Privacy Policy
Last updated 2026-09-25 · Draft, requires legal review. This draft describes how the service is built. The final version will name the data controller and a grievance contact.
What we collect
- Name, email, password (stored only as a secure hash), time zone: to provide your account.
- Workspace names, memberships, roles, invitation emails: so teams can work together.
- Terms acceptance time and version: proof of agreement.
- IP address and browser details in sessions and logs: security and abuse prevention.
- Contact form messages: to answer you.
- When publishing is available: connected account identifiers and access tokens, posts, media and schedules: to publish on your behalf.
We do not use advertising trackers or analytics cookies. The cookies we set are needed to keep you logged in and to protect forms.
How we protect it
Access tokens for social networks are encrypted at rest and never sent to your browser. Access inside a workspace is limited to its members.
Who we share it with
Only providers that run the service for us (hosting, database, email, file storage), under data processing agreements, and the social networks you ask us to publish to. We do not sell personal data.
How long we keep it
- Account and workspace data: while the account exists.
- Deleted accounts and workspaces: purged 30 days after deletion. Backups age out on their own schedule.
- Contact messages: 12 months (proposed).
- Logs: 30 days (proposed).
Your rights
You can access, correct, export or delete your data. Deleting your account is self-serve in Settings. For an export or anything else, contact us through the contact form; we answer within one month. These rights apply under the GDPR and India's Digital Personal Data Protection Act 2023, among others.
See also Data deletion.
