Privacy Policy

Last updated: August 7, 2026

1. Who We Are

Purefeed ("we", "us", "our") operates the purefeed.ai service. For privacy-related questions, contact us at privacy@purefeed.ai.

2. Information We Collect

2.1 Information You Provide

  • Account registration: email address, username, and password (stored as a bcrypt hash — we never store plaintext passwords)
  • Profile information: display name, avatar, X/Twitter handle, Telegram ID
  • Content: signals, search queries, and other content you create within the service

2.2 Information from OAuth Providers

When you sign in with Google or X/Twitter, we receive your email address, display name, and profile picture from the provider. We do not access your contacts, posts, or other account data beyond what is needed for authentication.

2.3 Connected Instagram Publishing

Instagram is an optional publishing integration, separate from signing in to Purefeed. When an authorized channel administrator explicitly connects an Instagram Professional account through Meta, we receive the following data and store it except where stated otherwise:

  • Connection identity: the Instagram Professional account ID, username, Business or Creator account type, and profile picture. Meta also returns an app-scoped binding ID during connection; we use it to verify that the OAuth callback matches the account Meta returns, not as the publishing account ID. We do not store the raw binding ID. We retain only a server-only keyed, non-reversible fingerprint so that a signed Meta deauthorization or deletion request can find the affected connection.
  • Authorization and health: granted permissions, including instagram_business_basic and instagram_business_content_publish, token expiry, publishing quota, connection status, and errors. The long-lived access token is held in an encrypted server-side credential record and is not displayed in the product.
  • Instagram versions and media: captions, selected JPEG derivatives and their URLs, dimensions and alt text, selected caption voice, visual style and model settings, generation snapshots, and revision history.
  • Publishing records: destinations, schedules, delivery attempts and errors, Meta container and media IDs, publication status, permalink, and timestamps.

Connecting Instagram or viewing an Inbox item does not automatically generate an Instagram version. Only when an editor explicitly chooses to create or regenerate one do we send the source and research context, current Telegram draft, selected caption voice and visual-style instructions, and any additional instructions to the selected OpenAI or Anthropic model. Image files are not sent to that caption model as part of this step.

2.4 Automatically Collected Information

  • Authentication cookies: session tokens required to keep you signed in (see Section 9)
  • Essential security and diagnostics: application errors and related request, browser, device, user, and release context needed to secure and operate the service. This processing continues when optional browser analytics are off.
  • Optional browser analytics: after you choose Allow analytics, PostHog may collect pages visited, explicit feature and interaction events, referrer, browser and device information, and analytics identifiers. PostHog may also receive your account identifier and email after sign-in. Vercel Speed Insights may collect the route or URL, network speed, browser, device, operating system, country, timestamp, and web-vital measurement and attribution. In the EEA, the United Kingdom, and Switzerland we do not load these two browser tools before you choose Allow analytics. Elsewhere they load unless you turn them off, which you can do at any time using the control in Section 9. We never load them after you choose Only necessary. Browser session replay, heatmaps, and generic DOM interaction autocapture are disabled.
  • Server-side operational telemetry: background operations may record explicit feature events, an internal account identifier, signup/login events and authentication method, and sampled model/provider usage and cost metadata needed to monitor service operation. Server authentication events do not include your email or username. This processing is separate from optional browser analytics and continues when browser analytics are off.

3. Legal Basis for Processing (GDPR)

We process your personal data on the following legal bases:

  • Contractual necessity (Art. 6(1)(b)): to create and maintain your account, provide the service, and process your requests
  • Legitimate interest (Art. 6(1)(f)): to operate, secure, and maintain the service, prevent fraud, diagnose failures, and ensure platform stability
  • Consent (Art. 6(1)(a)): where applicable, such as optional PostHog browser analytics, Vercel Speed Insights, and optional email communications. You may withdraw analytics consent at any time using the control in Section 9, without affecting the lawfulness of earlier processing

4. How We Use Your Data

  • Provide, maintain, and improve the service
  • Authenticate your identity and manage your account
  • Connect an authorized Instagram Professional account and show its publishing capabilities, health, and quota
  • Generate an Instagram-specific version only when an editor asks us to do so
  • Schedule, publish, reconcile, and prevent duplicate Instagram deliveries requested by authorized channel members
  • Send transactional emails (password resets, verification)
  • Respond to support requests

5. Third-Party Service Providers

We share data with the following service providers and external platforms as needed to provide the features you choose:

