This Privacy Policy explains how NewWave Platforms, Inc.(“NewWave”, “we”, “us”) collects, uses, and shares information when you use the NewWave mobile app and website (the “Service”). NewWave is a UGC (user-generated content) campaign platform that connects brands with content creators. If you don’t agree with this policy, please don’t use the Service.
Who this applies to
NewWave serves two kinds of users in one app:
- Creators: people who make content for brand campaigns and get paid.
- Brands: businesses that run campaigns and review and approve creator content.
Information we collect
Information you provide
- Account & contact information: name, email address, phone number, password, and the sign-in method you choose (email, phone, Google, or Apple).
- Profile information: creator profile details, portfolio links, social handles, avatar, and (for brands) workspace and company details.
- Content you submit: videos, images, captions, messages, and other materials you upload or send. Brands can view content that creators submit to their campaigns.
- Payment & payout information: handled by our payments processor, Stripe. We receive limited payout and transaction data (amounts, status) but don’t store full card or bank-account numbers ourselves.
- Support communications: information you send us when you contact support.
Information collected automatically
- Device & technical data: app version, device type and operating system, and a push-notification token (if you enable notifications).
- Usage & campaign performance: how you interact with campaigns and content, and performance metrics (views, likes, comments) for content you submit.
Information from third parties
- Sign-in providers: if you sign in with Google or Apple, we receive basic profile information (such as name and email) from that provider.
- Public social-platform metrics: when a creator links a published post (e.g. TikTok, Instagram, YouTube, Facebook), we collect publicly available performance metrics for that post to calculate views and payouts. We read some of these through the platforms’ own APIs and some through third-party data providers, which means we send those providers the creator’s public handle and the post’s public URL. Those providers are named under How we share information.
- Authorised social-platform data: if a creator chooses to connect a social account (see Connected accounts), we also receive data that is not public, read with their permission and only for as long as the account stays connected.
Device permissions
The app may ask for permission to use your camera, microphone, and photo library so you can record and upload content, and to send push notifications. You can grant or revoke these in your device settings at any time.
Product analytics and session replay
We use PostHogto understand how our own product is used and to find what is broken in it. Three things run through it, and one of them deserves to be spelled out rather than filed under “analytics”.
- Product analytics. Which pages and features you use, and when.
- Session replay. We record your sessions inside NewWave and can play them back as video-like recordings, to see what actually happened when something goes wrong or a flow is confusing. A recording can show anything visible on the page while you use the Service, including campaign details, amounts, and messages. We use replays to diagnose and improve the product, not to monitor individuals.
- Error monitoring and surveys. When the app throws an error we capture the technical context of it, and we occasionally show an in-product survey you can dismiss.
This is first-party: it covers your use of NewWave only. We do not use advertising SDKs or cross-app tracking SDKs, we do nottrack you across other companies’ apps or websites, and we do not sell or share your information for advertising. To ask us to delete your recordings, email support@new-wave.ai.
Connected accounts
Connecting an outside account is optional and separate from having an account with us. Nothing below is collected unless someone completes the connection themselves, and disconnecting deletes it. Creators may connect a social account; brands may connect an advertising account or a calendar and meeting account.
Creator social accounts
A creator may connect an Instagram professional account, a Facebook Page, a YouTube channel or a TikTok account, so NewWave can show them, and the brands they choose, how their work performed, and so they can schedule and publish their approved campaign posts without leaving NewWave. Each account is connected separately and each can be disconnected on its own.
What we read, with the creator’s authorisation:
- Account basics: the account’s id, and its username or page name.
- Post performance: reach, views, likes, comments, saves, shares, total interactions, follows, profile visits and watch time, depending on what the platform reports.
- A list of the account’s posts. To let a creator pick a post to read comments on, and to match a published post to the campaign it fulfils, we list posts on the connected account, not only the ones submitted to a campaign.
- Comments on those posts,including the commenter’s display name and their comment text. See People who comment on campaign posts.
- Audience make-up:aggregate counts of the account’s audience by country, age range, gender and city, as the platform reports them. On YouTube these describe who watched rather than who subscribed. These are group totals. They never include any individual follower’s identity, profile or contact details, and we cannot see who follows a creator.
What we write, and only when the creator asks for it:
- We publish posts they have approved. A creator schedules an approved campaign submission from NewWave and we publish it to the connected account at the time they chose, even if they close the app. They set the caption and, where the platform offers it, the title, description, visibility and disclosure. We never publish anything they have not approved for that account.
- We post comment replies they write. A reply a creator types in NewWave is posted publicly by their connected account. We never write, send or suggest a reply on our own.
We do not react to posts, send or read direct messages, follow or unfollow anyone, or change the account’s settings, profile or existing posts.
What each platform gives us
- Instagram. A professional account, connected either directly through Instagram or through a linked Facebook Page. Post performance, audience make-up, comments and replies, and publishing.
