CreatorKit Chrome Extension — Privacy Policy
Last updated: 12 August 2026
This policy covers the CreatorKit Chrome extension only. It is separate from the privacy policy for the CreatorKit web app (creatorkitapp.com), which is published at a different URL and governs that product. The extension is used with a CreatorKit account; account registration, billing, and anything you do on our website are governed by the web app's policy. This page covers what the extension does in your browser.
CreatorKit ("the extension", "we", "us") is a Chrome extension for Amazon affiliate creators. This policy explains exactly what the extension does and does not do with your data. The short version: the extension works alongside your own logged-in Amazon session, in your browser. The data it sends to our service is limited to your CreatorKit account sign-in (email and password, once, to sign you in), Amazon product IDs (ASINs), the IDs of Creator Connections campaigns you have accepted, the results of tasks you queue from the CreatorKit web app, and anonymous usage analytics and error reports (see "Usage analytics and error reports"). It never sends your Amazon password, cookies, or tokens, and your Amazon earnings figures never leave your browser.
- Extension privacy policy (this page):
https://www.creatorkitapp.com/privacy-ext - Web app privacy policy:
https://www.creatorkitapp.com/privacy
What CreatorKit does
CreatorKit runs on the Amazon Associates dashboard (https://affiliate-program.amazon.com) and, for
one feature, on your own Amazon storefront page (https://www.amazon.com/shop/…). Signed in to your
CreatorKit account, it:
- reads the list of your available Creator Connections / Sponsored Products offers from Amazon's own APIs, using your existing logged-in Amazon session, and lets you filter and sort them;
- lets you search a catalog of Creator Connections campaigns served by our own service;
- submits "accept" actions for the campaigns and offers you choose — individually or in bulk — to Amazon's own APIs;
- builds bulk-accept lists from sources you choose: your storefront's featured products, a CSV you upload or paste, or the products in your Amazon sales report;
- runs tasks you queue from the CreatorKit web app — for example, tapping "Accept" on your phone — the next time your desktop browser is available, using that same Amazon session in your browser;
- shows your 30-day Amazon earnings summary inside the panel (read from Amazon, displayed to you, never sent to us);
- helps you draft a social post for a product (caption + image), assembled in your browser; and
- shows badges on products that have an active Creator Connections campaign, and "Accepted" badges on campaigns you have already joined.
Your CreatorKit account
The extension is used with a CreatorKit account. When you sign in from the panel, your email address and
password are sent over HTTPS to our own backend (app.creatorkitapp.com), which returns a
sign-in token. The extension stores that token on your device and attaches it to its requests to our service —
so those requests are tied to your CreatorKit account. Your password is never stored by the extension. Your
subscription status is checked server-side to unlock the subscriber features. Signing out deletes the token from
your device.
Your Amazon credentials are different — we never touch them. The extension does not ask for, read, store, or transmit your Amazon password, session cookies, or account tokens. Requests to Amazon are made by your browser using the session you already have, exactly as when you use the site yourself. To complete actions you initiate — in the panel or queued from the web app — it reads an anti-CSRF token from Amazon's own pages, used only for those requests to Amazon, never sent elsewhere.
Data we send to our service
Beyond signing you in, the extension sends the following to our backend — and only this:
- Amazon product IDs (ASINs) — to look up which products have an active Creator Connections campaign (the badges) and to resolve the campaigns available for a bulk-accept list. Depending on the source you choose, these ASINs may come from the affiliate page you're viewing, your storefront sync, a CSV you provide, or your sales report. Only the product IDs are sent — never prices paid, order details, sales amounts, or earnings figures.
- IDs of the campaigns you have accepted (with their end dates) — synced from Amazon's own campaign export and from accepts you make in the extension, and stored in our database linked to your account, so campaigns you've joined show as "Accepted" wherever you use CreatorKit.
- Your A+ Campaigns search filters (price range, commission range, category, and so on) — sent as query parameters so our service can return matching campaigns.
- Tasks you queue from the web app, and their results — if you queue an accept or a storefront sync from the CreatorKit web app, the task and its outcome (which campaigns were accepted or skipped, or the sync's product and asset counts) are stored in your account so the web app can show them. While you're signed in, the extension periodically checks our service for queued tasks; that check also records when your desktop was last seen, so the web app can tell you why a task is still waiting.