  • Supabase — database hosting, authentication, and storage (data processor under GDPR)
  • Vercel — web application hosting and CDN, plus optional Speed Insights after you allow browser analytics. Speed Insights receives the route or URL, network speed, browser, device, operating system, country, timestamp, and web-vital measurement and attribution described in Section 2.4. Vercel states that this performance data is anonymous, cookie-free, and cannot identify or reconstruct an individual visitor across page views. See Vercel's Speed Insights privacy documentation.
  • Trigger.dev — background-job hosting for scheduled or retried Instagram publishing and maintenance. Its isolated worker receives the destination and content data needed for the job and accesses the encrypted credential using the same server-side encryption key as Purefeed; the access token is decrypted only inside that worker when it calls Meta. Trigger.dev also advances a verified Instagram deletion request after any already-running publication worker has safely stopped; it receives only the opaque deletion-request ID for that job. Trigger.dev processes data under its Privacy Policy.
  • PostHog — product analytics and operational telemetry. Its browser SDK is not initialized and does not contact PostHog until you allow browser analytics; it may then receive page and explicit feature events, browser and device metadata, and an account identifier and email after sign-in. Server-side operational events may include an internal account identifier, signup/login event and authentication method, and sampled model/provider usage and cost metadata independently of that browser preference. Server authentication events do not include email or username. Browser session replay, heatmaps, and generic DOM interaction autocapture are disabled. We do not intentionally include passwords, access tokens, or API keys in these events, and outbound browser events pass through our credential-redaction control. PostHog processes data under its Privacy Policy.
  • Sentry — application error monitoring. It may receive error details and related request, browser, device, user, and release context needed to diagnose failures. Known credential shapes are redacted before events leave our browser, Next.js web/edge, and Trigger.dev worker runtimes; browser session replay is disabled. Sentry processes data under its Privacy Policy.
  • Google — OAuth authentication provider only when you choose to sign in with Google
  • Google AI — optional location-query preparation. When a channel editor explicitly runs the Geo Location plugin, we send Google a cleaned copy of the draft so Gemini can reduce it to one concise place or address query. Gemini does not use web-search grounding for this step. Google processes this data under its Privacy Policy.
  • Google Maps Platform — optional location search. When Google Places is selected, it receives only the concise Gemini-prepared or editor-supplied place query, not the full draft.
  • Geoapify — optional location search. When a channel editor explicitly runs the Geo Location plugin with Geoapify selected, it receives only the concise Gemini-prepared or editor-supplied place query, not the full draft.
  • X/Twitter — OAuth authentication provider (only when you choose to sign in with X)
  • Meta/Instagram — optional account connection and publishing. When an authorized administrator connects an account, Meta provides the account identity, permissions, token information, and quota described in Section 2.3. When an authorized user publishes, Meta receives the caption, selected publicly retrievable JPEG URLs, alt text, carousel configuration, and AI-generated-media disclosure needed for that post, and returns delivery status, identifiers, timestamps, and a permalink. Meta processes data under the official Instagram Privacy Policy.
  • OpenAI — optional caption generation. OpenAI receives the textual generation material described in Section 2.3 only when an editor explicitly creates or regenerates an Instagram version using an OpenAI model. OpenAI processes that data under its Privacy Policy.
  • Anthropic — optional caption generation. Anthropic receives the textual generation material described in Section 2.3 only when an editor explicitly creates or regenerates an Instagram version using an Anthropic model. Anthropic processes that data under its Privacy Policy.

We do not sell your personal data to third parties.

6. Data Retention

  • Account data: retained for as long as your account is active. Deleted when you delete your account.
  • Usage and diagnostic data: retained according to the periods configured with the applicable analytics and monitoring provider, based on operational, security, and legal needs, and then deleted or anonymized. Browser-identifier lifetimes and your deletion control are described in Section 9.
  • Location candidates: provider result payloads used by the Geo Location plugin are deleted after 24 hours where provider policy requires it.
  • Connected Instagram credential: retained in encrypted form while the integration is connected and needed to provide publishing. Disconnecting Instagram deletes the active credential and prevents future new publishing through that connection.
  • Instagram content and history: connection identity, generated versions, stored Instagram JPEG derivatives and their metadata, and delivery and audit history may remain after Disconnect while the related Channel and content history remain, so we can preserve editorial records, reconcile publications, prevent duplicate deliveries, investigate errors, and protect the service. A verified Meta data-deletion callback instead removes the matching connection and its Meta-derived delivery history after a short worker-safety interval. Purefeed drafts and generated media that were authored in the Channel, rather than received from Meta, remain until the Channel, version, or Purefeed account is deleted. You may also request erasure as described in Section 7.
  • Backups: may persist for up to 30 days after deletion as part of standard backup cycles.

