Privacy Policy
Last updated 13 August 2026
FoundryStack Social ("the Service") publishes and schedules content to social media accounts on behalf of the people who connect those accounts. This policy describes what the Service stores, why, and how to get it deleted.
What we collect
| Data | Why |
|---|---|
| Account identity — your email address, name, and sign-in identifier | To authenticate you and associate your content with your account. |
| Social account credentials — OAuth access and refresh tokens, app passwords, and bot tokens for each channel you connect | To publish on your behalf. Required for the core function of the Service. |
| Social account profile — the handle, display name, avatar, and account identifier of each connected channel | So you can tell your connected accounts apart in the interface. |
| Content you create — post text, uploaded media, schedules, and drafts | To store, schedule, and publish what you asked us to publish. |
| Publishing records — what was posted, when, to which account, whether it succeeded, and the resulting post identifier | To show you a history, to avoid publishing the same post twice, and to diagnose failures. |
| Analytics we retrieve — engagement and audience metrics for your posts and accounts, as provided by each platform | To show you performance reporting inside the Service. |
How credentials are protected
Every social account credential is encrypted at rest with AES-based authenticated encryption before it is written to our database. Credentials are decrypted only in memory, only at the moment a publish or analytics request is made, and are never written to logs, never returned by our API, and never displayed in the interface.
How we use it
We use your data only to operate the Service: to publish what you schedule, to show you your own content and results, and to keep your account secure. We do not sell personal data. We do not use your content or your connected accounts' data to train machine learning models. We do not share data with third parties for advertising.
When you use the Service's AI features, the text of the post you are writing is sent to our AI provider solely to generate or rewrite that content. It is not used to train their models.
Who we share it with
- The social platforms you connect. We transmit your content to the platform you asked us to publish to, using that platform's API.
- Infrastructure providers who host our servers, database, and media storage, strictly to run the Service.
- Legal authorities, only where we are legally required to.
Platform data
Data we retrieve from a social platform's API is used only to provide the Service to the account owner who connected it, is subject to that platform's own developer terms and policies in addition to this policy, and is deleted when the channel is disconnected.
Retention
- Credentials are deleted immediately when you disconnect a channel.
- Content, publishing records, and analytics are retained while your account is active, and deleted within 30 days of account deletion.
- Backups are purged on a rolling 30-day cycle, after which deleted data is gone from backups too.
Your rights
You can access, export, correct, or delete your data at any time. Disconnecting a channel deletes its credentials right away. Deleting your account removes everything described above. See Data deletion for how to request it, including if you no longer have access to your account.
Children
The Service is not directed at children under 13, and we do not knowingly collect their data.
Changes
If we change this policy materially, we will update the date above and notify account holders by email before the change takes effect.
Contact
Questions or requests: support@foundrystack.app.