Legal

Privacy Policy

Effective date: June 8, 2026  ·  Last reviewed: June 8, 2026

1. Who We Are

Cloutbox Inc. ("Cloutbox", "we", "our", or "us") operates the social media management platform at https://cloutbox.ai (the "Service").

For privacy enquiries, rights requests, or data breach reports, contact our Privacy team at privacy@cloutbox.ai. For security vulnerabilities, contact security@cloutbox.ai.

2. Data Controller and Processor Roles

Under GDPR and UK GDPR, the roles of data controller and data processor carry distinct legal obligations. Cloutbox acts in both roles depending on the context:

2.1 When Cloutbox is the Data Controller

We are the data controller for personal data we collect and process for our own operational purposes:

  • Account registration and authentication data (email, display name, password hash).
  • Billing and payment records.
  • Service usage logs, IP addresses, and error reports.
  • Support correspondence and communications with us.
  • Marketing communications (where you have opted in).

For this data, we determine the purposes and means of processing and are fully responsible for compliance with applicable privacy laws.

2.2 When Cloutbox is a Data Processor

When you use Cloutbox to manage social media accounts, you (our customer) are the data controllerfor the personal data of your end users — including followers, commenters, and direct message senders on your connected pages and accounts. In this context, Cloutbox acts as a data processor, processing that data solely on your instructions to provide the Service.

As a data processor, we:

  • Process end-user data only as instructed by you (scheduling posts, displaying messages, retrieving analytics).
  • Do not use end-user data for our own purposes, including marketing, profiling, or product improvement.
  • Maintain appropriate technical and organisational security measures.
  • Notify you promptly of any personal data breach affecting your end users.
  • Delete or return your end-user data upon termination of the Service.
  • Only engage sub-processors under the controls described in Section 8.

2.3 Data Processing Agreement (DPA)

Business customers who require a formal GDPR Article 28-compliant Data Processing Agreement can request one at privacy@cloutbox.ai, or review our standard DPA template at /legal/dpa. The DPA governs the processing of your end users' personal data and includes the obligations described in §2.2 above.

If your organisation has EU or UK users, executing a DPA is mandatory under GDPR Article 28. We will co-sign our standard DPA or negotiate enterprise-specific terms upon request.

3. Information We Collect

3.1 Information You Provide

  • Account data: email address, display name, password hash.
  • Workspace data: organisation name, plan selection.
  • Content you create: social media posts, scheduled content, captions, media files.
  • Communications: support requests and correspondence sent to us.
  • Billing information: processed by Stripe; we store only the last four digits and billing address.

3.2 Information Collected Automatically

  • Log data: IP address, browser type and version, pages visited, time of access, referring URL.
  • Device data: device type, operating system, screen resolution.
  • Usage data: feature interactions, click events, session duration, error events.
  • Cookies: session tokens, preference cookies. See Section 10.

3.3 Information from Connected Social Platforms

When you connect a social media account via OAuth, we receive platform data as described in Section 5. This includes platform user IDs, OAuth tokens (stored encrypted), analytics metrics, and messages from accounts you manage through the Service.

4. How We Use Your Information

PurposeData usedLegal basis (GDPR)
Provide and operate the ServiceAccount data, usage data, platform tokensContract performance (Art. 6(1)(b))
Send transactional emails (invites, resets)Email addressContract performance (Art. 6(1)(b))
Monitor performance and fix errorsLog data, error eventsLegitimate interests (Art. 6(1)(f)) — service reliability
Improve the Service via aggregate analyticsAnonymised usage dataLegitimate interests (Art. 6(1)(f)) — product improvement
Comply with legal obligationsAll categories as required by lawLegal obligation (Art. 6(1)(c))
Marketing communications (opt-in only)Email address, display nameConsent (Art. 6(1)(a))
Fraud, abuse, and security detectionIP address, usage data, log dataLegitimate interests (Art. 6(1)(f)) — security
Process paymentsBilling informationContract performance (Art. 6(1)(b))

We do not sell your personal data. We do not use your content or social media data to train AI or ML models without your explicit consent.

