1. Overview & Commitment to Privacy
At Content Sync ("Service", "We", "Us", or "Our"), we take your privacy and data security seriously. This Privacy Policy explains how we collect, use, store, process, and protect your personal information and business data when you use our multi-workspace social automation platform.
By creating an account or accessing our services, you consent to the data collection and usage practices described in this policy.
2. Information We Collect
We collect several categories of information to operate, optimize, and secure Content Sync:
- Account & Profile Data: Full name, email address, company name, profile avatar, billing preferences, and encrypted password credentials.
- Workspace & Integration Data: Domain URLs, RSS feed links, connected social media account identifiers, and OAuth access tokens (Facebook Pages, Instagram, X, LinkedIn, Threads, Pinterest, Telegram, Discord).
- Content & Prompt Logs: URLs scraped for content extraction, AI generation prompts, drafted posts, carousel slides, script templates, and publishing schedules.
- System & Usage Analytics: IP address, browser type, device information, operating system, page response times, and feature usage telemetry collected via essential session cookies and performance logs.
3. How We Use Your Information
Your data is processed strictly for legitimate business and operational purposes:
- Providing Core Functionality: Automating RSS feed polling, scraping user-specified URLs, generating AI social posts, scheduling, and publishing to your connected social channels.
- OAuth Token Encryption: Encrypting and managing third-party social media access tokens to execute scheduled posts on your behalf.
- Service Optimization & Security: Improving AI post generation accuracy, monitoring system performance, preventing fraud or abuse, and enforcing account rate limits.
- Transactional Communications: Sending account setup confirmations, security alerts, billing invoices, and feature updates.
4. Third-Party Data Sharing & AI Processors
We do NOT sell, rent, or trade your personal information or content logs to third-party advertisers. We share data only with trusted service providers necessary to operate the platform:
- Generative AI Partners: Input prompts and scraped article text are submitted to AI service providers (such as OpenAI and Anthropic) via secure zero-data-retention Enterprise APIs strictly for generating post variations. Your data is NOT used to train public foundational models.
- Social Media Network APIs: Post text, imagery, and schedule parameters are transmitted to social networks (Meta, X, LinkedIn, etc.) as requested by your automated workflows.
- Payment & Cloud Infrastructure: Credit card processing is handled securely via PCI-DSS compliant providers (Stripe). Data storage and database instances are hosted on secure, SOC2-certified cloud infrastructure (AWS / Vercel / Prisma).
6. Data Security & Storage Standards
We employ industry-standard administrative, physical, and technical safeguards to protect your data against unauthorized access, alteration, disclosure, or destruction:
- Encryption in Transit & Rest: All traffic is encrypted via TLS 1.3 (HTTPS), and sensitive credentials (such as OAuth tokens) are stored using AES-256 encryption.
- Access Controls: Role-based access controls (RBAC) ensure that team members within a workspace only access resources designated by the workspace owner.
- Data Retention: Account data is retained for as long as your subscription is active. Upon account deletion, all connected tokens, workspace configurations, and scheduled drafts are permanently purged within 30 days.
7. Your Privacy Rights (GDPR, CCPA/CPRA)
Depending on your location, you possess specific statutory rights regarding your personal data under the General Data Protection Regulation (GDPR) or California Consumer Privacy Act (CCPA/CPRA):
- Right to Access & Portability: Request a copy of the personal data and workspace content stored in your account.
- Right to Rectification: Correct inaccurate or incomplete profile and organization details.
- Right to Erasure ("Right to be Forgotten"): Request permanent deletion of your account and associated social connection tokens.
- Right to Withdraw Consent: Revoke social media OAuth connections at any time directly through Content Sync settings or your social media provider's account security page.
8. International Data Transfers
Content Sync operates globally. Information collected from users in the European Economic Area (EEA), United Kingdom, or other regions may be transferred to and processed on secure servers located in the United States or other countries with equivalent data protection standards under standard contractual clauses (SCCs).
9. Contact Our Data Protection Officer (DPO)
If you wish to exercise your privacy rights, request data deletion, or submit questions regarding this Privacy Policy, please contact our Data Protection Officer:
- Email: privacy@contentsync.ai
- Security Portal: https://contentsync.ai/security
- Postal Address: Content Sync Inc., Attn: Privacy Officer, Legal Dept.
© 2026 Content Sync Inc. All rights reserved.