Privacy Policy
Last updated: September 1, 2026
1. Information We Collect
We collect only what we need to run SocialQueue for you and your workspace:
- Account data: your email address, your name, and a hashed password (we never store passwords in plain text). For workspaces, we also store the seat memberships and roles you configure.
- Billing data: processed through Stripe. We store the Stripe customer ID, subscription status, plan tier, and invoice metadata; we do not store full card numbers.
- Social platform OAuth tokens: when you connect an account (X, LinkedIn, Bluesky, Instagram, Threads, etc.), we store the access and refresh tokens issued to us, encrypted at rest. These are used only to read messages and post replies on behalf of that account.
- Messages and threads: direct messages, mentions, comments, and reply threads ingested from the social platforms you connect. We store the message body, sender handle, platform timestamps, and any tags, sentiment scores, or assignments you or your teammates apply.
- Reply drafts and AI suggestions: drafts that you compose, suggested replies generated by AI, and the prompts sent to AI providers. AI suggestions are processed through Anthropic Claude or a locally-hosted LLM; suggestions are not retained by the LLM provider beyond the provider's own operational logs and retention windows.
- Usage analytics: we capture aggregate product usage (pages viewed, features used, response-time metrics) through a product-analytics tool (such as PostHog or equivalent) to understand how SocialQueue is used and to improve it.
- Operational logs: standard server logs (IP address, user agent, request path, timestamps) kept for a limited window for security and debugging.
2. How We Use Information
We use the information above to:
- Provide and operate the Service for you and your workspace
- Ingest, organize, route, and let you respond to messages on connected social platforms
- Generate AI-suggested replies, sentiment tags, and listening summaries when you ask for them
- Send transactional notifications (new-message alerts, SLA breaches, billing receipts, security alerts)
- Process payments and manage your subscription
- Detect, investigate, and prevent abuse, fraud, and Terms violations
- Improve the Service and develop new features
3. Third-Party Sharing
We never sell your personal information. We share data only as necessary to deliver the Service:
- Connected social platforms: we send replies and read messages through the platform APIs you have authorized (X, LinkedIn, Bluesky, Instagram, Threads, and any future integrations you enable)
- Infrastructure providers: hosting, PostgreSQL, Redis, object storage, error monitoring, and transactional email providers used to run the Service
- Stripe: for payment processing and subscription management
- AI providers: message content and prompts may be sent to Anthropic Claude or a locally-hosted LLM when you use AI-suggested replies, sentiment tagging, or autoreply features
- Legal: we may disclose information when required to comply with law, valid legal process, or to protect the rights, safety, or property of SocialQueue, our users, or the public
4. GDPR and CCPA — Your Data Subject Rights
If you are located in the European Economic Area, the United Kingdom, or California, you have the following rights with respect to your personal data:
- Access: request a copy of the personal data we hold about you
- Correction: ask us to correct inaccurate or incomplete data
- Deletion: request deletion of your account and associated personal data (the "right to be forgotten")
- Portability / Export: request a portable export of your data. SocialQueue provides a self-service export endpoint at
GET /api/v1/me/exportthat returns your account, workspace, connected-account, and message data as JSON. - Objection / Restriction: object to or restrict certain processing of your data
- Withdraw consent: where processing is based on consent, you may withdraw it at any time
To invoke any of these rights, email [email protected] from the address tied to your account. We will respond within 30 days.
Data retention. We retain account, message, and workspace data while your account is active. After cancellation, we retain the data in a read-only state for 90 days so you can export or reactivate it, after which it is permanently deleted from our active systems (subject to limited retention in encrypted backups and as required by law).
5. Security
All connections to SocialQueue use HTTPS. OAuth tokens for connected social accounts are encrypted at rest. Passwords are hashed using a modern password-hashing function. We restrict production-data access to the minimum personnel needed to operate the Service, and we review our security practices regularly.
6. Cookies
SocialQueue uses a session cookie to keep you signed in. We do not use third-party advertising or cross-site tracking cookies. Product-analytics events (if enabled in your region) are tied to an anonymized analytics identifier, not to advertising cookies.
7. Children
SocialQueue is not directed to children under 18, and we do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, please contact us and we will delete it.
8. International Transfers
Your data is stored on servers operated by our infrastructure providers. If you are located outside the country where those servers are hosted, your data will be transferred to and processed in that country. We rely on appropriate safeguards (such as standard contractual clauses) for cross-border transfers where required by law.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email to the address on your account or by a prominent notice within the Service. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
10. Contact
Privacy questions, data-rights requests, and security reports can be sent to [email protected].