Privacy Policy
Last updated: April 1, 2026
Steadybeat is a social media management service that allows users to publish content to multiple platforms simultaneously. This privacy policy describes how we collect, use, and protect your information in our service.
What data we collect
We collect the following information:
- Email address and name (during registration)
- Social media account access tokens (when you connect your accounts)
- Information about your Facebook Pages, YouTube channels, TikTok and LinkedIn accounts (name, ID, and access token)
- Content you publish (text, images, and videos published through the service)
Social media data usage
When you connect your social media accounts to Steadybeat, we request access to the information necessary for managing your accounts. We use this data solely to:
- List your accounts and pages as publishing targets
- Publish content to your selected accounts on your behalf
- Discover Instagram accounts linked to your Facebook Pages
- Retrieve analytics and comment data to track your account performance
Supported platforms: Facebook, Instagram, YouTube, TikTok, and LinkedIn. We do not collect or store private messages, friend lists, or other personal data.
Data storage and security
Your data is stored on Supabase, hosted in the EU region. Access tokens are stored encrypted in a database protected by Row Level Security (RLS). Only you can access your own data.
Access token validity varies by platform (e.g. Facebook/Instagram ~60 days, YouTube ~6 months), after which the connection needs to be renewed.
Data protection measures
We implement the following technical and organizational measures to protect your data:
Encryption in transit: All communication between your browser and our servers is encrypted using TLS (HTTPS). API calls to social media platforms are also made over encrypted connections.
Encryption at rest: Your database is encrypted at rest using AES-256. Social media access tokens are stored with additional application-level encryption.
Access control: Our database uses Row Level Security (RLS), which ensures that each user can only access their own data. Administrative access to production systems is restricted and requires multi-factor authentication.
Data minimization: We only collect and store information that is necessary to provide the service. We do not store social media content after it has been published. Temporary files (such as images being processed for publishing) are deleted immediately after use.
Data retention: Account data is retained for as long as your account is active. Access tokens expire according to each platform's policy and are removed when you disconnect an account. When you delete your account, all associated data is permanently removed within 30 days.
Incident response: In the event of a data breach that poses a risk to your rights, we will notify affected users and the relevant supervisory authority within 72 hours, as required by the GDPR.
Infrastructure: Our data is hosted on Supabase in the EU region (Frankfurt, Germany). Supabase maintains SOC 2 Type II compliance and provides automated backups with point-in-time recovery.
Error tracking
We use the error-tracking service Sentry (Functional Software, Inc.) to detect and fix technical faults in the service.
Sentry receives the user's identifier and email address, plus technical error context: browser, page, error message, and stack trace. Post content, passwords, and access tokens are filtered out before any data is sent.
The legal basis for this processing is legitimate interest: keeping the service reliable and fixing faults quickly. Processing is governed by a data processing agreement (DPA) with Sentry. Data may also be processed outside the EU under appropriate safeguards.
Data sharing
We do not sell, rent, or share your personal data with third parties. Your data is used solely to provide the Steadybeat service.
We share data only in the following cases:
- With social media platform APIs (Facebook, Instagram, YouTube, TikTok, LinkedIn) to execute publishing and analytics requests (only with your explicit consent)
- With OpenAI's API for AI-assisted content generation (optional feature, no personal data shared)
- With the error-tracking service Sentry (Functional Software, Inc.) to detect and fix technical faults
- When required by law in response to legal requests
Data deletion
You can at any time:
- Disconnect a social media account in the dashboard, which deletes stored tokens
- Request deletion of your account and all data by contacting us via email
When your account is deleted, all your data, including access tokens and publishing history, is permanently removed.
Contact
If you have questions about privacy or want to request data deletion, contact us:
Email: ...