Privacy Policy

How we collect, use and protect your personal information

1. Information We Collect

We collect information you provide directly to us, such as when you create an account, use our services, or contact us for support.

Personal Information

  • Name and email address
  • Account credentials and profile information
  • Payment and billing information
  • Communication preferences
  • Support requests and correspondence

Usage Information

  • Content you create, upload, or publish
  • Social media account connections and permissions (see section 4)
  • Usage patterns and feature interactions
  • Device information and IP addresses
  • Cookies and similar tracking technologies

2. How We Use Your Information

We use the information we collect to provide, maintain and improve our services:

  • Provide and operate the auto-social.io platform
  • Process payments and manage subscriptions
  • Generate AI-powered content based on your preferences
  • Connect and manage your social media accounts
  • Publish, update, or delete posts on networks you connect, when you ask us to
  • Send important updates and notifications
  • Provide customer support and respond to inquiries
  • Analyze usage patterns to improve our services
  • Ensure security and prevent fraud
  • Comply with legal obligations

3. Information Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information in the following circumstances:

Service Providers

We work with trusted third-party service providers who assist us in operating our platform, including payment processors, cloud hosting providers and analytics services.

Social Media Platforms

When you connect a network, we send only what is needed to authenticate and to create, update, or delete posts on your behalf (for example post text, media URLs, and OAuth tokens presented to that network's API).

Legal Requirements

We may disclose your information if required by law, court order, or government request, or to protect our rights and safety.

Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction.

4. Social Network Connections

auto-social.io lets you connect Instagram, Facebook, X (Twitter), LinkedIn, TikTok, and YouTube from the Social accounts page. Each connection uses the relevant network's OAuth consent screen. auto-social.io requests only the permissions needed to identify the connected account and to publish content after you choose to publish or schedule it.

For Meta, Connect Facebook uses Facebook Login (Pages, and Instagram professional accounts linked to those Pages). Connect Instagram uses Instagram Login for a professional Instagram account without requiring a Facebook Page. Personal Instagram accounts cannot connect via Meta's API.

If you remove our app from Facebook or request data deletion there, Meta notifies us at our deauthorize and data-deletion callbacks. We then revoke encrypted OAuth tokens for matching Facebook Login connections. You can also disconnect accounts anytime from Social accounts.

What we store

  • Encrypted OAuth access tokens and refresh tokens (server-side only; never returned to the browser)
  • External account identifiers, display name, avatar URL when provided by the network
  • Granted OAuth scopes and connection status
  • Technical metadata needed to publish (for example Facebook Page id, Instagram business account id, LinkedIn person or organization URN, YouTube channel id)

TikTok integration

auto-social.io uses TikTok for Developers' Login Kit and Content Posting API to connect a user's own TikTok account and publish videos created or selected in auto-social.io. The TikTok integration is available from the Social accounts page and the publishing workflow on the auto-social.io website.

During TikTok authorization, auto-social.io requests these scopes only:

  • user.info.basic: to retrieve the TikTok open ID, display name, and avatar URL so we can identify and display the connected account
  • video.publish: to submit a video for direct posting to the connected TikTok account after the user explicitly chooses Publish or Schedule
  • video.upload: to upload a video as a TikTok inbox draft when direct posting is unavailable, so the user can review and post it in TikTok

auto-social.io does not request or access TikTok passwords, private messages, followers, liked videos, or unrelated profile data. We do not read or publish content without an action from the connected account owner. For AI-generated videos, auto-social.io identifies the content as AI-generated when required by TikTok's Content Posting API. auto-social.io does not edit or delete TikTok posts through this integration.

TikTok OAuth tokens and the TikTok open ID are stored securely on our server only while the TikTok connection is active. Disconnecting TikTok in auto-social.io, revoking access in TikTok settings, or deleting your auto-social.io account removes the stored TikTok tokens and connection data, subject to legally required retention.

How we use it

  • Publish, schedule (after your action), update, or delete posts for the connected account
  • List posts for connected accounts when the network API allows it (for LinkedIn Company Pages)
  • Retrieve available post and profile analytics for connected accounts you authorize
  • Refresh tokens so connections stay valid
  • Show which accounts are connected in the product UI and chat tools

We do not sell social connection data. We do not use LinkedIn (or other network) member content to build advertising audiences, for sales or recruiting prospecting, or to target ads to individuals.

LinkedIn specifically

auto-social.io integrates with LinkedIn through the LinkedIn Community Management API (and related member publishing permissions). When you connect LinkedIn, you authorize auto-social.io via LinkedIn's OAuth consent screen. Depending on the permissions you grant and the Pages you administer, auto-social.io may:

  • Retrieve your basic LinkedIn profile (name, photo, headline, public profile URL, and member id) using r_basicprofile
  • Create, update, and delete posts on your personal LinkedIn profile on your behalf using w_member_social
  • List Company Pages you administer and create, update, delete, and list posts for those Pages using organization permissions such as rw_organization_admin, w_organization_social, and r_organization_social
  • Retrieve available analytics for your profile and posts (for example impressions, reactions, comments, shares, and related metrics) using permissions such as r_member_postAnalytics, r_member_profileAnalytics, and organization reporting scopes

A single LinkedIn Connect may store your member profile and each administered Company Page as separate connections. You choose which Profile or Page to publish to for each post. auto-social.io does not request LinkedIn passwords, private messages, or unrelated profile scraping. We do not use LinkedIn data for employee advocacy redistribution, spam, artificial engagement, or social feed embedding on third-party sites.

