Privacy Policy
Last updated: June 30, 2026
Bifrost ("Bifrost", "we", "us") operates a unified creator-API platform at usebifrost.org that lets developers connect social accounts and read profile, content and analytics data across LinkedIn, YouTube, Instagram, TikTok, Facebook and X through a single API. This Privacy Policy explains what we collect, how we use it, and the choices you have.
1. Information we collect
- Account information — the email address and name you provide when you create a Bifrost account.
- OAuth credentials — when you connect a social account, we receive and store access and refresh tokens issued by that platform, on your authorization. Tokens are encrypted at rest.
- Connected-platform data — at your request, we retrieve and may cache profile details (username, picture, follower counts, verification status), recent posts/videos, and aggregate analytics (followers, likes, comments, shares, views) from the platforms you connect.
- Usage data — API request metadata (timestamp, endpoint, status, project) used for rate limiting, security and billing.
- Billing information — when you subscribe to a paid plan, payment is processed by our Merchant of Record, Paddle. Paddle collects the payment details and billing information needed to complete your purchase; Bifrost does not receive or store your full card details. We retain a record of your plan, subscription status and invoices.
2. How we use information
- To provide the Bifrost API and dashboard, including authenticating you and returning the data your application requests.
- To store and automatically refresh OAuth tokens so connections stay active.
- To monitor usage, enforce rate limits, prevent abuse, and operate the service securely.
3. Connected platforms
When you connect an account, you authorize Bifrost to access that platform's API on your behalf under the scopes you approve. Your use of connected data is also governed by each platform's terms and policies, including the LinkedIn, Google/YouTube, Meta (Instagram/Facebook) and TikTok policies. You can revoke Bifrost's access at any time from the platform's settings or from your Bifrost dashboard.
4. How we share information
We do not sell your personal data. We share data only: (a) with the social platforms you connect, as needed to make authorized API calls; (b) with the Bifrost organization, project and developers you grant access to; (c) with infrastructure providers that host the service, under appropriate safeguards; and (d) with Paddle, our payment Merchant of Record, to process subscriptions, payments and taxes. Paddle's handling of your data is governed by its own privacy policy. We may disclose information if required by law.
5. Data security
OAuth tokens are encrypted at rest, API keys are stored only as salted hashes, and all traffic is served over TLS. No method of transmission or storage is completely secure, but we work to protect your information using industry-standard measures.
6. Data retention & deletion
We retain account and connection data while your account is active. You may disconnect an account or delete your data at any time; on request we will delete your account and associated tokens and cached platform data, except where retention is required by law. Contact us at the address below to request deletion.
7. Cookies
We use a single authentication cookie to keep you signed in to the dashboard. We do not use third-party advertising or tracking cookies.
8. Your rights
Depending on your location, you may have the right to access, correct, export or delete your personal data, and to withdraw consent. To exercise these rights, contact us.
9. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
10. Contact
Questions or requests: [email protected].