Privacy Policy

Last updated: August 2026

1. What we collect

SocialPilot processes the following categories of data on behalf of your business when you connect your social media accounts:

2. How we use it

We use the data above solely to provide the SocialPilot service to you and your customers:

We do not sell your data to third parties. We do not use your customer messages or knowledge base content to train any AI model.

3. Third-party processors

4. Data retention

We retain messages, conversations, and knowledge base content for as long as your SocialPilot account is active. You can delete any individual conversation, knowledge base document, or your entire account at any time via the dashboard or by emailing privacy@socialpilot.tech. We back up the database nightly; backups older than 30 days are deleted automatically.

5. Security

Page Access Tokens are Fernet-encrypted (AES-128 in CBC mode + HMAC-SHA256) at rest, with the Fernet key derived from your Meta App Secret. All HTTP traffic uses TLS 1.2+ via Let's Encrypt certificates. We publish HSTS, X-Content-Type-Options, X-Frame-Options, and a security.txt at /.well-known/security.txt.

6. Your rights

You have the right to access, correct, port, or delete any personal data we hold about you or your customers. To exercise these rights, email privacy@socialpilot.tech. We respond to all verified requests within 30 days.

7. Contact

For any privacy-related question, reach out to privacy@socialpilot.tech. For security disclosures, see /.well-known/security.txt.