Legal

Privacy Policy

This Privacy Policy explains how Social Monkey collects, uses, shares, and protects information when you use the website, app, connected account features, AI tools, and related services.

Effective date: July 15, 2026

1. Scope

This policy applies to Social Monkey, including the public website, authenticated app, AI assistant, post composer, media library, connected account workflows, admin tools, notifications, and related API routes. Third-party platforms you connect, such as Pinterest, Meta, Facebook, Instagram, LinkedIn, TikTok, Google, Gmail, YouTube, Google Business Profile, Microsoft Outlook, or Microsoft Graph, also process information under their own privacy policies and account settings.

2. Information We Collect

  • Account data, such as your name, email address, sign-in details, user ID, role, preferences, and legal acceptance records.
  • Workspace content, such as business profile details, post drafts, captions, creative notes, calendars, saved ideas, customer notes, uploaded media, comments, inbox items, and task history.
  • Connected account data, such as account labels, page or location IDs, approved OAuth scopes, connection status, token expiration dates, and encrypted access or refresh tokens needed to provide connected features.
  • Google user data you authorize, such as Google account profile details, Google Business Profile locations, Gmail account and message data used by the inbox and reply features, YouTube channel details, publishing records, approved OAuth scopes, and sync results.
  • Meta data you authorize, such as Facebook Page information, linked Instagram professional account information, permissions, engagement metadata, post/comment data, and publishing information when those features are enabled and approved.
  • Pinterest data you authorize, such as Pinterest account/profile details, board IDs, Pin IDs, Pin publishing records, approved scopes, and connection or sync results.
  • LinkedIn, TikTok, YouTube, and Microsoft Outlook data you authorize, such as account or organization identifiers, channel/profile details, publishing metadata, upload or posting results, mailbox metadata, message/thread data, and send or reply records.
  • AI interaction data, such as prompts, chat messages, post planning context, calendar context, and generated outputs used to provide Social Monkey AI features.
  • Device and usage data, such as browser type, IP address, request logs, authentication cookies, local storage values, service worker cache entries, push subscription details, and diagnostics needed to run and secure the app.

3. Google User Data

Social Monkey accesses Google user data only after you authorize the relevant Google connection or sign-in flow. The exact Google data depends on the Google features you enable:

  • Google Sign-In data, such as the Google account identifier, name, email address, profile image if provided, authentication status, and session details used to sign you in.
  • Google Business Profile data, such as authorized business accounts, location names, store codes, storefront addresses, location metadata, local post content, publishing status, and sync or error results.
  • Gmail data, such as your Gmail email address, message IDs, thread IDs, sender and recipient headers, subject lines, dates, labels, importance or category signals, message snippets for synced inbox rows, and message text fetched when you request thread context, factual answer lookup, reply drafting, close-follow-up tracking, or reply-skill learning.
  • YouTube data, such as authorized channel IDs, channel titles, channel thumbnails, upload permissions, selected publishing settings, video or community post metadata, and publishing results.
  • OAuth connection records, such as approved scopes, platform account labels, token expiration dates, connection status, and encrypted access or refresh tokens needed to keep authorized Google features working.

Google user data may be stored in Social Monkey databases so the app can show connection state, keep authorized workflows available across sessions, display user-visible synced inbox or publishing history, and complete actions you request. Gmail inbox rows use provider snippets and headers for routine sync; full message text is fetched only for the specific thread, answer lookup, follow-up, drafting, or learning task that needs it. Reusable reply lessons contain sanitized patterns, not raw email bodies. Access and refresh tokens for implemented OAuth connections are encrypted before database storage.

4. Local Storage, Cookies, and Browser Features

Social Monkey uses authentication cookies, browser local storage, service worker caching, and push subscription records so the app can keep users signed in, save draft work, remember preferences, load faster, and send notifications you enable. Some post drafts and preferences may be stored in your browser until you clear them, reset the app, or use browser controls to remove site data.

5. How We Use Information

  • Provide the Social Monkey workspace, including drafting, scheduling, media, inbox, customer, notification, and approval workflows.
  • Authenticate users, maintain sessions, prevent abuse, secure accounts, and enforce admin access.
  • Connect to third-party platforms you authorize, such as Pinterest, Meta, Facebook, Instagram, LinkedIn, TikTok, Google Business Profile, Gmail, YouTube, and Microsoft Outlook.
  • Generate AI-assisted drafts, research responses, summaries, preference suggestions, and calendar descriptions.
  • Store uploads, post records, connection records, and workflow history so the app can work across sessions.
  • Troubleshoot errors, monitor security, respond to support requests, and comply with legal obligations.

