Privacy Policy

Effective date: 7 September 2026

Draft placeholder. This page is a starting template, not legal advice. Replace the bracketed fields with your real business/contact details and have this reviewed against applicable law (e.g. GDPR, India's DPDP Act, CCPA) before relying on it — including before submitting it as your app's privacy policy URL to Meta, Google, or LinkedIn during OAuth app review.

1. Who we are

Autopubly ("we", "us") is operated by [Company Legal Name]. This policy explains what data we collect when you use the Autopubly dashboard and API, why we collect it, and how you can control it.

2. Data we collect

  • Account data: name, email, password (stored as a bcrypt hash, never in plain text), and, if you sign in with Google, your Google profile ID and email.
  • Connected social account data: when you connect Instagram, Facebook, X, YouTube, or LinkedIn, we store the account's provider ID, display name/handle, and an OAuth access token (and refresh token, where the platform issues one). Tokens are encrypted at rest with AES-256-GCM and used only to publish the posts you create and to keep the connection alive (refreshing an expiring token). We never see or store your social account password.
  • Content you create: post captions, scheduling times, and media you upload or generate, stored so the Service can publish them on your behalf and show you a history.
  • Payment data: processed directly by Razorpay. We store the resulting invoice number, plan, amount, and payment status — we do not receive or store your card, UPI, or bank details.
  • Usage and device data: IP address, approximate geographic location (derived from IP via GeoIP, not GPS), browser/user-agent, and audit-log events (e.g. login, plan changes) for security and abuse prevention.
  • Cookies: httpOnly session cookies (apb_at, apb_rt) used solely to keep you signed in. We do not use third-party advertising or tracking cookies. See our Cookie Policy for the full list.

3. How we use your data

  • To operate the Service: authenticate you, publish scheduled posts, and show usage/history;
  • To process payments and manage your subscription and credit balance;
  • To send transactional email (verification, password reset, receipts) via our SMTP provider;
  • To detect fraud, abuse, and security incidents (audit logs, rate limiting);
  • To improve the Service, using aggregated, non-identifying usage patterns.

We do not sell your personal data, and we do not use your content to train AI models.

4. Who we share data with

We share data only with the processors needed to run the Service, each acting under their own privacy policy:

  • Meta, Google (YouTube), X, and LinkedIn — to publish the posts you schedule to your connected accounts, and nothing else;
  • Cloudinary — hosts uploaded/generated media so platform APIs can fetch it over HTTPS;
  • Clipdrop — processes text prompts you submit to generate AI images, when you use that feature;
  • Razorpay — processes subscription payments;
  • Our email provider — delivers transactional email on our behalf.

We disclose data to law enforcement only when legally required to do so.

5. Data retention

We retain account and content data for as long as your account is active. If you delete your account, we delete or anonymize your personal data and revoke stored OAuth tokens within [X days], except where we must retain records (e.g. payment/invoice records) to meet legal or tax obligations.

6. Your rights

Depending on your location, you may have the right to access, correct, export, or delete your personal data, and to withdraw consent for a connected account at any time by disconnecting it in Settings. To exercise these rights, contact us at privacy@autopubly.com. You can also revoke Autopubly's access directly from each platform's own app-permissions page (e.g. Facebook > Settings > Apps, Google Account > Security > Third-party access).

7. Security

We use industry-standard safeguards: encrypted transport (HTTPS), encrypted-at-rest OAuth tokens (AES-256-GCM), hashed passwords (bcrypt), httpOnly/rotating session cookies, and rate limiting. No system is perfectly secure, and we cannot guarantee absolute security of data transmitted to us.

8. Children's privacy

The Service is not directed at children under 18, and we do not knowingly collect their data.

9. International transfers

Our infrastructure and processors may be located outside your country. By using the Service, you consent to your data being processed in [hosting country/region] and by the processors listed above, wherever they operate.

10. Changes to this policy

We may update this policy from time to time. Material changes will be notified via email or an in-app notice before they take effect.

11. Contact

Questions about this policy or your data? Contact privacy@autopubly.com.