1. Data We Store
We only store the minimum necessary to operate the platform.
Personal Data
- Name, email, contact info
- Business profile details
- Uploaded brand assets (logos, product images)
Operational Data
- Campaign drafts
- AI prompts and user-generated content
- Credit usage logs
- Activity logs
- Preferences/settings
Does NOT include:
- ❌ Meta ad data
- ❌ Instagram media fetched through APIs
- ❌ Google OAuth data
- ❌ Social login data
API-fetched data is processed in-memory and not stored unless required for core functionality (e.g., analytics).
2. Token Storage & Access
- Access tokens (Meta, Google, Razorpay keys): Stored only in encrypted form
- Stored using industry-best practices (AES-256)
- Never shared with any third party
- Automatically deleted when a user disconnects integration, token expires and is replaced, or account is deleted
- Only backend systems—not frontend clients—can access these tokens.
3. Data Processing
We process data strictly to:
- Publish posts
- Run ads
- Fetch analytics
- Provide insights
- Improve platform features
- Generate user-requested AI output
We never use Meta/Google data for AI training or internal model development.
4. Security Controls
- SSL/TLS enforced
- Database encryption at rest
- Supabase RLS policies enabled
- Role-based access control
- API rate limiting
- Automatic session invalidation
- Audit logging of all sensitive actions
- Restricted admin access
- Daily encrypted backups
- Firewall & WAF protection
5. Data Retention
- User account data: retained until deletion
- API tokens: deleted immediately upon revocation
- Analytics logs: 60–90 days
- Backups: 30 days rolling
- Support conversations: 6 months
6. User Controls
Users can:
- Delete their account
- Disconnect their Meta/Google integrations
- Request deletion of all stored data
- Download their data (on request)
Requests are processed via info@skalxai.app within 15 days.