Privacy Policy
1. Introduction
PublishSocial is a social media publishing service operated by Think Company SRL, a company registered in Romania with its registered office at Miron Costin 65, Constanța, Romania (“PublishSocial”, “we”, “us” or “our”). This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, and the choices and rights you have when you use our website at publishsocial.com, our web application, our APIs and our email communications (together, the “Service”).
Think Company SRL is the controller of the personal data described in this Policy. Because we are established in the European Union, we process personal data in accordance with the General Data Protection Regulation (GDPR) and Romanian data protection law and, where they apply to you, other privacy laws such as the California Consumer Privacy Act (CCPA).
We process personal data only where we have a legal basis to do so, which is one of the following:
- Performance of a contract — for example, creating your account, operating the Service and managing your subscription;
- Compliance with a legal obligation — for example, keeping invoices and accounting records as required by tax law;
- Your consent — for example, for optional marketing communications, which you can withdraw at any time;
- Our legitimate interests — for example, keeping the Service secure, preventing abuse and improving functionality, provided these interests are not overridden by your rights and freedoms.
If you have any questions or requests regarding this Policy or your personal data, contact our data protection contact at gdpr@publishsocial.com. Please read this Policy carefully to understand how we handle your information before using the Service.
2. Information you provide to us
2.1 Account information
To use the Service you must create an account. We ask only for what we need: your name, email address, a password (stored exclusively as a one-way cryptographic hash — we cannot read it), your time zone and your preferred content language. You may optionally provide additional details, such as a company name. None of this information is made public by us.
2.2 Communications and support
If you contact us by email or through the Service — for example with a support question, a complaint or feedback — we keep the content of your message, your email address and related contact details so that we can respond, resolve your request and keep a record of the correspondence.
2.3 Payment information
Paid subscriptions and credit purchases are processed by our payment provider, Stripe. Your card details are entered on secure forms and transmitted directly to Stripe over an encrypted connection; we never see or store your full card number, expiry date or CVC on our servers. We receive and store only the information we need to manage your subscription: your plan, payment and trial status, invoices and billing history. Stripe processes payment data in compliance with the Payment Card Industry Data Security Standard (PCI DSS).
We retain invoices and related accounting records for up to 10 years, as required by Romanian fiscal and accounting legislation.
2.4 Content you create in the Service
We store the content you create, upload or import so that the Service can work for you: post drafts and published posts, images and videos you upload or edit, links and first comments, items saved to your content library, text you submit for AI rewriting together with the generated output, and the settings you choose for each post (such as scheduling and automatic deletion rules).
2.5 Sensitive personal data
The Service is not designed to collect special categories of personal data (such as data about health, political opinions, religion or ethnic origin) and we ask you not to submit such data to us. If you choose to include sensitive data in the content you create or publish, you do so at your own initiative and you remain responsible for that content.
3. Information we collect automatically
3.1 Device, location and sign-in information
When you use the Service we automatically record technical information such as your IP address, browser type and operating system, sign-in events and an approximate location derived from your IP address. We use this information to keep your account secure (for example, to detect suspicious sign-ins), to operate the Service reliably and to make scheduling work correctly. We also store your time zone setting so that posts are scheduled and displayed at the correct local time.
3.2 Product usage and activity logs
We keep activity logs of how the features of the Service are used in your account — for example publishing, scheduling, edits, deletions and the calls made to connected platforms on your behalf. We use these logs to operate and improve the Service, to troubleshoot problems, to prevent abuse and to give you a transparent history of what happened in your account. You may object to processing carried out for product-improvement purposes by contacting us at gdpr@publishsocial.com.
3.3 Cookies
We use a strictly necessary session cookie to keep you signed in and a CSRF token to protect forms against forgery. We do not use advertising or cross-site tracking cookies. If we ever introduce non-essential cookies (for example, analytics), we will ask for your explicit consent before placing them and you will be able to manage your preferences at any time through a consent banner or your browser settings.
4. Information we receive from Facebook and other connected services
4.1 Data received from Meta Platforms
PublishSocial integrates with Facebook through Meta's official tools: Facebook Login for Business and the Meta Graph API. When you choose to connect your Facebook Pages, you authorize Meta to share certain data with us. Depending on the permissions you grant during login, this data includes:
- your Facebook name and user ID, used to identify and maintain your connection;
- the list of Facebook Pages you manage, including each Page's ID, name, category and profile picture, so that you can select which Pages to use with the Service;
- Page access tokens that allow the Service to act only on the Pages you selected — these tokens are stored encrypted at rest and are never displayed;
- identifiers, links and status information for the posts you publish, edit or delete through the Service, together with delivery or error information returned by Meta.
