Privacy policy
Last updated 19 August 2026
What this is
BOSS MGMT Group is a creator management company. This platform is the system it runs that business on. Three kinds of people use it: BOSS MGMT staff, the creators BOSS represents, and contacts at brands and agencies BOSS has shared something with.
It is an internal business tool, not a consumer product. There is no public sign up, nothing on it is advertised or sold to the public, and an account exists only because BOSS MGMT created it.
This page says what the platform holds about people, what it does with it, and how to have it removed.
Who we are
This platform is operated by BOSS AGENCY LIMITED, a company incorporated in Hong Kong, CR number 3293167 and BR number 75458418, of Unit 2904 to 05, 29th Floor, Universal Trade Centre, 3 Arbuthnot Road, Central, Hong Kong. BOSS AGENCY LIMITED is the data controller for the records described on this page, and trades as BOSS MGMT Group.
Anything on this page, and any request to see, correct or delete what we hold about you, goes to ai@bossmgmtgrp.com.
What the platform holds
Creators BOSS represents, or is considering approaching. Name, handle, country, the categories they make videos in, links to their channels and social profiles, publicly visible channel figures such as subscriber and view counts, a business contact email address, notes BOSS staff write, files and links attached to their record, and the commercial terms of work BOSS arranges for them. Most of it comes from BOSS staff, from the creator themselves during onboarding, or from public sources such as the YouTube Data API and a channel's own public pages.
Contacts at brands and agencies. Name, work email address, the company they work for, which rosters and media kits BOSS has shared with them, what they marked against a creator on one of those, and notes BOSS staff write about the conversation.
BOSS MGMT staff. Name, work email address, role, and a log of the actions they take in the platform, which exists so BOSS can see who changed what.
Google account data
Read this section closely if you are a creator deciding whether to connect your YouTube channel.
Connecting is optional. Nothing else in the platform depends on it, and a creator who never connects still has a full record and a media kit.
What we ask for. Two scopes, and only these two. Both are read only.
- https://www.googleapis.com/auth/youtube.readonly
- https://www.googleapis.com/auth/yt-analytics.readonly
Read only means what it says. The platform cannot upload, edit, delete, publish or comment on anything, cannot change a channel's settings, and never acts as the creator anywhere. It holds no write permission of any kind.
What we read with them. The channel id. The channel's subscriber count and lifetime view count. And one report covering the last 90 days: total views, watch time, average view duration, the share of viewers by country, and the share of viewers by age band and by gender.
Everything the YouTube Analytics API returns here is aggregate. It is percentages and totals for a channel. The platform does not receive, and cannot receive, the identity of any individual viewer.
What we store. The aggregate figures above are saved on that creator's record in our database, with the date they were last refreshed. Separately, the access token and refresh token Google issues are stored in a single row belonging to that creator, so the figures can be brought up to date later without asking them to sign in again. Those tokens are used for nothing except calling the two APIs named above.
What we use it for. Keeping a creator's media kit and roster entry accurate, so a brand sees real audience figures rather than an estimate, and so BOSS can answer a brand asking for, say, a channel whose audience is mostly in Germany.
Who can see it. BOSS MGMT staff signed into the internal workspace. The aggregate figures also appear wherever BOSS presents that creator to a brand: on the creator's media kit, on roster pages BOSS shares with a named contact through a private link, and behind the audience filters on the openly published creators directory. When a BOSS manager asks the internal assistant about a creator, that creator's aggregate audience figures form part of the request sent to our AI provider. The access token and refresh token appear in none of those places. They never leave our server and are never shown in the interface.
What we do not do with it. We do not sell it. We do not use it for advertising and we do not build advertising profiles. We do not use it to train an artificial intelligence model of our own. We do not pass it to anyone beyond what is described on this page.
Limited use. This application's use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements.
How to disconnect. Two routes. Either one is enough on its own, and neither of them requires waiting on a person at BOSS MGMT.
- In the platform, with one button. A creator holding an onboarding link from BOSS MGMT opens it and presses "Disconnect my YouTube channel". BOSS MGMT staff can press the same button on that creator's record. Either way the platform asks Google to withdraw the permission, then deletes the stored access token and refresh token, then deletes the audience figures that were read using them. Before it happens, the page lists exactly what will be deleted and what will be kept; afterwards it says what Google answered, including if Google did not confirm. Audience figures a creator gave us some other way, such as a Studio export or a screenshot they sent, did not come from this permission and are not touched. Every disconnect is recorded with the date and who did it.
- At Google. Remove this application at myaccount.google.com/permissions. From that moment we can read nothing further from the channel. That is Google's own control and it takes effect immediately; it does not by itself delete what is already stored here, so follow it with the button above, or email ai@bossmgmtgrp.com and we will do it.
How long we keep it. The platform has no automatic deletion schedule. Google data stays until it is deleted with the disconnect button above, or on request, or until BOSS deletes the creator's record, which removes it with them. We do not commit to a fixed number of months, deliberately: a period we publish and then miss is worse than an honest description of what actually happens. What we hold about a creator we represent is kept for as long as we represent them, and afterwards for as long as the contract and tax records require. Records about a prospect we never signed are deleted on request and are reviewed periodically.
Where the data is held
The platform runs on Vercel. Records are held in a managed PostgreSQL database and uploaded files in Vercel Blob storage. Email such as a sign in link is sent through Resend. Some features summarise text and read screenshots using Anthropic's Claude API. BOSS also runs HubSpot as its customer relationship system, and creator and deal records move between the two.
These services hold data outside Hong Kong, and one of them may not be where you would guess, so it is written down rather than implied. The database sits in Amazon Web Services in Sydney, Australia. Vercel, Resend, Anthropic and HubSpot are United States companies and process data on infrastructure in the United States and in other countries they operate in. Each is engaged as a processor acting on our instructions under its own data processing terms.
If you would like to know where a particular record about you is held, ask at ai@bossmgmtgrp.com and we will tell you.
Cookies and what is recorded
Two cookies, neither for advertising and neither for tracking.
- A sign in cookie, set when a BOSS MGMT user signs in, which is what keeps them signed in.
- A preference cookie remembering whether they collapsed the sidebar.
There are no advertising cookies and no third party analytics scripts on the pages BOSS shares outside the company.
On a roster BOSS shares with a named contact, the platform does record which creators that recipient opened and what they marked, so the BOSS manager can follow the conversation up. That is recorded against the link BOSS issued, not against a cookie or a person's browser.
Your choices
Ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it, at ai@bossmgmtgrp.com.
Because BOSS AGENCY LIMITED is incorporated in Hong Kong, the Personal Data (Privacy) Ordinance applies to what we hold. Data protection law also follows the person rather than only the company, so if you are in the United Kingdom or the European Union the UK GDPR or the GDPR may give you rights over your record as well, and if you are in California or another state with its own privacy statute that law may too. We do not ask you to work out which one covers you. Whichever it is, ask us for a copy of what we hold, ask us to correct it, or ask us to delete it, and we will do it or tell you plainly why we cannot
Changes
If this page changes, the date at the top changes with it. Our terms of use cover what the platform may be used for.