Privacy & Cookie Policy

Last updated:

1. Who we are

Omnipost is a social media workspace: you connect the accounts you already run on X, Facebook, Instagram, TikTok and YouTube, and plan, schedule and publish to them from one place. Cublya (“we”, “us”) is the controller for the personal data described here. You can reach us at privacy@cublya.com about anything in this policy.

Omnipost publishes nothing you have not asked it to publish, and holds nothing about a platform account until you connect it.

2. What we process

  • Account data: your email address, and your name and picture if the sign-in provider you chose passes them to us. A password is stored only as a hash by our authentication provider, and if you sign in with Google there is no password at all.
  • Preferences: your timezone, time format, and appearance choice.
  • Connected platform accounts: for each account you connect, the platform, the account id on that platform, the handle, the display name, when it was connected, and whether its authorisation is still healthy. The access token itself is held by our publishing gateway (section 6), not by Omnipost.
  • What you create: drafts, scheduled and published posts, per-channel variants, schedules, automations and their run history, channel groups, and brand settings.
  • Media you upload: images and video, with file type, size, dimensions, duration, and any alt text you write. Whatever is visible in a file is in the file, including the people and places in it and any metadata you did not strip.
  • AI prompts and generations: what you ask the assistant, what it returns, the conversation history, and an audit record of every tool call made on your behalf, with the workspace and the member who made it.
  • Automation source connections: if you connect Notion, Slack, or Google Drive as a source for an automation, we store an access token encrypted with a key held outside the database, the scopes that system actually granted, and whatever a run read from it.
  • Sign-in sessions: our authentication provider records the IP address and browser string of each live session, which is what lets you see where your account is signed in and sign the other sessions out.
  • Consent and acceptance records: which version of these documents you accepted, whether you accepted or withdrew, when, and the IP address, browser string and language of the request that recorded it. Those last three are evidence of the click, stamped by our server rather than reported by your browser. We are required to be able to demonstrate this, and a withdrawal is added as a new entry rather than erasing the old one.
  • Technical data: IP address, browser and device type, processed by our hosting providers to deliver and secure the service and recorded in server logs.
  • Usage data: pseudonymous product analytics and session replay, only if you accept optional cookies (section 5).
  • Communications: the content of any email you send us.

Content you schedule can carry more than it looks like it carries. A campaign brief, a customer photograph, or a reply drafted in the composer can contain personal data about other people, and you decide what to put there.

3. Why we process it, and on what basis

  • Running the service (storing drafts and media, scheduling, delivering posts to the accounts you connected, showing you what happened): performance of our contract with you, Art. 6(1)(b) GDPR. This is not optional; without it there is no product.
  • Creating and securing your account, including authentication, session management, rate limiting, and abuse prevention: performance of the contract, and our legitimate interest in keeping the service available and safe, Art. 6(1)(f).
  • Keeping the service working: error logs, uptime and gateway health monitoring, and diagnosing failed deliveries. Legitimate interest in operating a reliable service, Art. 6(1)(f). You can object to this at any time, see section 9.
  • Product analytics and session replay: consent, Art. 6(1)(a), given through the cookie banner and withdrawable at any time. Nothing is collected until you accept.
  • Answering you when you write to us: legitimate interest in supporting our own users, Art. 6(1)(f).
  • Proving consent and acceptance: legal obligation, Art. 6(1)(c), read with Art. 7(1).

Providing this data is a contractual requirement in the sense that Omnipost cannot work without the accounts and content you choose to give it. There is no consequence to not providing them other than having nothing to publish.

4. Automated processing and AI

Omnipost drafts and rewrites copy, suggests variants, and can run AI steps inside an automation. A language model reads your instruction and the content you point it at, and returns text that the app shows you before anything is published. Nothing is decided about you: this produces no legal or similarly significant effect and is not automated decision-making in the sense of Art. 22. You can edit or discard everything a model produces, and a scheduled post can be changed or cancelled until it is sent.

We do not train any model on your content, and nobody at Cublya reads your drafts or media to improve the product.

What a model provider does with a request while it processes it is governed by that provider's own terms. To be straight about a gap: Omnipost does not currently set a no-training or zero-retention flag on those requests, and some routes in the fallback chain are free tiers whose provider may use prompts to improve their own models. If that matters for your content, an admin can switch the assistant off for the whole workspace in AI settings, and you can leave the AI blocks out of your automations.

We do not sell or share a profile of you, and we do not use your content to advertise to you.

5. Cookies and similar technologies

This covers anything stored on or read from your device, not only cookies: local storage counts too.

  • Strictly necessary: keeping you signed in, remembering your cookie choice, and holding interface preferences such as your theme. These need no consent and cannot be switched off without breaking the app.
  • Optional analytics: Vercel Analytics, which counts page views and gives us aggregate traffic figures. It loads only after you accept, and stops when you withdraw.
  • Optional session replay: OpenReplay, which records how a session moved through the interface so we can see where it went wrong. Same rule: only after you accept, and it stops when you withdraw.

