Privacy Policy
Last updated: July 23, 2026
This English version is provided for convenience. In case of any discrepancy, the Portuguese version prevails.
1. Data Controller
The party responsible for processing your personal data is:
- Name: Thiago Ramires Kairala
- CPF (Brazilian taxpayer ID): 046.407.041-43
- E-mail: thiago@kairala.com.br
- Platform: www.midiakits.com
2. Data We Collect
We collect the following categories of data:
2.1 Registration Data
- Full name
- E-mail address
- Password (stored as a hash — never in plain text)
2.2 Data via OAuth — Meta (Instagram)
- Public username
- Follower count
- Post reach
- Engagement rate
2.3 Data via OAuth — Google (YouTube)
- Public channel name
- Subscriber count
- Total views
- Channel performance metrics (views and watch time over time), via YouTube Analytics
2.4 Data via OAuth — TikTok
- Public profile information (username, display name, avatar, bio, verification badge)
- Account statistics (followers, following, likes and video count)
- List of recent public videos with their metrics (views, likes, comments and shares)
2.5 Usage Data
- IP address
- Device and browser type
- Access and interaction logs
3. Purpose and Legal Basis
We process your data for the following purposes and legal bases (LGPD, Brazilian Law 13,709/2018):
- Service provision — creating and displaying your media kit with metrics from the connected social networks (art. 7, V — performance of contract).
- Transactional communications — sending registration confirmation, password reset and important change e-mails (art. 7, V).
- Platform improvement — analyzing usage patterns to improve features (art. 7, IX — legitimate interest).
- Compliance with legal obligations — meeting LGPD and other applicable requirements (art. 7, II).
4. Sharing with Third Parties
We do not sell or share your personal data for commercial purposes. Third-party access is limited to:
- Meta Platforms, Inc. — read access to your Instagram metrics via the official API, as authorized by you via OAuth.
- Google LLC — read access to your YouTube metrics via the official API, as authorized by you via OAuth.
- TikTok Pte. Ltd. — read access to your public TikTok profile and video data via the official API (Display API), as authorized by you via OAuth.
- Infrastructure providers — hosting, database and transactional e-mail services, bound by confidentiality agreements and processing data only under our instruction.
Under no circumstances is data collected via OAuth (Meta, Google or TikTok) passed on to third parties for advertising or commercial purposes.
5. YouTube API Services
MidiaKits uses the YouTube API Services to access the data described in section 2.3. By connecting your channel, you also agree to the YouTube Terms of Service and the Google Privacy Policy.
- YouTube data is refreshed by a daily import and stored only to display metrics on your media kit and dashboard;
- The use of this data follows the Google API Services User Data Policy, including the Limited Use requirements: we do not transfer, sell or use the data for advertising, and no human reads it outside the purposes described in this policy;
- Besides disconnecting the channel from the MidiaKits dashboard, you may revoke access at any time in your Google Account security settings. Upon revocation, stored YouTube data is removed as per section 7.
6. TikTok Data
When you connect your TikTok account (via TikTok Login Kit and Display API), MidiaKits collects: public profile information (username, display name, avatar, bio, verification badge), account statistics (follower, following, like and video counts) and the list of your recent public videos with their metrics (views, likes, comments and shares). This data is used exclusively for display on your own media kit, is refreshed daily and stored in historical snapshots. MidiaKits does not publish content on your behalf and does not access private messages. You may disconnect your TikTok account at any time in the settings, which immediately stops collection; deletion of already-stored data follows the procedure described in Data Deletion.
7. Data Retention
Your data is kept while your account is active. After account termination or a deletion request, data is removed within 30 (thirty) days, unless a legal obligation requires longer retention. OAuth tokens are revoked immediately upon account deletion.
8. Data Subject Rights (LGPD art. 18)
You have the following rights regarding your personal data:
- Confirmation of processing and access to the data;
- Correction of incomplete, inaccurate or outdated data;
- Anonymization, blocking or deletion of unnecessary data;
- Portability of the data to another service provider;
- Deletion of data processed on the basis of consent;
- Withdrawal of consent at any time;
- Information about sharing with third parties.
To exercise your rights, send a request to thiago@kairala.com.br with the subject "Direitos LGPD". We will respond within 15 business days.
To delete your data, visit our Data Deletion page.
9. Security
We adopt the following security measures:
- Encrypted communication via HTTPS across the entire platform;
- Passwords stored exclusively as hashes (bcrypt);
- OAuth tokens stored with encryption at rest;
- Database access restricted by authentication and private networking.
10. Cookies
We use only cookies strictly necessary for the platform to work (authentication session and interface preferences). We do not use third-party tracking or advertising cookies.
11. Contact and Data Protection Officer (DPO)
The Data Protection Officer (DPO) is Thiago Ramires Kairala, who can be reached at thiago@kairala.com.br.
Privacy questions? thiago@kairala.com.br