative rate card in INR, and drafting pitches you can edit and send yourself. A narrow slice — job status, error logs, provider spend — keeps the service running and stops it overspending.
If you build a media kit, a second purpose: to build it and, only when you publish it, show what you published to anyone you give its link to. Publishing is your choice; unpublishing ends it.
We do not sell personal data, share it with data brokers, or build advertising profiles. We do share limited conversion data with Meta to measure our own Facebook and Instagram ads, as set out in the processor table below and on Cookies.
The basis we rely on
- For your own data: you asked for it. Processing starts when you verify your email and submit a handle for a scan, and that act is your consent. You can withdraw it at any time — see your rights below. Because the verified email does not have to belong to the handle, a handle can still be submitted by someone who does not own it. The Terms of Use forbid that, and anyone whose handle was submitted can have the data deleted and the handle blocked from future scans, unconditionally, through Data Removal.
- For payment records: a completed purchase creates records we are obliged to keep under Indian tax and accounting law, so those are retained on that basis rather than on consent, and survive a withdrawal.
- For third-party data: the source is publicly available information. DPDP section 3(c)(ii) provides that the Act does not apply to personal data a Data Principal has themselves made publicly available, or that is made public under a legal obligation. Meta Ad Library disclosures and public Instagram profiles fall in that category, and that is the basis we rely on. It is not a licence to be careless, so anyone — including people who never touched this product — can ask us to remove their data, with no conditions and no need to explain, through Data Removal.
We are not affiliated with, endorsed by or partnered with Meta Platforms, Instagram, Hunter.io or any brand named in a report, and claim no permission from any of them — see Data Sources.
Data categories, sources, purposes and retention
| Data category | Source | Purpose | Retention |
|---|---|---|---|
| Handle, public display name, follower and post counts | You, then Monid/Apify (public profile) | Identify you; size the rate card | 3 months |
| Post metadata (shortcode, type, plays, likes, comments, posted-at) | Monid/Apify (public posts) | Measure engagement; pick reels | 3 months |
| Captions, tagged brands, paid-partnership flag | Monid/Apify (public posts) | Detect past brand work and your vertical | 3 months |
| Reel audio transcripts | Deepgram or Groq, whichever is configured | Extract topics and evidence | 3 months |
| Advertiser pages, ad creatives, search terms | Meta Ad Library (public, India, active) | Find brands spending in your space | 3 months |
| Business contact email at a brand domain | Hunter.io | Give you a person to pitch (max five) | 3 months |
| Business contact email and LinkedIn profile of a marketing person at a brand | Hunter.io; LinkedIn company pages through Apify, when you unlock a brand with nobody on file | Give you a person to pitch | 3 months |
| Report: matches, evidence, rate card, pitch drafts | Produced by us | Deliver what you asked for | 3 months |
| Media kit draft: your edits (about, rates, collabs, contact), images copied from your public profile and reels | You; Instagram's image servers | Build the media kit you asked for | 3 months after your last edit unless published |
| Published media kit: a frozen copy of what you published, its link, the attestation you gave and when | You | Serve the kit to people you send the link to; show you had the right to publish it | Until you unpublish it or ask us to erase your data |
| Insights screenshots you upload, and the audience numbers read from them | You | Pre-fill your kit's audience section, which you confirm | Screenshots: 90 days from upload. Confirmed numbers: with the kit |
| Photos you upload into a media kit | You | Show them on your kit where you choose; they are copied to a new image, which removes camera and location data | With the kit: until you delete the photo, the kit is deleted, or you ask us to erase your data. Public only while a published kit shows it |
| Videos you upload into a UGC deck | You | Play them on your deck's project slides. Stored as you uploaded them, so any metadata the file carries is kept | With the kit: until you delete the video, the kit is deleted, or you ask us to erase your data. An upload that never finishes is deleted within a day. Playable only while a published kit shows it |
| Video links you add to a UGC deck (Instagram, YouTube, Google Drive) | You | Link to the video from your deck | With the kit. We store the link only, never the video behind it |
| Reports about a published kit: reason, details, and an email if the reporter gives one | The reporter | Review and, where needed, take a kit down | 3 months |
| Account email address and user ID | You, via Clerk | Identify your account; hold your credits and reports | While the account exists, then 3 months |
| Credit balance, each grant and the date it expires, and ledger movements | Produced by us | Meter what you were granted and what you spent, and expire a subscription allowance at the end of its cycle | As long as tax and accounting law requires |
| Activity days: which days you opened the app, and how many pitches you copied or opened in Gmail that day (a count, never which brand) | Produced by us | Show your streak on your home screen | While the account exists |
| Brands you have unlocked | Produced by us | Keep an unlock permanent, so a later scan does not charge you again for the same brand | While the account exists |
| Order and subscription references, plan, pack or top-up, amount, mandate and payment status | Razorpay | Grant credits; renew or cancel a subscription; issue invoices; settle disputes | As long as tax and accounting law requires |
| Random visitor/session IDs, opaque account ID, signed-in account name and verified primary email, and product events; purchase amount, currency, cycle and opaque payment references | Your browser and verified payment settlement | Understand conversion, recognize signed-in accounts and troubleshoot where product flows fail | 3 months |
| Scan ID, job status, timestamps, error logs | Produced by us | Run and debug the scan | 3 months |
Raw API responses (http_cache) | The providers above | Avoid re-paying for the same data | Up to 3 months, pruned earlier |
| Provider spend and LLM call metadata | Produced by us | Cost control and budget caps | As long as tax and accounting law requires |
Application records are stored in a PostgreSQL database. Product analytics are processed by PostHog as described below.
