Privacy Policy

Last updated: 2026-01-01

This is a placeholder. Replace with your finalized policy before public launch.

1. What we collect

  • Account info — email, password hash, name, workspace name.
  • OAuth tokens — Facebook, Instagram and YouTube access tokens you authorize. Stored encrypted at rest.
  • Content — media you upload or link from Google Drive, scheduled captions, publishing logs.
  • Usage — pages viewed, actions taken, IP address for audit logging and rate limiting.

2. How we use it

We use your data solely to operate the Service: authenticate you, publish content on your behalf to the channels you authorize, compute analytics shown to you in the app, and contact you about the Service.

3. Sharing

We do not sell your data. We share it with sub-processors strictly necessary to operate the Service (cloud hosting, email delivery, OAuth providers) under contractual confidentiality obligations.

4. Retention

We retain account data while your workspace is active. After deletion we keep a 30-day recovery window, then permanently delete within 60 days. Audit logs are kept for 12 months for security.

5. Your rights

You can access, export, or delete your data at any time from Settings → Account. Email us if you need help.

6. Security

Passwords are bcrypt-hashed; OAuth tokens are encrypted at rest. Two-factor authentication is available from Account Settings.

7. Contact

Questions? Email privacy@socialburst.me.