Privacy Policy
Last updated: September 2026
Social Pilot ("we", "our") is a self-hosted social media operating tool. This policy explains what data is processed when you use Social Pilot and how it is protected.
1. Who is responsible
Social Pilot is deployed as a dedicated instance on the infrastructure of each customer (the "Client"). The Client is the data controller for the content and account data processed through their instance. We operate the tooling but do not host or store Client data on our own infrastructure.
2. Data we process
- Account connection data. When you connect a social media account (e.g. TikTok, Instagram, Bluesky) via OAuth, we store the access token and related identifiers (account handle, account ID). Tokens are encrypted at rest.
- Content you create. Drafts, captions, hashtags, scheduled posts, and the media files (images, videos) you upload or generate.
- Performance and analytics data. Metrics retrieved from the connected platforms (impressions, engagement, comments) for the accounts you connect.
- Account and configuration data. Email addresses and settings of the operators using the instance.
3. How we use data
- To publish content to the social media accounts you connect, strictly following your explicit approval at every step.
- To retrieve and display analytics and comments for those accounts.
- To provide AI-assisted drafting. Text generation is performed by a provider you configure; media and brand assets default to local processing.
4. Legal basis (GDPR)
- Consent — granted when you connect a social account and use the service.
- Performance of a contract — processing needed to provide the publishing and analytics features.
- Legitimate interest — operating, securing and improving the service.
5. Data sharing
- Social platforms. Content and requests are sent to TikTok, Meta (Instagram) and other platforms exclusively through their official APIs, to perform actions you request.
- AI providers. If you enable AI features, drafts may be processed by a language-model provider you select. Media is never sent to a cloud model without your explicit consent.
- No selling. We do not sell, rent or share personal data with third parties for their own marketing.
6. Storage and security
All data is stored on the Client's own server. OAuth tokens are encrypted at rest. Connections are encrypted in transit (TLS). Access is protected by authentication and two-factor authentication.
7. Data retention
Account connection data and content are retained for as long as the account remains connected or the content is relevant, and are deleted upon disconnection or account deletion. You may disconnect a social account at any time, which revokes our access.
8. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict and port your personal data, and to object to processing. To exercise these rights, contact the Client operating your instance, or us at the contact below.
9. International transfers
Data is processed and stored in the European Union by default. When a third-party processor is used, we select providers offering appropriate safeguards (Standard Contractual Clauses) where applicable.
10. Changes
We may update this policy. The latest version is always published at this address.
11. Contact
For any privacy question, contact us at contact@aiturn.io.