Privacy Policy

Last updated: January 19, 2026

SocialSpy ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

Information We Collect

Information You Provide

  • Account Information: Email address, business name, and website URL when you create an account.
  • Business Data: Information about your business that you provide or that we collect from your public website to help generate content.
  • Content: Posts, images, and other content you create using our service.
  • Communications: Messages you send to us for support or feedback.

Information Collected Automatically

  • Usage Data: How you interact with our service, including pages visited, features used, and actions taken.
  • Device Information: Browser type, operating system, and device type.
  • IP Address: Used for security, rate limiting, and approximate location.

Information from Third Parties

  • Website Scraping: We analyze publicly available information from your business website to understand your offerings and generate relevant content.
  • Social Media Connections: If you connect your Instagram or Facebook accounts, we receive access tokens to publish content on your behalf.

Social Media Account Access

SocialSpy allows you to connect your social media accounts to publish content directly. This section explains what access we request and how we use it.

OAuth Permissions We Request

When you connect your Instagram or Facebook account via Meta's OAuth flow, we request the following permissions:

PermissionWhat It AllowsWhy We Need It
instagram_basicRead your Instagram profile info and mediaTo display your connected account and verify the connection
instagram_content_publishPublish posts to your Instagram accountTo post content you've approved to your feed
pages_show_listList Facebook Pages you manageTo let you select which Page to connect
pages_read_engagementRead Page engagement dataTo show basic analytics on your posts
pages_manage_postsCreate and manage Page postsTo publish content you've approved to your Page

Data We Access

When you connect your social accounts, we access:

  • Profile Information: Your account username, profile picture, and account ID
  • Page Information: Names and IDs of Facebook Pages you manage
  • Publishing Capability: The ability to post content on your behalf (only when you explicitly approve a post)

We do NOT access: Your private messages, friend lists, personal timeline, photos you haven't shared with us, or any data from accounts you haven't explicitly connected.

How to Revoke Access

You can disconnect your social media accounts and revoke our access at any time:

  1. Within SocialSpy: Go to Settings → Connected Accounts → Click "Disconnect" next to any account
  2. Via Instagram: Go to Settings → Apps and Websites → Remove SocialSpy
  3. Via Facebook: Go to Settings → Apps and Websites → Remove SocialSpy

When you revoke access, we immediately delete your access tokens and can no longer post to or access your social accounts. Previously published posts remain on your social accounts (you can delete them directly on the platform).

How We Use Your Information

  • To provide and improve our AI-powered content generation service
  • To publish content to your connected social media accounts
  • To send you magic link emails for authentication
  • To communicate about your account, updates, and promotional offers
  • To prevent fraud and abuse of our service
  • To comply with legal obligations

AI and Content Generation

We use artificial intelligence (Claude by Anthropic) to generate social media content based on your business information. Your data is sent to Anthropic's API for processing. We do not use your content to train AI models. Generated content is stored in your account and is not shared with other users.

Data Sharing

We do not sell your personal information. We may share data with:

  • Service Providers: Third-party services that help us operate (hosting, email, analytics, AI processing).
  • Social Platforms: When you connect accounts and publish content.
  • Legal Requirements: When required by law or to protect our rights.

Our Service Providers

ProviderPurposeData Shared
Anthropic (Claude)AI content generationBusiness info, prompts
NeonDatabase hostingAll account data
CloudinaryImage storageUploaded images
ResendEmail deliveryEmail addresses
VercelHostingUsage logs
FirecrawlWebsite analysisYour website URL

Data Retention

We retain your data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we need to retain it for legal purposes.

Data Security

We implement appropriate security measures including encryption in transit (HTTPS), secure authentication (magic links, JWT), and access controls. However, no method of transmission over the Internet is 100% secure.

Your Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Delete your data
  • Export your data in a portable format
  • Opt out of marketing communications
  • Withdraw consent for data processing

To exercise these rights, contact us at privacy@socialspy.app.

Cookies

We use essential cookies to maintain your session and remember your preferences. We do not use third-party tracking cookies or sell data to advertisers.

Children's Privacy

Our service is not intended for users under 18 years of age. We do not knowingly collect data from children.

International Data Transfers

Your data may be processed in the United States where our service providers are located. By using our service, you consent to this transfer.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.

Third-Party Platform Disclaimer

SocialSpy is not affiliated with, endorsed by, or sponsored by Meta Platforms, Inc. (Facebook, Instagram), or any other social media platform. Instagram® and Facebook® are registered trademarks of Meta Platforms, Inc. Our use of their APIs is subject to their respective terms and policies.

Contact Us

If you have questions about this Privacy Policy, please contact us at:

Email: privacy@socialspy.app