Privacy Policy
Last updated: August 20, 2026
Pheme (“we”, “us”) values your privacy. This Privacy Policy describes the information we collect, how we use, share, and protect it, and the rights available to you when you use the Pheme websites (pheme.work, app.pheme.work, creator.pheme.work, creators.lessie.ai) and our two browser extensions — the Pheme creator-analysis extension and the Pheme Account Verification extension (together, the “Service”).
The Service is built for businesses and professionals engaged in creator marketing. Its features include creator search, similar-creator discovery, contact email lookup, fake-follower detection, AI-assisted outreach with automated follow-up, online contracting and delivery tracking, performance data tracking, and a credit-based billing system. This Policy applies across all of these features. The Service also has a creator-facing side at creator.pheme.work (previously creators.lessie.ai), where creators maintain their own profile and verify that they own the social accounts listed on it.
By using the Service you agree to this Policy. If you do not agree, please stop using the Service.
1. Information we collect
Account information: your email address, collected when you sign up and sign in. If you sign in with Google, we receive the basic profile details you authorize through Google OAuth (such as your email address, name, and avatar); if you sign in with an email verification code, we process the issuance and validation records for that code. We do not receive or store your Google password.
Usage data: your activity within the Service, including creator searches and filter criteria, similar-creator lookups, contact email lookups, fake-follower detection requests, favorites and creator lists, the delivery and follow-up status of outreach campaigns, milestones in contracting and delivery tracking, and your credit acquisition and consumption ledger. We use this data to operate features, meter billing, and maintain activity records.
Content you provide: instructions and prompts you submit to the AI outreach and expert Agent features, email templates and outreach copy, draft collaboration terms, approval decisions, and contact details you upload or maintain. You are responsible for having the lawful right to use such content.
Device and log information: technical data generated automatically when you access the Service, such as IP address, browser type and version, operating system, language settings, access times and page paths, and crash or error logs, used for security, troubleshooting, and service improvement.
Public creator information: creator search (a database covering 50 million+ creators), similar-creator discovery, and fake-follower detection operate on creator information that is publicly visible on social platforms. If you are a creator and wish to correct or remove indexed public profile data relating to you, contact us using the details at the end of this Policy.
2. Cookies and similar technologies
We use cookies and similar technologies to operate the Service. Strictly necessary cookies maintain your signed-in session — session credentials are stored in HttpOnly cookies that page scripts cannot read, reducing the risk of credential theft. Functional cookies remember preferences such as your language.
Strictly necessary cookies cannot be switched off within the Service, because the Service does not function without them. You may view, restrict, or delete cookies through your browser settings, but disabling essential cookies will end your session and some features may stop working.
If we later deploy analytics cookies or similar technologies, we will update this Policy and, where applicable law requires, obtain your consent or provide an opt-out.
3. Data handling in our browser extensions
We publish two browser extensions, described separately below. Neither of them collects, reads, stores, or transmits any social platform cookies, passwords, session tokens, or access tokens — not a single byte. Neither reads the platforms' localStorage or sessionStorage. Neither contains remotely hosted code: every file they execute ships inside the extension package reviewed by the Chrome Web Store. Neither sends data to any third party, analytics service, or advertising network. The browser permissions each one requests are limited to what its own functions require.
(a) Pheme creator-analysis extension. It runs only on TikTok, Instagram, and YouTube, to recognize the creator page you are viewing and provide analysis. It reads only publicly visible creator information on the page (such as handle, follower count, and public content metrics) and sends it to our servers to generate analysis results such as creator profiles and fake-follower scores. It does not collect your browsing history, does not read any page outside the three sites above, and does not collect data unrelated to its declared purpose. Data it stores locally is limited to your sign-in state and preferences.
(b) Pheme Account Verification extension. Its single purpose is to confirm that you own the social media accounts you added to your creator profile at creator.pheme.work. It does nothing until you explicitly start a verification, either in the web app or from the extension's own popup. At that moment it opens (or reuses) a tab showing your own profile page on the platform you asked to verify, reads that page, and sends a short report to our API. It runs on exactly these sites and no others: youtube.com, instagram.com, tiktok.com, x.com (and its alias twitter.com), facebook.com, linkedin.com, and our own domains creator.pheme.work and creators.lessie.ai. It does not request access to all websites.
