cCadalio.

Privacy Policy

Last updated: 14 September 2026

The service operator’s legal details must be configured before this service opens to the public.

Who is responsible for your data?

Operator details pending configuration. Privacy inquiries: Privacy contact pending configuration.

What we collect

We store your name, email address, password hash, workspace memberships, account preferences, uploaded media, draft and scheduled content, publishing records, and analytics returned by the platforms you connect. We keep encrypted OAuth access and refresh tokens so the service can act within the permissions you grant.

Why we process it

We process account and content data to provide the service you request, secure accounts, schedule and publish content, administer subscriptions, and respond to support requests. Billing and tax records may be retained to meet legal obligations. We do not sell your personal information.

Connected platforms

We use official Meta, TikTok, and Google APIs. You choose which accounts to connect and which content to publish. Provider access is limited by the permissions you grant. You can disconnect accounts in Social Accounts or revoke access directly with the provider. Platform privacy policies also apply to data you publish there.

Use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You may revoke Google access from your Google Account permissions. This service uses YouTube API Services; see Google’s Privacy Policy.

Service providers and transfers

Our infrastructure, object storage, transactional email, payment, and optional monitoring providers process data needed to operate the service. Stripe processes payment details; we do not store card numbers. The operator must identify the deployed service providers, hosting regions, and any applicable international transfer safeguards before launch.

Retention and deletion

We retain your content while your account is active or as needed to deliver scheduled posts. You can remove unused media and disconnect social accounts. Account deletion removes owned workspaces, posts, media, and local social credentials. Published posts remain on the social platforms unless you remove them there. Security, billing, and audit records may be retained when required by law or to prevent abuse. Backup retention follows the operator’s documented hosting policy.

Provider analytics are refreshed from the source and subject to periodic cleanup. We remove revoked credentials promptly and retain only operational event metadata rather than raw credential-bearing webhook payloads.

Your rights and choices

You can access your profile, export your data, update notification preferences, and request deletion from Settings. Depending on applicable law, you may also request correction, restriction, objection, or portability, and lodge a complaint with your data protection authority. Contact the privacy address above for assistance.

Cookies and local preferences

We use an essential HTTP-only session cookie for sign-in. A local theme preference may be stored on your device. These are used to deliver the service and are not advertising trackers. We do not set optional advertising or behavioral analytics cookies. There is no optional cookie consent to enable. You can clear the theme preference or session cookie through your browser settings.

Security

We use encrypted OAuth credentials, password hashing, server-side permissions, signed webhook verification, and separated workspace access. No method of transmission or storage is risk-free. Contact support if you suspect unauthorized access.

Changes and contact

We may update this policy to reflect service or legal changes. Material changes will be communicated through the service or by email where appropriate. Contact the configured privacy contact with questions.

Contact support