Privacy Policy
Last updated August 6, 2026
Topped (“Topped,” “we,” “us”) is operated by Lior Cohen, sole proprietor, at topped.ai. This policy explains what information we collect when you use Topped, why we collect it, and the choices you have. If you have questions, email support@topped.ai.
1. Account data
When you sign up we collect your email address and authenticate you with a passwordless magic-link sign-in. We use this to operate your account and send account-related email (invoices, activation and reconnect notices).
2. Connected social accounts
If you connect a TikTok, Instagram, or YouTube account, we use each platform’s official OAuth flow. We never ask for or store your platform password.
The access tokens we receive are used only to:
- publish posts you have explicitly approved to that account,
- read metrics on posts published through Topped and on your own connected account’s history, so your scoreboard can show the view and like counts each platform reported.
Access tokens are stored encrypted at rest and are never written to logs. You can revoke access at any time by disconnecting the account inside Topped, or by revoking Topped’s access directly from the platform’s own app settings (TikTok, Instagram/Meta, or Google). Disconnecting stops all future publishing and metric reads for that account.
For each account you connect, this is everything we access, collect, and store:
- Profile identifiers - the account or channel ID, username or handle, display name, and avatar image - so Topped can show you which account a post is going to. We copy the avatar into our private storage because provider image links expire, and periodically refresh this profile data while the account remains connected.
- OAuth tokens - the access and refresh tokens the platform issues (stored encrypted; see “How we protect your data” below).
- Published-post records - the platform’s ID and status for each post you publish through Topped.
- Engagement counts - view, like, and comment counts for posts published through Topped and for recent public posts on your own connected account, used only to show how a post performed on your Scoreboard.
We access nothing else from a connected account: no private messages, no follower or subscriber lists, no contacts, and no email addresses from the platform.
When you disconnect an account, Topped immediately stops using it, removes its stored profile information and engagement data, and marks its stored avatar image for deletion. An encrypted OAuth token and the minimum provider account identifier needed to address the revocation request may be retained briefly only for that purpose; they are then deleted, with a maximum retry window of six days.
YouTube. Topped uses YouTube API Services. For a connected YouTube account, the list above is exactly the YouTube API Data we access, collect, and store: your channel ID, handle, title, and avatar; the OAuth tokens Google issues; the video IDs of uploads made through Topped; and the view, like, and comment counts the YouTube Data API reports for them. If you connect a YouTube account you also agree to the YouTube Terms of Service, and Google’s handling of your data is described in the Google Privacy Policy. Topped’s use, storage, and sharing of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements: we use YouTube data only to publish posts you approve and to read metrics on your own connected account, never for advertising and never to train AI models. You can revoke Topped’s access at any time in your Google security settings.
3. How we protect your data
The most sensitive data we hold is the OAuth access and refresh tokens for your connected social accounts, and we protect all of your data with the following mechanisms:
- Encryption in transit. All traffic between your browser and Topped, and between Topped and every platform API or subprocessor, is encrypted with TLS (HTTPS). Topped serves no unencrypted endpoints.
- Encryption at rest. OAuth tokens are encrypted at the application layer with AES-256-GCM (a unique random initialization vector per value) before they are written to the database, which itself sits on provider-managed disk encryption. The encryption key lives only in the deployment environment’s secret store - never in source code or the repository.
- Access controls. Tokens are decrypted only server-side, at the moment an action you initiated requires a platform call (publishing a post you approved, or reading your own metrics). They are never sent to the browser, never written to logs or error reports, and no person views them in normal operation. Production access is restricted to Topped’s operator.
- Data minimization. We request only the minimum platform permissions needed for the features described in this policy, and use the data we receive only for those features.
- Revocation and deletion. Disconnecting an account inside Topped immediately makes it unusable and removes its stored profile and metrics. Tokens are deleted after the provider revocation attempt (or the bounded retry period described above); you can also revoke access from the platform’s own settings at any time. Full account deletion and export are described in the “Data retention, deletion, and export” section below.
- Incident response. If we become aware of a security breach affecting your personal data, we will notify affected users by email without undue delay and report to authorities where required by law.
4. How we use, process, and share your information
We use the information described in this policy only to provide the features you invoke:
- publishing the posts you approve to the accounts you connected,
- showing how your posts performed on your Scoreboard,
- building your post suggestions from your app profile and the post templates our team curates, and
- operating your account - sign-in, your plan, billing statements, and support.
Processing happens on our servers (hosted by Vercel) and in our database (hosted by Supabase); background generation and publishing jobs run on Trigger.dev. These providers act only on our instructions, as subprocessors - the complete list is in the “Subprocessors” section below.
