Privacy Policy

Last updated August 6, 2026

Topped (“Topped,” “we,” “us”) is operated by Lior Cohen, sole proprietor, at topped.ai. This policy explains what information we collect when you use Topped, why we collect it, and the choices you have. If you have questions, email support@topped.ai.

1. Account data

When you sign up we collect your email address and authenticate you with a passwordless magic-link sign-in. We use this to operate your account and send account-related email (invoices, activation and reconnect notices).

2. Connected social accounts

If you connect a TikTok, Instagram, or YouTube account, we use each platform’s official OAuth flow. We never ask for or store your platform password.

The access tokens we receive are used only to:

Access tokens are stored encrypted at rest and are never written to logs. You can revoke access at any time by disconnecting the account inside Topped, or by revoking Topped’s access directly from the platform’s own app settings (TikTok, Instagram/Meta, or Google). Disconnecting stops all future publishing and metric reads for that account.

For each account you connect, this is everything we access, collect, and store:

We access nothing else from a connected account: no private messages, no follower or subscriber lists, no contacts, and no email addresses from the platform.

When you disconnect an account, Topped immediately stops using it, removes its stored profile information and engagement data, and marks its stored avatar image for deletion. An encrypted OAuth token and the minimum provider account identifier needed to address the revocation request may be retained briefly only for that purpose; they are then deleted, with a maximum retry window of six days.

YouTube. Topped uses YouTube API Services. For a connected YouTube account, the list above is exactly the YouTube API Data we access, collect, and store: your channel ID, handle, title, and avatar; the OAuth tokens Google issues; the video IDs of uploads made through Topped; and the view, like, and comment counts the YouTube Data API reports for them. If you connect a YouTube account you also agree to the YouTube Terms of Service, and Google’s handling of your data is described in the Google Privacy Policy. Topped’s use, storage, and sharing of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements: we use YouTube data only to publish posts you approve and to read metrics on your own connected account, never for advertising and never to train AI models. You can revoke Topped’s access at any time in your Google security settings.

3. How we protect your data

The most sensitive data we hold is the OAuth access and refresh tokens for your connected social accounts, and we protect all of your data with the following mechanisms:

4. How we use, process, and share your information

We use the information described in this policy only to provide the features you invoke:

Processing happens on our servers (hosted by Vercel) and in our database (hosted by Supabase); background generation and publishing jobs run on Trigger.dev. These providers act only on our instructions, as subprocessors - the complete list is in the “Subprocessors” section below.

Sharing, internally: Topped is run by a single operator. Production access is restricted to that operator; there is no wider team with access to your data.

Sharing, externally: we never sell your information and never share it for advertising. It is shared with no external party other than (a) the subprocessors listed below, strictly as needed to run the features described in this policy, and (b) where disclosure is required by law. Information received from platform APIs - including YouTube API Data - is never transferred to any other third party and is used only for the user-facing features described here.

5. Content you provide

You describe your Product in a setup conversation, which we store so we can build and maintain your Product Profile. You may optionally share an App Store link or website; when you do, we read public listing or page metadata such as its name, description, and screenshots to help fill in that profile. You may also upload demo footage or other assets to use in generated posts. This content is stored to produce and edit your posts and is not sold or shared for advertising.

6. AI processing of your content

We use OpenAI’s models to plan post structure, write captions, and generate images, and fal’s Seedance to generate video, when rendering your slides and clips. Content you provide, including your stored setup-conversation transcript, and the public posts we analyze may be sent to the relevant model provider as part of setup or generating your posts. Generated posts carry an AI-disclosure line by default, in line with platform policy; you can review this before you post.

7. Public-data analysis of watched accounts

To show you recent and historical posts from the creators on your watchlist, we collect publicly available posts and engagement metrics from creator accounts you choose to watch (via ScrapeCreators). We do not collect private data from these accounts and do not attempt to access anything not publicly visible on the platform.

8. Payments

Billing is handled by Polar, our merchant of record. Checkout is a redirect to Polar’s own hosted checkout page, where Polar collects and processes your payment details directly; Topped never sees or stores your card number. Polar acts as the seller for tax and compliance purposes. See Polar’s privacy policy for how they handle payment data.

9. Subprocessors

We use the following subprocessors to run Topped. Each is bound by a data-processing agreement appropriate to the data it handles:

Planned, not yet active - these are on our roadmap but are not yet processing any of your data; we will update this policy before turning any of them on:

10. Analytics and error tracking

We use PostHog to understand product usage (for example, which steps of onboarding people complete) and Sentry to capture crashes and errors so we can fix them. Both are configured to avoid collecting your platform access tokens or payment details.

Topped uses cookies and similar local-storage technologies only to keep you signed in and to support the analytics described above. We do not use third-party advertising cookies or cross-site trackers.

11. Data retention, deletion, and export

We keep your account data for as long as your account is active. If you cancel, your account downgrades to the free tier rather than being deleted, so your history and scoreboard are preserved. If you want your data deleted or exported instead, email support@topped.ai and we will:

This is our walk-away promise: you can always leave with your data, and you are never locked in.

12. Your rights

Depending on where you live, you may have rights to access, correct, delete, or export your personal data, and to object to or restrict certain processing (for example under the GDPR or similar laws). You can exercise any of these rights by emailing support@topped.ai. We will respond within a reasonable time and verify your identity before making changes to your account.

13. Changes to this policy

We may update this policy as Topped changes. Material changes will be posted here with an updated date, and where required we will notify you by email.

14. Contact

Topped is operated at topped.ai. For any privacy question, deletion or export request, email support@topped.ai.

Back to home