CreatorKit Chrome Extension — Privacy Policy

Last updated: 12 August 2026

This policy covers the CreatorKit Chrome extension only. It is separate from the privacy policy for the CreatorKit web app (creatorkitapp.com), which is published at a different URL and governs that product. The extension is used with a CreatorKit account; account registration, billing, and anything you do on our website are governed by the web app's policy. This page covers what the extension does in your browser.

CreatorKit ("the extension", "we", "us") is a Chrome extension for Amazon affiliate creators. This policy explains exactly what the extension does and does not do with your data. The short version: the extension works alongside your own logged-in Amazon session, in your browser. The data it sends to our service is limited to your CreatorKit account sign-in (email and password, once, to sign you in), Amazon product IDs (ASINs), the IDs of Creator Connections campaigns you have accepted, the results of tasks you queue from the CreatorKit web app, and anonymous usage analytics and error reports (see "Usage analytics and error reports"). It never sends your Amazon password, cookies, or tokens, and your Amazon earnings figures never leave your browser.

What CreatorKit does

CreatorKit runs on the Amazon Associates dashboard (https://affiliate-program.amazon.com) and, for one feature, on your own Amazon storefront page (https://www.amazon.com/shop/…). Signed in to your CreatorKit account, it:

Your CreatorKit account

The extension is used with a CreatorKit account. When you sign in from the panel, your email address and password are sent over HTTPS to our own backend (app.creatorkitapp.com), which returns a sign-in token. The extension stores that token on your device and attaches it to its requests to our service — so those requests are tied to your CreatorKit account. Your password is never stored by the extension. Your subscription status is checked server-side to unlock the subscriber features. Signing out deletes the token from your device.

Your Amazon credentials are different — we never touch them. The extension does not ask for, read, store, or transmit your Amazon password, session cookies, or account tokens. Requests to Amazon are made by your browser using the session you already have, exactly as when you use the site yourself. To complete actions you initiate — in the panel or queued from the web app — it reads an anti-CSRF token from Amazon's own pages, used only for those requests to Amazon, never sent elsewhere.

Data we send to our service

Beyond signing you in, the extension sends the following to our backend — and only this:

Data that stays in your browser

Everything else the extension touches is read from Amazon and used locally, and is never sent to us (beyond the counts and durations in the analytics below):

Usage analytics and error reports

The extension sends anonymous usage analytics and error reports to PostHog, Inc. (a US analytics provider), which processes them on our behalf, so we can see which features get used and fix what breaks: which scans, accepts, syncs, and searches you run — including the text you type in the A+ Campaigns search — with counts and durations, plus technical error messages. Events are identified by your CreatorKit account's internal numeric user ID and a random device identifier that is rotated when you sign out — never your email, your Amazon credentials, cookies or tokens, page contents, or earnings figures. There is no autocapture and no session recording, and none of it needs extra browser permissions. As with any internet request, PostHog's servers receive the connection's IP address. This data is deleted along with your account on request.

Data stored on your device

CreatorKit uses Chrome's local storage on your device to store: your CreatorKit sign-in token and a cached session status (your email and subscription state), your Amazon creator ID and storefront handle, a cache of campaign-badge results (with automatic expiry), the set of campaigns you've accepted through the extension, your last storefront-sync result, a cached earnings summary, the state of an in-progress bulk-accept run (so it can resume if you close the panel), a random analytics identifier, and your UI preferences. A session-only flag remembers whether the panel was left open. You can clear all of it at any time by signing out and/or removing the extension.

Permissions

Third parties

The extension uses one analytics service, PostHog, which processes usage events and error reports on our behalf as described above. There are no advertising or tracking networks in it, and we do not sell or share your data. Our backend is hosted on Amazon Web Services (AWS), which processes requests on our behalf as our infrastructure provider. Subscriptions are purchased and managed on our website — payment details are handled there, never in the extension, and are governed by the web app's privacy policy. The extension also contains links to our website (creatorkitapp.com); visiting those links is subject to that site's own policy.

Data retention and deletion

The data linked to your account (your email and the campaign IDs you've synced) is kept while your CreatorKit account exists; the analytics events and error reports are held by PostHog on our behalf. To delete your account and its data — including the person and events linked to your user ID at PostHog — contact us at the address below. Data stored on your device is removed when you remove the extension.

Relationship to Amazon

CreatorKit is an independent tool and is not affiliated with, endorsed by, or sponsored by Amazon. "Amazon" and related marks are trademarks of Amazon.com, Inc. or its affiliates.

Changes

We may update this policy; material changes will be reflected by the "Last updated" date above.

Contact

Questions about this policy: team@creatorkitapp.com