BrandRhythms

Privacy Policy

Effective date: October 10, 2026

The short version

  • We collect what we need to run your brands' social media: your account, your brand content, and the social accounts you connect.
  • We only publish what you or your team create or approve. Nothing posts without a person's say-so.
  • Social account tokens are encrypted and never shown in your browser.
  • AI drafts are written by Anthropic's Claude from your brand's details. Anthropic doesn't train its models on that content by default.
  • We don't sell your data or use it for advertising.
  • You can disconnect accounts and ask us to delete your data at any time. See Data Deletion.

1. Who we are

BrandRhythms is a service that helps you plan, create, schedule, and publish social media posts for the brands you run. It is operated by [LEGAL ENTITY NAME] ("BrandRhythms", "we", "us"), [MAILING ADDRESS].

This policy covers our website at brandrhythms.com and the BrandRhythms app at app.brandrhythms.com. When we say "you", we mean anyone who uses them, including people invited to a team.

For the content you put into BrandRhythms about your own brands and customers, you decide what goes in and why, and we process it on your instructions to provide the service.

2. What we collect

Information you give us

Information from social platforms you connect

When you connect an account, we receive the details listed in section 4, including an access token that lets us publish for you, and later the results of posts we published (like reach and likes).

Information collected automatically

3. How we use it

We don't sell personal information, share it for cross-context behavioral advertising, or use your content to advertise to anyone.

4. Connected social accounts

You choose which accounts to connect, and you can disconnect them at any time. We only use what a platform shares with us to provide BrandRhythms to you, in line with that platform's developer terms.

Facebook and Instagram (Meta)

You sign in with Facebook and choose which Facebook Pages and linked Instagram professional accounts to connect. We receive your Facebook user ID and name, the Pages you manage (name, ID, picture, and your tasks on the Page), each Page's access token, and each linked Instagram account's ID, username, name, and profile picture. We ask for these permissions:

pages_show_list, business_management
List the Pages you manage, including Pages owned through a business account, so you can choose which to connect.
pages_manage_posts
Publish the posts you schedule or publish to your Page.
pages_read_engagement, pages_read_user_content
Confirm a post went out and get its link, and check your Page's most recent posts so a retry never posts twice.
pages_manage_engagement
Post the first comment you wrote, if you added one.
read_insights
Show results (such as reach and engagement) for posts BrandRhythms published.
instagram_basic
Identify your Instagram professional account (ID and username).
instagram_content_publish
Publish the photos, carousels, and Reels you schedule.
instagram_manage_comments
Post the first comment you wrote, if you added one.
instagram_manage_insights
Show results for posts BrandRhythms published.

We don't read your private messages, your followers' personal data, or posts by other people, and we don't use Meta data for advertising or to build profiles of anyone.

TikTok

When you connect a TikTok account, you sign in with TikTok and approve access. We receive your TikTok account's ID, display name, and avatar, plus an access token and a refresh token, which are stored encrypted. We ask for these permissions, and no others:

user.info.basic
Identify the account you connected and show its name and avatar.
video.publish
Post the videos and photos you schedule or approve to your TikTok profile, and check whether each post finished.
video.upload
Send videos and photos to your TikTok inbox as drafts, for you to finish and post in the TikTok app.

Each time you set up a TikTok post, and again just before it goes out, we ask TikTok which posting options your account has (your nickname, the privacy levels you can choose, whether comments, Duet, and Stitch are allowed, and the longest video you can post), so you can choose the post's settings. We save the settings you choose, and that you confirmed TikTok's Music Usage Confirmation (and Branded Content Policy, if you mark a post as branded content), with the post.

To post photos, TikTok fetches them from a temporary, expiring link on our website; the copies are deleted after the post is done. When you disconnect a TikTok account, we delete its tokens and ask TikTok to revoke our access. We don't read your private messages, followers, analytics, or other people's videos.

5. What we publish

BrandRhythms only publishes posts that someone on your team created or approved, to accounts your team connected, at the time your team chose.

6. How we protect access tokens

7. How we use AI

BrandRhythms uses Claude, an AI model from Anthropic, PBC, to write platform versions of captions, rewrite captions, suggest hashtags and ideas, and draft Autopilot weeks.

We keep the drafts and ideas the AI writes as part of your content. We keep a record of each AI request's feature, brand, person, and credits used, but not the full prompt.

8. Your team's access

Each business on BrandRhythms has an owner, who controls who can see what:

Teammates who share a brand can see each other's name and email address, and owners and managers can see that brand's activity record. When someone is removed from a team, their access ends immediately, and the content they created stays with the brand.

BrandRhythms staff access customer data only to provide support, investigate problems or abuse, or meet legal obligations. Staff access requires two-factor authentication, a stated reason, and is recorded. Staff never post, connect, or approve anything for you.

9. Who we share data with

We share data only with service providers that help us run BrandRhythms, under contracts that limit how they use it, and with the platforms you tell us to publish to.

