Privacy Policy
Applies to: datafort.com, creativeguru.ai, socialengine.app, Social Engine: Frame, and associated websites and applications
Last updated: 27 August 2026
This Privacy Policy is issued jointly by DATAFORT Ltd and Newsguru.ai Ltd (trading as “Creativeguru” / “Creativeguru.ai”), both registered in England and Wales with a registered office at DataFort House, 113 Walnut Tree Close, Guildford, Surrey, GU1 4UQ, United Kingdom (“DATAFORT Group”, “we”, “us”, “our”). References to “our Services” or “our sites” mean datafort.com, creativeguru.ai, socialengine.app, Social Engine: Frame (“Frame”), and any other website, application, or social media presence operated by either company.
This Policy explains how and why we collect, use, store, and share information about visitors and users of our Services, and describes your rights over that information.
By accessing or using our Services, you acknowledge this Policy. If you do not agree with it, please do not use our Services. This Policy is governed by the laws of England and Wales.
Questions or concerns? Contact us at [email protected] or [email protected], or by post to the address above.
1. Information We Collect
You can browse our sites without providing any personal information. Where you register, contact us, purchase a service, or connect a third-party account, we collect additional information as described below.
1.1 Information you provide directly
Name, email address, username and password, company details, phone number, payment details (processed by our payment provider, currently Stripe — see Stripe’s Privacy Policy), and any other information you choose to submit through forms, bookings, account settings, content uploads, or correspondence with us.
1.2 Information collected automatically
When you visit or use any of our Services, we automatically collect technical and usage information, including:
IP address and approximate location;
browser type, language, and version;
device type, operating system, and unique device identifiers;
pages visited, features used, referring pages, and timestamps; and
cookie and similar tracking identifiers (see Section 5 below).
1.3 Digital fingerprinting
We capture a digital fingerprint of visitors across our online assets, including our websites, hosted applications, and social media presences. This fingerprint may include device characteristics, browser configuration, IP address, and other technical signals. We collect this information automatically; it does not on its own reveal your name or contact details.
1.4 Social login and connected-account data
If you register or log in using a third-party account, such as Google, we receive the profile information you make available through that provider, typically your name, email address, profile image, and an account identifier.
If you connect a social media or content-platform account to Frame, we may receive account or channel identifiers, names, profile information, permissions, publishing destinations, OAuth access and refresh tokens, and information about content published through Frame. The information received depends on the provider, the permissions you grant, and the Frame features you use.
1.5 Content submitted to our Services
We collect photographs, videos, audio, text, descriptions, captions, scheduling instructions, publishing preferences, and other content that you upload, create, select, or approve through our Services. This includes content provided to Frame for creating and publishing social media posts and videos.
1.6 Sensitive information
We do not intentionally collect sensitive personal data, such as information about health, religion, or biometric identity, and ask that you do not submit it to us, except where you provide voice recordings, photographs, or video for a voice cloning or avatar/video-generation service as described in Section 2A below.
2. Why We Collect and Process Your Information
We process the information above for the following purposes:
Security. To protect the integrity of our infrastructure, detect and prevent fraud, abuse, unauthorised access, and other security threats across our Services.
Service effectiveness. To understand how our Services are used, diagnose errors, and improve functionality, performance, and user experience.
Account and service delivery. To create and administer accounts, connect authorised third-party accounts, deliver the products and services you request, and provide customer support.
Content creation and publishing. To create, process, schedule, upload, and publish content according to your instructions and to report the status of those actions.
Communications. To respond to enquiries, send service-related updates, and, where you have opted in, send marketing communications, which you may unsubscribe from at any time.
Analytics and reporting. To analyse usage trends and the effectiveness of our marketing and promotional activity.
AI model training and improvement. To train, test, and improve artificial intelligence and machine learning models used in or alongside our Services, including for security, personalisation, and product-development purposes. Where reasonably practicable, we use aggregated or de-identified data for this purpose. This does not include voice recordings, images, video, or cloned voice models or avatars submitted for a voice cloning or avatar/video-generation service, or Google user data and YouTube API data obtained through Google or YouTube API Services.
