Data Processing Policy

Lawful Basis for Processing (GDPR)

We process your personal data on the following legal bases under GDPR Article 6:

  • Consent (Art. 6(1)(a)): When you grant OAuth access to your social media accounts, you explicitly consent to data collection for dashboard functionality.
  • Contractual Necessity (Art. 6(1)(b)): Processing is necessary to provide the service you signed up for — managing your social media accounts.
  • Legitimate Interest (Art. 6(1)(f)): We process minimal analytics data to improve the service, with your privacy balanced against our legitimate interest.

Your Rights (GDPR & CCPA)

Under GDPR and CCPA, you have the following rights:

RightDescriptionHow to Exercise
AccessRequest a copy of all data we hold about youSettings → Export Data
RectificationCorrect inaccurate personal dataSettings → Profile
ErasureDelete all your data permanentlyDelete Account
PortabilityReceive your data in a machine-readable formatCompliance → Export
RestrictionRestrict processing of your dataContact us
ObjectionObject to processing based on legitimate interestContact us
Opt-Out of Sale (CCPA)We do NOT sell personal dataN/A

Data We Process per Platform

PlatformData CategoriesPurpose
Meta (FB/IG)Page insight metrics, comments, messages, post contentAnalytics display, content management, inbox
Google (YouTube)Video analytics, subscriber count, commentsAnalytics display, comment management
PinterestPin metrics, board info, follower countAnalytics display, pin creation
X (Twitter)Tweet metrics, follower count, DMsAnalytics display, posting, inbox

Data Retention Schedule

Data TypeRetention PeriodAfter Deletion
OAuth tokensUntil disconnected or expiredImmediately destroyed
Analytics cache30 days rollingAuto-purged
Audit logs90 daysAuto-purged
User profileUntil account deletionImmediately destroyed
Media uploadsUntil user deletesRemoved from Cloudinary within 24hrs
Backups7 days after deletionPurged from backup rotation

Data Breach Notification

In the unlikely event of a data breach affecting your personal data, we will:

  • Notify the relevant supervisory authority within 72 hours (GDPR Art. 33)
  • Notify affected users without undue delay if the breach is likely to result in a high risk to their rights and freedoms
  • Document the breach and remediation steps in our internal incident log

Sub-Processors

ServicePurposeLocation
SupabaseDatabase & authenticationUS / EU (configurable)
CloudinaryMedia storage & deliveryUS / EU regions
VercelHosting & edge functionsGlobal edge network

Data Protection Officer

For data protection inquiries, rights requests, or to file a complaint: