Privacy Policy
Last updated: September 10, 2026
This policy describes what data SociOps processes, why we process it, who we share it with, and how you can delete it.
1. Who we are
SociOps (“we”, “us”) provides an AI content studio at sociops.com that helps people plan, generate, and publish blog posts, images, and social media content. This policy explains what personal data we process when you use the website, the free Studio chat, and the signed-in application.
2. Information we collect
- Account data: email address, hashed password (when you sign up with email), and the profile fields returned by social login providers.
- Content you create or upload: prompts, chat messages, blog drafts, generated images and videos, reference photos, documents, and brand/company profile details.
- Connected accounts: access tokens and account identifiers for social platforms you deliberately connect for publishing.
- Usage and technical data: feature usage events, generation counts and costs, error logs, approximate location derived from IP, browser and device information.
- Guest sessions: if you use Studio without an account, we create an anonymous session so your work is not lost during that visit.
- Support communication: messages you send us by email.
3. How we use information
- Provide the service: generate content, store your work, and publish where you ask.
- Authenticate you and keep your account secure.
- Apply plan limits, quotas, and cost tracking.
- Diagnose errors, monitor performance, and improve product quality.
- Communicate service notices, and respond to support requests.
- Detect abuse and comply with legal obligations.
5. Connected social accounts and publishing
When you connect a social platform to publish content, we store the tokens needed to post on your behalf and the metadata of posts we publish or schedule. We only publish content you have created or approved in the product. You can disconnect a platform at any time from the connections screen; this revokes our stored token for that platform.
6. AI processing and subprocessors
To generate text, images, and video we send your prompts and the relevant context (including reference material you provide) to third-party AI and infrastructure providers acting as our processors. Categories of subprocessors include:
- Cloud hosting and application delivery.
- Database, storage, and authentication infrastructure.
- AI model providers for text, image, and video generation.
- Web research and content-scanning services used by the research features.
- Social publishing and scheduling services.
- Payment processing (Paddle, acting as Merchant of Record — see below).
We ask providers to process data only on our instructions. Please do not paste secrets, passwords, or sensitive personal data into prompts.
7. Payment processing
If you buy a paid plan or credit pack, our order process is conducted by our online reseller Paddle.com, which acts as Merchant of Record for all orders and handles billing, tax collection, invoicing, and refunds. We never receive or store your full card details — Paddle processes them under its own privacy policy. We receive and store the transaction and subscription status needed to grant access to paid features (plan, renewal date, amount, currency), plus the billing name and email Paddle shares with us.
9. Legal bases for processing
- Contract: to provide the service you request.
- Legitimate interests: security, abuse prevention, and product improvement.
- Consent: optional communications and any non-essential processing, where applicable.
- Legal obligation: accounting, tax, and lawful requests.
11. Data retention
We keep account and content data while your account is active. Guest session data is short-lived and may be cleaned up automatically if it is never linked to an account. Logs and analytics are kept for a limited period for security and reliability. When you delete your account, we delete or anonymise personal data within a reasonable period, except where we must retain records for legal reasons.
12. Your rights
Depending on where you live (for example under GDPR or Turkish KVKK) you may have rights to access, correct, delete, export, or restrict processing of your personal data, to object to certain processing, and to lodge a complaint with your local supervisory authority. Contact support@sociops.com to exercise these rights.
13. Data deletion instructions
You can remove your data in either of these ways:
- In the app: delete individual content items, disconnect any connected social accounts, and then request account deletion from your profile page or by email.
- By email: send a deletion request from your registered address to support@sociops.com with the subject “Delete my account”. We verify the request and complete deletion, normally within 30 days.
If you signed in with Google, Apple, or Meta, you can additionally revoke our access from your provider’s account settings. Revoking access stops future sign-ins but does not by itself delete data already stored in SociOps, so please also send a deletion request.
14. Security
We use encryption in transit, access controls, row-level authorisation rules, and least privilege for administrative keys. No system is perfectly secure; if we become aware of a breach affecting your personal data we will notify you and regulators where required.
15. International transfers
Our providers may process data in countries other than yours, including the United States and the European Union. Where required, transfers rely on appropriate safeguards such as standard contractual clauses.
16. Children’s privacy
The service is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.
17. Changes to this policy
We may update this policy as the product evolves. We will change the “last updated” date above and, for material changes, provide a more prominent notice.
18. Contact
For privacy questions or data requests, email support@sociops.com.
4. Social login (Google, Apple, Meta)
If you sign in with Google, Apple, or Meta, we receive a limited profile from that provider — typically your name, email address, and profile picture — in order to create and identify your account.