Privacy Policy
Last updated: June 15, 2026
BlogSocials ("we", "us", "our") operates the website www.blogsocials.com and the BlogSocials platform. This policy explains what data we collect, how we use it, and the controls you have over it. It is written to be honest and specific rather than legalistic.
The short version. We store the content you create in BlogSocials, the OAuth tokens for the social accounts you connect, and standard account details. We use those to publish your approved content to your own accounts and to show you your own analytics. We do not sell your data, use it for advertising, target ads to you, or build audiences from it. You can disconnect an account or delete your account at any time and the data goes with it.
1. Information we collect
When you use BlogSocials we collect:
- Account information: your email address and, if you set one, a password hash (via Supabase Auth, hashed with bcrypt).
- Company data: your company name, website domain, brand colors, logo, and blog configuration.
- Strategy data: the publishing voices you set up (name, persona type, target audience, voice, content pillars, goal).
- Content: the articles and social posts you create, generate, or import.
- Social media OAuth tokens: access and refresh tokens for the social accounts you connect (currently LinkedIn; other platforms may be added over time).
- Post analytics: engagement metrics (impressions, clicks, likes, comments, shares) fetched from the platforms where you have published, for the posts you have published.
- Blog analytics: aggregate page views on the articles you publish on your BlogSocials-hosted blog.
2. How we use your information
We use the data above to:
- Provide and maintain the BlogSocials platform.
- Generate articles and draft social posts on your behalf, using the strategy context you have configured.
- Publish content to your connected social accounts, only after you have explicitly approved each post.
- Host your blog on its subdomain or your custom domain.
- Show you analytics for your own published posts and articles.
- Send transactional emails (account confirmation, password reset, magic-link sign-in).
- Diagnose issues and improve the service.
3. Social accounts and the LinkedIn Community Management API
When you connect a social account, we store an OAuth access token that lets us post on your behalf. The workflow is the same on every platform:
- You authorize a specific account (your personal profile, or a company page you administrate) via the platform's own OAuth flow.
- BlogSocials generates a draft post.
- You review, edit, and either schedule or discard the draft.
- On the scheduled time, our backend cron publishes the exact approved content, unchanged.
- You can disconnect the account at any time. On disconnect, we revoke the token and cancel any pending scheduled posts for that account.
We never post without per-post approval. We do not access private messages, personal contact data, or content from accounts or pages you do not administrate. For company page posting on LinkedIn, we use the w_organization_social and r_organization_social scopes solely to publish approved posts and fetch engagement metrics for those posts.
4. What we do NOT do with your data
To be explicit about this because it is often the first question:
- We do not sell, rent, or license your data to anyone.
- We do not use data obtained from connected social accounts for advertising, sales prospecting, lead generation, or building marketing audiences.
- We do not target ads to you, and we do not run any advertising on the BlogSocials platform.
- We do not use tracking cookies, advertising cookies, or third-party analytics that profile you across other sites.
- We do not train AI models on your content.
5. Data storage, location, and security
Your data is stored in Supabase (Postgres on AWS). Application traffic runs on Vercel. All connections use TLS. Passwords are hashed by Supabase Auth (bcrypt). OAuth access tokens are stored server-side and are never exposed to your browser. Row-level security in the database isolates each customer's data from every other customer's.
6. Service providers (sub-processors)
We share limited data with a small set of infrastructure providers required to run the service:
- Supabase: hosted database and authentication.
- Vercel: application hosting and edge functions.
- Anthropic: LLM API used to generate article and social post drafts. Prompt content is sent, output is returned; Anthropic's API policy is not to train on API traffic.
- Google (Gemini): optional image generation, only when you choose "AI-generated" for hero images.
- Resend: transactional email delivery (signup confirmation, password reset, etc.).
- Social platforms: we send them only the content you have approved for publishing, and receive back only public engagement metrics for those posts.
7. Your rights
You can:
- Access: see all your data in your dashboard at any time.
- Correct: edit any of it directly in the UI.
- Disconnect a social account: revokes the token immediately and cancels pending scheduled posts for it.
- Export: your articles and posts are yours; contact us for a full export in JSON.
- Delete your account: triggers a cascade that removes your company, strategies, articles, social posts, tokens, and settings from our database. Backups age out within 30 days.
If you are in the EU/EEA or the UK, you additionally have the rights under the GDPR (access, rectification, erasure, restriction, portability, objection). Exercise any of them by emailing privacy@blogsocials.com and we will respond within 30 days.
8. Data retention
We keep your data as long as your account is active. On account deletion, active data is removed immediately from the primary database. Encrypted backups age out within 30 days. Post analytics for a disconnected account are deleted alongside that account's token.
9. Cookies
We use essential cookies only, for authentication (keeping you signed in). No tracking, advertising, or profiling cookies. No third-party analytics beacons.
10. Privacy responsibility and contact
BlogSocials is a small, founder-run company. Privacy compliance sits with the founder, contactable at privacy@blogsocials.com. If LinkedIn, Meta, or any other platform requires us to securely delete data obtained via their API, we have the technical capability to do so and will act within their required timeframe.
11. Changes to this policy
We may update this policy from time to time. We will notify you of material changes by email or through the platform, and update the "Last updated" date above.