Privacy Policy
The short version
- We collect what we need to run your brands' social media: your account, your brand content, and the social accounts you connect.
- We only publish what you or your team create or approve. Nothing posts without a person's say-so.
- Social account tokens are encrypted and never shown in your browser.
- AI drafts are written by Anthropic's Claude from your brand's details. Anthropic doesn't train its models on that content by default.
- We don't sell your data or use it for advertising.
- You can disconnect accounts and ask us to delete your data at any time. See Data Deletion.
1. Who we are
BrandRhythms is a service that helps you plan, create, schedule, and publish social media posts for the brands you run. It is operated by [LEGAL ENTITY NAME] ("BrandRhythms", "we", "us"), [MAILING ADDRESS].
This policy covers our website at brandrhythms.com and the BrandRhythms app at app.brandrhythms.com. When we say "you", we mean anyone who uses them, including people invited to a team.
For the content you put into BrandRhythms about your own brands and customers, you decide what goes in and why, and we process it on your instructions to provide the service.
2. What we collect
Information you give us
- Account details: your email address, password (stored only as a secure hash by our authentication provider), and name.
- Business and team details: your business name, your brands (name, timezone, color), the people you invite (their email address, role, and the brands they can work on), and who invited them.
- Brand Brain: what each brand does, its audience, voice and tone, offers, website, calls to action, words to use and avoid, FAQs, brand colors, and content pillars.
- Content: ideas, posts, captions, hashtags, first comments, notes, campaigns, review comments, assignments, and schedules.
- Uploaded media: the images and videos you add to your library, with their file details (type, size, dimensions, length), names, folders, and tags.
- Early-access list: if you join the list on brandrhythms.com, your email address and when you signed up.
- Messages to us: anything you send when you contact support.
Information from social platforms you connect
When you connect an account, we receive the details listed in section 4, including an access token that lets us publish for you, and later the results of posts we published (like reach and likes).
Information collected automatically
- Activity records: a log of important actions, such as who scheduled, approved, published, or deleted something, who connected or disconnected an account, and team changes.
- Publishing records: each scheduled post's status, attempts, errors, and the platform's response (with tokens removed), so we can retry and help when something fails.
- AI usage: which AI feature was used, by whom, for which brand, and how many credits and tokens it used. We don't store the prompt itself in this record.
- Technical data: IP address, browser and device type, pages requested, and error details, recorded in our hosting provider's logs.
- Your timezone and display preference: see section 12.
3. How we use it
- To provide BrandRhythms: sign you in, show your brands and calendar, store your media, and publish posts when you schedule them.
- To write AI drafts and suggestions for a brand when you or your team ask, or when you turn on Autopilot.
- To show results of posts we published for you.
- To run teams: send invites, apply roles, and show who did what.
- To enforce plan limits (brands, accounts, seats, AI credits) and, once billing launches, to bill you.
- To keep the service secure, prevent abuse, and fix problems.
- To send service emails, such as sign-up confirmation, password reset, team invites, and important changes. If you joined the early-access list, we send one email when early access opens.
- To comply with law and enforce our Terms of Service.
We don't sell personal information, share it for cross-context behavioral advertising, or use your content to advertise to anyone.
4. Connected social accounts
You choose which accounts to connect, and you can disconnect them at any time. We only use what a platform shares with us to provide BrandRhythms to you, in line with that platform's developer terms.
Facebook and Instagram (Meta)
You sign in with Facebook and choose which Facebook Pages and linked Instagram professional accounts to connect. We receive your Facebook user ID and name, the Pages you manage (name, ID, picture, and your tasks on the Page), each Page's access token, and each linked Instagram account's ID, username, name, and profile picture. We ask for these permissions:
- pages_show_list, business_management
- List the Pages you manage, including Pages owned through a business account, so you can choose which to connect.
- pages_manage_posts
- Publish the posts you schedule or publish to your Page.
- pages_read_engagement, pages_read_user_content
- Confirm a post went out and get its link, and check your Page's most recent posts so a retry never posts twice.
- pages_manage_engagement
- Post the first comment you wrote, if you added one.
- read_insights
- Show results (such as reach and engagement) for posts BrandRhythms published.
- instagram_basic
- Identify your Instagram professional account (ID and username).
- instagram_content_publish
- Publish the photos, carousels, and Reels you schedule.
- instagram_manage_comments
- Post the first comment you wrote, if you added one.
- instagram_manage_insights
- Show results for posts BrandRhythms published.
We don't read your private messages, your followers' personal data, or posts by other people, and we don't use Meta data for advertising or to build profiles of anyone.
TikTok
When you connect a TikTok account, you sign in with TikTok and approve access. We receive your TikTok account's ID, display name, and avatar, plus an access token and a refresh token, which are stored encrypted. We ask for these permissions, and no others:
- user.info.basic
- Identify the account you connected and show its name and avatar.
