Privacy Policy
ContentGenerator ("we", "us", or "our") provides tools for small businesses to draft, refine, and schedule social marketing content. This Privacy Policy explains what information we collect, how we use it, whom we share it with, and the choices you have. By creating an account or connecting a social platform, you agree to this policy.
Information we collect
We collect information you provide directly, information generated when you use the service, and limited information from third-party platforms you choose to connect.
- Account information: email address and authentication credentials managed through our identity provider (Supabase Auth).
- Workspace and profile data: workspace name, brand kit fields (business name, tone, audience notes, and similar marketing context you enter).
- Content you create: drafts, chat messages used to refine drafts, scheduled posts, ad campaign details, checklist answers, and past post examples you add or import.
- Uploaded files: images or other media you attach to drafts or campaigns, stored in our cloud storage bucket.
- Connected platform data: when you connect Instagram, Meta Ads, TikTok, or TikTok Ads, we receive OAuth tokens and basic account identifiers (such as platform user IDs and usernames) needed to publish or manage content on your behalf. We only request scopes required for the features you enable.
- Usage and technical data: server logs, integration telemetry (for example OAuth success or failure events), and generation usage counters (daily or monthly limits).
- Cookies and session data: HTTP-only session cookies used to keep you signed in and short-lived OAuth state cookies during platform connection flows.
How we use information
We use the information above to:
- Provide, operate, and improve ContentGenerator.
- Authenticate you and secure your workspace.
- Generate and refine marketing copy using AI models (see Third-party services).
- Schedule and publish content to platforms you connect, when you request it.
- Enforce usage limits, prevent abuse, and troubleshoot errors.
- Comply with law and respond to lawful requests.
Legal bases (EEA/UK users)
Where applicable, we process personal data on the basis of: (a) performance of our contract with you; (b) your consent (for example when you connect a social account or enable optional imports); (c) our legitimate interests in operating and securing the service, balanced against your rights; and (d) compliance with legal obligations.
Third-party services
We rely on service providers that process data on our behalf. They may only use data as needed to provide their services to us:
- Supabase — authentication, database, and file storage.
- Cloudflare — application hosting and delivery.
- OpenRouter — routes requests to large language model providers for AI-assisted drafting and chat. Prompts may include your brand context and draft content; do not submit sensitive personal data you do not want processed by AI providers.
- Meta (Facebook / Instagram) — when you connect Instagram or Meta Ads, Meta processes data under its own terms and privacy policy.
- TikTok — when you connect TikTok or TikTok Ads, TikTok processes data under its own terms and privacy policy.
How we share information
We do not sell your personal information. We share information only in these circumstances:
- With platform providers (Meta, TikTok, and similar) when you direct us to publish or manage content on your connected accounts.
- With infrastructure and AI vendors listed above, under data-processing agreements or their standard terms.
- When required by law, regulation, legal process, or to protect rights, safety, and security.
- In connection with a merger, acquisition, or asset sale, with notice where required by law.
Data retention
We retain account and workspace data while your account is active. If you disconnect an integration, we delete or invalidate the associated OAuth tokens. You may delete drafts, examples, and other content through the app. Server logs and telemetry are retained for a limited period for security and debugging. We may retain certain records where required by law.
Security
We use industry-standard measures including encrypted transport (HTTPS), server-side storage of OAuth tokens, workspace-scoped access controls, and HTTP-only session cookies. No method of transmission or storage is completely secure; please use a strong, unique password and revoke integrations you no longer need.
Your choices and rights
Depending on where you live, you may have the right to:
- Access, correct, or delete personal data we hold about you.
- Disconnect social integrations at any time from the Integrations page, which revokes our access tokens.
- Export or delete content you stored in your workspace through in-app actions.
- Object to or restrict certain processing, or withdraw consent where processing is consent-based.
- Lodge a complaint with your local data protection authority.
Children's privacy
ContentGenerator is not directed to children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will delete it.
International transfers
We and our service providers may process data in the United States and other countries. Where required, we use appropriate safeguards for cross-border transfers.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the effective date. Material changes may be communicated through the app or by email where appropriate. Continued use after changes take effect constitutes acceptance of the updated policy.
Contact us
For privacy questions or requests, contact us using the email address on your account or through in-app Settings. For a summary of data stored in your workspace, visit Settings → Data & privacy after signing in.