4.2 What we do not access
We request only the permissions needed for Page publishing and management. We do not request, receive or store your private messages or your Page inbox, your friends list, the content of your personal profile or timeline, or any other Facebook data beyond what is described in section 4.1.
4.3 How we use Meta platform data
Data received from Meta is used exclusively to provide the features you request: listing your Pages, publishing, editing and deleting posts, adding a first comment where you choose to, and showing you the status and links of your posts. We do not use platform data for advertising, we do not sell it, we do not build profiles from it, and we do not use it for any purpose unrelated to the Service. We process platform data in accordance with Meta's Platform Terms and Developer Policies.
4.4 Disconnecting and deleting your Facebook data
You are in control of the connection at all times. You can disconnect a Page from within the Service, which deletes or invalidates its stored access token. You can also remove PublishSocial from your Facebook settings (Settings → Business integrations); when you do, Meta notifies us automatically and we mark your connections as revoked. You may request deletion of the Facebook-related data we hold about you in any of the following ways: through your Facebook settings (which sends us an automated data deletion request that we honour), by visiting publishsocial.com/data-deletion, or by emailing gdpr@publishsocial.com.
4.5 Other services you connect
If you connect your own WordPress website, we store the site address and the credentials you provide in encrypted form and use them solely to publish the articles you choose to that site. If you ask the Service to fetch publicly available content from a URL you submit, that URL is processed by our automation provider solely to carry out your request; you are responsible for ensuring that your use of any fetched content complies with applicable law and third-party terms.
4.6 Third-party privacy policies
The data you share with Meta, and Meta's own processing of your data, are governed by Meta's privacy policy, and your use of Facebook remains subject to Meta's terms. We encourage you to review those documents on Meta's website.
5. How we use your information
5.1 To provide, improve and develop the Service
We use the information described above to deliver and improve the Service. This includes:
- operating the core features: connecting Pages, composing posts, editing images and video, scheduling to your per-Page time slots, publishing, adding first comments, applying the automatic deletion rules you configure, and managing your content library;
- generating AI rewrites: the text you submit is sent to our AI provider in order to produce the output you requested, in your chosen content language;
- managing plans, free trials, credits, invoices and payments;
- understanding, in aggregate, how the Service is used, so that we can fix problems, test changes and develop new features.
5.2 To communicate with you
We use your contact details to send service communications — such as account, security and billing notices and information about material changes to the Service — on the basis of our contract with you and our legitimate interest in keeping you informed. With your consent, we may also send marketing communications about features and offers; every marketing email contains an unsubscribe link and you can opt out at any time without any effect on your use of the Service.
5.3 To protect the Service and comply with the law
We use information, in particular technical and activity logs, to keep the Service and our users safe, to detect and prevent fraud and abuse, to enforce our Terms of Service and Acceptable Use Policy, and to comply with our legal obligations.
6. Information we share and disclose
We do not sell or rent your personal data, and we do not share it with third parties for their own advertising purposes.
6.1 Sharing you control
The core purpose of the Service is to transmit content at your direction. When you publish, edit or delete a post, we share that content and the related instructions with Meta so that it appears on — or is removed from — the Facebook Pages you selected. When you publish an article to your WordPress site, we transmit it to that site using the credentials you provided. You control these flows: you decide what is published, where and when, and you can stop them at any time.
6.2 Service providers
We share the minimum necessary data with a small number of providers who process it on our behalf and under our instructions, based on data processing agreements:
- Stripe — payment processing, subscriptions, free trials and invoicing;
- Meta Platforms — carrying out the Facebook publishing, editing and deletion actions you request;
- OpenAI — processing the text you submit for AI rewriting in order to generate the requested output;
- Apify — fetching publicly available content from URLs you submit;
- hosting and email infrastructure providers used to run the Service and to deliver transactional email.
Each provider is contractually bound to confidentiality and to appropriate security measures and may use the data only to provide its service to us. A current list of sub-processors is available on request at gdpr@publishsocial.com.
6.3 Legal reasons
We may disclose information where we believe in good faith that disclosure is necessary to comply with a law, regulation or valid legal process, to enforce our agreements, or to protect the rights, property or safety of PublishSocial, our users or others.
6.4 Business transfers
If we are involved in a merger, acquisition, reorganisation, insolvency proceeding or sale of assets, your personal data may be transferred as part of that transaction. This Privacy Policy will continue to apply to your data, and we will notify you of any material changes resulting from such a transaction.
7. Where we store your data and international transfers
Your account data and content are stored on secure servers located in the European Union. Some of our service providers — including Stripe, Meta, OpenAI and Apify — are established in the United States or other countries outside the European Economic Area, so limited personal data may be transferred to those countries when their services are used. Where personal data is transferred outside the EEA, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses and, where the recipient is certified, the EU–U.S. Data Privacy Framework. You may request more information about these safeguards at gdpr@publishsocial.com.
