DOC SOC-002 · REV B
Privacy Policy
1. Scope
This policy covers the public website, the optional Socheli-hosted dashboard, and self-hosted Socheli software. Their privacy profiles are described separately below.
2. Data this website collects
The public marketing and documentation site sets no advertising cookies and runs no behavioral advertising tracker. The web server keeps standard, short-lived access logs (such as IP address and requested URL) for security and capacity purposes. The hosted dashboard uses authentication cookies required to keep users signed in and associates an account email address with the user's workspace.
3. Data the software handles
When you run Socheli on your own hardware, it stores everything it works with as flat JSON files and media on your devices:
- OAuth tokens you grant for your own social accounts (for example, an Instagram access token), stored in local data files on your machine.
- Generated media: scripts, storyboards, and rendered videos, written to your disk.
- Run and mission records: pipeline logs, schedules, and engagement metrics, kept as flat JSON on your device.
If you use a Socheli-hosted workspace, Socheli stores the data needed to provide the features you enable. This can include OAuth or business-system-user tokens; Facebook Page, Instagram professional-account, ad-account, WhatsApp Business Account, and phone-number identifiers; selected profile and media metadata; comments, direct messages, webhook events, insights, templates, ad drafts and campaign results; schedules; generated content; and audit records. Platform data is scoped to the customer's workspace and is deletable on request (see Data Deletion).
4. Data we never hold
Socheli never asks for or stores a customer's Facebook, Instagram, or WhatsApp password. Payment-card details are handled by the payment provider, not stored by Socheli. Self-hosted data remains on the operator's devices. In hosted workspaces, access tokens and platform data are kept server-side and are not returned to browser responses or sent to an AI model provider.
5. Third-party platforms
When Socheli publishes to or reads from a platform (Meta/Instagram, Google/YouTube, TikTok), it does so through that platform's standard OAuth and official APIs, under your authorization, subject to that platform's own privacy policy. Socheli requests only the permissions needed for the features you enable, and you can revoke them at any time in the platform's settings.
Use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Use of Meta Platform data adheres to the Meta Platform Terms.
6. Service providers and retention
The hosted service uses Hetzner Online GmbH for server and application-data hosting, Clerk, Inc. for authentication, and OpenRouter, Inc. to process message text only when a workspace enables an AI responder. Socheli does not send Meta access tokens or Meta asset identifiers to the model provider. We retain hosted workspace data while the account is active and remove it within 30 days of a verified deletion request, except where a longer period is required by law or needed to resolve abuse or security incidents.
7. Changes
If this policy changes, the new version is published at this URL with an updated effective date. The document history is in the public repository.
8. Contact
For any privacy question or request: contact@socheli.com.