5. Platform-Specific Data Practices

5.1 Google and YouTube

Google API Services Limited Use Disclosure

Cloutbox's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements:

  • We only request the minimum scopes necessary to provide the Service.
  • We do not use Google user data for advertising or to create advertising profiles.
  • We do not transfer Google user data to third parties except to provide or improve the Service, as required by law, or in connection with a merger or acquisition.
  • We do not allow humans to read Google user data unless you give us express permission, it is necessary for security, or it is required by law.
  • YouTube data is retained for a maximum of 30 days, after which it is purged.

You can revoke access at any time via your Google Account permissions page.

5.2 Meta (Facebook and Instagram)

  • We request only the permissions required for features you use (e.g., pages_manage_posts, instagram_content_publish).
  • Facebook and Instagram are separate connected apps. Revoking one does not automatically revoke the other.
  • We do not share Meta data with third parties for advertising.
  • If you remove Cloutbox from Facebook, Meta sends a deletion callback to our systems and we delete the associated tokens within 48 hours. See our Data Deletion Instructions.
  • Revoke Facebook access: Facebook App Settings. Revoke Instagram access: Instagram Manage Access.

5.3 LinkedIn

  • Per LinkedIn API Terms, social activity data (posts, comments, reactions) is retained for no more than 48 hours.
  • We publish to LinkedIn only with explicit per-post consent triggered by your action.
  • Revoke: LinkedIn Permitted Services.

5.4 TikTok

  • We do not post to TikTok without you initiating the action. Any preset captions are editable before posting.
  • We do not share TikTok user data beyond what is necessary to operate the Service.
  • Revoke: TikTok Settings → Apps and Permissions.

5.5 X (formerly Twitter)

  • We do not use X API data to train AI or ML models.
  • We do not sell, license, or sublicense X data to third parties.
  • We store X data only to provide the Service to you.
  • Revoke: X Connected Apps.

6. Special Categories of Personal Data

GDPR Article 9 affords additional protections for "special categories" of personal data, which include health and medical information, political opinions, religious or philosophical beliefs, racial or ethnic origin, trade union membership, biometric data, genetic data, and data concerning sexual orientation.

We do not intentionally collect special categories of personal data. We do not ask for, prompt, or require users to submit such information to use the Service.

However, the social media content you create or schedule through the Service may incidentally contain special category data (for example, a post about a health campaign or political commentary). In that case:

  • We process such content solely to transmit it to the relevant social media platform on your instructions (acting as your data processor).
  • We do not analyse, profile, or use such content for any purpose beyond storage and transmission.
  • We apply the same encryption and access controls as to all other content.
  • You remain the data controller for such content and are responsible for ensuring your legal basis for processing it (e.g., explicit consent from the data subjects if required).

If you believe we have inadvertently collected special category data outside of user-generated content, please contact privacy@cloutbox.ai.

7. How We Share Information

We do not sell your personal data. We share information only in the following circumstances:

  • Sub-processors: companies that help us operate the Service under data processing agreements (see Section 8).
  • Platform APIs: when you initiate a publish action, we transmit your content to the relevant social media platform on your behalf.
  • Legal requirements: when required by applicable law, court order, or lawful government authority. Where permitted, we will notify you before complying.
  • Business transfers: in the event of a merger, acquisition, or sale of substantially all assets, your data may transfer to the successor entity. We will notify you before your data becomes subject to a different privacy policy and provide 30 days to export or delete your data if you do not consent.
  • With your consent: for any other purpose you explicitly and actively agree to.
  • Truly anonymised aggregate data: statistical data that cannot by any means be re-linked to an individual. Pseudonymised data is not shared as anonymous data.

Where we share personal data with third-party processors, we require them to execute a Data Processing Agreement providing at minimum the protections required by GDPR Article 28.

8. Sub-Processors

We use the following third-party sub-processors. Each is bound by a DPA, and international transfers use Standard Contractual Clauses (SCCs) or equivalent safeguards where applicable.