- IP address: as with any internet request, our server (hosted on Amazon Web Services) necessarily receives the connection's IP address. We use it only to operate the service and to rate-limit abuse, not to profile you.
Data that stays in your browser
Everything else the extension touches is read from Amazon and used locally, and is never sent to us (beyond the counts and durations in the analytics below):
- your offer lists, product details, prices, and discounts;
- your earnings summary and sales reports — read to display your 30-day earnings and to derive the list of products you sold (only those products' ASINs are then used, as described above; the figures themselves never leave your browser);
- your storefront contents (the products featured in your videos, photos, and idea lists), fetched from your own storefront page and cached on your device;
- your Amazon creator ID and store/tracking IDs, used to build links and requests to Amazon;
- Amazon's anti-CSRF and reporting tokens, used only for the requests you initiate to Amazon.
Usage analytics and error reports
The extension sends anonymous usage analytics and error reports to PostHog, Inc. (a US analytics provider), which processes them on our behalf, so we can see which features get used and fix what breaks: which scans, accepts, syncs, and searches you run — including the text you type in the A+ Campaigns search — with counts and durations, plus technical error messages. Events are identified by your CreatorKit account's internal numeric user ID and a random device identifier that is rotated when you sign out — never your email, your Amazon credentials, cookies or tokens, page contents, or earnings figures. There is no autocapture and no session recording, and none of it needs extra browser permissions. As with any internet request, PostHog's servers receive the connection's IP address. This data is deleted along with your account on request.
Data stored on your device
CreatorKit uses Chrome's local storage on your device to store: your CreatorKit sign-in token and a cached session status (your email and subscription state), your Amazon creator ID and storefront handle, a cache of campaign-badge results (with automatic expiry), the set of campaigns you've accepted through the extension, your last storefront-sync result, a cached earnings summary, the state of an in-progress bulk-accept run (so it can resume if you close the panel), a random analytics identifier, and your UI preferences. A session-only flag remembers whether the panel was left open. You can clear all of it at any time by signing out and/or removing the extension.
Permissions
affiliate-program.amazon.com— the panel runs there: it reads your offers, campaign results, and reports, and submits the accept actions you choose to Amazon's own APIs.www.amazon.com— limited to your own storefront: a banner appears only onwww.amazon.com/shop/…when it's your storefront, and the storefront sync fetches your storefront's item list to build your bulk-accept product list.app.creatorkitapp.com— our own backend: sign-in, campaign lookups by ASIN, the A+ Campaigns catalog, and the accepted-campaigns sync, as described above.*.media-amazon.com— fetches a product image for the "Create Post" feature when you copy it; the image is processed in your browser and not sent to us.*.s3.amazonaws.com— Amazon delivers its own "download all campaigns" export as a file on Amazon S3; the extension downloads and reads that report in your browser to power the "Accepted" badges. Nothing else is fetched from this host.- Storage — to save the items listed in "Data stored on your device".
- Scripting — to show the panel in the dashboard tab when you click the extension icon.
Third parties
The extension uses one analytics service, PostHog, which processes usage events and error reports on our behalf as described above. There are no advertising or tracking networks in it, and we do not sell or share your data. Our backend is hosted on Amazon Web Services (AWS), which processes requests on our behalf as our infrastructure provider. Subscriptions are purchased and managed on our website — payment details are handled there, never in the extension, and are governed by the web app's privacy policy. The extension also contains links to our website (creatorkitapp.com); visiting those links is subject to that site's own policy.
Data retention and deletion
The data linked to your account (your email and the campaign IDs you've synced) is kept while your CreatorKit account exists; the analytics events and error reports are held by PostHog on our behalf. To delete your account and its data — including the person and events linked to your user ID at PostHog — contact us at the address below. Data stored on your device is removed when you remove the extension.
Relationship to Amazon
CreatorKit is an independent tool and is not affiliated with, endorsed by, or sponsored by Amazon. "Amazon" and related marks are trademarks of Amazon.com, Inc. or its affiliates.
Changes
We may update this policy; material changes will be reflected by the "Last updated" date above.
Contact
Questions about this policy: team@creatorkitapp.com