Legal

Privacy Policy

Last updated June 23, 2026

bluo (“bluo”, “we”, “us”, or “our”) is a customer relationship manager built for talent agencies. We help agencies manage their creator roster, deal pipeline, brand contacts, media kits, reports, invoices, and earnings, and we let creators connect their social accounts so their agency can present accurate, up-to-date analytics. This Privacy Policy explains what information we collect, how we use it, and the choices you have.

This policy applies to the bluo web application, the talent portal, and our website at bluo.io. It includes specific detail about data we receive from Meta Platforms (Instagram and Facebook) and other social platforms, because those connections are central to how bluo works.

Information we collect

Information you give us

  • Account and agency details. Your name, email address, password or sign-in credentials, agency name, and team members you invite.
  • Roster and CRM data. Information you add about creators, brands, and contacts, including names, categories, handles, email addresses, deals and campaigns, deal values, commission rates, invoices, and earnings.
  • Content you create. Media kits, pitch decks, reports, notes, and files you build or upload inside bluo.

Information from connected social accounts

When a creator (or an agency acting with the creator’s authorization) connects a social account to bluo, we access and store data from that platform through its official API, only to the extent the connecting user authorizes during the consent flow. Connectable platforms include Instagram and Facebook (Meta Platforms), YouTube, and Twitch. From a connected account we may collect:

  • Profile information. Account ID, username or handle, display name, profile picture, profile link, and audience size (followers or subscribers).
  • Content and media. Metadata about recent posts and media, such as captions, media type, thumbnails or links, and publish dates.
  • Insights and engagement metrics. Aggregate performance figures such as likes, comments, reach, impressions, saves, shares, and views.
  • Authorization tokens. The access and refresh tokens the platform issues, which we store securely so we can keep analytics in sync until the account is disconnected.

We request the minimum scope needed to display these analytics. We do not collect private messages, and we do not post, comment, or take actions on your behalf on any connected platform.

Information we collect automatically

  • Authentication and session data. We use session cookies to keep you signed in. The talent portal can sign creators in with a one-time code sent to their email.
  • Log and usage data. IP address, browser and device type, pages viewed, and timestamps, used to operate, secure, and improve the service.

How we use information

  • To provide and operate bluo, including the roster, deals, invoices, and talent portal.
  • To build and keep media kits, decks, and reports accurate by syncing the public analytics of connected social accounts.
  • To power the in-app AI assistant, which drafts pitches, bios, media plans, and answers questions using your own workspace data when you ask it to.
  • To authenticate users, secure accounts, prevent abuse, and provide support.
  • To send service communications such as sign-in codes and account notices.

How we use Meta Platform data

Data we receive from Instagram and Facebook is used solely to display the connected creator’s own analytics inside their agency’s workspace and in the media kits, decks, and reports that agency creates. We comply with the Meta Platform Terms and the Meta Developer Policies. We do not sell Meta Platform data, we do not use it for advertising or profiling, and we do not transfer it to data brokers. Use of information received from Meta APIs follows the Meta Platform Terms, including any limited-use requirements that apply.

How we share information

We do not sell your personal information. We share it only as follows:

  • With your agency.A creator’s connected-account data is available to the agency the creator authorized, so they can build and share that creator’s materials.
  • With brands, at your direction. Analytics appear to brands only inside the media kits, decks, or reports an agency chooses to share.
  • With service providers (subprocessors). Vendors who process data on our behalf under contract, listed below.
  • For legal reasons. When required by law, to enforce our terms, or to protect the rights and safety of users and the public.
  • In a business transfer. In connection with a merger, acquisition, or sale of assets, subject to this policy.

Subprocessors

  • Cloud hosting provider. Application hosting and content delivery.
  • Managed database provider. Hosts the database where your data is stored.
  • AI model provider. Powers the AI assistant. Prompts and the relevant workspace data are processed to generate a response when you use the assistant.
  • Meta, Google, and Twitch platform APIs. Source the public analytics of accounts you connect.
  • Email delivery provider. Sends transactional email such as sign-in codes and account notices.

Data retention

We keep your information for as long as your account is active and as needed to provide the service. Connected social data stays in sync only while the account is connected. Disconnecting a social account stops syncing and removes the stored authorization tokens. Removing a creator from a roster unlinks their connected accounts and deletes the associated analytics, media kit, deck, and report content. When you close your account, we delete or anonymize your personal data within 30 days, unless we are required to retain it for legal or accounting reasons.

Your choices and rights

  • Disconnect a platform anytime.In the talent portal, open Socials and disconnect the account. This revokes bluo’s access and stops further syncing.
  • Access, correct, export, or delete. You can request a copy of your data, ask us to correct it, or ask us to delete it.
  • Depending on where you live, you may have rights under the GDPR, UK GDPR, or CCPA, including the right to object to or restrict certain processing.

How to revoke access and delete your data

To revoke bluo’s access to a connected Instagram or Facebook account, you can either disconnect it in the talent portal under Socials, or remove bluo from your account settings on the platform itself (for Meta, in your Instagram or Facebook Apps and Websites settings). To request deletion of the personal data we hold about you, email privacy@bluo.io from the address associated with your account. We will confirm and complete verified deletion requests within 30 days.

Security

We protect your data with encryption in transit and at rest, role-based access controls, a talent portal that is isolated from agency-only numbers, and activity logging of changes to sensitive records. No method of storage or transmission is perfectly secure, but we work to protect your information using industry-standard safeguards.

International transfers

bluo is operated from, and stores data on infrastructure located in, the United States. If you access bluo from outside the United States, your information may be transferred to and processed in the United States and other countries where our service providers operate.

Children

bluo is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.

Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the date above and, where appropriate, notify you in the product or by email.

Contact us

Questions about this policy or your data? Email us at privacy@bluo.io.