Privacy Policy
This policy describes what Social Growth stores about you, why, who else is involved, and how you can have it removed.
Effective date: [REQUIRED: effective date]
1. Who we are
Social Growth is a web application that helps you create, review, schedule and publish social content for your brand and learn from how it performs. It is operated by [REQUIRED: legal entity name], of [REQUIRED: registered postal address]. In this policy, “we” means that operator.
Privacy questions and requests: [REQUIRED: privacy and support contact email].
2. Information we handle
Account information
You sign in with Google. We store your email address, your name and your Google account identifier so we can recognise you when you return. We never receive or store your Google password, and the application has no password of its own. A session cookie keeps you signed in (see Cookies).
Workspaces and brand information
Everything you create lives in a workspace. We store the workspace name, the members you invite (their email addresses and roles), the brand profile and preferences you enter, competitor accounts and research sources you add, and the brief, plan and settings you choose for content.
Connected social accounts
When you connect an Instagram professional account (and, where offered, a Facebook Page), we store the platform account identifier, username, display name, profile picture link, account type and the permissions you granted. We use the connection only for that workspace. We never ask for your Instagram or Facebook password.
OAuth credentials
When you approve the connection on Instagram, Meta gives us an access token. We store it encrypted (AES-256-GCM) with a key that is held in the application’s secret configuration and is not stored in the database. The token is never shown in the interface or returned by the application’s API, and it is used only by our servers to read your account data and to publish content you have approved.
Content you create and content we generate
We store the drafts, captions, hashtags, images, Reel projects, festival and recurring-post plans and the review, approval and scheduling history for your workspace, together with a record of what was published and when. Content generated for you is a draft: it is your decision whether to approve and publish it.
Analytics
For accounts you connect, we read from the platform your account’s profile figures (such as follower and media counts), the list of your published posts, and performance metrics for the account and for individual posts (for example reach, views, likes, comments, shares, saves and interactions, as Meta returns them). We store snapshots so the Analytics views can show change over time, and we use them to suggest what to post next.
Uploaded media
Brand images and other files you upload, and images and videos generated for you, are stored in private object storage under your workspace. The storage is not public: files are reached through time-limited signed links. When a post is published, Instagram needs to download the file, so we give it such a link for that post.
Technical and security records
Our servers use your IP address to apply rate limits. We keep an audit record of important actions (for example connecting or disconnecting an account, inviting a member, requesting deletion) and operational logs. Your browser also requests web fonts from Google’s font service when a page loads, which discloses your IP address to Google.
3. How we use it
- To sign you in, keep workspaces separate from one another and enforce member roles.
- To generate content you ask for, run safety checks on it, and schedule and publish what you approve to the accounts you connected.
- To show analytics and to learn from your results so later suggestions fit your account.
- To detect abuse, apply rate limits, keep records of security-relevant actions, and fix faults.
The application has no advertising features and no integration with advertisers or data brokers. We do not use data received from Meta for advertising, and we do not sell it.
4. Data from Instagram and Meta
Social Growth uses Instagram API with Instagram Login. We ask you to approve only these permissions:
instagram_business_basic— read your professional account’s profile, posts and (with that access) their performance figures.instagram_business_content_publish— publish content to your account that you have approved.
We use data received from Meta only to provide those features to the workspace that connected the account. Meta data is stored per workspace, and an account that is active in one workspace cannot be connected to another at the same time. Meta’s own use of your data is governed by Meta’s terms and policies, not this one.
Disconnecting an account in Social Growth permanently deletes our stored token and stops all publishing for it. It does not by itself tell Meta to withdraw the authorisation, so to remove the app’s access on Meta’s side, also remove it in your Instagram account’s settings for connected apps. Posts already published to Instagram are not removed by us. See Data Deletion.
5. AI processing
We use OpenAI’s services to write captions, hashtags and content briefs, to generate images and narration for Reels, and to check text and images for safety before they can be published. To do this we send OpenAI the information needed for the request: for example the brand details and instructions you entered, the draft being written or checked, relevant performance context, and images to be checked. We do not send your OAuth tokens or passwords to any AI provider.
AI output can be wrong, repetitive or unsuitable, so it is always a draft for you to review. We keep records of AI use (which model was used, token counts and cost, and safety results) for cost and audit purposes; these records reference the content rather than copying its text. How OpenAI handles the data it receives is governed by OpenAI’s own terms and settings and is outside our control.
7. How credentials and data are protected
- Access tokens are encrypted at rest and never returned to the browser.
- Every request is checked against your workspace membership and role; workspaces cannot read one another’s data.
- Uploaded and generated files are kept in private storage, not a public bucket.
No system is perfectly secure. We do not claim any security certification or third-party compliance attestation.
8. How long we keep data
Workspace data is kept until you delete it. You can disconnect an account, delete a workspace, or delete your account (see Data Deletion). Some records are kept after deletion: an anonymised placeholder for a deleted workspace or account, audit records of security-relevant actions, the record of the deletion request itself, and AI usage and cost records with their links to you removed.
Fixed retention periods have not yet been defined for every category of data. [REQUIRED: retention period for each category of data] Copies in backups are kept for [REQUIRED: backup retention period] and are outside the application’s deletion process.
10. Your choices and rights
You can edit workspace and brand information in the application, disconnect accounts at any time, and remove data as described on the Data Deletion page. Depending on where you live, you may have further legal rights over your personal data (for example to access or correct it). To use them, write to [REQUIRED: privacy and support contact email].
11. Where data is processed
Data is processed on the infrastructure of the providers in section 6. Data is hosted in: [REQUIRED: regions where data is hosted]. Those providers, and OpenAI and Meta, may process data in other countries.
12. Changes and contact
We will update this page when the product’s handling of data changes, and change the effective date above. Contact: [REQUIRED: privacy and support contact email], [REQUIRED: legal entity name], [REQUIRED: registered postal address].