- Facebook Pages. Page and post performance, followers by country and city, Page comments and replies, and publishing. We do not read personal Facebook profiles.
- YouTube. Channel and video performance including watch time, viewer make-up, comments and replies, and uploading. Our use of YouTube is also governed by the YouTube Terms of Service and the Google Privacy Policy. A creator can revoke our access to their Google data at Google security settings.
- TikTok. Two separate connections. The basic connection verifies the creator owns the handle and reads only their public profile. A TikTok for Business connection additionally reads video performance, audience make-up and comments, and can publish.
A creator controls who sees this. Post insights are shared with a brand only for that brand’s own campaign, and only after the creator agrees on a consent screen naming that brand. Audience make-up is shared only if the creator turns it on, either for one brand or for brands viewing their creator profile. Every one of these can be withdrawn independently, at any time, from the creator’s Profile page, and disconnecting the account withdraws all of them at once.
Disconnecting.When a creator disconnects an account we stop collecting from it, delete the performance and audience figures we collected for it, end our permission to publish to it, and hand the authorisation back to the platform so it stops being listed in the creator’s own settings there. Posts we already published stay where they are, because they belong to the creator and to the campaign they fulfilled.
We keep a record of what a creator agreed to and when, including after they withdraw it, because it is the evidence of the permission they gave. That record contains no Instagram data.
Deleting this data is described in full on our Data Deletion page.
Advertising accounts
A brand may connect a Meta or TikTok advertising account so NewWave can show paid performance alongside organic performance. We read advertising reporting figures only (impressions, clicks, reach, spend and conversions). We never create, edit, pause or delete an ad, and never spend a budget.
Google Calendar and Google Meet
A brand may connect a Google account so that NewWave can put a scheduled campaign call on that account’s calendar and create the Google Meet link for it. NewWave requests a single Google Calendar permission, calendar.events, alongside basic sign-in information.
- What we write.When someone schedules a campaign call in NewWave, we create one event on the connected account’s primary calendar, carrying the call title, its time, the participating creators as invitees, and a Google Meet conference. When the call is cancelled, we delete that same event.
- What we read. The email address and display name of the connected Google account, so a workspace can see which account it is connected as. Nothing else.
- What Google receives from us.Creating the event sends Google the call title, the campaign name, the time, and the email address of each creator invited to the call, and Google then emails them the invitation on the brand’s behalf. We set the event so that guests cannot see one another’s email addresses.
We do not read, list, download, index, or store the contents of your calendar. We cannot see your existing events, your availability, your other invitees, or any event NewWave did not itself create. The only Google Calendar data we retain is the identifier and Meet link of the event we created, kept so that we can delete that event later.
Google Calendar data is used solely to provide this scheduling feature. We do not use it for advertising, we do not sell it, we do not transfer it to anyone except as necessary to provide the feature or where the law requires it, we do not use it to build profiles, and we do not use it to develop, train, or improve any artificial-intelligence or machine-learning model. No data obtained from Google APIs is sent to any AI model, ours or anyone else’s (see AI and automated processing). No human at NewWave reads it, except where you have asked us to for support, where the law requires it, or where it is necessary for security.
Disconnecting the Google account in workspace Settings deletes our stored authorisation immediately. You can also revoke NewWave’s access at any time from your Google Account permissions page.
NewWave’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
Zoom
A brand may instead connect a Zoom account, which NewWave uses in the same narrow way: to create the meeting for a scheduled campaign call and to delete it if the call is cancelled. We read the email address and display name of the connected account. We do not read your existing meetings, recordings, or contacts.
People who comment on campaign posts
This section is about people who are not NewWave users. When a creator publishes a campaign post on TikTok, Instagram, YouTube, Facebook or X, that post collects public comments. We read those comments so the brand can understand how its campaign landed.
For each public comment on a campaign post we store:
- The comment text, its like count, and when it was posted, all of it already public.
- The commenter’s public handle, display name, and the identifier the platform gives them.
- Labels we generate ourselves with an AI model: a sentiment, a topic, a category, and whether the comment looks abusive or unsafe. These are our own assessments, not something the platform publishes.
The brand running that campaign can see these comments and labels for its own campaign posts. We use them for that purpose only. We do not sell them, do not use them to build a profile of anyone beyond the campaign they commented on, do not use them for advertising or to target anyone, do not try to identify the person behind a handle, and do not use them to train any AI model.
If you commented on a post and want your comment and its labels removed from NewWave, email support@new-wave.ai with the handle and the post, and we will delete them. Deleting a comment on the platform itself also removes it from NewWave the next time we read that post. Depending on where you live you may have further rights over this information, described under Your rights and choices.
How we use information
- Provide and operate the Service (accounts, campaigns, content review, payouts).
