Privacy Policy

Version 2026-09-29 · Effective 29 September 2026

This policy explains what personal data SocialMetrics collects, why, on what legal basis, who we share it with, how long we keep it, and what rights you have. It applies to the SocialMetrics website and application.

We have tried to write it in plain language. If anything is unclear, ask us — the contact details are in section 1.

1. Who is responsible for your data

ControllerNicolás Olmedo
Registered address185 Mathilda Ct, Morgan Hill, CA 95037, United States
Privacy contact[email protected]
EU/UK representative (if applicable)Not appointed

We have not appointed a Data Protection Officer, because we are not required to. Privacy questions go to the address above.

2. What we collect

2.1 Data you give us

  • Account data — your email address, and your name if you provide one.
  • Authentication data — a hash of your password (never the password itself), or your Google account identifier, display name and profile picture URL if you sign in with Google.
  • Support correspondence — anything you send us by email.

2.2 Data from Instagram, with your authorisation

When you connect an Instagram Business or Creator account through Instagram Business Login, we receive, on your behalf and within the permissions you granted (instagram_business_basic, instagram_business_manage_insights):

  • your Instagram account identifier, username, profile picture and follower/media counts;
  • your posts and Reels, including captions, thumbnails, media URLs, timestamps and per-post metrics;
  • account insights — reach, views, follower count, accounts engaged, likes, comments, shares, saves and related metrics;
  • aggregated audience demographics — age bands, gender split, cities and countries. Instagram provides these only as aggregate totals. We never receive a list of your followers, and we cannot identify any individual follower.
  • an access token, which we store encrypted (see section 7).

2.3 Data from YouTube, with your authorisation

SocialMetrics uses YouTube API Services. When you connect a YouTube channel through your Google account, you also agree to the YouTube Terms of Service, and we receive, on your behalf and within the scopes you granted (youtube.readonly, yt-analytics.readonly):

  • your channel profile — channel identifier, name, profile picture and the public subscriber, video and view counts;
  • your videos' metadata — titles, thumbnails, durations, publication dates, privacy status (public, unlisted or private) and per-video view, like and comment counts;
  • channel analytics — views, watch time, likes, comments, shares, daily subscriber gains and losses, traffic sources, device types, and aggregated audience demographics provided by YouTube only as percentages. We never receive a list of your subscribers or viewers, and we cannot identify any individual among them;
  • an access token and a refresh token, which we store encrypted (see section 7).

We use this data only to show your own dashboards, reports and exports to you and to the people you explicitly authorise, in line with Google's Limited Use requirements — we do not sell it, use it for advertising, or use it for any other purpose. Google's handling of your data is described in the Google Privacy Policy.

Disconnecting a YouTube channel deletes the YouTube data we stored for it: we revoke our access with Google and delete the channel's stored tokens and daily snapshots. You can also revoke SocialMetrics' access at any time from your Google security settings.

2.4 Data we generate

  • Daily snapshots of selected metrics, so you keep history beyond the API's short windows.
  • AI outputs — Reel transcripts, written analyses of Reels and YouTube videos, and Brand Kit documents, and a usage ledger recording which feature consumed how many credits and when.
  • Team and sharing records — memberships, permissions, invitation records, brand dashboards and share tokens (stored hashed).
  • Legal acceptance records — the version of these documents you accepted and when.
  • Session records — a hashed session identifier and its expiry.

2.5 Data collected automatically

  • Server logs, kept briefly for security, abuse prevention and debugging.
  • Local storage in your browser — your session identifier, language, theme and a cache of the data already shown to you. This stays on your device.
  • Google Analytics — see section 6 and the Cookie Policy.

2.6 What we do not collect

We do not collect payment card details — Stripe does, directly. We do not receive your Instagram or Google passwords. We do not collect special-category data (health, biometrics, political opinions and similar), and you should not send it to us.