6. How We Use Google User Data

  • Authenticate users and maintain secure app sessions when Google Sign-In is used.
  • Discover and display the Google accounts, business locations, Gmail inboxes, and YouTube channels you authorize.
  • Sync recent Gmail inbox items, help organize customer communication, and support user-authorized email drafting or sending workflows.
  • Fetch relevant Gmail message text only when a user-requested inbox, answer lookup, thread, follow-up, or learning workflow needs it; reusable learning stores compact sanitized lessons rather than raw email bodies.
  • Prepare, schedule, publish, and track Google Business Profile local posts and YouTube posts you create through Social Monkey.
  • Provide AI-assisted drafting, summaries, planning, and recommendations only when those features are requested and the Google-derived context is relevant to the task.
  • Troubleshoot connected account errors, protect the service, prevent abuse, respond to support requests, and comply with legal obligations.

Social Monkey does not use Google user data for advertising, unrelated profiling, surveillance, or determining creditworthiness. We do not sell Google user data.

7. AI Features and Google Data

When you use AI features, Social Monkey may send your prompts, messages, drafts, calendar context, business profile context, customer notes, or other workspace content to OpenAI or another configured AI provider to generate a response. For a Gmail task, this can include the relevant message text or sanitized sent-mail pattern needed for the requested inbox, lookup, draft, follow-up, or learning feature. Do not enter information you do not want processed by an AI provider. AI outputs should be reviewed before publishing or sending.

If a user-requested AI workflow needs Google-derived context, such as a Google Business Profile location, Google post history, Gmail message text, Gmail snippet, or YouTube channel detail, Social Monkey uses that context only to provide or improve the specific app functionality requested by the user. Social Monkey does not use Google Workspace API data, including Gmail data, to develop, improve, or train generalized or non-personalized AI or machine learning models.

8. Platform APIs We Use

Social Monkey uses official platform APIs and authorized OAuth connections only. We do not scrape these platforms, and we only access platform data after you connect an account, approve permissions, or ask Social Monkey to complete a supported workflow.

Separately, if you provide your own website address (or a direct link to your services or products page) and ask Social Monkey to analyze it, we read the public pages of that site — prioritizing your services and products — to learn your offerings, brand voice, and tone and help set up your account, posts, and customer replies. We do this only for a website you provide, only when you ask, and we stay on your own site.

Social Monkey is not endorsed by, sponsored by, certified by, or affiliated with Pinterest, Meta, Facebook, Instagram, LinkedIn, TikTok, YouTube, Google, Gmail, Google Business Profile, Microsoft, Outlook, or Microsoft Graph. All platform names, logos, and trademarks belong to their respective owners.

Social Monkey does not resell, redistribute, broker, license, or provide platform content, platform API data, or platform-derived data to third parties. We use platform data to provide the user-facing Social Monkey features you request, such as account connection, drafts, publishing, inbox review, scheduling, media, reporting, support, security, troubleshooting, and compliance.

  • Pinterest API: authorized Pinterest account/profile details, boards, Pins, Pin publishing metadata, approved scopes, connection status, and sync or error results.
  • Meta Graph APIs: Facebook Page data, Instagram professional account data, comments, post and publishing data, permissions, engagement metadata, connection status, and sync or error results.
  • LinkedIn APIs: authorized member, organization, page, publishing, account, connection, and sync metadata.
  • TikTok APIs: authorized account/profile information, upload or posting metadata, selected publishing settings, connection status, and sync or error results.
  • YouTube API Services: channel details, upload permissions, selected publishing settings, video or community post metadata, thumbnails, and publishing results.
  • Google APIs: Google Sign-In, Google Business Profile, Gmail, and YouTube-related Google user data, including account identifiers, location/channel details, Gmail message metadata, publishing records, approved scopes, and sync results.
  • Microsoft Graph API: Microsoft Outlook account identifiers, mailbox metadata, message IDs, conversation or thread data, sender and recipient metadata, subject lines, snippets, send/reply records, approved scopes, and connection status.

Access and refresh tokens are encrypted before database storage where live OAuth connections are implemented. Connected platforms may still process information under their own terms, developer policies, privacy policies, account settings, and platform controls when you use their services.

9. Google API Limited Use

Social Monkey's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Social Monkey's use and transfer of information received from Google Workspace APIs, including Gmail data, will also adhere to the Google Workspace API User Data and Developer Policy, including its Limited Use requirements. The use of information received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. We only transfer Google user data to service providers when needed to provide or improve user-facing Social Monkey features, maintain security, comply with law, or complete an action you request. We do not use it for advertising, credit or lending decisions, data brokerage, or generalized AI model training.

