Privacy Policy

Last updated

King's Cross Labs, Inc.

New York, NY, United States

ask@kingscrosslabs.com · kingscrosslabs.com

Effective date:

Last updated:

This Privacy Policy explains what personal information King's Cross Labs, Inc. ("King's Cross Labs," "we," "us") collects, why we collect it, and what you can do about it. It covers our website at kingscrosslabs.com, our products and integrations — including Instasights — and any other service that links to this policy (together, the "Service").

It matters to us that this document is specific rather than decorative. Where we connect to a third-party platform on your behalf, we say which platform, what we read, how long we keep it, and how you revoke it.

1. Information We Collect

1.1 Information you provide

  • Account information — your name, email address, and the identifier of the account you sign in with.
  • Billing information — where you purchase a paid product. Card details are collected and processed by our payment processor; we do not store full card numbers on our systems.
  • Communications — messages you send us by email, through forms on our site, or through support channels.
  • Content you submit — anything you upload, paste, or write into the Service.

1.2 Information collected automatically

  • Log data — IP address, browser type and version, pages viewed, time and date of access, referring page, and the time spent on each page.
  • Device and diagnostic data — technical details captured when an error occurs, including what you were attempting at the time.
  • Usage data — which features you use and how often, used to operate and improve the Service.

1.3 Information from platforms you connect

When you authorize King's Cross Labs to connect to a third-party platform, we receive data from that platform's API. Depending on the platform and the permissions you grant, that may include:

  • Authorization credentials — OAuth access tokens and refresh tokens issued by the platform. These are stored encrypted. We never receive or store your password for a connected platform.
  • Account and profile data — the account or channel identifier, display name, handle, profile image, and follower or subscriber counts.
  • Content and metadata — posts, videos, captions, publish timestamps, and media identifiers for the account you connect.
  • Analytics and insights — the performance metrics the platform makes available for your own account, such as reach, impressions, saves, watch time, and engagement.
  • Derived content — transcripts we generate from your video content. See Section 8.

We request the narrowest set of permissions that lets the feature work. We do not request permission to read your direct messages, your private contacts, or the accounts of people you follow.

2. Legal Bases for Processing

Where the GDPR or UK GDPR applies to you, we rely on the following lawful bases:

  • Performance of a contract — to provide the Service you signed up for, authenticate you, sync the accounts you connect, and process payments.
  • Consent — to connect a third-party platform on your behalf, to send you marketing email, and to set non-essential cookies. You may withdraw consent at any time; withdrawal does not affect processing that already took place.
  • Legitimate interests — to secure the Service, prevent fraud and abuse, debug errors, and understand aggregate usage so we can improve the product. We balance these against your rights and do not rely on legitimate interests where your interests override ours.
  • Legal obligation — to meet tax, accounting, and regulatory requirements, and to respond to lawful requests from authorities.

3. How We Use Your Information

  • To provide, operate, and maintain the Service
  • To authenticate you and keep your connected accounts in sync
  • To generate the reports, analyses, and transcripts you request
  • To process payments and manage subscriptions
  • To respond to your support requests and communicate about the Service
  • To detect, investigate, and prevent security incidents, fraud, and abuse
  • To understand aggregate usage patterns and improve the product
  • To comply with legal obligations and enforce our Terms of Service

What we do not do. We do not sell your personal information. We do not sell, license, or otherwise transfer data obtained from a connected platform's API to a data broker, advertising network, or any third party for their own purposes. We do not use data obtained from a connected platform's API to build or serve advertising targeting, and we do not use it to train generalized machine learning or AI models. See Sections 6 and 7.

4. Information Sharing and Disclosure

We disclose personal information only in the following circumstances:

  • Service providers (subprocessors) — vendors that host, secure, or operate parts of the Service on our behalf, under contract, and only for that purpose. See Section 4.1.
  • Platforms you connect — where a feature you use requires us to send a request back to that platform on your behalf.
  • At your direction — where you ask us to share, export, or publish something.
  • Legal requirements — where we are required by law, court order, or a valid request from a public authority, or to establish, exercise, or defend legal claims.
  • Business transfers — if we are involved in a merger, acquisition, or sale of assets, in which case we will give notice before your information becomes subject to a different privacy policy.

4.1 Subprocessors

We use the following subprocessors to operate the Service. This list is current as of the date at the top of this policy.

SubprocessorPurposeLocation
Vercel, Inc.Website and application hosting, content deliveryUnited States
Neon, Inc.Managed database hostingUnited States
Stripe, Inc.Payment processing and subscription billingUnited States
PostHog, Inc.Product analytics and error monitoringUnited States
Google LLC (Google Analytics)Website traffic analyticsUnited States
Resend, Inc.Transactional email deliveryUnited States
Tally BVForms and survey collectionEuropean Union
Anthropic, PBCModel inference for analysis and transcription features, under a zero-retention configuration where offeredUnited States

We will update this list before adding a new subprocessor that processes personal information. If you would like to be notified of changes, email us at ask@kingscrosslabs.com.

