Back to Trust & Security Center

Privacy Policy

Effective Date: March 1, 2026 · Version 2.4

1. Introduction

SocialHive Systems Inc. ("SocialHive", "we", "us", or "our") is committed to safeguarding your privacy and protecting the confidentiality of your data. This Privacy Policy describes how we collect, process, encrypt, and store information when you access our autonomous social publishing platform, APIs, and services.

2. Information We Collect

We collect only the minimal data necessary to deliver autonomous publishing and workflow capabilities:

  • Account Credentials: Email address, name, organization identifier, and WebAuthn / Passkey public credentials. We never store plain-text passwords.
  • Connected Social Tokens: OAuth 2.0 PKCE access and refresh tokens for connected platforms (LinkedIn, X, Instagram, Facebook, Threads, YouTube, TikTok, Pinterest, Google Business, Bluesky, Mastodon). All tokens are encrypted using AES-256-GCM.
  • Content and Campaign Data: Text drafts, RSS feed sources, prompt configurations, character seeds, and generated media assets.
  • Telemetry and Health Data: IP addresses, browser user agents, and API access logs captured for audit verification and DDoS prevention.

3. Zero-Retention AI Policy

When utilizing our Multi-Model AI Router (including Claude 3.7, GPT-4o, DeepSeek R1, and Gemini 2.0 Flash) or Bring-Your-Own-Key (BYOK) configurations, your prompt data, character voice profiles, and draft contents are transmitted via encrypted TLS 1.3 tunnels exclusively for ephemeral inference. We enforce strict non-training clauses ensuring your data is never used to train or fine-tune public foundation models.

4. Encryption & Security Architecture

All data at rest is encrypted using PostgreSQL row-level isolation and AES-256-GCM authenticated cipher suites. Hardware-backed security modules (HSM) manage root key rotation. All inter-service transit is encrypted via TLS 1.3 with Strict Transport Security (HSTS).

5. Third-Party Platform Access

SocialHive interacts with third-party social networks solely via their official public APIs using customer-approved granular scopes. We never scrape, resell, or distribute your social graph or audience metrics to data brokers.

6. Your Rights (GDPR & CCPA)

Regardless of your geographic location, you retain the right to access, export, rectify, or completely delete your account data and cryptographic keys. Upon account termination, all stored OAuth tokens, BYOK keys, and draft caches are permanently purged within 30 days.

7. Contact Information

For privacy inquiries, Data Protection Officer requests, or to exercise your rights, contact our security council at privacy@socialhive.pro.