Sub-ProcessorPurposeData locationTransfer mechanismPrivacy policy
SupabaseDatabase, authentication, file storageUS (AWS us-east-1)SCCsPolicy ↗
VercelHosting, CDN, serverless functionsUS / EU (AWS, GCP)SCCs / EU regionPolicy ↗
ResendTransactional email deliveryUSSCCsPolicy ↗
InngestBackground job orchestrationUSSCCsPolicy ↗
SentryError monitoring and crash reportingUSSCCsPolicy ↗
StripePayment processingUS / EUSCCs / EU regionPolicy ↗

Sub-Processor Data Deletion Cascade

When your account is deleted, we instruct sub-processors to delete your personal data as follows:

  • Supabase: profile and content rows deleted immediately via service role API; backup purge within 30 days.
  • Sentry: error events associated with your user ID are anonymised within 30 days per Sentry's data retention settings.
  • Resend: email delivery logs containing your address are deleted within 30 days of a deletion request submitted to Resend.
  • Vercel: edge function logs containing your IP address are purged after 90 days per Vercel's log retention policy.
  • Inngest: job run data containing your identifiers is purged after 30 days per Inngest's data retention policy.
  • Stripe: billing records are retained for 7 years as required by tax law; your email may persist in Stripe's records but is no longer linked to an active Cloutbox account.

Enterprise customers may request advance notice of sub-processor changes by contacting privacy@cloutbox.ai.

9. Data Retention

Data typeRetention period
Account data (email, display name, profile)Duration of account; hard-deleted within 30 days of deletion request
Social posts and scheduled contentDuration of account; hard-deleted within 30 days of deletion request
Platform OAuth tokensUntil platform is disconnected or account deleted
YouTube / Google API dataMaximum 30 days from retrieval (Google API policy requirement)
LinkedIn social activity dataMaximum 48 hours from retrieval (LinkedIn API policy requirement)
Messages and conversation data24 hours from receipt (soft-deleted); 30 days until hard-deleted
Log data and IP addresses90 days
Error and crash reports (Sentry)90 days, then anonymised
Billing records7 years (legal/tax obligation)
Security and fraud logsUp to 12 months (legal/security obligation)
Marketing consent recordsDuration of consent; 3 years after withdrawal for legal proof of consent

10. Cookies and Tracking Technologies

Please see our full Cookie Policy for details. We use only essential cookies (required for login) and optional analytics/preference cookies. We do not use advertising cookies or share cookie data with ad networks.

11. Your Rights

RightWhat it means
Access (Art. 15)Request a copy of the personal data we hold about you.
Rectification (Art. 16)Ask us to correct inaccurate or incomplete data.
Erasure (Art. 17)Request deletion of your personal data. See our Data Deletion Instructions.
Portability (Art. 20)Receive your personal data in a structured, machine-readable format (JSON/CSV) for transfer to another service. Exercise before requesting deletion.
Restriction (Art. 18)Ask us to limit processing in certain circumstances (e.g., while a dispute is resolved).
Object (Art. 21)Object to processing based on legitimate interests or for direct marketing. Objecting to marketing is always honoured immediately.
Withdraw consent (Art. 7)Where processing is based on consent (e.g., marketing emails), withdraw at any time. Withdrawal does not affect lawfulness of prior processing.
No automated decisions (Art. 22)We do not make solely automated decisions with legal or significant effects on you.

To exercise any right, email privacy@cloutbox.ai. We respond within 30 days (extendable by 60 days for complex requests, with notice). We may verify your identity first.

EEA/UK residents: if you are dissatisfied with our response, you may lodge a complaint with your local supervisory authority (e.g., ICO in the UK, your national DPA in the EU).

Privacy Contact

Cloutbox has designated a Privacy Contact responsible for overseeing privacy compliance. Reach them at privacy@cloutbox.ai with subject "Privacy Rights Request". Note: A formal GDPR Data Protection Officer (DPO) under Article 37 will be appointed if and when our processing activities meet the mandatory threshold.

12. CCPA / CPRA — California Residents

The CCPA as amended by the CPRA grants California residents additional rights:

  • Right to know — categories and specific pieces of personal information collected.
  • Right to delete — subject to certain exceptions (legal hold, active fraud investigation, etc.).
  • Right to correct — inaccurate personal information.
  • Right to opt-out of sale/sharing — we do not sell personal information or share it for cross-context behavioural advertising. This right is therefore automatically satisfied.
  • Right to limit sensitive PI use — we do not use sensitive personal information beyond what is necessary to provide the Service.
  • Right to non-discrimination — exercising your rights will not affect your access to or pricing of the Service.

Respond time: 45 days (extendable by 45 days with notice). We will provide written confirmation of opt-out requests as required. Submit requests to privacy@cloutbox.ai.