5. AI Assistants and MCP Access

Parts of the Service are designed to be used from an AI assistant — for example Claude, ChatGPT, or a coding agent — through a skill, a Model Context Protocol (MCP) server, or our API. This section explains what that access means in practice.

5.1 How authorization works

You authorize an assistant through a standard OAuth 2.0 flow. Access tokens are short-lived and expire automatically. Refresh tokens are stored encrypted at rest and are used only to obtain new access tokens for the account that granted them.

5.2 What the assistant can reach

Authorization is scoped to your King's Cross Labs account and to the platform connections you have made. An authorized assistant can read the account data, media, metrics, and transcripts you have synced, and can perform the actions the specific product exposes. It cannot reach another user's account.

5.3 What we can see

We log API requests made on your behalf — the endpoint called, the timestamp, and the result — for security, abuse prevention, and debugging. We do not receive your conversations with the assistant. We see the request the assistant makes to us, not the prompt or the surrounding chat.

5.4 Model training

We do not use your personal information, your connected-platform data, or your transcripts to train generalized machine learning or AI models, and we do not permit our subprocessors to do so. Where a model provider offers a zero-retention or no-training configuration for business use, we enable it.

5.5 The assistant is a third party

The AI assistant you use is operated by a third party under its own terms and privacy policy. Once data reaches your assistant, that provider's practices govern what happens to it. We are not responsible for how a third-party assistant handles data after it leaves our systems.

5.6 Revoking assistant access

You can revoke an assistant's authorization at any time from your account settings or by emailing us. Revocation takes effect immediately: existing refresh tokens are invalidated and no further requests will be honored.

6. Connected Platform APIs

This section covers each third-party platform we integrate with. A section applies to you only if you have connected an account on that platform. Across all of them, the following commitments hold:

  • We access only the account you explicitly connect.
  • We request the minimum permissions the feature requires.
  • We do not sell, rent, or transfer platform data to data brokers, advertising networks, or any third party for their own purposes.
  • We do not use platform data for advertising targeting or for model training.
  • Disconnecting an account deletes the stored tokens for it immediately and the associated platform data on the schedule in Section 9.

6.1 Meta Platforms — Instagram and Facebook

Instasights connects to a professional (business or creator) Instagram account through the Instagram Graph API. Personal Instagram profiles are not supported, because Instagram Insights are only available for professional accounts.

With your authorization we access and store:

  • Your Instagram account identifier, username, profile image, and follower count
  • Your media objects — Reels, posts, carousels, and stories — including captions, media URLs, media type, and publish timestamps
  • Insights metrics for your own account and media, such as reach, impressions, saves, shares, profile views, and video watch metrics
  • Where a connection is made through a linked Facebook Page, the Page identifier and name required to complete the Instagram authorization

We use this data only to provide the analysis, reporting, and transcript features you request. Our use of Meta Platform Data complies with the Meta Platform Terms and Developer Policies. We do not use Meta Platform Data to build user profiles for advertising, to evaluate eligibility for credit, insurance, employment, or housing, or for surveillance purposes.

You can revoke our access at any time from Facebook Settings → Business Integrations, or from Instagram under Settings → Website Permissions → Apps and Websites.

6.2 Google API Services

We use Google Sign-In to authenticate you. With your authorization we receive your Google account email address, name, profile image, and a stable account identifier. We use these solely to create and secure your King's Cross Labs account.

Limited Use disclosure. King's Cross Labs' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not use Google user data for serving advertisements, we do not transfer it to third parties except as necessary to provide or improve the Service, to comply with applicable law, or as part of a merger or acquisition, and we do not allow humans to read it except with your affirmative consent, for security purposes, to comply with applicable law, or where the data has been aggregated and anonymized.

You can review and revoke our access at myaccount.google.com/connections.

6.3 YouTube API Services

Where you connect a YouTube channel, the Service uses YouTube API Services. By using those features you agree to be bound by the YouTube Terms of Service, and Google's handling of your data is governed by the Google Privacy Policy.

With your authorization we access and store:

  • Your channel identifier, title, description, and subscriber count
  • Your video identifiers, titles, descriptions, and publish timestamps
  • YouTube Analytics metrics for your own channel, such as views, watch time, average view duration, and retention
  • The OAuth tokens needed to keep the connection active

Disconnecting your channel clears the stored tokens immediately and removes the associated YouTube data within 30 days. You can also revoke access directly through Google at security.google.com/settings/security/permissions.

6.4 TikTok

Where you connect a TikTok account, we use the TikTok Developer APIs. With your authorization we access your account identifier, display name, avatar, follower count, and your own video list with the metadata and performance metrics TikTok exposes for your account.

Our use of TikTok data complies with the TikTok Developer Terms of Service. We do not use TikTok data for advertising targeting, we do not combine it with data from other sources to identify you beyond the account you connected, and we delete it when you disconnect. You can revoke access from TikTok under Settings and privacy → Security and permissions → Manage app permissions.

6.5 LinkedIn

Where you connect a LinkedIn account or advertising account, we use the LinkedIn Marketing Developer Platform and related APIs. With your authorization we access your member identifier and basic profile, the organization pages you administer, and the content and performance data for the posts, pages, or ad accounts you connect.