- Connect creators with relevant brand campaigns.
- Process payouts and billing through Stripe.
- Calculate campaign performance and creator earnings.
- Send transactional and (if enabled) push notifications.
- Provide support, maintain security, prevent fraud, and comply with law.
We use information only for the purposes above, which are the purposes of providing and improving the Service itself. We do not use it for advertising, and we do not sell it.
AI and automated processing
NewWave uses AI models for a small, defined set of product features: checking a submitted video against the campaign brief it was made for, drafting scripts and campaign copy, grouping the public comments on a published post into themes, researching a brand from its public website, and drafting first replies to support questions.
What is never sent to a model
No data received from Google APIs is sent to any artificial-intelligence or machine-learning model, ours or a third party’s, in raw, aggregated, anonymised, or derived form, and none of it is used to develop, train, or improve any model. This holds by construction rather than by promise: NewWave never reads the contents of a connected calendar in the first place, so there is nothing from it for a model to receive, and our AI features have no access path to connected meeting accounts at all. The same exclusion applies to authentication credentials and payment details.
Where these models run
- Self-hosted, on infrastructure we control. Our video-understanding and text-judgment models are open-weight models published by Thinking Machines and Z.ai that we run self-hosted on GPUs we rent and operate. Data sent to them is processed locally inside our own isolated environment. It is never transmitted back to Thinking Machines, to Z.ai, or to any other model publisher, whether for training or for any secondary purpose. No data received from Google APIs reaches these models either, for the reason given above.
- Through a model gateway. Some text features call hosted models through OpenRouter. Prompt logging and model training are switched off for our account, and every request we send additionally carries an explicit instruction to route only to model providers that do not retain the contents of the request.
We do not permit any model provider to use our users’ data to train or improve their models, and we do not train models of our own on your personal information. AI output is a draft or a recommendation for a person to act on; it does not by itself decide anything with a legal or similarly significant effect on you.
How we share information
- Between campaign participants: creators’ submitted content and relevant profile information are shared with the brand running that campaign; brands’ campaign details are shown to participating creators.
- Service providers running the Service for us, each receiving only what its job needs:
- Supabase (authentication and database) and Amazon Web Services (cloud hosting, file storage, and the transactional email we send you).
- Stripe and Wise (payments and payouts).
- Apple and Google (sign-in), and Apple, Google and Expo (delivering push notifications to your device).
- Google also receives the calendar event we create on a connected account, described under Connected accounts, and a business address you ask us to look up.
- Twilio (sending the verification code when you confirm a phone number).
- PostHog (product analytics, session replay, error monitoring and surveys, described under Product analytics and session replay).
- ScrapeCreators, TikWM, RapidAPI providers and Firecrawl (reading public post metrics and public web pages). These receive public handles and public post or page URLs, not your account information.
- The AI providers named in AI and automated processing.
- Legal & safety: when required by law, to enforce our terms, or to protect rights and safety.
- Business transfers: in connection with a merger, acquisition, or sale of assets.
We do not sell your personal information.
Payments
Payments and payouts are processed by Stripe, subject to Stripe’s privacy policy, and some international payouts are made through Wise, subject to Wise’s privacy policy. NewWave does not receive or store full payment-card or bank-account numbers.
Data retention
We keep personal information for as long as your account is active or as needed to provide the Service, comply with legal obligations (including tax and payment records), resolve disputes, and enforce our agreements. When no longer needed, we delete or de-identify it.
Your rights and choices
- Access, correction, deletion: you can access and update most profile information in the app, and request access to or deletion of your personal information by emailing support@new-wave.ai.
- Delete your account: you can delete your account from within the NewWave app, or by emailing support@new-wave.ai. Deleting your account removes your personal data, subject to records we must retain by law (e.g. payment and tax records).
- Push notifications: turn these off in your device settings.
- Tracking: we do not track you across other apps or websites.
- Region-specific rights: depending on where you live (e.g. the EEA/UK or California), you may have additional rights such as the right to object to, restrict, or port your data. Contact us to exercise them.
Security
We use industry-standard safeguards, including encryption in transit (HTTPS) and secure on-device storage of your login session. No method of transmission or storage is 100% secure, but we work to protect your information.
Children
NewWave is intended for users age 16 and older. You must be at least 16 years old to use the Service. If you are under the age of majority where you live, you may use the Service only with the permission and supervision of a parent or legal guardian. Any campaign agreement, tax form, or payout account must be completed or approved by that adult when required by applicable law or our payment processor. We do not knowingly collect personal information from anyone under 16.
International users
We operate in the United States. If you use the Service from outside the U.S., your information will be transferred to and processed in the U.S. and other countries where we or our providers operate.
Changes to this policy
We may update this policy from time to time. We’ll post the updated version here and revise the “Last updated” date. Material changes may be communicated in-app or by email.