- video.publish
- Post the videos and photos you schedule or approve to your TikTok profile, and check whether each post finished.
- video.upload
- Send videos and photos to your TikTok inbox as drafts, for you to finish and post in the TikTok app.
Each time you set up a TikTok post, and again just before it goes out, we ask TikTok which posting options your account has (your nickname, the privacy levels you can choose, whether comments, Duet, and Stitch are allowed, and the longest video you can post), so you can choose the post's settings. We save the settings you choose, and that you confirmed TikTok's Music Usage Confirmation (and Branded Content Policy, if you mark a post as branded content), with the post.
To post photos, TikTok fetches them from a temporary, expiring link on our website; the copies are deleted after the post is done. When you disconnect a TikTok account, we delete its tokens and ask TikTok to revoke our access. We don't read your private messages, followers, analytics, or other people's videos.
5. What we publish
BrandRhythms only publishes posts that someone on your team created or approved, to accounts your team connected, at the time your team chose.
- AI and Autopilot only write drafts. Autopilot posts wait for approval, and nothing is scheduled until an owner or Social Media Manager approves it.
- Content Creators can't schedule posts themselves; they submit posts for review.
- Every scheduling, approval, and publishing action is recorded with the person who did it.
- We never post, like, follow, comment, or message on your behalf beyond the post and optional first comment you scheduled.
6. How we protect access tokens
- Access tokens are encrypted (AES-256-GCM) before they are stored, in a separate table that only our servers can read. They are never sent to your browser, written to logs, or put in links.
- Each encrypted token is tied to its own account, so it can't be reused elsewhere.
- We check connected accounts daily and flag any whose access was removed, so you know to reconnect.
- When an account is disconnected, its token is deleted right away.
7. How we use AI
BrandRhythms uses Claude, an AI model from Anthropic, PBC, to write platform versions of captions, rewrite captions, suggest hashtags and ideas, and draft Autopilot weeks.
- What is sent: one brand's Brand Brain (description, audience, voice, offers, website, calls to action, words to use and avoid, FAQs, and content pillars), the caption or request being worked on, and that brand's existing idea titles so suggestions aren't repeated. Images, videos, your account details, and access tokens are not sent.
- One brand at a time: each request contains exactly one brand's details. Content from one brand is never used to write for another.
- Training: [CONFIRM against your Anthropic Commercial Terms] Under Anthropic's commercial terms, Anthropic does not use inputs or outputs from its API to train its models by default. Anthropic deletes API inputs and outputs within 30 days, except that content flagged for violating its usage policy may be kept for up to 2 years, or longer where required by law.
- Review before posting: AI output can be wrong. You and your team review and approve every draft before it is published.
We keep the drafts and ideas the AI writes as part of your content. We keep a record of each AI request's feature, brand, person, and credits used, but not the full prompt.
8. Your team's access
Each business on BrandRhythms has an owner, who controls who can see what:
- Owners can see and manage every brand, the team, and billing, and are the only people who can disconnect social accounts.
- Social Media Managers can see and manage the brands they were given, including the Brand Brain, scheduling, and connecting accounts.
- Content Creators can create drafts, media, and ideas and read the Brand Brain for the brands they were given, and submit posts for review.
Teammates who share a brand can see each other's name and email address, and owners and managers can see that brand's activity record. When someone is removed from a team, their access ends immediately, and the content they created stays with the brand.
BrandRhythms staff access customer data only to provide support, investigate problems or abuse, or meet legal obligations. Staff access requires two-factor authentication, a stated reason, and is recorded. Staff never post, connect, or approve anything for you.
9. Who we share data with
We share data only with service providers that help us run BrandRhythms, under contracts that limit how they use it, and with the platforms you tell us to publish to.
- Supabase
- Database, sign-in, and file storage. Holds the data described in this policy.
- Vercel
- Hosts the website and app. Receives requests (including IP addresses) and server logs, and passes early-access sign-ups to our database.
- Inngest
- Runs scheduled publishing and Autopilot jobs. Receives job and record IDs, not your content or tokens.
- Anthropic
- Writes AI drafts. Receives the brand details described in section 7.
- Resend
- Sends team invite emails. Receives the invitee's email address, the inviter's name, the business and brand names, the role, the invite link, and the inviter's email address (so replies go to them).
- [AUTH EMAIL PROVIDER]
- Sends sign-up confirmation and password reset emails. Receives your email address.
- Google Fonts
- Serves the typeface on brandrhythms.com, so your browser shares your IP address with Google when you visit. The app itself doesn't load fonts from Google.
- Meta and TikTok
- Receive the posts, captions, media, and first comments you schedule, sent to the accounts you connected. Their own privacy policies apply to what you publish on their platforms.
When we add the following planned providers, we'll update this list first:
- Stripe
- Payments. Stripe collects your card and billing details directly; we keep only customer and subscription IDs and plan status.