3. Why we use it, and on what legal basis

Under the GDPR and equivalent laws, we rely on:

PurposeLegal basis
Creating and running your account; authenticationPerformance of a contract (Art. 6(1)(b))
Fetching and displaying your Instagram and YouTube analyticsPerformance of a contract
Daily snapshots that build your historyPerformance of a contract
Processing payments, invoicing, preventing chargebacksContract; legal obligation (Art. 6(1)(c))
Sending verification, password-reset and security emailsContract
AI analysis and Brand Kit generationPerformance of a contract — you trigger each job explicitly
Keeping the Service secure, rate-limiting, preventing abuseLegitimate interests (Art. 6(1)(f))
Keeping records of accepted termsLegal obligation; legitimate interests
Analytics about how the site is usedConsent (Art. 6(1)(a)) — you can refuse or withdraw it
Service announcements about changes that affect youContract; legitimate interests

Where we rely on legitimate interests, we have weighed those interests against your rights and consider the processing proportionate and expected. You may object — see section 9.

We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not use it for automated decision-making that produces legal or similarly significant effects.

4. AI processing

When you run a Reel analysis or generate a Brand Kit, we send the audio and video of the Reels you selected, plus the associated metrics, to our AI provider (Google — Gemini API) to be processed and returned.

When you run a YouTube video analysis, we do not send the video file. We send the address (URL) of the video, which our AI provider retrieves directly from YouTube, together with its title, duration, the video's aggregate analytics and the language of your interface. Only videos that are public on YouTube can be analysed; unlisted and private videos are never sent.

When a user with AI permission runs the content classification (content pillars and sponsored-post detection), we send the caption of each post being classified and, if you previously ran a paid Reel analysis on that post, an excerpt of its stored transcript, to a second AI provider (TypeSafe AI). We never send images, audio or video to TypeSafe. We store only the resulting classification and a hash of the input, not the caption text itself.

  • The output is generated by an AI model and is labelled as such in the interface. It may contain errors.
  • Our AI providers (Google and TypeSafe) are engaged as processors on terms that do not permit them to train models on your data. TypeSafe acts under a data processing agreement.
  • Processing is triggered by you, per job. If you never use these features, nothing is ever sent.
  • Transcripts and analyses are stored in your account so you can revisit them, and are deleted with your account.

5. Who we share data with

We use a small number of processors. Each acts on our instructions, under a contract that includes the data-protection terms required by Article 28 GDPR.

ProcessorWhat it doesWhere
DigitalOceanApplication hosting and the PostgreSQL databaseNYC, United States
Meta Platforms (Instagram)Source of your Instagram analytics data, via the Graph APIUnited States / global
Google (YouTube API Services)Source of your YouTube analytics data, via the YouTube Data and Analytics APIsUnited States / global
Google (Gemini API)AI transcription and analysis of Reels and YouTube videos, only when you trigger itUnited States / global
TypeSafe (TypeSafe AI)AI classification of post captions into content categories and sponsored-content detection. Receives post captions and, if you previously ran a paid Reel analysis, an excerpt of its stored transcript; never images, audio or videoUnited States
Google (Sign-In)Optional authenticationUnited States / global
Google AnalyticsWebsite usage statistics — only with your consentUnited States / global
StripePayment processing, subscriptions, customer portalUnited States / global
ResendTransactional email (verification, password reset, notices)United States / global

We may also disclose data where we are legally required to, to establish or defend legal claims, or as part of a merger or sale of the business — in which case we would notify you first.

People you invite see the account sections you grant them. Anyone you send a share link to sees the contents of that brand dashboard. Those disclosures are made by you, and you control them.

6. Analytics

Our public website loads Google Analytics. It collects usage information such as pages viewed, approximate location derived from IP address, device and browser type.

This is not strictly necessary to run the Service, so in the European Economic Area, the United Kingdom and other regions with equivalent rules we ask for your consent before loading it, and you can withdraw that consent at any time. Details, and how to change your choice, are in the Cookie Policy.

7. How we protect your data

  • Instagram access tokens and YouTube (Google) access and refresh tokens are encrypted at rest with AES-256-GCM; the key is held only in the server environment.
  • Passwords are stored as scrypt hashes. We never store or log a password in clear.
  • Session identifiers are stored as SHA-256 hashes; the raw value exists only in your browser.
  • Share-link tokens and invitation codes are stored hashed. Share passwords are scrypt-hashed and never stored in clear.
  • Our application secrets and your Instagram and YouTube tokens are never sent to the browser.
  • Traffic is served over HTTPS; the database connection uses TLS.
  • Requests are rate-limited per account and per user; public share links have their own stricter limits.

