This is a placeholder. Replace with your finalized policy before public launch.
1. What we collect
- Account info — email, password hash, name, workspace name.
- OAuth tokens — Facebook, Instagram and YouTube access tokens you authorize. Stored encrypted at rest.
- Content — media you upload or link from Google Drive, scheduled captions, publishing logs.
- Usage — pages viewed, actions taken, IP address for audit logging and rate limiting.
2. How we use it
We use your data solely to operate the Service: authenticate you, publish content on your behalf to the channels you authorize, compute analytics shown to you in the app, and contact you about the Service.
3. Sharing
We do not sell your data. We share it with sub-processors strictly necessary to operate the Service (cloud hosting, email delivery, OAuth providers) under contractual confidentiality obligations.
4. Retention
We retain account data while your workspace is active. After deletion we keep a 30-day recovery window, then permanently delete within 60 days. Audit logs are kept for 12 months for security.
5. Your rights
You can access, export, or delete your data at any time from Settings → Account. Email us if you need help.
6. Security
Passwords are bcrypt-hashed; OAuth tokens are encrypted at rest. Two-factor authentication is available from Account Settings.
7. Contact
Questions? Email privacy@socialburst.me.