Closing the banner without choosing rejects optional cookies. You can change your mind at any time from Cookie settings in the footer, and withdrawing is exactly as easy as accepting. We ask again at least once a year.

If your browser sends a Global Privacy Control signal, we treat it as a refusal of optional cookies and of any sale or sharing of personal information, and we honour it without you having to touch the banner. Session replay also stays off when your browser sends the older Do Not Track header.

6. Who else processes your data

We do not sell your personal data and we do not share it for advertising. We do use service providers, who process it on our instructions:

  • Supabase: authentication, the application database, and object storage for the media you upload. Holds your account identity, everything you create in Omnipost, and your files.
  • Vercel: hosts and serves the web application, so it handles the technical data in every request.
  • Google Cloud: the machine our API and background workers run on, and the queue behind scheduled publishing.
  • Postproxy: our publishing gateway. It runs the OAuth connection to X, Facebook, Instagram, TikTok and YouTube, holds the access tokens for the accounts you connect, and delivers your posts. Your post text and media reach a platform through it.
  • OpenRouter and Google: the model providers behind AI features. What you send the assistant, and the content an AI automation step reads, goes to whichever route answers. OpenRouter may route a request onward to a further model host, currently Google or Amazon Bedrock.
  • Resend: sends the account emails our authentication provider triggers, such as sign-up confirmation, magic links, password resets, and invitations. It sees your email address and the link.
  • Vercel Analytics and OpenReplay: product analytics and session replay, only with your consent, and never with the media you upload.

X, Facebook, Instagram, TikTok and YouTube are not our processors. When you publish, you are sending your content to a platform you have your own relationship with, and what happens to it there is governed by that platform's terms and privacy policy.

We may also disclose data where the law requires it, or to establish or defend legal claims.

7. International transfers

Some of the providers above are established outside the EEA, mainly in the United States. Where personal data is transferred there, we rely on the European Commission’s Standard Contractual Clauses, which form part of our agreements with those providers, together with technical measures such as encryption in transit and at rest. Write to privacy@cublya.com for the safeguards covering a particular provider.

8. How long we keep it

  • Posts, drafts, automations, and everything derived from them: until you delete them, or until your account is closed.
  • Media you upload: until you delete it from the gallery, or until your account is closed.
  • Connected platform account records: until you disconnect the account, or until your account is closed.
  • Assistant conversations: 30 days after the last message in the thread, removed by a daily sweep.
  • AI tool-call audit records: 400 days. They are the answer to “the assistant did something odd”, so they outlive the conversation that caused them.
  • Account data: for as long as your account exists.
  • Consent records: for the life of the account, and deleted with it. Once the relationship ends there is nothing left to demonstrate consent for.
  • Sign-in sessions: until the session expires or you end it.
  • Server and access logs: kept by our hosting providers on their own schedules, on the order of 30 days.
  • Backups: deleted data can persist in encrypted backups for a period before those backups age out.
  • Support email: 12 months after the conversation ends.

To be straight about a gap: the two AI sweeps above are the only retention periods Omnipost enforces in code today. The rest describe how long we intend to keep things, and depend on us and our providers acting on them rather than on an automated deletion job.

9. Your rights

Wherever you live, you can ask us to:

  • give you a copy of your data (access)
  • correct anything wrong (rectification)
  • delete it (erasure)
  • hand it over in a portable format (portability)
  • pause processing while a dispute is resolved (restriction)
  • stop processing based on legitimate interests (objection), which you can do at any time and for reasons particular to your situation
  • withdraw a consent you gave, without affecting what happened before you did

Some of this you can do yourself: edit or delete any post, draft or media file in the app, disconnect a platform account from channel settings, sign every other session out from security settings, and change your cookie choice from the footer.

For the rest, including a full export of your workspace and deletion of your account, write to privacy@cublya.com. There is no self-serve export or delete button today, so email is the route, and we answer within one month.

If you are unhappy with how we have handled your data, you can complain to your local data protection supervisory authority. You do not have to come to us first, though we would rather you did.

10. If you are in the United States

We do not sell your personal information and we do not share it for cross-context behavioural advertising, as those terms are used in US state privacy laws. We honour the Global Privacy Control signal as an opt-out request. The rights listed in section 9 cover the access, correction, deletion and portability rights those laws give you, and we will not discriminate against you for exercising them.

11. Security

Data is encrypted in transit and at rest, and access to production systems is limited to the people who need it. Tokens for optional automation sources are encrypted with a key held outside the database and stored under a key version, so a key can be rotated without a plaintext window. Workspace boundaries are enforced on every request, so one workspace’s content cannot be read from another. No system is perfect; if a breach affects you and carries a high risk, we will tell you.

12. Children

Omnipost is not for anyone under 16. We do not knowingly collect data from children, and we delete it if we find we have.

13. Changes to this policy

We update this page when our practices change, and revise the “Last updated” date above. When a change is material we will not simply post it: you will be asked to read and accept the new version the next time you sign in, and until you do, the version you accepted is the one that applies to you.

14. Contact

Questions about this policy or our data practices go to privacy@cublya.com. See also our Terms of Use.

Start publishing