Supabase
Database, sign-in, and file storage. Holds the data described in this policy.
Vercel
Hosts the website and app. Receives requests (including IP addresses) and server logs, and passes early-access sign-ups to our database.
Inngest
Runs scheduled publishing and Autopilot jobs. Receives job and record IDs, not your content or tokens.
Anthropic
Writes AI drafts. Receives the brand details described in section 7.
Resend
Sends team invite emails. Receives the invitee's email address, the inviter's name, the business and brand names, the role, the invite link, and the inviter's email address (so replies go to them).
[AUTH EMAIL PROVIDER]
Sends sign-up confirmation and password reset emails. Receives your email address.
Google Fonts
Serves the typeface on brandrhythms.com, so your browser shares your IP address with Google when you visit. The app itself doesn't load fonts from Google.
Meta and TikTok
Receive the posts, captions, media, and first comments you schedule, sent to the accounts you connected. Their own privacy policies apply to what you publish on their platforms.

When we add the following planned providers, we'll update this list first:

Stripe
Payments. Stripe collects your card and billing details directly; we keep only customer and subscription IDs and plan status.
Sentry
Error reports, which may include your user ID, browser details, and the page you were on.
PostHog
Product analytics and feature flags (which features are used, and how).

We may also disclose information if required by law, to protect the rights, property, or safety of our users or others, or as part of a merger, acquisition, or sale of assets, in which case this policy continues to apply to your data.

10. How long we keep data

Account, brands, content, media
While your account is active. Deleted within 30 days after you ask us to delete them or close your account.
Access tokens
Until you disconnect the account, remove our access on the platform, or delete your account. Deleted immediately when an account is disconnected.
Post results (metrics)
Collected daily for 14 days after a post is published, and kept while your account is active.
Platform responses on publishing records
90 days.
Activity records
12 months, for security and to resolve disputes about what was posted.
AI usage records
While your account is active, for credit limits and billing.
Expired invites and connection requests
30 days after they expire.
Early-access list
Until 12 months after launch, or until you ask us to remove you.
Server logs
As kept by our hosting provider, typically [LOG RETENTION PERIOD].
Backups
Deleted data can remain in encrypted backups for up to [BACKUP RETENTION PERIOD] until those backups expire.
Billing records
As long as tax and accounting law requires (once billing launches).

We may keep information longer if the law requires it or to resolve a dispute or investigate abuse.

11. Disconnecting and deleting

Step-by-step instructions are on our Data Deletion page.

12. Cookies and browser storage

We only use cookies and browser storage that make BrandRhythms work. We don't use advertising or tracking cookies.

Sign-in cookies
Keep you signed in to the app (set by our authentication provider).
tz cookie
Remembers your timezone so "this week" matches your clock. Lasts 1 year.
Theme setting
Remembers Light, Dark, or System appearance on this device (browser local storage).

If we add product analytics, we'll update this section before it goes live.

13. Security

No system is perfectly secure. If we learn of a breach that affects your personal information, we'll notify you as the law requires. Please keep your password private and tell us right away at [CONTACT EMAIL] if you think your account was accessed without permission.

14. Where your data is stored

BrandRhythms is operated from the United States. Our database and file storage are hosted in [SUPABASE REGION]. Our other providers may process data in the United States and other countries. If you use BrandRhythms from outside the United States, your information is transferred to and processed in the United States, where privacy laws may differ from those where you live.

15. US state privacy rights

Depending on where you live (for example California, Colorado, Connecticut, Virginia, Texas, Oregon, and other states with privacy laws), you may have the right to:

To make a request, email [CONTACT EMAIL]. We'll verify the request by confirming it from the email address on your account, and we respond within 45 days (or the time your state allows). You may use an authorized agent; we'll ask for proof that they're allowed to act for you. If we decline your request, you can appeal by replying to our decision; if your appeal is denied, you can contact your state attorney general.

For California residents: in the last 12 months we collected the categories of information described in section 2 (identifiers, commercial information once billing launches, internet activity, and the content you provide), for the purposes in section 3, from you, your team, and the platforms you connect, and disclosed them to the service providers in section 9 for business purposes. We have not sold or shared personal information.

If someone on your team added information about you, such as your email address in an invite, or if your business is our customer, we may ask you to contact that business first, since it decides how that information is used.

16. Children

BrandRhythms is a business tool for adults. It is not directed to children under 13, and we don't knowingly collect personal information from them. You must be at least 18 to create an account. If you believe a child has given us personal information, contact us at [CONTACT EMAIL] and we'll delete it.

17. Changes to this policy

We'll update this policy when our practices change, and change the effective date at the top. If a change is significant, we'll tell account owners by email or in the app before it takes effect.

18. Contact us

Questions or requests about privacy:

[LEGAL ENTITY NAME]
[MAILING ADDRESS]
[CONTACT EMAIL]