Our use of LinkedIn data complies with the LinkedIn API Terms of Use. We do not store LinkedIn member data beyond the retention period LinkedIn permits, we do not use it to build a profile of any individual other than the account holder, and we do not disclose it to third parties. You can revoke access from LinkedIn under Settings → Data privacy → Permitted services.

6.6 Revoking platform access

Revoking access at the platform stops future data collection. To also delete the data we have already synced, disconnect the account inside the Service or email us at ask@kingscrosslabs.com.

7. Content Analysis and Transcription

Some features generate transcripts of your video content so that spoken words can be analyzed alongside performance metrics. Transcription is performed on the video content of the account you connected, at your direction.

  • Transcripts and analysis outputs are stored with your account and treated as your content.
  • Where we use a third-party model provider to perform transcription or analysis, that provider acts as our subprocessor under contract and is not permitted to use your content for its own purposes or for model training.
  • You can delete transcripts at any time by disconnecting the account or requesting deletion.

8. Data Security

We protect personal information using measures appropriate to its sensitivity, including encryption in transit (TLS) and at rest, encrypted storage of OAuth tokens, access controls limiting internal access to those who need it, and logging of administrative access.

No method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for the strength and confidentiality of your own credentials. If we become aware of a breach affecting your personal information, we will notify you and the relevant supervisory authorities as required by applicable law.

9. Data Retention

We keep personal information only as long as we need it for the purposes described in this policy, or as long as the law requires.

DataRetention
Account informationFor the life of your account; deleted within 30 days of account deletion
OAuth tokens for a connected platformDeleted immediately when you disconnect that platform or revoke access
Synced platform data, metrics, and transcriptsDeleted within 30 days of disconnecting the platform or deleting your account
Payment and billing recordsRetained as required by tax and accounting law, typically 7 years
Server and security logsUp to 12 months, then deleted or aggregated
Support correspondenceUp to 24 months after the request is resolved

Backups are retained on a rolling schedule and are overwritten in the ordinary course. Data in a backup is deleted from live systems on the schedule above and expires from backups within 90 days.

10. Your Rights Under the GDPR and UK GDPR

King's Cross Labs is the data controller for the personal information described in this policy. If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the right to:

  • Access — obtain confirmation of whether we process your personal information and a copy of it
  • Rectification — have inaccurate or incomplete information corrected
  • Erasure — request deletion of your personal information
  • Restriction — request that we limit processing in certain circumstances
  • Portability — receive your personal information in a structured, commonly used, machine-readable format
  • Objection — object to processing based on our legitimate interests, and to direct marketing at any time
  • Withdraw consent — where processing is based on consent, without affecting processing already carried out
  • Complain — lodge a complaint with your local supervisory authority

To exercise any of these rights, email ask@kingscrosslabs.com. We will respond within 30 days. We may ask you to verify your identity before we act on a request. We will not discriminate against you for exercising your rights.

11. Your Rights Under California Law

If you are a California resident, the California Consumer Privacy Act as amended by the CPRA gives you the right to know what personal information we collect, to access and delete it, to correct inaccuracies, to opt out of the sale or sharing of personal information, and to limit the use of sensitive personal information.

We do not sell or share personal information as those terms are defined under the CCPA, and we have not done so in the preceding 12 months. We do not knowingly sell or share the personal information of consumers under 16.

In the preceding 12 months we have collected the categories of personal information described in Section 1: identifiers, commercial information, internet or network activity information, and audio or visual information in the form of media and transcripts from accounts you connect. We collect it from you, from your devices, and from platforms you authorize, for the business purposes described in Section 3.

To exercise your rights, email ask@kingscrosslabs.com with "California Privacy Request" in the subject line. An authorized agent may submit a request on your behalf with proof of authorization. We will respond within 45 days and may extend once by a further 45 days with notice.

Do Not Track. We do not currently respond to browser Do Not Track signals, because no common standard for them has been adopted.

12. Cookies and Tracking

We use cookies and similar technologies for two purposes: essential cookies that keep you signed in and secure the Service, and analytics cookies that help us understand aggregate usage. Most browsers let you refuse or delete cookies; refusing essential cookies may prevent parts of the Service from working.

13. Children's Privacy

The Service is not directed at children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, email us and we will delete it.

14. International Data Transfers

We are based in the United States, and personal information we collect is stored and processed in the United States and in other countries where our subprocessors operate. These countries may not offer the same level of data protection as your own.

Where we transfer personal information out of the EEA, the UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism, together with supplementary measures where appropriate.

15. Changes to This Policy

We may update this Privacy Policy to reflect changes to the Service, our practices, or the law. We will post the updated policy at this address and revise the "Last updated" date. If the changes are material, we will give you at least 30 days' notice by email or through the Service before they take effect, and where the law requires it we will ask for your consent.

16. Contact Us

For privacy questions, requests, or complaints:

King's Cross Labs, Inc.
New York, NY, United States
ask@kingscrosslabs.com
kingscrosslabs.com