/ privacylegal

Privacy Policy.

Effective July 27, 2026. This page describes what data we collect, how we use it, and the specific way we handle data accessed through the Google API services.

1. Who we are

GC Spoofer (the "Service") is operated by gh0stc0de and hosted at gcspoofer.com. For any questions about this policy, contact support@gcspoofer.com.

2. What we collect

The Service stores only what's needed to operate it:

  • Account data: email address, name, phone number, Telegram username, signup IP and device fingerprint. Used to authenticate you and to prevent duplicate / abusive signups.
  • Content metadata: file names, captions, hashtags, durations, and storage paths for the videos and images you process through the Service. The Service does NOT durably store the raw video/image bytes — those live in your own Dropbox / Google Drive / Bunny.net storage and are only fetched in cache during sanitization.
  • API keys you supply: OpenRouter, Google OAuth tokens, Bunny.net / S3 credentials. Stored encrypted-at-rest on our database and only used to make calls on your behalf.
  • Operational logs: request logs, job status, error traces. Retained for up to 90 days for debugging.

3. How we use Google user data — Limited Use Disclosure

GC Spoofer's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, when you connect a Google account we request:

  • .../auth/spreadsheets — required to create and edit the per-influencer "Daily Plan" spreadsheet that powers the Distribution feature.
  • .../auth/drive.file — required to set sharing permissions on spreadsheets the Service itself created. This scope cannot see files we did not create.

We use Google API data solely to:

  • Create the per-influencer distribution spreadsheet in your Google Drive on your explicit request.
  • Append daily content rows to that spreadsheet according to the quotas you configure.
  • Read back the "Used ✓" checkbox column to mark variants as used in our internal database.
  • Apply the sharing permission you select (anyone-with-link editor, or kept private).

We do not transfer Google user data to any third party, use it to serve advertisements, allow humans to read it (except by you, or with your explicit permission, or as needed for security and debugging), or use it for any purpose other than the features described above.

4. How we use Meta platform data (Instagram, Threads, Facebook)

When you connect an Instagram, Threads, or Facebook account through Meta's official login, GC Spoofer receives and stores an access token, the account identifier, and the account username. We use this data only to publish the content you schedule to the account you connected, at your direction, and to show the connection status in your dashboard.

  • We request the minimum permissions needed to publish content — for example instagram_business_content_publish and threads_content_publish.
  • We do not receive or store your Instagram, Threads, or Facebook password. Authentication happens on Meta's own login screen.
  • We do not sell Meta platform data, use it to serve advertising, or share it with third parties. Your content is transferred only to Meta's own APIs to carry out the publishing action you requested.

You can disconnect a Meta account at any time in Settings, which revokes and deletes the stored access token, and you can remove GC Spoofer's access directly from Instagram / Meta → Apps and websites. To request deletion of data associated with a Meta account, email support@gcspoofer.com.

5. Where data is stored

All Service data is stored on a server we operate in Germany (Hetzner Online GmbH, Falkenstein). Backups are encrypted and retained for 30 days. We do not maintain offices in jurisdictions that would compel disclosure of customer data.

6. Who has access

Only the platform administrator account (blackroseentertainment333@gmail.com) and engineers acting under that account can read tenant data, and only when required to investigate a support request or a production incident. All such access is recorded in our audit log and surfaced to tenants on request.

We do not sell, rent, or share tenant data with any third party other than the strictly-necessary subprocessors listed in §6.

7. Subprocessors

The Service depends on these third parties to operate:

  • Meta Platforms, Inc. — Instagram, Threads, and Facebook APIs, used to publish the content you schedule to the accounts you connect
  • Hetzner Online GmbH — server hosting (Germany)
  • Brevo (Sendinblue) — transactional email (France)
  • NowPayments.io — crypto invoicing (Netherlands)
  • OpenRouter / Anthropic / Google / OpenAI — AI inference for caption generation (only when you supply your own API key)
  • Bunny.net / Amazon S3 — variant content delivery (only when you supply your own CDN credentials)

8. Your rights

You can at any time:

  • Export your tenant data (influencers, videos, variants, payments) — email us and we will produce a JSON export within 7 days.
  • Disconnect Google by visiting Settings → Integrations → Disconnect, or by revoking access at myaccount.google.com/permissions.
  • Delete your account by emailing support@gcspoofer.com — all tenant data is purged within 30 days.

9. Changes to this policy

If we make material changes we will notify active tenants by email at least 14 days before the changes take effect. The effective date at the top of this page always reflects the version currently in force.