What the Account Verification extension sends: the one-time challenge value issued by our server for that verification; the account handle being verified; optionally your public display name; optionally your public follower count; and optionally the names of the owner-only interface elements found on the page (the element names only, never their contents). Nothing else is sent.
Never collected by the Account Verification extension: cookies, passwords, session tokens or access tokens of any platform; email addresses, direct messages, follower or friend lists, or post contents; your browsing history; anything from tabs other than the profile page being verified; or any data from websites outside the list above.
Stored on your device by the Account Verification extension: in session storage (memory only, cleared when the browser closes), a short-lived, narrow-scope verification token issued by us that can call only our three verification endpoints and cannot read your email or reach any other part of your account; in local storage, the status and result text of your most recent verification, the cached list of accounts awaiting verification (platform and handle), and an optional developer-only backend address override.
Uninstalling either extension removes its locally stored data; your account data remains managed server-side under this Policy. A successful account verification is recorded against your creator profile as a verification badge, together with the handle, the method used, and the timestamp; verification challenges expire automatically. You may delete a social account from your creator profile at any time, which removes its verification record.
4. AI outreach, emails sent on your behalf, and automated processing
When you use AI outreach and automated follow-up, we send emails on your behalf to the creators you designate. To do so, we process recipient email addresses, subject lines and message bodies, send times, and delivery and reply status, in order to run the outreach workflow, show you its progress, and drive automated follow-ups.
You decide, or confirm, the content and recipients of outreach emails. As the originator of those emails, you are responsible for ensuring that your acquisition and use of recipient contact details and your sending of commercial email comply with applicable law and relevant platform rules; we process the related data on your instructions.
The expert Agent feature generates recommendations or performs tasks based on your instructions and the business data in your account (such as candidate creator lists and prior correspondence). For key steps such as outbound sends and contract signing, the workflow includes an approval checkpoint that requires your confirmation before execution; approval records are retained for auditability.
Fake-follower detection and data tracking operate on creators' public data and on your own campaign data, and their outputs are shown only to your account.
5. Google user data (Gmail and Google Sign-In)
This section applies to all data we receive through Google APIs (“Google user data”) and, where it is more specific or more restrictive, prevails over the rest of this Policy for that data. Our use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
Google Sign-In: we receive only the basic profile details you authorize (email address, name, and avatar) and use them solely to create and authenticate your account.
Connected Gmail accounts (creator side): creators may optionally connect a Gmail account at creator.pheme.work. We request the following permissions, each used only for the user-facing feature described here: read access (gmail.readonly), to display your mailbox inside the app and to identify brand-collaboration inquiries for you; modify access (gmail.modify), used solely to mark a message as read when you open it in the app; and send and compose access (gmail.send and gmail.compose — both optional, and you may untick them on Google's consent screen), to send replies you have written or explicitly approved and to save drafts to your own Gmail Drafts folder. If you decline the optional permissions, reading continues to work and only the sending features are disabled.
We do not store your email content. Messages, threads, and attachments are retrieved from Gmail in real time each time you view them and are never copied to our servers, databases, or backups. We store only your OAuth tokens (encrypted at rest with AES-256-GCM), your Gmail address and connection status, and — for threads our system identifies as brand-collaboration deals — the conclusions we derive (such as brand name, quoted price, and negotiation status) together with the thread identifier, never the underlying message content.
Where our brand-deal features process Gmail content with the assistance of large-language models, limited message excerpts are sent to our AI infrastructure provider strictly to generate the results shown to you (for example, recognizing a collaboration inquiry or drafting a reply for your approval). We contractually and technically restrict this processing — including by programmatically requiring model routes whose data policy prohibits retention of inputs — so that Google user data is never retained by any model provider and is never used to create, train, or improve any machine-learning or artificial-intelligence model, whether generalized or otherwise, by us or by any third party.
We do not use Google user data for advertising or marketing; we do not sell it; we do not use it for market research, credit assessment, or any purpose unrelated to the user-facing features described above; and we do not allow humans to read it except with your explicit consent, where necessary for security or abuse investigation, to comply with applicable law, or where the data has been aggregated and anonymized for internal operations. The general statements elsewhere in this Policy about aggregated analysis, product improvement, new purposes, and business transfers apply to Google user data only within these limits; any transfer of Google user data as part of a merger or acquisition would additionally require your explicit consent.
