Rights management
Clear the rights before the post sells anything.
Three ways to capture creator consent, four tracked statuses with expiry, and a tamper-evident audit row behind every decision.
No code. Free plan, no card.
Capture paths · last 30 days
0
Hashtag
organic
0
Registration
link · v3
0
Manual
offline doc
Recent activity
- 09:14pending
Hashtag ingest · @sky.b
system
- 09:14awaiting
Awaiting signature · v3
system
- 09:42approved
Signed · 2-year licence
@sky.b
- 12:08cleared
Reviewed · brand-safe
judge_ana
- 28drevoked
Revoked via email
creator
- 28dhidden
Removed from 4 surfaces
system
01
Three decision sources, one ledger
Consent arrives by hashtag (auto-grant on entry), by a DM reply, or by a registration form. Whichever path a creator takes, the decision lands in the same ledger with its source recorded.
Rights management
Every decision logged with its source, reviewer and expiry
Approved
3
Pending
1
Rejected / revoked
2
Default expiry
2 yrs
| Creator | Channel | decision_source | Status | Expires |
|---|---|---|---|---|
| @sky.b | hashtag | approved | 2028-06-12 | |
| @ines.wears | TikTok | response | pending | — |
| @marcus.k | registration | approved | 2028-03-02 | |
| @lena.j | YouTube | response | rejected | — |
| @ayo.runs | hashtag | expired | 2026-08-30 | |
| @priya.k | registration | revoked | — |
02
Statuses that expire on their own
Pending, approved, rejected and revoked, plus a computed Expired state when the licence window closes. The default window is two years; the ledger flags what is about to lapse.
The main line
Post ingested, no consent yet. Hidden from widgets by default.
Creator signed. confirmation_from_user: true. Surfaces in widgets and exports.
Approval is the only gate. There is no separate “published” toggle to forget.
Where it can fork
- pending →rejected
Creator declined. Post hidden permanently. Logged for audit + analytics.
- approved →revoked
Creator pulled consent after the fact. Idukki removes the post from every surface within minutes.
- approved →expired
Default 2 years from signature. Triggers a renewal-request flow before the deadline.
03
An audit row you can hand to legal
Creator handle, channel, email, timestamp, comment, consent document and expiry date on every record. Export it as CSV for a GDPR, CCPA or DSA request.
How Idukki works
One post, collected to attributed
Collect
Rights
Tag
Display
Measure
Result: 3 orders, $74.28 attributed to one post.
04
Rights state travels with the post
The content queue shows the rights state on every tile, so a post without consent never reaches a widget by accident, and a revoked one drops out everywhere at once.
Content
Everything collected, moderated and tagged before it reaches a widget
- ReelWROGN Men Silver-Toned Watch@sky.bApproved
- VideoAirlift Overcoat Brown@ines.wearsPending
- PhotoJute Tote Bag@marcus.kApproved
- ShortTennis Cardigan Spring/Summer@lena.jRequested
- ReviewBodycon Sunscreen SPF 50Google ReviewsNot needed
- PhotoHeldWhite Sweater Green Stripes@ayo.runsHeld
How it works, from switched on to paying for itself.
- Step 1
Post lands in the queue
From hashtag ingestion, manual upload or a competition entry, every UGC post starts in pending state.
- Step 2
Request consent
A branded hashtag entry, a standalone registration link or a manual offline capture. Multi-language templates for the form.
- Step 3
Decision recorded
Approved, rejected or revoked, with the decision source, the reviewer and the consent document attached.
- Step 4
Expiry tracked
Two-year default. The ledger computes Expired and surfaces what is about to lapse so you renew before it matters.
“Idukki is truly an all-in-one solution for brands looking to leverage UGC effectively. We would highly recommend it to any business aiming to enhance customer trust and engagement through authentic content.”
Three things this tier does not do.
The in-app rights manager covers the brand workflow. Running rights for an ad network or a DSP needs the Rights API tier, which adds tamper-evident audit chains, per-region templates and webhook events.
- 01
Multi-language templates ship in English first
The in-app registration templates are English-only today; per-region templates are on the Rights API tier.
- 02
GDPR right-to-be-forgotten is operator-driven
Revocations propagate to every widget at once; full creator data deletion is a per-business operator action.
- 03
Audit export is JSON-first
The per-collection audit log exports as JSON (and CSV for legal requests). Signed-PDF and W3C verifiable-credential exports live in the Rights API tier.
The questions to ask before you switch it on.
What counts as consent in Idukki?
A hashtag entry under published campaign terms, a direct reply to a rights request, or a signed registration form. Each is stored as a decision_source on the record, with the consent document and timestamp.
How long does a licence last?
Two years by default. You can set a different window per collection, and the ledger computes an Expired state when the window closes.
Can I revoke rights after approval?
Yes. Revoking a record removes the post from every widget it appears in and logs the revocation with reviewer and reason.
Is this GDPR and CCPA compliant?
The workflow is built for GDPR, CCPA and DSA requests: every decision is logged with its source and document, and the audit log exports as CSV.
Which plans include rights management?
Every plan, including Free. Rights management and rights requests are listed for every band in the comparison table at /pricing.
Unsure whether a post is cleared?
Bring one campaign and we will walk the consent path with you, end to end.