10. Service Providers and Disclosures

We may share information with service providers that help operate Social Monkey, including:

  • Supabase, for authentication, database, storage, and session cookies.
  • Hosting and infrastructure providers, for website hosting, server logs, delivery, and security.
  • OpenAI or other configured AI providers, for AI chat, drafting, summarization, planning, and related generation features. Google-derived context is sent only when needed for a requested user-facing feature and is not used by Social Monkey to train a generalized model.
  • Meta, including Facebook and Instagram APIs, when you connect Meta accounts or pages.
  • Pinterest APIs, when you connect Pinterest accounts or authorize Pin and board workflows.
  • LinkedIn and TikTok APIs, when you connect those accounts or authorize publishing workflows.
  • Google APIs, including Google Sign-In, Google Business Profile, Gmail, and YouTube APIs, when you connect Google accounts or authorize Google workflows.
  • Microsoft Graph API and Microsoft services, if Outlook or Microsoft-connected workflows are enabled.
  • Email, security, browser push, and support providers, when those services are configured for alerts, authentication, or notifications.

We may also disclose information if required by law, to protect rights and safety, to investigate abuse or security issues, or in connection with a business transfer such as a merger, acquisition, financing, or sale of assets.

We do not allow service providers to use Google user data for their own advertising, unrelated profiling, or purposes outside providing services to Social Monkey and our users.

11. Selling or Sharing Personal Information

As of the effective date above, Social Monkey does not sell personal information and does not share personal information, Google user data, platform content, platform API data, or platform-derived data for cross-context behavioral advertising. We do not resell, redistribute, broker, or license platform data to third parties. If this changes, the policy will be updated and any legally required choices will be provided.

12. Retention

We keep information for as long as needed to provide the app, maintain your account, support connected features, comply with legal obligations, resolve disputes, prevent abuse, and maintain security. OAuth tokens and connected account records are retained while the connection is active or as needed for security, legal, and operational records.

Platform-derived records, such as synced inbox items, Pinterest Pin records, Meta/Facebook/Instagram publishing history, LinkedIn or TikTok publishing metadata, Google Business Profile publishing history, YouTube publishing records, Microsoft Outlook send/reply records, account labels, page IDs, location IDs, board IDs, channel IDs, and connection status, may be retained while your Social Monkey workspace or connected account remains active so the app can show history, drafts, approvals, and results. Gmail message text stored for a user-enabled close-follow-up workflow is retained only while that workflow is active or until the user requests deletion; sanitized reply lessons do not contain raw message bodies.

If you disconnect a connected platform account, Social Monkey stops future API access after the platform processes the revocation unless you reconnect it. Where technically available, Social Monkey removes or invalidates stored OAuth tokens for the disconnected account. Stored platform-derived records can be deleted or de-identified by request unless retention is required or permitted for legal, security, audit, fraud prevention, abuse-prevention, dispute, backup, or operational reasons.

Browser-stored drafts and preferences remain under your control in your browser. Deleted data may remain in backups, audit records, or logs for a limited time before being removed according to provider and operational schedules.

13. Your Choices and Rights

You can choose not to connect third-party platforms, disconnect connected accounts, clear browser site data, disable notifications, or stop using AI features. Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, objection, or appeal related to your personal information.

To make a privacy request, email info@socialmonkeyai.com. We may need to verify your identity before fulfilling a request. We may retain certain information when required or permitted by law, including for security, fraud prevention, legal compliance, or dispute resolution.

14. Account and Platform Data Deletion

To request deletion of your Social Monkey account data or data received through Pinterest, Meta, Facebook, Instagram, LinkedIn, TikTok, Google, Google Business Profile, Gmail, YouTube, Microsoft Outlook, Microsoft Graph, or another connected platform, email info@socialmonkeyai.com with the subject line "Social Monkey Data Deletion Request." Include the email address for your account and the connected page, profile, board, inbox, channel, account, or business location you want removed.

You can also remove Social Monkey's access from the connected platform's own account or business integration settings. Removing access at the platform stops future access after the platform processes the revocation, but it may not automatically delete records already stored in Social Monkey, so contact us if you want stored data deleted or de-identified too.

For Google data, you can revoke Social Monkey's access from your Google Account permissions or from the relevant Google product settings. Revoking access stops future Google API access after the revocation is processed, but you should also contact us if you want previously stored Social Monkey records deleted.

Content that has already been published, sent, exported, or copied to a third-party platform may need to be deleted from that third-party platform directly. For example, a published Pin, post, video, local update, or sent email may remain available through the platform or recipient unless removed there.

Step-by-step deletion details are available in our Data Deletion Policy.

15. Security

We use reasonable administrative, technical, and organizational safeguards intended to protect information, including encrypted token storage for implemented OAuth connections, hardened authentication cookies, scoped workspace access, provider-side access controls, and operational monitoring. No website, app, storage system, or internet transmission can be guaranteed to be completely secure.

16. Children

Social Monkey is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us so we can review and delete it as appropriate.

17. International Use

Social Monkey is operated from the United States. Information may be processed in the United States and other countries where our service providers operate. Those countries may have privacy laws that differ from the laws where you live.

18. Updates

We may update this Privacy Policy from time to time. The effective date above shows when this version became effective. If changes are material, we may provide notice through the app, website, or account email when practical.

19. Contact

For privacy questions or requests, contact Social Monkey at info@socialmonkeyai.com.