← marketingmagic

Privacy Policy

Effective 2026-05-24

Who we are

marketingmagic (“we”, “us”) is an auto-posting tool that helps founders publish to social networks on a schedule. We're a small team. If you need to reach a human about privacy, email mawad10101@gmail.com.

What we collect

  • Account data: your email address and a hashed password (managed by Supabase Auth). We never see or store your plain-text password.
  • Social account credentials: when you connect X, LinkedIn, Bluesky, Instagram, Threads, Facebook, or TikTok, we receive OAuth tokens (or app passwords for Bluesky) from the provider. These are stored encrypted server-side and never exposed to the browser.
  • Content you create: posts you write or generate, drafts, themes, and any source material (URLs, transcripts, audio notes) you provide.
  • Public post metrics: impressions, likes, replies, etc. that the social platforms expose for posts you ship through us.
  • Usage telemetry: standard server logs (IP, user-agent, paths) for security and debugging. Vercel Analytics for aggregate page-view counts. No third-party advertising trackers.

How we use it

  • To publish posts to the social networks you've connected.
  • To generate post drafts, themes, and analytics for your workspace.
  • To pull back engagement metrics for posts we published.
  • To send transactional email (password reset, billing receipts).
  • To debug errors and prevent abuse.

We do not sell your data. We do not use your post content to train AI models. We do not share your social account tokens with anyone outside the providers themselves.

Third parties we share with

These are the subprocessors that handle slices of the service. We share only what each needs to do its job.

  • Supabase — database + auth (everything we store).
  • Vercel — hosting + analytics (aggregated traffic).
  • OpenAI / Anthropic — drafting and editing post text. Content sent for generation is not stored by them beyond their abuse-detection windows.
  • Social platforms (X, LinkedIn, Meta for Instagram + Threads + Facebook, Bluesky, TikTok) — for publishing and reading public metrics on your behalf.
  • Stripe— payment processing (if you're on a paid plan).

Meta-platform data (Instagram + Threads)

When you connect an Instagram or Threads account, Meta returns an access token tied to your business account. We store that token encrypted server-side and use it only to publish posts you authorize, list your business accounts, and read engagement on posts we publish.

We honor Meta's Data Deletion callback. If you remove marketingmagic from your Facebook account, Meta will notify us automatically and we'll delete the associated tokens and account record within 30 days. You can also request deletion directly: /data-deletion.

Retention

Account and post data live as long as your account exists. When you delete your workspace or your account, we cascade-delete all rows tied to it from our database within 30 days. Server logs roll off on a 90-day window.

Your rights

  • Access and export your data — email us and we'll bundle it up.
  • Correct anything that's wrong.
  • Delete your account and everything tied to it — email mawad10101@gmail.com or use the in-app delete affordance.
  • Disconnect any social account at any time from /settings/channels.

Cookies

We set a session cookie (Supabase auth), a workspace cookie that remembers which workspace you last opened, and short-lived OAuth state cookies during connect flows. We don't use third-party tracking cookies.

Changes

If we change this policy materially, we'll update the effective date at the top and notify you by email before the change takes effect.