Legal and compliance. To comply with legal obligations, enforce our terms, and protect the rights, property, or safety of the DATAFORT Group, our users, or others.
2A. Voice Cloning and Likeness/Avatar Services
Where a customer requests a voice cloning, video avatar, or other synthetic-media service that uses a person’s voice or image or likeness, such as a photograph or video used to generate an avatar or animated video, we process that biometric data on the following basis:
Whose voice or likeness. The service is intended for customers to clone their own voice or likeness, or a voice or likeness they have obtained clear, documented permission to use. By submitting a voice recording, photograph, or video, you confirm and warrant that it depicts you, or that you hold the necessary rights and consents from the individual whose voice or likeness it is.
Explicit consent required. Voice recordings and images or videos of a person’s face can constitute biometric data under UK GDPR. Before we process it, we obtain your explicit consent, separate from this general Policy, specifically covering the capture, storage, and use of the voice sample, image, or video and any resulting voice model, avatar, or generated content.
Purpose limitation. Voice recordings, images, video, and any resulting voice model or avatar are used only to deliver the specific service you requested, such as generating audio or video content on your behalf. They are not used to train or improve our general AI models and are not shared with third parties beyond the processors necessary to deliver the service, unless you separately opt in.
Retention and deletion. We retain voice recordings, images, video, and derived voice models or avatars only for as long as needed to provide the service or as you instruct, and will delete them on request or on account closure, subject to any legal retention requirement.
Withdrawing consent. You may withdraw consent and request deletion of your voice recordings, images, video, and any derived voice model or avatar at any time by contacting us using the details in Section 12. Withdrawal does not affect content already generated before withdrawal.
2B. Social Engine: Frame and YouTube API Services
Frame uses YouTube API Services to allow users to connect a YouTube account or channel and upload and publish videos through Frame.
When you connect YouTube to Frame, Google will ask you to authorise the permissions required by Frame. Frame only accesses YouTube information and permissions necessary to provide the features you request. You can choose not to connect YouTube or can disconnect it later.
Depending on the permissions you grant and the features you use, Frame may access and process:
your Google account identifier and basic profile information;
your YouTube channel identifier, channel name, profile information, and available publishing destination;
information about videos uploaded through Frame, including titles, descriptions, tags, categories, audience settings, privacy settings, video identifiers, upload status, and processing status;
videos that you select, create, or approve for upload; and
OAuth access tokens and refresh tokens issued by Google.
Frame uses this information to:
connect your selected YouTube account or channel to Frame;
display the connected account or channel within Frame;
upload videos that you have selected, created, or approved;
publish or schedule content according to the instructions you provide;
display upload, processing, and publishing results; and
diagnose errors, prevent abuse, and provide technical support.
Frame does not upload a video to YouTube unless the video and publishing action have been selected, approved, or scheduled by the user. Before publishing, Frame may show the selected channel, content, accompanying text, scheduling details, audience selection, and available privacy setting so that the user can review the proposed action.
OAuth tokens
Frame stores Google OAuth access and refresh tokens so that it can maintain your authorised YouTube connection and perform publishing actions you request without requiring you to sign in to Google for every upload.
OAuth tokens and YouTube API data are protected using access controls and appropriate technical and organisational security measures. Access is limited to authorised personnel and contracted service providers who need it to operate, secure, or support Frame.
Google user data and YouTube API data obtained through Google or YouTube API Services are not sold, used for advertising, or used to train Frame’s or the DATAFORT Group’s general artificial-intelligence models.
Service providers and sharing
Frame may share the minimum information necessary with contracted service providers that provide hosting, storage, security, monitoring, and technical infrastructure. These providers process information on our behalf under appropriate confidentiality and data-protection obligations.
Information is transmitted to Google and YouTube when necessary to authenticate your account, upload a video, retrieve publishing information, or perform another action you have requested.
We do not transfer Google or YouTube user data to another party except as necessary to provide or improve the user-facing Frame features you request, for security purposes, to comply with applicable law, or as otherwise permitted by the Google API Services User Data Policy.
Disconnecting YouTube and revoking access
You can disconnect YouTube through the connected social-account settings in Frame. When you disconnect YouTube, Frame deletes the associated OAuth access tokens, refresh tokens, and stored YouTube API data from its active systems as soon as reasonably practicable and no later than seven calendar days, unless retention is required by law.