7.1 Data security
We protect your data using technical and organisational measures appropriate to the risk, including: TLS encryption for all traffic between you and the Service; one-way hashing of passwords; encryption at rest of access tokens and third-party credentials; access controls, hardened configurations and logging on our infrastructure; and the data minimisation practices described in this Policy.
No method of transmission over the internet or of electronic storage is completely secure. While we work continuously to protect your personal data, we cannot guarantee its absolute security during transmission, and any transmission is at your own risk. Once we receive your data, we apply strict procedures to protect it against unauthorised access.
8. Data retention and deletion
- Account data and content are kept for as long as your account exists and as long as they are needed to provide the Service.
- You can delete your account at any time from your account settings, or by writing to gdpr@publishsocial.com. Deletion permanently erases your content, connected Pages, stored access tokens and personal data from our production systems without undue delay, and from backups within the normal backup rotation cycle. Deleted data cannot be recovered.
- Disconnecting a Facebook Page deletes or invalidates the stored access token for that Page.
- Automated Facebook data deletion requests received from Meta are honoured as described in section 4.4, and you can check the status of such a request at publishsocial.com/data-deletion.
- Invoices and accounting records are retained for up to 10 years, as required by Romanian law.
- Technical and activity logs are retained for a limited period for security, audit and troubleshooting purposes and are then deleted or anonymised.
9. Your rights
If you are in the EU or EEA — and in many other jurisdictions — you have the following rights in relation to your personal data:
- Access — to obtain confirmation that we process your data and a copy of it;
- Rectification — to have inaccurate or incomplete data corrected;
- Erasure (“right to be forgotten”) — to have your data deleted where there is no lawful reason for us to keep it;
- Restriction — to limit the processing of your data in certain circumstances, for example while a dispute about accuracy is resolved;
- Portability — to receive the data you provided to us in a structured, commonly used, machine-readable format;
- Objection — to object to processing based on our legitimate interests, and to object to direct marketing at any time;
- Withdrawal of consent — to withdraw any consent you have given at any time, without affecting the lawfulness of processing carried out before withdrawal.
You can exercise these rights using the tools in your account or by contacting gdpr@publishsocial.com. We respond to requests within one month, as required by the GDPR, and we may need to verify your identity before acting on a request. We will not discriminate against you for exercising any of your rights.
You also have the right to lodge a complaint with a data protection supervisory authority. In Romania, this is the National Supervisory Authority for Personal Data Processing (ANSPDCP, www.dataprotection.ro); you may also complain to the authority in your own country of residence or work.
9.1 California residents
If you are a California resident, the CCPA gives you the right to know the categories and specific pieces of personal information we have collected about you, the sources of that information, the purposes for which it is used and the categories of third parties with whom it is shared; the right to request deletion; and the right not to be discriminated against for exercising these rights. We do not sell personal information. To exercise these rights, contact gdpr@publishsocial.com.
10. Children's privacy
The Service is intended for adults and may only be used by persons aged 18 or over. We do not knowingly collect, use or share personal information of anyone under 18. If we become aware that a person under 18 has provided us with personal data, we will delete it promptly. If you are a parent or guardian and believe that your child has provided personal information to us, please contact us at gdpr@publishsocial.com and we will take the necessary steps to remove it. We cannot be held responsible for users who misrepresent their age; however, we act on every report we receive.
10.1 Child safety standards
We maintain a zero-tolerance policy towards child sexual abuse and exploitation (CSAE). Any content or behaviour that shares, promotes or facilitates such material, in any form, results in immediate account termination and, where appropriate, reporting to the competent authorities. If you encounter content or activity on our platform that you believe violates these standards, report it immediately to contact@publishsocial.com; we treat every report seriously and act on it promptly.
11. Contact us
If you have questions, concerns or requests regarding this Privacy Policy or your personal data, you can reach us at:
- Data protection contact: gdpr@publishsocial.com
- General enquiries: contact@publishsocial.com
- Postal address: Think Company SRL, Miron Costin 65, Constanța, Romania
We are committed to addressing your concerns and will respond to your enquiries as soon as possible.
12. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in the Service or in our legal obligations. The current version is always available at publishsocial.com/privacy, and the “Last updated” date at the top shows when it was last revised. If we make material changes, we will notify you by email (to the address associated with your account) or through a notice in the Service, and where the law requires it we will ask for your consent before the changes take effect. Previous versions of this Policy are available on request. If you continue to use the Service after a revised Policy takes effect, the revised Policy applies to your use of the Service; if you do not agree with an update, you may delete your account or contact us for assistance.