7. Instagram Data Deletion Instructions

To stop future Instagram publishing, open the relevant Channel, go to Settings, choose Integrations, open Instagram, and select Disconnect. Disconnecting deletes the active encrypted access credential and disables the connection. It does not by itself erase the disconnected account identity, Instagram versions, stored media derivatives, or delivery and audit history described above.

If you remove Purefeed from Instagram and request deletion through Meta, Meta sends Purefeed a cryptographically signed request. We immediately disable every matching Instagram connection and remove its usable credential. After any publication worker already in flight has safely stopped, we erase the matching Meta-derived connection, delivery, and attempt records. Meta receives an unguessable confirmation code and a public status page that shows the same result whether or not matching records were present. We clear the matching identity fingerprint when processing finishes and retain only the confirmation receipt and status timestamps for 90 days so the requester can check completion; that receipt is then automatically purged.

To request full erasure of retained Instagram data, email privacy@purefeed.ai from the email address associated with your Purefeed account where possible. State that you are requesting Instagram data erasure and identify the Purefeed account, affected Channel, and Instagram username as needed for us to locate the data. Never send us your password, Instagram access token, API key, or any other secret.

We will respond within 30 days. We will delete or de-identify the retained Instagram data covered by a verified request unless we must retain specific records for legal, security, fraud-prevention, or dispute-resolution purposes. If an exception applies, we will restrict use of those records and explain the applicable reason. Deleted data may remain in backups for the limited period stated in Section 6.

8. Your Rights (GDPR)

If you are in the EU/EEA, you have the following rights:

  • Access: request a copy of your personal data
  • Rectification: correct inaccurate data via your Profile Settings
  • Erasure: delete your account using available Profile Settings controls or request erasure of personal data; for Instagram-specific data, follow the instructions in Section 7
  • Restriction: request that we limit processing of your data
  • Portability: receive your data in a machine-readable format
  • Objection: object to processing based on legitimate interest

To exercise these rights, use the self-service options in your Profile Settings or email us at privacy@purefeed.ai. We will respond within 30 days.

9. Cookies and Local Storage

We use strictly necessary browser storage for authentication, session management, and recording your analytics preference. PostHog browser storage is optional and is created only after you choose Allow analytics. Vercel Speed Insights is also enabled only after that choice and is designed to operate without cookies.

  • Session cookie (sb-*-auth-token): stores encoded authentication session data needed to keep you signed in. The cookie may persist for up to 400 days, subject to session and token expiry and rotation, and is cleared on sign-out.
  • Analytics region flag (pf_analytics_consent_required): a single0 or 1 set from the country your request arrives from, recording whether we must ask before loading optional analytics. It holds no identifier and expires after one day.
  • Analytics preference (purefeed:analytics-consent:v1): records your allowed or denied selection in local storage so we can honor your choice on later visits. This necessary preference remains until you change it or clear site storage.
  • PostHog analytics storage (typically a key beginning with ph_): stores a pseudonymous distinct identifier, session state, and analytics configuration. The PostHog browser cookie may persist for up to 365 days unless deleted or reset sooner.

Choosing Only necessary prevents the PostHog browser SDK and Vercel Speed Insights from initializing or sending browser analytics. You can withdraw an earlier allowance below. We then stop those browser tools, remove known PostHog and legacy analytics identifiers from this browser, and reload the page. The preference is synchronized across open tabs. Strictly necessary authentication, security, diagnostics, and server-side operations continue.

We do not use advertising cookies or sell data for cross-context behavioral advertising. You can delete or block browser storage through your browser controls, although blocking strictly necessary authentication storage may prevent you from signing in.

10. California Privacy Rights (CCPA)

California residents have additional rights:

  • Right to know what personal information is collected
  • Right to delete personal information
  • Right to opt-out of the sale of personal information
  • Right to non-discrimination for exercising CCPA rights

We do not sell personal information. To exercise your rights, contact privacy@purefeed.ai.

11. Security

We protect your data through:

  • Encryption in transit (TLS/HTTPS)
  • Encryption at rest for stored data
  • Passwords hashed with bcrypt (never stored in plaintext)
  • Row-Level Security (RLS) policies on all database tables

12. International Transfers

Your data may be processed outside the EU/EEA. Our service providers listed in Section 5 maintain appropriate safeguards for international data transfers where required, which may include Standard Contractual Clauses (SCCs).

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised "Last updated" date.

14. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your rights, contact us at:
privacy@purefeed.ai