Privacy Policy
Last updated: September 9, 2026
Steadybeat is a social media management service that allows users to publish content to multiple platforms simultaneously. This privacy policy describes how we collect, use, and protect your information in our service.
What data we collect
We collect the following information:
- Email address and name (during registration)
- Social media account access tokens (when you connect your accounts)
- Information about your Facebook Pages, YouTube channels, TikTok, X and LinkedIn accounts (name, ID, and access token)
- Content you publish (text, images, and videos published through the service)
Social media data usage
When you connect your social media accounts to Steadybeat, we request access to the information necessary for managing your accounts. We use this data solely to:
- List your accounts and pages as publishing targets
- Publish content to your selected accounts on your behalf
- Discover Instagram accounts linked to your Facebook Pages
- Retrieve analytics and comment data to track your account performance
Supported platforms: Facebook, Instagram, YouTube, TikTok, X, and LinkedIn. We do not collect or store private messages, friend lists, or other personal data.
Data storage and security
Your data is stored on Supabase, hosted in the EU region. Access tokens are stored encrypted in a database protected by Row Level Security (RLS). Only your own company can access the data. If the company has more than one user, they see all of the company's shared data: brands, connected social accounts, posts and analytics. Of each other, users see the email address, the role and the join date, along with any open invitations and the addresses they went to. Profile names are not shown to other users.
Access token validity varies by platform (e.g. Facebook/Instagram ~60 days, YouTube ~6 months), after which the connection needs to be renewed.
Data protection measures
We implement the following technical and organizational measures to protect your data:
Encryption in transit: All communication between your browser and our servers is encrypted using TLS (HTTPS). API calls to social media platforms are also made over encrypted connections.
Encryption at rest: Your database is encrypted at rest using AES-256. Social media access tokens are stored with additional application-level encryption.
Access control: Our database uses Row Level Security (RLS), which limits rows to the company they belong to. Members of the same company see the company's data and each other's basic details. No other company sees any of it. Administrative access to production systems is restricted and requires multi-factor authentication.
Data minimization: We only collect and store information that is necessary to provide the service. We do not store social media content after it has been published. Temporary files (such as images being processed for publishing) are deleted immediately after use.
Data retention: Account data is retained for as long as your account is active. Access tokens expire according to each platform's policy and are removed when you disconnect an account. When the last member of a company deletes their login, the company's data is permanently removed within 30 days.
Incident response: In the event of a data breach that poses a risk to your rights, we will notify affected users and the relevant supervisory authority within 72 hours, as required by the GDPR.
Infrastructure: Data is hosted on Supabase in the EU region (Ireland). Supabase maintains SOC 2 Type II compliance and takes a daily database backup. We also copy the database and files daily to Cloudflare R2, restricted to the EU region. A database copy is deleted after 30 days, and a file you remove is gone from the backup within 21. The application itself runs on Vercel, which handles traffic and passes publications onward but is not a permanent store for your data. The execution region is pinned to Frankfurt, so application logic runs inside the EU. Vercel's delivery network is global, so your connection may be routed through the nearest node outside the EU with appropriate safeguards.
Access to your account for support
When we look into a problem you have reported, we may sign in to your account to see the same view you do. Without signing in, an administrator sees only part of your data, and not your connected social accounts or their access tokens.
Access is limited to the administrator, and every sign-in is written to a separate access log. We use it only to resolve support requests.
The legal basis for this processing is legitimate interest: providing support and keeping the service running.
Error tracking
We use the error-tracking service Sentry (Functional Software, Inc.) to detect and fix technical faults in the service.
Sentry receives the user's identifier and email address, plus technical error context: browser, page, error message, and stack trace. Post content, passwords, and access tokens are filtered out before any data is sent.
The same error context is also stored temporarily in our own database in the EU region while our use of Sentry is limited. Those rows carry the user's identifier, not post content, and they are deleted automatically after seven days.
The legal basis for this processing is legitimate interest: keeping the service reliable and fixing faults quickly. Processing is governed by a data processing agreement (DPA) with Sentry. Data may also be processed outside the EU under appropriate safeguards.
Data sharing
We do not sell, rent, or share your personal data with third parties. Your data is used solely to provide the Steadybeat service.
We share data only in the following cases:
- With social media platform APIs (Facebook, Instagram, YouTube, TikTok, X, LinkedIn) to execute publishing and analytics requests (only with your explicit consent)
- With OpenAI's API for AI-assisted content generation (optional feature, no personal data shared)
- With the error-tracking service Sentry (Functional Software, Inc.) to detect and fix technical faults
- With Cloudflare to store our backups (R2, restricted to the EU region)
- With Vercel (Vercel Inc.) as the technical platform the service runs on: the content you publish passes through it on the way to the social media platforms
- When required by law in response to legal requests
Data deletion
You can at any time:
- Disconnect a social media account in the dashboard, which deletes stored tokens
- Request deletion of your account and all data by contacting us via email
When your login is deleted, we remove the login and your membership in the company. If you were the company's only member, the company's data goes with it, access tokens and publishing history included. If the company has other members, its data stays with them.
We keep a record in the admin log that the deletion was carried out (the email address and the time), so we can show the request was fulfilled.
Contact
If you have questions about privacy or want to request data deletion, contact us:
Email: ...