You can disconnect Gmail at any time on the Mailboxes page, which deletes the stored tokens, or revoke our access in your Google Account settings at https://myaccount.google.com/permissions. The same no-storage discipline described above also applies to mailboxes you connect through Microsoft Outlook or IMAP.
6. How we use information
We use the information we collect to provide, maintain, and improve the Service; to run the search, analysis, outreach, contracting, and delivery-tracking workflows you initiate; to meter credits, manage billing, and prevent abuse; to keep accounts and systems secure, including risk detection and troubleshooting; and to send service notifications where you have agreed.
We may use de-identified or aggregated data — which no longer identifies any individual — for statistical analysis and product improvement. This does not apply to Google user data, whose use is limited to what Section 5 describes.
We collect only what is necessary for these purposes and do not use your data for unrelated purposes. If we intend to use your information for a new purpose not covered by this Policy, we will seek your consent first.
7. How we share information; third-party services
We do not sell your personal information.
We share necessary information only: (1) with service providers that support the Service — cloud infrastructure and hosting providers, payment processors that handle credit purchases (your payment card details are processed directly by them), and email delivery infrastructure used to deliver verification codes and the outreach emails you initiate — in each case limited to what is required to perform their services and bound by confidentiality and data protection obligations; (2) where required by law or by lawful requests from judicial or governmental authorities; and (3) where necessary to protect our or our users' legitimate rights.
When you sign in with Google, Google processes your information as an independent provider under its own privacy policy; we receive only the basic profile details within the scope you authorize.
If we are involved in a merger, acquisition, or asset transfer, your information may be transferred as part of that transaction. We will require the successor to remain bound by this Policy and will notify you of material changes.
8. Storage, cross-border transfers, and retention
Your information may be stored on servers located both inside and outside your jurisdiction. Where data is transferred across borders, we follow applicable legal requirements and use reasonable measures, such as contractual commitments, to keep it protected to a standard no lower than that of this Policy.
We retain your information only as long as necessary for the purposes described in this Policy. Retention periods are determined by the ongoing need to provide the Service to you, statutory retention requirements for records such as the credit ledger and transaction history, and limitation periods for dispute resolution and legal claims.
After account deletion, we delete or anonymize your personal information within a reasonable period. Where the law requires longer retention (for example, transaction and billing records), we continue to protect that data — including through segregated storage — for the statutory period and delete or anonymize it thereafter.
9. Security
We apply industry-standard safeguards, including encryption in transit (HTTPS), access controls and the principle of least privilege, HttpOnly cookie storage for session credentials, and auditing of internal access.
Keep your sign-in email and verification codes secure. Actions taken through your authenticated session are treated as taken by you or with your authorization; contact us immediately if you suspect unauthorized use of your account.
No method of transmission or storage over the internet is completely secure, and we cannot guarantee absolute security. If an incident compromises the security of your personal information, we will take remedial measures and provide notice as required by applicable law.
10. Your rights and account deletion
Subject to applicable law, you may access, correct, or delete your personal information, obtain a copy of it, and withdraw consent; withdrawal does not affect the lawfulness of processing carried out before it.
You can manage some information yourself in your account settings, or submit a request using the contact details at the end of this Policy. We will verify your identity before acting and respond within a reasonable period; for requests that are manifestly repetitive or exceed a reasonable scope, we may charge a reasonable fee or decline with an explanation.
To delete your account, contact us at support@pheme.work. After deletion you will no longer be able to use the Service, and the data in your account will be deleted or anonymized in accordance with Section 8.
11. Children
The Service is intended for businesses and adult users and is not directed at minors; we do not knowingly collect minors' personal information.
If we learn that we have collected a minor's personal information without guardian consent, we will delete it promptly. If you believe we may hold information about a minor, please contact us using the details at the end of this Policy.
12. Changes to this policy
We may update this Policy from time to time to reflect changes in features, legal requirements, or our data practices. Updates take effect when published, and the “Last updated” date at the top of this page will change accordingly.
For material changes — such as substantive changes to processing purposes, sharing recipients, or your rights — we will notify you via a site announcement or other prominent means. Continued use of the Service after an update takes effect constitutes acceptance of the updated Policy.
13. Contact us
For any questions, comments, or requests about this Policy or your personal information — including exercising the rights described in Section 10 — contact: support@pheme.work.
We will respond within a reasonable period after verifying your identity. If you are dissatisfied with our response, you may also lodge a complaint with a competent supervisory authority where applicable law so provides.