Privacy Policy

Revision: DRAFT · updated: —

Draft. The technical part below describes how the product actually behaves — that has been checked against the code. The legal wording (legal bases, retention periods, DPAs with subprocessors) has to be closed by a lawyer: this is GDPR territory, and the list of subprocessors must match the ones actually connected at the time of publication.

1. Who is responsible for the data

[full legal entity name], [NIP], [address]. Data questions: [email].

2. What data we process

  • Account — name, email, password stored as a hash. The password is never stored in plain form anywhere.
  • Brand data — what you upload: business description, products, images, video, content plan.
  • Social data — access tokens, messages, comments and post metrics for the accounts you connected.
  • Technical — error and usage logs, needed to run the service and to account for the credits charged.

3. Separation between brands

Each brand's data is stored separately rather than in one shared pile: library, posts, inbox, leads, analytics and media belong to a specific brand. A team member sees only the brands they have been given access to.

4. Who the data is passed to

To carry out your task, data is passed to providers:

  • Model providers — the task text and the images needed to generate.
  • Social platforms — what you publish or send.
  • Object storage — media files.
  • Payment provider — payment details. Card details never reach us and are not stored in our system.

[Named list of subprocessors with jurisdictions and DPAs — to be completed before publication.]

5. How long we keep it

  • Account data — for as long as the account exists.
  • Generated media — 90 days by default, then deleted automatically.
  • Temporary publishing files — 1 day.
  • Spend logs — kept for reconciliation and invoicing.

6. Client links

Approvals and reports can be opened by someone without an account through a link. Such a link is tied to one brand, has an expiry date and can be revoked. It is not indexed by search engines. Whoever holds the link sees the data, so treat it like a password.

7. Your rights

Access, rectification, erasure, portability, restriction of processing, objection. Requests to [email]. Deleting a brand removes its media from storage.

8. Security

Connections are encrypted. The session cookie is not readable by JavaScript and is sent only over a secure connection. Passwords are stored as hashes. Sign-in attempts are rate-limited. Share-link tokens are stored only as hashes and cannot be recovered from storage.

9. Cookies

Technical only: the session and your theme choice. There are no advertising or tracking cookies.