No system is perfectly secure. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours and you without undue delay, as the GDPR requires.

8. International transfers

We are based in the United States, as are most of our processors. Where personal data leaves the European Economic Area or the United Kingdom, the transfer is protected by the European Commission's Standard Contractual Clauses, by an adequacy decision, or by the EU–US Data Privacy Framework where the processor is certified. You can ask us for details of the safeguards applying to a specific transfer.

9. Your rights

Wherever you live, you can ask us to:

  • access the personal data we hold about you, and get a copy;
  • correct anything inaccurate or incomplete;
  • delete your account and your data ("right to erasure");
  • export your data in a portable, machine-readable format;
  • restrict or object to processing based on legitimate interests;
  • withdraw consent at any time, without affecting processing already carried out.

How to exercise them. Some things you can do yourself, right now:

RightHow
Export your metrics"Export CSV" on any page, and PDF reports
Delete your account and your dataSettings → Profile & security → Delete account. Takes effect immediately
Withdraw Instagram accessDisconnect the account in Settings → Connected accounts, or revoke it in Instagram. Removing SocialMetrics from your Instagram or Meta account settings also sends us a deletion request, which we honour automatically
Withdraw YouTube accessDisconnect the channel in Settings → Connected accounts, or revoke SocialMetrics' access at Google security settings. Disconnecting revokes our access and deletes the channel's stored data, including its daily snapshots
Change your passwordSettings → Profile & security → Sign-in & security
Withdraw analytics consentSee the Cookie Policy
Cancel a subscriptionSettings → Plan & credits

For anything else — including a full data export — write to [email protected] from the email address on the account. We respond within 30 days.

We do not charge for this, and we will not treat you worse for exercising a right.

If you are in the EEA or the UK, you may lodge a complaint with your national data-protection authority. We would appreciate the chance to resolve it first.

If you are in California, you have the rights above plus the right to know the categories of data collected, disclosed and sold or shared. We do not sell or share personal data as those terms are defined by the CCPA/CPRA, and we do not process it for cross-context behavioural advertising. We honour the Global Privacy Control signal where our analytics vendor supports it. You may designate an authorised agent to act for you.

If you are in another US state with a comprehensive privacy law — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, New Hampshire, New Jersey, Nebraska, Minnesota, Maryland, Rhode Island, Indiana, Kentucky, Iowa, Tennessee or Florida — the same rights apply. Where your state provides an appeal from a refused request, tell us and we will review the decision and explain the outcome in writing.

10. How long we keep data

DataRetention
Account and profileWhile your account exists
Instagram access tokenUntil you disconnect the account, delete your account, or Meta forwards us a deletion request for it
YouTube (Google) access and refresh tokensUntil you disconnect the channel or delete your account — we also revoke the authorisation with Google at that moment
Metrics cacheMinutes to hours (5–30 minutes per endpoint)
Daily snapshotsWhile your account exists — this is the history feature. Exception: a YouTube channel's snapshots are deleted the moment you disconnect it
AI outputs and usage ledgerWhile your account exists; the ledger may be kept longer where needed for billing records
Sessions30 days, sliding; deleted on sign-out or password reset
Verification and reset tokens24 hours (verification) / 1 hour (reset); single-use
Invitations7 days, or until accepted or revoked
Billing recordsAs long as tax and accounting law requires — typically 7 years
Legal acceptance recordsFor the limitation period applicable to the contract
Server logsShort-term, for security and debugging

When you delete your account, we delete or irreversibly anonymise your personal data immediately, except where we must keep specific records — billing and tax documents above all. Those keep the amount, currency and date, with the reference to you removed. Backups are overwritten on their normal cycle.

11. Children

The Service is not for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.

12. Changes to this policy

We may update this policy. Each version has a version identifier and an effective date. If a change materially affects how we use your personal data, we will notify you by email or in the application before it takes effect, and where the law requires it we will ask for fresh consent.

13. Contact

Privacy questions, and requests to exercise your rights:

[email protected]

This is version 2026-09-29 of this document. Earlier versions are available on request.