Who we share it with
We do not sell or rent data. Processors do specific jobs, and each gets only what its job needs.
| Processor | What it receives | Where it is processed |
|---|---|---|
| Monid (alternate: Apify) | Your handle, to return your public profile and posts | Provider infrastructure outside India |
| Deepgram | Audio of selected public reels, to return a transcript | Outside India |
| Groq | The same reel audio, when Groq is the configured provider instead of Deepgram | Outside India |
| Azure OpenAI | Your handle, your public display name, follower count, your post captions, your reel transcripts and summaries derived from them, to classify your vertical, extract topics and draft prose, and, when you upload them, your Insights screenshots, to read the audience numbers on them. This content can identify you. It does not train on this data. | The Azure region configured for the service |
| Hunter.io | A brand's company domain, to return a work email there | Outside India |
| Apify | A brand's LinkedIn company page, to return its marketing staff | Outside India |
| Clerk | Your email address and sign-in credentials, to authenticate you. We never receive your password | Provider infrastructure outside India |
| Razorpay | Your payment details and any recurring mandate, taken on their checkout. We receive only the order or subscription reference, the amount, the mandate state and whether it succeeded | India |
| PostHog | Visitor/account/session IDs, signed-in account name and verified primary email as profile labels, product events, normalised page paths, purchase metadata, masked session recordings, click positions and filtered technical errors. No Instagram handle, pitch contents, card/UPI details or authentication tokens | United States |
| Meta (Pixel and Conversions API) | Page views and a pricing-section view from your browser; for sign-up, checkout start and subscription: the plan, amount, currency and our order reference, the _fbp/_fbc cookie values, your IP address and browser user agent, and SHA-256 hashes of your email address and account ID. No Instagram handle, pitch or report contents, card/UPI details or unhashed email | Meta's infrastructure, outside India |
| Microsoft Azure Blob Storage | Images and PDFs for media kits, including Insights screenshots until they are deleted, and the photos and videos you upload. Private: nothing is publicly addressable. Images and PDFs are served through our own servers; a video is uploaded and played through a link to that one file that expires within an hour, issued only to you or to a viewer of a published kit that shows it | The Azure region configured for the service |
| PostgreSQL hosting | The stored scan data above | Managed database host used by Abscissa AI LLP |
A published media kit is disclosed at your direction to whoever holds its link. It is not a processor and not a sale.
We may also disclose data where a law, a court, or a lawful government request requires it.
Automated processing and LLM use
PostHog processes product events to help us understand conversion. We also measure page visits and exits, time on a page, scroll depth, and numeric page-performance measurements (Web Vitals). Page elements and resource details behind performance measurements are not collected.
We record masked sessions to understand where navigation fails. Input values and private page content are masked before transmission. Public landing-page and policy text, styling and static images remain visible so that recordings are understandable. Other images, embedded payment/authentication components and other sensitive elements are blocked. Sign-in, sign-up, account and payment pages are excluded, and recording stops before an on-page payment window opens. Recordings are retained for 30 days. We collect button/link interactions and mouse positions for click, rage-click, dead-click and heatmap analysis, without button text or arbitrary element attributes.
We capture browser exceptions and web-server errors with error types and code locations. Free-form error messages, request bodies, headers, console logs and local variable values are excluded. Source maps are uploaded privately to make code locations readable. Feature flags and experiments can use the existing analytics identifiers; no additional account credentials are sent. Network payloads and console logs are not collected.
Reports are produced by automated systems, including a large language model. Nobody hand-writes yours. That has consequences:
- Follower counts, engagement rates and the indicative rate card in INR are estimates — a machine-generated guess from public numbers, not a quote or a valuation.
