Legal
Privacy Policy
Draft pending legal review
1. What we collect
Three categories, and nothing beyond what the service needs:
- Account data: name, email address, hashed password or federated identity, workspace membership and role.
- Content data: posts, drafts, media, brand kits, voice profiles, prompts, and analytics returned by the networks you connect.
- Operational data: log entries, IP address, device and browser information, and product events used for reliability and abuse prevention.
2. Social account credentials
Access and refresh tokens for connected networks are encrypted with envelope encryption and decrypted only inside the worker processes that make the publishing calls. They are never exposed to the browser and never written to logs.
3. Why we process it
Each purpose maps to a lawful basis:
- To provide the service you asked for — performance of a contract.
- To keep the service secure, prevent abuse and debug failures — legitimate interests.
- To send product and billing email — performance of a contract; marketing email only with consent.
- To meet tax, accounting and legal obligations — legal obligation.
4. AI processing
Content you submit for generation is sent to the model providers listed as subprocessors, solely to return the output you requested. Your content is not used to train shared models.
The weekly learning loop analyses your workspace’s own published analytics and updates your workspace’s own prompts and voice profiles. It does not read across workspaces.
5. Subprocessors
We use infrastructure and service providers for hosting, storage, email delivery, payments and model inference. The current list, with locations and roles, is maintained alongside the DPA and must be completed before launch.
6. Retention
Account and content data is retained while the workspace is active and for a limited grace period after cancellation so it can be recovered or exported. Operational logs are retained on a short rolling window. Financial records are retained as long as tax law requires.
7. Your rights
Depending on where you live you may have rights of access, correction, deletion, portability, restriction and objection, and the right to complain to a supervisory authority.
Requests can be made from account settings or by email; we respond within the statutory window.
8. International transfers
Where data is transferred outside its region of origin, we rely on the appropriate transfer mechanism for that route. The specific mechanisms are listed with the subprocessor list.
9. Contact
Privacy questions and rights requests can be sent to the address on this page. The named controller entity and any EU or UK representative must be completed before launch.