- Sentry
- Error reports, which may include your user ID, browser details, and the page you were on.
- PostHog
- Product analytics and feature flags (which features are used, and how).
We may also disclose information if required by law, to protect the rights, property, or safety of our users or others, or as part of a merger, acquisition, or sale of assets, in which case this policy continues to apply to your data.
10. How long we keep data
- Account, brands, content, media
- While your account is active. Deleted within 30 days after you ask us to delete them or close your account.
- Access tokens
- Until you disconnect the account, remove our access on the platform, or delete your account. Deleted immediately when an account is disconnected.
- Post results (metrics)
- Collected daily for 14 days after a post is published, and kept while your account is active.
- Platform responses on publishing records
- 90 days.
- Activity records
- 12 months, for security and to resolve disputes about what was posted.
- AI usage records
- While your account is active, for credit limits and billing.
- Expired invites and connection requests
- 30 days after they expire.
- Early-access list
- Until 12 months after launch, or until you ask us to remove you.
- Server logs
- As kept by our hosting provider, typically [LOG RETENTION PERIOD].
- Backups
- Deleted data can remain in encrypted backups for up to [BACKUP RETENTION PERIOD] until those backups expire.
- Billing records
- As long as tax and accounting law requires (once billing launches).
We may keep information longer if the law requires it or to resolve a dispute or investigate abuse.
11. Disconnecting and deleting
- Disconnect a social account: owners can open the brand's Brand settings → Social accounts and choose Disconnect. You can also remove BrandRhythms in your Facebook, Instagram, or TikTok settings.
- Delete your account or data: email [CONTACT EMAIL] from your account's email address. We confirm the request and complete it within 30 days.
Step-by-step instructions are on our Data Deletion page.
12. Cookies and browser storage
We only use cookies and browser storage that make BrandRhythms work. We don't use advertising or tracking cookies.
- Sign-in cookies
- Keep you signed in to the app (set by our authentication provider).
- tz cookie
- Remembers your timezone so "this week" matches your clock. Lasts 1 year.
- Theme setting
- Remembers Light, Dark, or System appearance on this device (browser local storage).
If we add product analytics, we'll update this section before it goes live.
13. Security
- Data is encrypted in transit (HTTPS) and at rest by our providers. Access tokens are also encrypted by us.
- Database rules make sure people only see the businesses and brands they belong to.
- Media files are stored privately and shared through links that expire.
- Staff access requires two-factor authentication, a reason, and is recorded.
No system is perfectly secure. If we learn of a breach that affects your personal information, we'll notify you as the law requires. Please keep your password private and tell us right away at [CONTACT EMAIL] if you think your account was accessed without permission.
14. Where your data is stored
BrandRhythms is operated from the United States. Our database and file storage are hosted in [SUPABASE REGION]. Our other providers may process data in the United States and other countries. If you use BrandRhythms from outside the United States, your information is transferred to and processed in the United States, where privacy laws may differ from those where you live.
15. US state privacy rights
Depending on where you live (for example California, Colorado, Connecticut, Virginia, Texas, Oregon, and other states with privacy laws), you may have the right to:
- know what personal information we collect, use, and disclose, and get a copy of it;
- correct inaccurate personal information;
- delete personal information;
- opt out of the sale of personal information, sharing for cross-context behavioral advertising, targeted advertising, and certain profiling. We don't do any of these;
- limit the use of sensitive personal information. We don't collect sensitive personal information for those purposes; and
- not be treated differently for using these rights.
To make a request, email [CONTACT EMAIL]. We'll verify the request by confirming it from the email address on your account, and we respond within 45 days (or the time your state allows). You may use an authorized agent; we'll ask for proof that they're allowed to act for you. If we decline your request, you can appeal by replying to our decision; if your appeal is denied, you can contact your state attorney general.
For California residents: in the last 12 months we collected the categories of information described in section 2 (identifiers, commercial information once billing launches, internet activity, and the content you provide), for the purposes in section 3, from you, your team, and the platforms you connect, and disclosed them to the service providers in section 9 for business purposes. We have not sold or shared personal information.
If someone on your team added information about you, such as your email address in an invite, or if your business is our customer, we may ask you to contact that business first, since it decides how that information is used.
16. Children
BrandRhythms is a business tool for adults. It is not directed to children under 13, and we don't knowingly collect personal information from them. You must be at least 18 to create an account. If you believe a child has given us personal information, contact us at [CONTACT EMAIL] and we'll delete it.
17. Changes to this policy
We'll update this policy when our practices change, and change the effective date at the top. If a change is significant, we'll tell account owners by email or in the app before it takes effect.
18. Contact us
Questions or requests about privacy:
[LEGAL ENTITY NAME]
[MAILING ADDRESS]
[CONTACT EMAIL]