Categories collected (last 12 months): identifiers (email, IP address), commercial information (billing records), internet/network activity (usage data, logs), approximate geolocation (from IP). We have not sold or shared any personal information for cross-context behavioural advertising.

13. Children's Privacy

The Service is for business use only and is not directed to individuals under 18. We do not knowingly collect personal data from children under 13 (or under 16 in the EEA). If we learn that we have inadvertently collected such data, we will delete it promptly. Contact privacy@cloutbox.ai if you believe we have collected data from a child.

14. International Data Transfers

Cloutbox Inc. is based in the United States. If you access the Service from the EEA, UK, or Switzerland, your data may be transferred to and processed in the US, which does not have an adequacy decision equivalent to the EEA for all transfer mechanisms.

We rely on the following transfer mechanisms:

  • EU-US: Standard Contractual Clauses (SCCs) adopted by the European Commission (2021 modules), supplemented by a Transfer Impact Assessment (TIA) confirming that US law does not undermine the protection afforded.
  • UK-US: the UK Addendum to the EU SCCs (IDTA), together with a UK Transfer Risk Assessment (TRA) as required by the UK ICO's international transfer guidance.
  • Switzerland-US: the Swiss Federal Act on Data Protection (nFADP) SCCs.

Enterprise customers requiring executed SCCs as part of their transfer documentation may request them alongside a DPA at privacy@cloutbox.ai.

15. Data Security

We implement and maintain the following security measures:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256).
  • Encrypted storage of platform OAuth tokens.
  • Role-based access controls with principle of least privilege; privileged access is logged and reviewed.
  • Real-time error monitoring and security alerting (Sentry).
  • Regular dependency updates and automated vulnerability scanning.
  • Annual third-party penetration testing; summary results available to enterprise customers under NDA on request.
  • SOC 2 Type II certification is planned; current status is available on request.

Breach Notification

In the event of a personal data breach likely to result in high risk to individuals:

  • GDPR (EEA): we will notify the competent supervisory authority within 72 hours of becoming aware, and notify affected data subjects without undue delay (GDPR Articles 33–34).
  • UK GDPR: we will notify the ICO within 72 hours (UK GDPR Articles 33–34).
  • US state laws: we will notify affected individuals and applicable state regulators in accordance with applicable state breach notification laws (California DBRA: within 72 hours; New York SHIELD Act: expedient notice; other states: typically 30–90 days). Notification will be provided in the most expedient manner required by the most stringent applicable law.

To report a security vulnerability, contact security@cloutbox.ai. See our Security Policy for responsible disclosure details.

16. Export Controls and Sanctions

The Service is subject to US export control laws and regulations, including the Export Administration Regulations (EAR) and the sanctions programmes administered by the Office of Foreign Assets Control (OFAC).

By using the Service, you represent and warrant that:

  • You are not located in or acting on behalf of a person or entity in a US-embargoed country or territory (currently: Cuba, Iran, North Korea, Syria, and the Crimea, Donetsk, and Luhansk regions of Ukraine).
  • You are not listed on any US government sanctions list, including the OFAC Specially Designated Nationals (SDN) list, the Bureau of Industry and Security Entity List, or any other applicable restricted-party list.
  • You will not use the Service to export, re-export, or transfer any data or technology in violation of applicable export control laws.

We reserve the right to suspend or terminate the Service immediately and without notice if we determine or have reason to believe that you are in violation of this section.

17. Changes to This Policy

We may update this Privacy Policy from time to time. We classify changes as follows:

  • Non-material changes (e.g., clarifications, new contact details, updated sub-processor links): we will update the "Last reviewed" date. No further action required.
  • Material changes (e.g., new categories of data collected, new purposes, new sharing partners, changed legal basis): we will notify you by email at least 30 days in advance and require your affirmative acknowledgement within the Service before the change takes effect for your account. If you do not accept a material change, you may terminate your subscription and request deletion of your data before the effective date.

"Continued use" does not, by itself, constitute acceptance of material changes to the legal basis or scope of data processing under GDPR.

18. Contact Us

Cloutbox Inc.

Privacy / rights requests: privacy@cloutbox.ai

Security vulnerabilities: security@cloutbox.ai

General support: support@cloutbox.ai

Website: https://cloutbox.ai