1. Information We Collect
We collect information to provide, maintain, and improve our services.
1.1 Information You Provide
- Account Information: Name, email, company name, and password.
- Billing Information: Payment details processed securely by Stripe.
- Profile Information: Photo, bio, website, social media handles.
- Content: Posts, captions, images, videos, and comments.
- Communications: Support tickets, survey responses, and correspondence.
1.2 Information Collected Automatically
- Usage Data: Pages visited, features used, time spent, clicks.
- Device Information: IP address, browser type, OS, device type.
- Log Data: Server logs, error reports, performance data.
1.3 Information from Third Parties
- Social Media Platforms: Profile info, post history, engagement data via APIs.
- Payment Processors: Stripe shares transaction status and billing details.
- Authentication Services: Google and Apple SSO share basic profile info.
2. How We Use Your Information
- Service Delivery: Account management, payments, scheduling, AI content, analytics.
- Service Improvement: Usage analysis, debugging, AI model training (anonymized).
- Communications: Service updates, billing reminders, product announcements.
- Security: Fraud detection, abuse prevention, access control.
- Legal Compliance: Complying with applicable laws and regulations.
Note: We do not use your personal content to train AI models for third-party use. AI features use your data only within your account.
3. Data Sharing and Disclosure
We do not sell your personal information. We may share data with:
- Service Providers: AWS, GCP, Stripe, SendGrid, PostHog - contractually bound to protect data.
- Social Media Platforms: Content is transmitted to platforms per your instructions.
- Legal Requirements: When required by law or to protect our rights.
- Business Transfers: In case of merger or acquisition, with notification.
4. Data Security
- Encryption: TLS 1.3 in transit, AES-256 at rest.
- Access Controls: Role-based access, MFA, regular audits.
- Infrastructure: SOC 2-compliant data centers (AWS Frankfurt, GCP Belgium).
- Monitoring: 24/7 threat detection, intrusion prevention, pen testing.
- Incident Response: Notification within 72 hours of confirmed breach.
5. Your Rights and Choices
Depending on your jurisdiction, you may have rights to:
- Access: Request a copy of your data.
- Correction: Correct inaccurate data.
- Deletion: Delete your data (subject to legal retention).
- Portability: Export your data from Settings.
- Objection: Object to processing for direct marketing.
Exercise rights at Privacy Settings or contact us.
GDPR: EEA/UK users may lodge complaints with local data authorities. DPO: contact us
6. Cookies and Tracking
See our Cookie Policy for full details. Summary:
| Type | Purpose | Duration |
| Essential | Authentication, security | Session / 1 year |
| Functional | Preferences, settings | 1 year |
| Analytics | Usage tracking | 13 months |
| Marketing | Advertising (opt-in) | 90 days |
7. Data Retention
We retain data while your account is active and for 90 days after cancellation. Billing records retained 7 years for tax purposes.
8. Children Privacy
Not intended for users under 16. We do not knowingly collect children data. Contact us if concerned.
9. International Data Transfers
Servers located in EU (Frankfurt, Brussels). Transfers safeguarded via Standard Contractual Clauses.
10. Changes to This Policy
Material changes communicated via email and in-app notification.