Legal
Privacy policy
Last updated September 26, 2026
This policy explains what Socialuxy collects, why, and the choices you have. It applies to the Socialuxy web app and to data we receive from the social networks you connect.
Information we collect
- Account information: your name, email address and an encrypted (hashed) password.
- Workspace content: brands, scheduled posts, drafts, reports, link-in-bio pages and team membership.
- Connected social accounts: when you connect a profile (for example Instagram), we receive an access token and the data the permissions you grant allow — profile details, audience size, account and post insights, and comments on your posts.
- Usage data needed to run the service securely, such as IP addresses in server logs used for rate limiting.
How we use it
- To publish the posts you schedule, show your analytics and reports, and let you reply to comments from the inbox.
- To keep the service secure, prevent abuse and fix problems.
We do not sell your data or use data from connected networks for advertising.
Storage and security
Access tokens are encrypted at rest with AES-256-GCM. Passwords are hashed with bcrypt. Sessions use signed, HTTP-only cookies. Access to brand data is limited to members of that brand.
Retention and deletion
Disconnecting a profile removes its access token. Deleting your account (Settings → Danger zone) deletes your data and any brands you solely own. You can also remove Socialuxy from your Instagram settings; we then revoke access, and a deletion request removes all data we stored for that Instagram account — see data deletion.
Contact
Questions or requests: [email protected].