You can also review or revoke Frame’s access directly through your Google third-party access settings.
If you revoke Frame’s access through Google rather than through Frame, we will delete the associated stored YouTube API data and credentials promptly after we become aware of the revocation and within the period required by Google’s applicable policies.
Disconnecting YouTube or deleting your Frame account does not automatically delete videos or other content already published to YouTube. You must manage or delete published content through your YouTube account or YouTube Studio.
Frame’s use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
Your use of YouTube through Frame is also subject to the YouTube Terms of Service and the Google Privacy Policy.
To ask a question about Frame’s use of YouTube API Services, disconnect YouTube, or request deletion of associated YouTube data, contact [email protected] or [email protected].
2C. Social Engine: Frame and Google Business Profile API Services
Frame uses Google Business Profile API Services to allow users to connect a Google Business Profile account and publish user-approved Local Posts to locations they own or manage.
When you connect Google Business Profile to Frame, we may process your Google account identifier and basic profile information, authorised business-account and location identifiers and names, OAuth access and refresh tokens, and information about posts created through Frame. We use this information only to identify the accounts and locations you are authorised to manage, display those destinations in Frame, and create or report on publishing actions you explicitly request.
Frame does not publish to a Google Business Profile location unless you have selected that location and approved or scheduled the publishing action. Google Business Profile data is not sold, used for advertising, or used to train Frame’s or the DATAFORT Group’s general artificial-intelligence models.
You can disconnect Google Business Profile in Frame at any time. Frame then deletes the associated stored connection credentials and Google Business Profile API data from its active systems as soon as reasonably practicable and no later than seven calendar days, unless retention is required by law. Disconnecting Frame does not delete posts already published on Google; these must be managed through Google Business Profile.
3. Legal Basis for Processing (UK/EU Visitors)
Where UK GDPR or EU GDPR applies, we rely on the following legal bases:
Legitimate interests — for security monitoring, fraud prevention, digital fingerprinting, service improvement, analytics, and training and improving our AI models, where these interests are not outweighed by your rights and freedoms.
Consent — for marketing communications, non-essential cookies, and third-party account permissions where consent is the appropriate legal basis. You may withdraw consent at any time.
Explicit consent — for voice recordings, images, video, and cloned voice models or avatars submitted for a voice cloning or avatar/video-generation service that constitute biometric data under UK GDPR (see Section 2A).
Contract — where processing is necessary to create or administer your account, connect a service at your request, publish content according to your instructions, provide another service you have requested, or fulfil a contract with you.
Legal obligation — where we must process information to comply with applicable law or a request from a regulator or law-enforcement body.
4. How We Share Your Information
We do not sell your personal information. We may share it with:
service providers who perform functions on our behalf, such as hosting, storage, payment processing, analytics, email delivery, security monitoring, and customer-support tools, under appropriate confidentiality and data-protection terms;
third-party platforms, including Google, YouTube, LinkedIn, Meta, Instagram, Facebook, TikTok, and other services you choose to connect, where necessary to authenticate your account or perform an action you request;
professional advisers and regulators, where necessary for legal, accounting, or compliance purposes;
business-transfer recipients, in connection with a merger, acquisition, financing, or sale of some or all of either company’s business or assets; and
law enforcement or public authorities, where required by law or to protect the rights, property, or safety of the DATAFORT Group or others.
Where we embed or connect third-party tools, those providers may separately process information you provide through those features, subject to their own privacy notices and terms.
Specific restrictions applying to Google user data and YouTube API data are described in Section 2B.
5. Cookies
We use first- and third-party cookies and similar technologies for:
Essential functions — required for the site or application to operate and which cannot be disabled without affecting functionality;
Performance and analytics — to understand and improve use of our Services; and
Advertising — to measure and, where applicable, personalise marketing.
You can manage cookie preferences through our cookie-consent banner where shown, or through your browser settings. Disabling non-essential cookies will not stop the site from working but may reduce certain functionality.
