Privacy Policy

Last updated: June 15, 2026

BlogSocials ("we", "us", "our") operates the website www.blogsocials.com and the BlogSocials platform. This policy explains what data we collect, how we use it, and the controls you have over it. It is written to be honest and specific rather than legalistic.

The short version. We store the content you create in BlogSocials, the OAuth tokens for the social accounts you connect, and standard account details. We use those to publish your approved content to your own accounts and to show you your own analytics. We do not sell your data, use it for advertising, target ads to you, or build audiences from it. You can disconnect an account or delete your account at any time and the data goes with it.

1. Information we collect

When you use BlogSocials we collect:

2. How we use your information

We use the data above to:

3. Social accounts and the LinkedIn Community Management API

When you connect a social account, we store an OAuth access token that lets us post on your behalf. The workflow is the same on every platform:

We never post without per-post approval. We do not access private messages, personal contact data, or content from accounts or pages you do not administrate. For company page posting on LinkedIn, we use the w_organization_social and r_organization_social scopes solely to publish approved posts and fetch engagement metrics for those posts.

4. What we do NOT do with your data

To be explicit about this because it is often the first question:

5. Data storage, location, and security

Your data is stored in Supabase (Postgres on AWS). Application traffic runs on Vercel. All connections use TLS. Passwords are hashed by Supabase Auth (bcrypt). OAuth access tokens are stored server-side and are never exposed to your browser. Row-level security in the database isolates each customer's data from every other customer's.

6. Service providers (sub-processors)

We share limited data with a small set of infrastructure providers required to run the service:

7. Your rights

You can:

If you are in the EU/EEA or the UK, you additionally have the rights under the GDPR (access, rectification, erasure, restriction, portability, objection). Exercise any of them by emailing privacy@blogsocials.com and we will respond within 30 days.

8. Data retention

We keep your data as long as your account is active. On account deletion, active data is removed immediately from the primary database. Encrypted backups age out within 30 days. Post analytics for a disconnected account are deleted alongside that account's token.

9. Cookies

We use essential cookies only, for authentication (keeping you signed in). No tracking, advertising, or profiling cookies. No third-party analytics beacons.

10. Privacy responsibility and contact

BlogSocials is a small, founder-run company. Privacy compliance sits with the founder, contactable at privacy@blogsocials.com. If LinkedIn, Meta, or any other platform requires us to securely delete data obtained via their API, we have the technical capability to do so and will act within their required timeframe.

11. Changes to this policy

We may update this policy from time to time. We will notify you of material changes by email or through the platform, and update the "Last updated" date above.