Data Protection
Our Data Minimization Philosophy
Section titled “Our Data Minimization Philosophy”At Sociable AI, we follow a strict data minimization approach. We only collect and store the absolute minimum data needed to provide our services:
- Limited Content Storage: We store social-media content only when needed for core functionality
- Access Token Focus: We store access tokens rather than credentials, ensuring we never have access to your passwords
- Purpose-Limited Processing: Social-media content is processed and retained only as needed to provide enabled features
Data Categories and Protection
Section titled “Data Categories and Protection”| Data Type | Storage Approach | Protection Measures |
|---|---|---|
| Authentication data | Handled by Clerk | Industry-standard encryption via Clerk’s SOC 2 compliant service |
| OAuth tokens | Encrypted at rest | Access controlled, rotated per platform requirements |
| User settings | Minimal storage | Encrypted at rest |
| Message data, including TikTok direct messages | Until subscription or contract ends, a shorter contractual retention period applies, or deleted earlier | Encrypted at rest, deletion requests supported |
Privacy Principles
Section titled “Privacy Principles”Our data protection practices are designed with privacy in mind:
- Access Controls: Users can request access to their personal data
- Deletion Rights: We provide account deletion functionality
- Data Portability: We support export options for user data when requested
- Purpose Limitation: Data used only for specified, legitimate purposes
- Transparency: Clear communication about our data practices
Third-Party Data Processing
Section titled “Third-Party Data Processing”When we engage third-party services to process data:
- We select providers with strong security credentials (those with SOC 2, GDPR compliance)
- We implement appropriate data processing agreements
- We limit data sharing to only what’s necessary for service provision
Technical Protection Measures
Section titled “Technical Protection Measures”Encryption
Section titled “Encryption”- TLS 1.3 for all data in transit
- AES-256 encryption for data at rest
- Secure key management practices
Access Controls
Section titled “Access Controls”- Role-based access controls
- Least privilege principle
- Regular access reviews
Monitoring
Section titled “Monitoring”- Continuous monitoring for unusual access patterns
- Automated alerts for potential security events via Google Cloud Security Command Center, AWS CloudWatch, Sentry, Clerk Security Alerts, Supabase Security Monitoring, and infrastructure monitoring systems
- Regular security reviews of data access logs
Retention and Deletion
Section titled “Retention and Deletion”- Regular data review and cleanup processes
- Automatic deletion of transient processing data
- TikTok direct message content may be stored for reply drafting, conversation history, and automation
- TikTok direct message content is deleted when the relevant subscription or contract ends, when a shorter contractual retention period applies, following a valid deletion request, or when the relevant account or workspace is deleted
- Data is returned before deletion when required by a written contract
- User-controlled data deletion options
- Clear retention periods defined for each data category
Contact for Data Concerns
Section titled “Contact for Data Concerns”If you have questions about how we handle your data or wish to exercise your data rights, please contact us at:
- Email: product@sociable.how
- Response time: Within 48 hours