Privacy Policy

Last updated 13 August 2026

FoundryStack Social ("the Service") publishes and schedules content to social media accounts on behalf of the people who connect those accounts. This policy describes what the Service stores, why, and how to get it deleted.

What we collect

DataWhy
Account identity — your email address, name, and sign-in identifier To authenticate you and associate your content with your account.
Social account credentials — OAuth access and refresh tokens, app passwords, and bot tokens for each channel you connect To publish on your behalf. Required for the core function of the Service.
Social account profile — the handle, display name, avatar, and account identifier of each connected channel So you can tell your connected accounts apart in the interface.
Content you create — post text, uploaded media, schedules, and drafts To store, schedule, and publish what you asked us to publish.
Publishing records — what was posted, when, to which account, whether it succeeded, and the resulting post identifier To show you a history, to avoid publishing the same post twice, and to diagnose failures.
Analytics we retrieve — engagement and audience metrics for your posts and accounts, as provided by each platform To show you performance reporting inside the Service.

How credentials are protected

Every social account credential is encrypted at rest with AES-based authenticated encryption before it is written to our database. Credentials are decrypted only in memory, only at the moment a publish or analytics request is made, and are never written to logs, never returned by our API, and never displayed in the interface.

How we use it

We use your data only to operate the Service: to publish what you schedule, to show you your own content and results, and to keep your account secure. We do not sell personal data. We do not use your content or your connected accounts' data to train machine learning models. We do not share data with third parties for advertising.

When you use the Service's AI features, the text of the post you are writing is sent to our AI provider solely to generate or rewrite that content. It is not used to train their models.

Who we share it with

Platform data

Data we retrieve from a social platform's API is used only to provide the Service to the account owner who connected it, is subject to that platform's own developer terms and policies in addition to this policy, and is deleted when the channel is disconnected.

Retention

Your rights

You can access, export, correct, or delete your data at any time. Disconnecting a channel deletes its credentials right away. Deleting your account removes everything described above. See Data deletion for how to request it, including if you no longer have access to your account.

Children

The Service is not directed at children under 13, and we do not knowingly collect their data.

Changes

If we change this policy materially, we will update the date above and notify account holders by email before the change takes effect.

Contact

Questions or requests: support@foundrystack.app.