Privacy policy
Last updated: 1 October 2026 · Draft for legal review
Social Engine is a content-marketing platform operated by Involve Digital Pty Ltd ("Involve Digital", "we", "us"), an Australian company. This policy explains what we collect when you use the Social Engine web app, mobile apps, API and MCP server (together, "the Service"), why, and the choices you have.
If you have a question or want to exercise a right described below, email hello@involvedigital.com.
1. Who this applies to
- Customers and their team members who sign in to the Service.
- People whose social, analytics or advertising accounts are connected to a workspace by a customer.
- Visitors to our public pages.
When a customer uses the Service to manage their own brand, the customer decides what is connected and published. For that data we act on the customer's instructions.
2. What we collect
| Category | Examples | Source |
|---|---|---|
| Account details | Name, email address, profile picture, organisation and workspace names, your role | You, or the sign-in provider you choose (for example Google) |
| Connected-account data | Access tokens and account identifiers for the social, analytics and advertising accounts you connect; page, profile, channel or board names; your published posts and their public metrics; comments on your own posts (only if you turn on engagement features) | The platform you connect, through its official API, after you authorise it |
| Analytics and advertising data | Read-only reports from Google Analytics, Google Search Console, Google Ads, Meta Ads, LinkedIn Ads, X Ads and YouTube Analytics that you connect | The platform you connect |
| Content you provide | Brand guidelines, tone-of-voice documents, case studies, images, videos, drafts, comments and approvals | You |
| Content we generate for you | Draft articles, posts, captions, images and videos created on your instruction | The Service |
| Usage and device data | Log entries, IP address, browser and device type, and the cookies needed to keep you signed in | Your browser or app |
| Billing data | Plan, subscription status and invoices. Card details are handled by Stripe and never reach our servers | You and Stripe |
We do not collect sensitive information (as defined in the Australian Privacy Act) on purpose, and we ask you not to upload it.
3. How we use it
- To provide the Service: planning, writing, scheduling, publishing to the accounts you connect, and reporting on results.
- To keep accounts secure, prevent abuse and diagnose faults.
- To bill subscriptions and provide support.
- To improve the reliability and quality of the Service, using aggregated and de-identified information where possible.
We do not sell personal information, and we do not use your connected-account data to target advertising.
4. Artificial intelligence
The Service uses large language models to analyse performance data and draft content. Your content and connected-account data are sent to our AI provider (Anthropic) only to perform the task you asked for. Under our commercial agreement, the provider does not use this data to train its models. Every piece of content is subject to the approval rules you set before it is published.
5. Google user data
Social Engine's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We request read-only access to Google Analytics, Search Console and Google Ads reporting, and upload and analytics access to YouTube, only so the Service can report on and publish for the workspace you connect them to. We do not use Google user data to develop or train generalised AI models, and we do not transfer it to third parties except as needed to provide the Service, to comply with law, or as part of a merger or acquisition with notice to you.
The Service uses YouTube API Services. By connecting a YouTube channel you agree to the YouTube Terms of Service, and Google's handling of your data is described in the Google Privacy Policy. You can revoke the Service's access at any time from your Google security settings.
6. Meta, LinkedIn, X, TikTok and Pinterest data
We use data from these platforms only to provide the features you turn on for the workspace you connected them to: publishing, scheduling, comment replies you approve, and performance reporting. You can disconnect any account at any time in the Service or in the platform's own settings. See our data deletion instructions.
7. Who we share it with
We use the following service providers ("sub-processors"). Each processes data only on our instructions.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication and file storage | Sydney, Australia |
| Vercel | Web hosting | Global edge, with functions in Sydney |
| Railway | Background processing | Asia-Pacific |
| Anthropic | AI analysis and drafting | United States |
| Stripe | Payments and invoicing | Global |
| Resend | Transactional email | United States |
| Sentry | Error monitoring, configured not to collect request data | United States |
We also send data to the platforms you connect, because publishing to them is what you asked the Service to do. For workspaces managed by Involve Digital, our staff can access the workspace to deliver the service.
We may disclose information if the law requires it, or to protect the safety of people or the Service.
8. Overseas transfers
Some providers above store or process data outside Australia, including in the United States. We choose providers with appropriate security and contractual safeguards. Where the GDPR or UK GDPR applies, we rely on standard contractual clauses.
9. How long we keep it
- Connected-account tokens are deleted as soon as you disconnect the account.
- Workspace data is kept while the workspace is active. When a workspace is deleted, its data is removed within 30 days, and from backups within a further 30 days.
- Logs and error reports are kept for up to 90 days.
- Billing records are kept for as long as tax law requires, currently seven years in Australia.
10. Security
Data is encrypted in transit. Platform access tokens are additionally encrypted at rest with AES-256-GCM, and only the background service that publishes for you can decrypt them. Database access is restricted per workspace by row-level security, and administrative actions are recorded in an append-only audit log.
11. Your rights
You can ask us to give you a copy of, correct, or delete your personal information, and you can export a workspace's data. If you are in the European Union or United Kingdom, you also have the rights to object, restrict processing and data portability. Email hello@involvedigital.com and we will respond within 30 days.
If you are unhappy with our response, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au) or your local data protection authority.
12. Children
The Service is for businesses and is not directed to anyone under 18.
13. Changes
We will post changes here and update the date at the top. If a change is significant, we will tell account owners by email before it takes effect.