LinkedIn data retrieved through the Marketing / Community Management APIs is processed in line with the LinkedIn Marketing API Program Terms and LinkedIn's Data Storage Requirements. In particular:

  • Authenticated member person id / URN and basic authenticated profile data needed to keep your connection working may be stored while the connection remains active
  • Organization posts and related organization social activity retrieved for Pages you connect may be stored only for the periods LinkedIn allows (generally up to six weeks, or up to six months when the organization has authenticated into auto-social.io)
  • Member social activity data retrieved from LinkedIn (when applicable) is not retained beyond LinkedIn's allowed window (generally 48 hours)
  • Non-authenticated member profile data retrieved from LinkedIn (when applicable) is not stored beyond LinkedIn's allowed caching window (generally 24 hours)
  • Organization admin and reporting analytics that do not include individual member-level data may be retained only for the periods LinkedIn allows (generally up to one year)

Content you create in auto-social.io and ask us to publish to LinkedIn is treated as your content on our platform. External post identifiers returned by LinkedIn after a successful publish may be stored so we can show publication status, open the live post, and support update or delete when you request it. Cached LinkedIn API payloads used only for listing or analytics are refreshed or discarded according to the LinkedIn storage limits above.

Withdrawing consent and deletion

  • Disconnect in Social accounts removes that connection, deletes stored tokens for it, and (when the network supports it) attempts to revoke the token with the provider
  • You can also revoke access in the network's own security or app settings
  • If you delete your auto-social.io account or ask us to erase your data, we delete remaining social connection rows and tokens, except where law requires retention

5. Data Security

We implement appropriate technical and organizational measures to protect your personal information:

  • Encryption of data in transit and at rest (including social OAuth tokens)
  • Regular security assessments and updates
  • Access controls and authentication measures
  • Secure data centers and infrastructure
  • Employee training on data protection

However, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security of your information.

6. Data Retention

We retain your personal information for as long as necessary to provide our services and fulfill the purposes outlined in this Privacy Policy:

  • Account information: Until you delete your account
  • Content and posts: As long as you maintain your account
  • Social connection tokens and authenticated connection metadata: Until you disconnect the account or delete your auto-social.io account
  • LinkedIn API-derived social activity, analytics caches, and non-authenticated LinkedIn profile fields: Only for the shorter of our operational need and LinkedIn Marketing API Data Storage Requirements (see section 4)
  • Payment information: As required for tax and legal purposes
  • Usage data: Typically 2-3 years for analytics purposes
  • Support communications: Up to 3 years

You can request deletion of your data at any time by contacting us. When you disconnect LinkedIn or delete your account, we delete stored LinkedIn tokens and LinkedIn connection rows, and we delete or expire LinkedIn API-derived caches subject to the LinkedIn limits above and any legally required retention.

7. Your Rights and Choices

In accordance with the GDPR and French data protection laws, you have the following rights:

Access and Portability

You can access and download your personal information through your account settings or by contacting us.

Correction and Updates

You can update your account information and preferences at any time through your dashboard.

Deletion

You can disconnect social accounts anytime, delete your account, and request removal of your personal information. Some information may be retained for legal or legitimate business purposes.

Marketing Communications

You can opt out of marketing emails by clicking the unsubscribe link or updating your communication preferences.

8. Cookies and Tracking

We use cookies and similar technologies to enhance your experience and analyze usage:

  • Essential Cookies: Required for basic functionality
  • Analytics Cookies: Help us understand how you use our service
  • Preference Cookies: Remember your settings and preferences
  • Marketing Cookies: Used for targeted advertising (with consent)

You can manage cookie settings anytime with the floating cookie button, or through your browser preferences. Disabling certain cookies may affect functionality.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for international transfers, including:

  • Standard contractual clauses approved by the European Commission
  • Adequacy decisions by relevant data protection authorities
  • Certification schemes and codes of conduct

10. Children's Privacy

Our service is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If we become aware that we have collected such information, we will take steps to delete it promptly.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last Updated" date.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

12. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Email: [email protected]
Privacy: [email protected]
Address: 52 rue de la Moselle, 69008 Lyon, France

For EU residents, you also have the right to lodge a complaint with your local data protection authority (in France: CNIL, Commission Nationale de l'Informatique et des Libertés).

Last Updated: September 2026
This Privacy Policy is effective as of the date last updated. Your continued use of our service after any changes indicates your acceptance of the updated Privacy Policy.