- Brand matches are suggestions. A brand in your report has not asked for you, has not heard of you, and has committed to nothing.
- Extracted topics and drafted pitches can be wrong or out of date. Read them before sending.
- A media kit's "about" line is drafted by a language model once, and audience numbers are read from your screenshots by one; you edit and confirm both before anything is published.
- Who's Paying promises no deal, no income, no reply and no brand response.
No decision with a legal effect on you is made by this system. If a report gets something about you wrong, tell us at raghav@ostryaai.com and we will correct or delete it.
How long we keep data
Scan data — profile and post data, transcripts, ad matches, contacts and the report — is kept for 3 months from the scan date, then deleted. Three things sit outside that:
http_cache, the table of raw third-party API responses, stops us re-fetching and re-paying for identical data. Entries live up to 3 months and are pruned earlier where we can.- Spend and LLM call logs record what a scan cost us. As financial records they are kept for as long as tax and accounting law in India requires.
- Published media kits are a copy you chose to publish. They stay online until you unpublish them or ask us to erase your data, even after the scan they came from has been deleted.
If you ask for erasure, we delete your scan data ahead of that schedule.
Security
- Access to the production database and provider accounts is limited to the operators who need it.
- Data in transit moves over encrypted connections (HTTPS/TLS), to us and to every provider above.
- API keys and secrets live in environment configuration and are not committed to source control.
- Provider budgets are capped, which caps how much data any one run can pull. Scanning is free and open, so it is bounded instead by a per-handle cache and a daily ceiling on new scans; spending credits to unlock a brand needs a signed-in account.
- The brands you unlock are attached to your account and shown only to it.
- We never receive your password or your full card details: Clerk holds the first, Razorpay the second.
We do not claim ISO 27001, SOC 2 or any other certification, and we hold no independent security audit. We do not offer end-to-end encryption — we can read the data we store, because the product cannot work otherwise. No system is perfectly secure and we will not pretend ours is. If we become aware of a personal data breach we will notify the Data Protection Board of India and affected Data Principals as DPDP requires.
Your rights under DPDP
As a Data Principal you may:
- Access a summary of the personal data we hold about you and how we process it.
- Correct, complete or update anything wrong or incomplete.
- Have your data erased, unless we must keep it for a legal purpose.
- Raise a grievance with a real person, named below, who has to answer you.
- Nominate someone to exercise these rights if you die or become incapable of doing so yourself.
- Withdraw consent at any time. That stops future processing; it does not undo lawful processing already done.
To use any of these, write to raghav@ostryaai.com with your handle and, if you have it, your scan ID. The full process — including what to do if someone else scanned you, or your work email appeared as a brand contact — is on Data Removal.
Please be honest with us. DPDP places a duty on Data Principals not to file false or frivolous grievances, not to impersonate anyone, and not to suppress material information. We will ask for enough proof that a removal request comes from the right person — that protection exists for you.
Two things we will not oversell: there is no self-serve delete button and no automated deletion endpoint yet. Erasure is carried out by hand by an operator — acknowledged within 24 hours, completed within 15 days.
Children
Who's Paying is not for anyone under 18, and we do not knowingly process a child's personal data.
DPDP requires verifiable parental consent before a child's data may be processed, and we have no way to verify it. Because that flow does not exist, the handle of anyone under 18 must not be submitted to Who's Paying — not your own, not anyone else's. If you learn a scan was run on an under-18 handle, tell us at raghav@ostryaai.com and we will delete the data.
Changes to this policy
We update this page when the product changes, along with the updated date at the top. If a change materially affects how your data is used, we will say so plainly rather than bury it. Continuing to use Who's Paying after a change means you accept the updated policy. The current version always lives at /legal/privacy.
Grievance redressal
Under the Information Technology Act, 2000, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the Consumer Protection (E-Commerce) Rules, 2020, our Grievance Officer is:
- Grievance Officer: Raghav Mandhana
- Email: raghav@ostryaai.com
- Phone: +91 93527 04864
- Address: 130, 3rd Floor, Right Side, Kirti Nagar, New Delhi, West Delhi, Delhi, India – 110015
We acknowledge complaints within 24 hours and resolve them within 15 days of receipt.
If we do not answer, or you are not satisfied with the answer, you may escalate to the Data Protection Board of India under the Digital Personal Data Protection Act, 2023.
This policy is governed by the laws of India, and courts at New Delhi have jurisdiction.
Contact
Questions about this policy or the data we hold: Raghav Mandhana at raghav@ostryaai.com. Other routes are on Contact.