Privacy Policy
This policy explains what personal data we process, why, and the rights you have over it.
Social Media Digital Marketer ("the Service") is operated by Phronesis AI Lab Private Limited, a private limited company incorporated in India ("we", "us", "our"). This Privacy Policy describes how we collect, use, disclose, and safeguard personal data when you use our website, applications, and AI-powered social-media management services.
We act as a data controller (a "data fiduciary" under the Indian Digital Personal Data Protection Act, 2023) for the personal data of our account holders, and as a data processor for the content and connected-account data you entrust to us to publish on your behalf. Where we process customer content on your instructions, our Data Processing Addendum also applies.
1. Who we are and how to contact us
Controller: Phronesis AI Lab Private Limited (India). For any privacy matter, including to exercise your rights, contact our privacy team at [email protected]. General enquiries: [email protected].
2. Personal data we collect
Data you provide directly
- Account data: name, email address, password (stored hashed), organisation name, role, and time zone.
- Billing data: billing name, address, country, tax identifiers, and the last four digits and brand of your payment card. Full card numbers are handled by our payment processors (Razorpay and Stripe) and never stored on our systems.
- Content data: prompts, briefs, drafts, images, captions, scheduling instructions, and any other material you submit to generate or publish social-media content.
- Support data: the contents of messages you send us and any attachments.
Data from connected social accounts
- Authorisation tokens: OAuth access and refresh tokens granted when you connect a social network (for example, an account on a supported platform). We store these securely and use them only to perform the actions you request.
- Profile and publishing metadata: connected account handles, page or profile identifiers, permitted scopes, published post identifiers, and engagement metrics returned by platform APIs to power analytics and scheduling.
Data collected automatically
- Usage data: features used, actions taken, timestamps, and session information.
- Device and log data: IP address, browser and device type, operating system, and referring URLs.
- Cookies and similar technologies: see our Cookie Policy.
3. How we use personal data and our lawful bases
| Purpose | Lawful basis (GDPR) |
|---|---|
| Providing, operating, and maintaining the Service | Performance of a contract |
| Generating AI content and publishing to your connected networks | Performance of a contract |
| Processing payments and preventing fraud | Contract; legitimate interests; legal obligation |
| Security, monitoring, and abuse prevention | Legitimate interests; legal obligation |
| Product analytics and improving the Service | Legitimate interests (or consent where required) |
| Service and transactional communications | Contract; legitimate interests |
| Marketing communications | Consent (withdrawable at any time) |
| Complying with legal and regulatory obligations | Legal obligation |
Under the Indian DPDP Act, 2023, we process personal data on the basis of your consent or for legitimate uses permitted by that Act. For California residents, the "business purposes" for processing are described above.
4. AI-generated content
The Service uses large language models and other AI models, some operated by third-party providers such as Anthropic and OpenAI, to generate text and related outputs from the prompts and content you supply. We send prompts and the context necessary to fulfil your request to these providers. We contract with providers who commit not to train their foundation models on our customers' business data through their commercial APIs. For the ownership, limitations, and responsibilities that apply to AI outputs, see our AI Content Terms.
5. How we share personal data
We do not sell your personal data. We share it only as follows:
- Subprocessors: vendors who process data on our behalf under contract (see Section 6).
- Social networks: when you instruct us to publish, we transmit your content and required metadata to the relevant platform via its API.
- Legal and safety: where required by law, regulation, legal process, or to protect rights, safety, and property.
- Business transfers: in connection with a merger, acquisition, or asset sale, subject to this policy.
6. Subprocessors and international transfers
| Subprocessor | Purpose | Primary location |
|---|---|---|
| Cloudflare, Inc. | Hosting, storage, CDN, security | Global (EU/US) |
| Razorpay Software Private Limited | Payments (INR) | India |
| Stripe, Inc. | Payments (USD, global) | United States |
| Resend, Inc. | Transactional email delivery | United States |
| Anthropic, PBC | AI model provider | United States |
| OpenAI, L.L.C. | AI model provider | United States |
Because we and our subprocessors operate globally, your data may be transferred to and processed in countries other than your own, including outside the EEA, the UK, and India. Where we transfer personal data internationally, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and equivalent mechanisms. A current subprocessor list is maintained in our Trust Center.
7. Data retention
- Account data: retained while your account is active and for a limited period afterwards to meet legal and accounting obligations.
- Content and connected-account data: retained while your account is active; deleted or anonymised within 30 days of a verified deletion request, subject to backup cycles.
- OAuth tokens: deleted promptly when you disconnect an account or close your account.
- Logs and analytics: retained for up to 12 months, then deleted or aggregated.
8. Data security
We apply technical and organisational measures including encryption in transit (TLS) and at rest, access controls, secrets management, least-privilege access, and monitoring. See our Security page for details. No method of transmission or storage is completely secure, but we take commercially reasonable steps to protect your data.
9. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you and obtain a copy.
- Correct inaccurate or incomplete data.
- Delete your personal data ("right to be forgotten").
- Restrict or object to certain processing.
- Data portability.
- Withdraw consent at any time, without affecting prior processing.
- Lodge a complaint with a supervisory authority (see below).
To exercise any right, email [email protected]. We respond within the timeframes required by applicable law. For region-specific detail see our GDPR Statement, our CCPA notice, and the DPDP information below.
European Economic Area and United Kingdom (GDPR/UK GDPR)
You may lodge a complaint with your local Data Protection Authority. See our GDPR Statement.
California (CCPA/CPRA)
California residents have additional rights, including to know, delete, correct, and opt out of "sharing". See our Do Not Sell or Share My Personal Information page.
India (DPDP Act, 2023)
As a data principal you may access, correct, and erase your data, nominate a representative, and raise a grievance. Contact our grievance channel at [email protected]. You may also escalate to the Data Protection Board of India.
10. Children's privacy
The Service is intended for business users and is not directed to children. We do not knowingly collect personal data from children under 18. If you believe a child has provided us data, contact [email protected] and we will delete it.
11. Changes to this policy
We may update this policy. We will change the "Last updated" date above and, for material changes, notify you by email or in-product.
12. Contact
Phronesis AI Lab Private Limited — privacy: [email protected]; security: [email protected]; general: [email protected].
Last updated: 20 September 2026.