mnCollab
LeaderboardNewConnectedFor creatorsFor brands
01Leaderboard02New03Connected04For creators05For brands

[ Weekly digest ]

© 2026 mnCollab — Ulaanbaatar · info@mncollab.com

MethodologyPrivacy policyTerms of service

Privacy Policy

Last updated: 2026.09.11. This policy explains what information the mnCollab platform collects, how it uses that information, and what rights creators have.

What information do we collect?

We collect only the statistics that are publicly available on the platforms (YouTube, Facebook, Instagram, Twitch): channel name, follower and view counts, and public profile information. We never collect private personal data such as phone numbers, home addresses, or payment information.

Information collected during verification

When a creator connects an account under their own authorization, what we store depends on the platform:

  • YouTube (sign in with Google). At the moment of connection we call the YouTube Data API once to read which channel the signed-in account owns — its channel ID, title, handle and thumbnail — and store that together with the OAuth access and refresh tokens. We do not read YouTube Analytics, audience demographics, subscriptions or video content, and we make no further YouTube API calls with your credentials. We keep the refresh token only to revoke the grant when you disconnect and to detect when you remove our access at Google.
  • Facebook / Instagram (sign in with Meta). We additionally store the aggregated age, gender and country breakdown of the audience — anonymized figures from which no individual can be identified — and aggregated engagement metrics (reach, views), together with the connection token.

We never share tokens with any third party. A creator can revoke a connection from their dashboard at any time; the token is then revoked and deleted, together with any audience data obtained through it. Figures measured from public sources — followers, views, the ★ rating — never depended on that consent, so they remain and the profile stays listed.

YouTube API Services

mnCollab uses YouTube API Services. We use the YouTube Data API to read publicly available channel and video statistics, and — only when a creator connects their own YouTube account — to confirm which channel that account owns (the youtube.readonly permission). We do not use the YouTube Analytics API.

By using mnCollab you are agreeing to be bound by the YouTube Terms of Service. Data obtained through Google APIs is handled in accordance with the Google Privacy Policy.

Revoking access.Besides revoking from your mnCollab dashboard, you can remove mnCollab’s access to your Google account at any time from the Google security settings page. Revoking there stops any further access immediately; to also have the data already stored on our servers deleted, use any of the methods on our data deletion page.

Limited Use.mnCollab’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use this data for advertising, we do not sell it, and we do not allow humans to read it except where required for security, to comply with the law, or with the creator’s explicit consent.

How we protect your data

Security procedures are in place to protect the confidentiality of your data — in particular the Google user data and access tokens described above:

  • Encryption in transit. Every connection to mnCollab uses HTTPS (TLS). Plain HTTP requests are redirected, and browsers are instructed to use HTTPS only (HSTS). Our servers talk to Google, Meta and our database over TLS as well.
  • Encryption at rest. Our database and its backups are hosted by Supabase, which encrypts all stored data with AES-256.
  • Tokens never reach the browser.OAuth access and refresh tokens are used only by our server. They are kept in a database table protected by row-level security with no access rules, so no one can read them through the public API — not even the creator’s own browser session. Only server code holding a secret service key can read them.
  • Restricted access.Only mnCollab’s administrator can access our production systems (database, hosting and Google Cloud project). Server secrets — database keys, OAuth client secrets and API keys — are kept in our hosting provider’s protected configuration and never appear in our source code or in the browser.
  • Least privilege and minimisation. We request read-only YouTube access and store only the channel details needed to confirm ownership.
  • Revocation and deletion.When a creator disconnects, we revoke the token at Google’s revocation endpoint and delete it. If access is removed from the Google Account instead, our next daily token refresh fails and we delete the connection automatically.
  • No sale, no advertising. Google user data is never sold, used for advertising, or transferred to third parties, as set out in the Limited Use section above.

Security questions can be sent to info@mncollab.com.

Brand and marketplace information

The information a brand enters at registration — name, logo, website — is displayed publicly on the platform. All interaction between brands and creators takes place within the platform: the content of proposals and messages is visible only to the brand that sent it and the creator that received it, and is not passed on to any third party.

Sources

Information is obtained from the platforms’ official APIs (for example the YouTube Data API) and from publicly available profiles. Some public statistics are also entered manually.

Purpose

The collected information is used to display creator rankings and statistics openly. In the future we plan to expand toward supporting collaboration between creators and brands.

Cookies

The site uses only functional cookies: login session cookies, a short-lived security cookie during Facebook sign-in, your language preference, and the list of creators you follow on this device. There are no tracking or advertising cookies whatsoever.

Creator rights

As a creator, you may request to have your information corrected, updated, or deleted, as well as request verification of your profile, by writing to info@mncollab.com. Requests are resolved within 5 business days.

Contact details and email

Creators commonly publish a business email in the public parts of their platforms — channel descriptions, video descriptions, profile bios. We may collect those addresses and use them to send one introduction to the platform, recording where each address came from.

Replying is enough to stop further email; we remove the address from the list. Newsletter subscribers are stored separately and every issue carries an unsubscribe link.

Processors and cross-border transfer

The platform runs on third-party services: Supabase (database and file storage), Vercel (hosting), Resend (email delivery), and Google and Meta (sign-in and statistics APIs). Their servers sit outside Mongolia, so data is transferred across borders. Each is bound by its own privacy policy and processing terms.

Retention

Public statistics are kept while a creator is listed. Connection tokens, and the demographic and statistical data obtained through them, are deleted the moment a connection is revoked; figures measured from public sources remain. Contract records are kept for as long as they may be needed as evidence — both parties hold their own emailed copy. Contact addresses are kept until someone asks to be removed.

Contract records

When a contract is signed on the platform we store the signature path, the time it was signed, the IP address, browser details and a hash of the content. These exist to show the document was not altered, and are produced only to the parties themselves or on a lawful request.

Legal compliance

We operate in compliance with the principles of Mongolia’s Law on the Protection of Personal Data — consent, purpose limitation, and data minimization. The consent source of each creator is recorded in the database (the consent_source field of the creators table).