6. International Data Transfers
Your information may be stored and processed in the UK and other countries where we or our service providers operate. Where we transfer personal data outside the UK or EEA, we rely on appropriate safeguards, such as the UK International Data Transfer Addendum or equivalent EU Standard Contractual Clauses, to protect it.
When you connect a third-party platform, information may also be transferred to and processed by that provider in accordance with its privacy policy and applicable data-transfer arrangements.
7. Data Retention and Deleting a Social Engine: Frame Account
We retain personal information only for as long as necessary for the purposes described in this Policy or as required by law, such as applicable tax and accounting requirements. Where retention is no longer necessary, we securely delete or anonymise the information or, where immediate deletion is not possible, such as within protected backup archives, isolate it from further routine processing until deletion can occur.
7.1 Requesting deletion of a Frame account
You may request deletion of your personal Frame account through the Delete Account option in your Frame account settings, where available, or by emailing [email protected] or [email protected]. We may ask you to verify your identity before processing the request.
When you request deletion and complete the required verification:
Your Frame account is permanently deleted from the active Frame service. You will no longer be able to use the account or access it through Frame.
We disconnect connected third-party accounts. Google and YouTube OAuth tokens and associated authorised YouTube API data are deleted promptly and no later than seven calendar days. They are not retained for an account-recovery period.
Associated personal information and content held by Frame is deleted or anonymised unless retention is necessary to comply with law, resolve disputes, prevent fraud or abuse, defend legal claims, or enforce our agreements.
Information in protected backups may remain until overwritten in the normal backup cycle. Backup information is isolated from normal use and is not restored except for disaster recovery, security, or legal reasons.
Deleting your Frame account does not delete your Google, YouTube, LinkedIn, TikTok, Facebook, Instagram, or other third-party account. It also does not automatically remove content that has already been published to a third-party platform. You must manage or delete that content through the relevant third-party service.
If you make a valid deletion or erasure request under applicable data-protection law, including UK GDPR, we will process it within the period required by that law. Where applicable law or a platform policy requires particular information to be deleted sooner than the timetable above, the earlier deadline will take precedence.
7.2 Disconnecting an account without deleting Frame
You may disconnect a supported social-media or content-platform account without deleting your Frame account. Disconnecting prevents Frame from carrying out new publishing actions for that account unless you reconnect it. Retention and deletion of YouTube credentials and API data following disconnection are described in Section 2B.
8. Security
We maintain technical and organisational measures designed to protect personal information against unauthorised access, alteration, disclosure, or destruction. These measures include appropriate access controls, credential protection, system monitoring, and controls over service providers. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Children’s Privacy
Our Services are not directed at, and are not intended for use by, anyone under 18. We do not knowingly collect personal information from children under 18. If we become aware that we have done so, we will take reasonable steps to delete that information and close any associated account. If you believe a child has provided us with personal information, please contact us using the details in Section 12.
10. Your Rights
Depending on your location, you may have rights to:
access the personal information we hold about you;
correct inaccurate information;
request deletion or restriction of processing;
object to certain processing, including direct marketing and the use of your information to train AI models;
withdraw consent at any time where processing is based on consent;
request portability of your data; and
complain to your local data-protection authority. In the UK, this is the Information Commissioner’s Office at ico.org.uk.
To exercise these rights, disconnect a connected account, request deletion of YouTube API data, or request deletion of a Frame account, contact us at [email protected] or [email protected].
California residents: You may have rights under applicable California law, including the “Shine the Light” law, Cal. Civ. Code § 1798.83, to request information about our disclosure of personal information to third parties for direct-marketing purposes. Contact us using the details above to exercise applicable rights.
Canada: Where applicable, we rely on express or implied consent to process your information, which you may withdraw at any time, subject to legal or contractual restrictions.
11. Changes to This Policy
We may update this Policy from time to time. Changes take effect once posted on this page, and the “Last updated” date above will be revised accordingly. We encourage you to review this Policy periodically.
12. Contact Us
DATAFORT Ltd / Newsguru.ai Ltd (trading as Creativeguru)
DataFort House
113 Walnut Tree Close
Guildford, Surrey
GU1 4UQ
United Kingdom
Email: [email protected] / [email protected]
Phone: 0800 45 44 35
© Creativeguru 2026. All rights reserved.