Sharing, internally: Topped is run by a single operator. Production access is restricted to that operator; there is no wider team with access to your data.
Sharing, externally: we never sell your information and never share it for advertising. It is shared with no external party other than (a) the subprocessors listed below, strictly as needed to run the features described in this policy, and (b) where disclosure is required by law. Information received from platform APIs - including YouTube API Data - is never transferred to any other third party and is used only for the user-facing features described here.
5. Content you provide
You describe your Product in a setup conversation, which we store so we can build and maintain your Product Profile. You may optionally share an App Store link or website; when you do, we read public listing or page metadata such as its name, description, and screenshots to help fill in that profile. You may also upload demo footage or other assets to use in generated posts. This content is stored to produce and edit your posts and is not sold or shared for advertising.
6. AI processing of your content
We use OpenAI’s models to plan post structure, write captions, and generate images, and fal’s Seedance to generate video, when rendering your slides and clips. Content you provide, including your stored setup-conversation transcript, and the public posts we analyze may be sent to the relevant model provider as part of setup or generating your posts. Generated posts carry an AI-disclosure line by default, in line with platform policy; you can review this before you post.
7. Public-data analysis of watched accounts
To show you recent and historical posts from the creators on your watchlist, we collect publicly available posts and engagement metrics from creator accounts you choose to watch (via ScrapeCreators). We do not collect private data from these accounts and do not attempt to access anything not publicly visible on the platform.
8. Payments
Billing is handled by Polar, our merchant of record. Checkout is a redirect to Polar’s own hosted checkout page, where Polar collects and processes your payment details directly; Topped never sees or stores your card number. Polar acts as the seller for tax and compliance purposes. See Polar’s privacy policy for how they handle payment data.
9. Subprocessors
We use the following subprocessors to run Topped. Each is bound by a data-processing agreement appropriate to the data it handles:
- Vercel - application hosting
- Supabase - database, authentication, and interim file storage, hosted in AWS us-east-1
- Trigger.dev - background job processing - content generation and publishing
- Polar - payments and billing, as merchant of record (Polar processes your payment details directly; Topped never stores your card number)
- Sentry - error tracking
- PostHog - product analytics
- OpenAI - AI language model for post planning, captions, and agent chat, and AI image generation
- Google - YouTube Data API publishing and metrics, only if you connect a YouTube account
- fal - AI video generation (Seedance)
- ScrapeCreators - collection of public creator posts and metrics for watchlists
- Meta / Instagram - Instagram Graph API, only if you connect an Instagram account, to publish posts you approve and read their metrics
- TikTok - Content Posting API, only if you connect a TikTok account, to publish posts you approve and read their metrics
Planned, not yet active - these are on our roadmap but are not yet processing any of your data; we will update this policy before turning any of them on:
- Resend - transactional email delivery. Not yet wired; email support is handled manually at support@topped.ai until then.
- Cloudflare - media storage (R2). Media is stored via Supabase Storage today; this is a planned, config-only swap.
- A music-catalog provider is not active. Topped originals are curated outside the product and stored through Supabase today. We will list any provider and its rights terms here before it begins processing customer data.
10. Analytics and error tracking
We use PostHog to understand product usage (for example, which steps of onboarding people complete) and Sentry to capture crashes and errors so we can fix them. Both are configured to avoid collecting your platform access tokens or payment details.
Topped uses cookies and similar local-storage technologies only to keep you signed in and to support the analytics described above. We do not use third-party advertising cookies or cross-site trackers.
11. Data retention, deletion, and export
We keep your account data for as long as your account is active. If you cancel, your account downgrades to the free tier rather than being deleted, so your history and scoreboard are preserved. If you want your data deleted or exported instead, email support@topped.ai and we will:
- export everything we hold about you - posts, generated assets, scoreboard history, and account data - as a downloadable archive, and
- permanently delete your account data on request, including revoking any stored platform tokens.
This is our walk-away promise: you can always leave with your data, and you are never locked in.
12. Your rights
Depending on where you live, you may have rights to access, correct, delete, or export your personal data, and to object to or restrict certain processing (for example under the GDPR or similar laws). You can exercise any of these rights by emailing support@topped.ai. We will respond within a reasonable time and verify your identity before making changes to your account.
13. Changes to this policy
We may update this policy as Topped changes. Material changes will be posted here with an updated date, and where required we will notify you by email.
14. Contact
Topped is operated at topped.ai. For any privacy question, deletion or export request, email support@topped.ai.