Overview
"OmniSocials," "we," "us," or "our" refers to OmniSocials Inc. "You" and "your" refer to anyone using our websites, apps, emails, or other interfaces we provide. This Privacy Policy explains what personal data we collect, how we use it, and the choices you have.
This policy covers data we obtain through our website, our app at app.omnisocials.com, email communications, and any social platform you choose to connect to OmniSocials.
Information We Collect
Information you provide
When you create an account or use our services, we may collect your name, email address, password, billing details, profile information, and any content (text, images, video) you choose to upload, draft, or schedule through the platform.
Information collected automatically
We collect technical data each time you use our service: IP address, browser type, operating system, device information, and usage data such as pages visited and time spent. This helps us secure, debug, and improve the platform.
Advertising and tracking
With your consent, we use the Meta Pixel to measure advertising performance on Facebook and Instagram, and Endorsely to attribute affiliate referrals. These trackers are only activated when you accept marketing cookies, and you can withdraw consent at any time through your cookie preferences.
How We Use Your Data
We use your data to:
- Provide, operate, and improve the OmniSocials service
- Schedule and publish content to your connected social accounts
- Generate analytics and reporting across your social channels
- Send service updates, security alerts, and billing notifications
- Send marketing communications (only when you opt in)
- Detect, prevent, and respond to fraud, abuse, and security incidents
- Comply with legal obligations
We do not sell or rent your personal data, and we never use your content or social platform data to train AI or machine learning models.
Social Platform Integrations
OmniSocials connects to social platforms through their official developer APIs. The same data-handling practices apply to every connected platform:
- We only access data you explicitly authorize during the OAuth flow
- Access tokens are encrypted at rest using AES-256-GCM
- All API traffic is transmitted over HTTPS
- Data is used solely to operate our service: never sold, shared with advertisers, or used to train AI models
- You can disconnect any account at any time from Settings → Organisation → Workspaces. We delete the access token immediately and associated data within 30 days, unless we are legally required to retain it
Facebook & Instagram (Meta)
Through Meta's Graph API we access your Facebook profile, the Facebook Pages you administer, Instagram business profiles, posts, comments, Messenger conversations (when you use the social inbox), page insights, and post analytics. Permissions include instagram_business_basic, instagram_business_content_publish, instagram_business_manage_messages, instagram_business_manage_comments, and instagram_business_manage_insights. We comply with Meta's Platform Terms, Developer Policies, and Community Standards. See Meta's Privacy Policy.
Threads
Through Meta's Threads API we access your Threads profile, posts, engagement metrics (views, likes, replies, reposts, quotes), and publishing capabilities. Our use complies with Meta's Threads API requirements and Platform Terms.
LinkedIn (Profile & Company Page)
Through LinkedIn's Developer APIs we access your profile (name, headline, email, profile picture), the company pages you administer, posts you publish through OmniSocials, and basic engagement metrics where available. Our integration complies with LinkedIn's User Agreement and Developer API Terms. See LinkedIn's Privacy Policy.
YouTube
OmniSocials uses YouTube API Services. We access your channel information, video upload capabilities, channel analytics, and video performance data. We do not sell or transfer Google user data to third parties, do not use it for advertising, and do not use it to train AI or ML models. You can revoke access at any time through Google security settings, and we will delete YouTube data within 7 days of revocation. Use of our YouTube integration is also subject to the YouTube Terms of Service and the Google Privacy Policy.
TikTok
Through TikTok's Developer APIs we access your profile, account statistics, video content, engagement metrics, and publishing capabilities. Our integration complies with TikTok's Developer Terms and Content Sharing Guidelines. See TikTok's Privacy Policy.
X (Twitter)
Through X's API v2 we access your profile, account statistics, and post engagement metrics for content published via OmniSocials. Requested scopes are tweet.read, tweet.write, users.read, media.write, and offline.access.
Through Pinterest's Developer APIs we access your profile, the boards you manage, and the pins you publish through OmniSocials, along with related analytics. Our integration complies with Pinterest's Developer Guidelines and Terms of Service.
Bluesky & Mastodon
For decentralized platforms, we connect via AT Protocol (Bluesky) or your chosen instance's API (Mastodon). We access your profile, posts you publish through OmniSocials, and engagement metrics where available. Note that decentralized platforms may have additional instance-specific rules that apply to your usage.
Google Business
Through Google's Business Profile APIs we access your business profile information, posts you publish through OmniSocials, and account-level performance metrics (impressions, direction requests, calls, website clicks). As with all Google user data, we do not sell it, share it with advertisers, or use it to train AI models.
Email Marketing
We use Brevo to deliver email communications, including service updates, billing notifications, security alerts, product updates, and (with your opt-in) marketing offers. We collect your email address, name, and communication preferences for this purpose.
You can update your preferences or unsubscribe from non-essential email at any time through your account notification settings. Essential emails (security, billing, service disruptions) cannot be opted out of as they are required for account operation.
Data Sharing
We do not sell or rent your personal data. We share data only in the following limited circumstances:
- Social platforms: when you publish, reply, or schedule content, that content is sent to the corresponding social platform's API
- Infrastructure providers: encrypted data is stored on secure cloud servers (e.g. our hosting and storage providers) solely to operate the service
- Service providers: Brevo (email), Stripe (payments), Sentry (error monitoring), and similar processors strictly bound by data processing agreements
- Legal obligations: when required by law, legal process, or to protect the rights, property, or safety of OmniSocials, our users, or the public
- With your consent: when you explicitly authorize sharing with a third party
Security
We implement administrative, physical, and technical safeguards designed to protect your data, including AES-256-GCM encryption for access tokens at rest, HTTPS for data in transit, Row-Level Security policies in our database, restricted personnel access, and continuous security monitoring. No method of transmission or storage is 100% secure, but we work to maintain industry-standard protections and will notify users and authorities promptly in the event of a qualifying security incident.
Data Retention
We retain your data for as long as your account is active or as needed to provide the service. When you disconnect a social account, we delete the associated access token immediately and remove related data within 30 days. When you close your OmniSocials account, we delete your personal data within 30 days unless we are required to retain it for legal, accounting, or fraud-prevention purposes.
Anonymized and aggregated analytics may be retained beyond this period for service improvement.
Your Rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Delete your personal data
- Export your data in a portable format
- Restrict or object to certain processing
- Withdraw consent for processing based on consent
- Lodge a complaint with your local data protection authority
To exercise any of these rights, contact us at privacy@omnisocials.com. We will respond within the timeframe required by applicable law.
Data Deletion
You can delete your OmniSocials account at any time from Settings → Account → Delete Account. To disconnect a single social platform while keeping your OmniSocials account, go to Settings → Organisation → Workspaces and disconnect the channel.
For platform-initiated deletion requests (for example, Facebook's Data Deletion Callback), we process the request automatically. You may also email privacy@omnisocials.com to request manual deletion.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or through an in-app notice. The updated date will always appear at the top of this page.
Contact Us
Questions about this Privacy Policy or our data practices? Reach us at:
- Email: privacy@omnisocials.com
- Support: robert@omnisocials.com
- OmniSocials Inc., Simon van Collemstraat, 1325NB, Flevoland, The Netherlands
