Legal
Privacy overview
How Promote HQ handles data on your behalf.
Template — review with counsel before relying on it.
Data we process
- Account and workspace data you provide (name, email, company, time zone).
- Connected source data: website pages, analytics aggregates, search performance, feed items.
- Social account metadata and the posts you create and publish through Promote HQ.
- Operational telemetry required to run the service (audit logs, job history, usage counters).
How we use it
To discover and score opportunities, generate drafts, schedule and publish content, measure results, enforce plan limits, and keep an auditable record. We do not sell personal data.
Storage and security
Data is stored in Supabase Postgres with Row Level Security. OAuth tokens and customer AI keys are encrypted with AES-256-GCM. Secrets are redacted from logs.
Retention and your rights
You can export or delete workspace data from settings, and revoke any connector. Deletion removes tenant-owned rows subject to short-lived backups and legal obligations.
Sub-processors
Core processing uses Supabase (database, auth, storage), Stripe (billing), Vercel (hosting) and an optional AI provider you configure.