1. Information We Collect
SpaceAI connects to multiple social platforms on your behalf. The data we collect depends on which platforms you choose to connect.
1a. Meta (Instagram and Facebook)
When you connect an Instagram professional account or Facebook Page via Meta's OAuth, we collect:
- Meta user ID provided during login
- Facebook Page ID(s) you authorize
- Instagram professional account ID(s) you authorize
- OAuth access tokens and token metadata required to maintain the connection
- Content you submit for publishing (captions, media files, scheduled publish time)
- Publish status logs, error logs, and timestamps
1b. LinkedIn (Personal Profile)
When you connect your personal LinkedIn account via LinkedIn's OAuth, we collect:
- LinkedIn member ID (the OpenID Connect
sub field) - Full name, first name, and last name
- Email address (used as your SpaceAI account identifier for this connection)
- Profile picture URL
- OAuth access tokens required to post on your behalf
- Content you submit for publishing (captions, hashtags, media files)
- Publish status logs, error logs, and timestamps
1c. LinkedIn (Organization / Company Pages)
When you connect a LinkedIn Company Page via our dedicated LinkedIn Pages integration (which uses the LinkedIn Community Management API), we collect everything listed in section 1b above, plus:
- The LinkedIn Organization ID(s) of Company Pages you administer
- Organization name and logo URL for display in the SpaceAI dashboard
- Your administrator role information for each connected page (used to verify you have permission to publish)
- Content you submit for publishing to the page (captions, hashtags, media files)
Important: We only access LinkedIn Company Pages where you hold an Administrator or Content Admin role. We do not access or store data about pages you do not administer.
LinkedIn member profile data (name, email, profile picture) is fetched at connection time and is not persistently cached beyond your active connected account session, in compliance with LinkedIn's Marketing Developer Platform (MDP) data storage requirements (profile data: maximum 24-hour cache; social activity data: maximum 48-hour cache).
1d. Other Connected Platforms (Twitter/X, Reddit, YouTube)
When you connect other social platforms, we collect the minimum data necessary for publishing:
- Twitter/X: Twitter user ID, username, display name, profile picture, and OAuth access token
- Reddit: Reddit username, user ID, profile picture, and OAuth access token
- YouTube: YouTube channel ID, channel name, channel thumbnail URL, and OAuth access token
1e. General SpaceAI Account Data
- Your SpaceAI account email address and business profile information
- Product usage analytics (features used, publish history, error logs)
- Content you create within SpaceAI (post drafts, captions, generated images)
2. How We Use Information
We use the data we collect solely to provide the SpaceAI service. Specifically:
- Meta (Instagram and Facebook): Connect your Meta assets, publish Instagram posts and Facebook Page posts that you explicitly create and approve within SpaceAI.
- LinkedIn (Personal Profile): Publish posts to your personal LinkedIn feed on your explicit instruction.
- LinkedIn (Organization Pages): Publish posts to LinkedIn Company Pages you administer, retrieve the list of pages you manage for display during setup, and retrieve organization information (name, logo) for the SpaceAI dashboard.
- Other platforms: Publish content you create in SpaceAI to Twitter/X, Reddit, and YouTube on your explicit instruction.
- Display connected accounts and publish history in your dashboard.
- Provide customer support and troubleshoot publishing failures.
We do not use your social media data for advertising, profiling, training AI models, or any purpose beyond operating the SpaceAI publishing service.
3. Sharing of Information
We do not sell your data. We share information only in the following limited circumstances:
- With Meta/Instagram and Facebookto perform the publishing actions you request (we transmit your content and tokens as required by Meta's APIs).
- With LinkedInto perform the publishing actions you request, whether to your personal profile or to a Company Page you administer (we transmit your content and tokens as required by LinkedIn's APIs).
- With Twitter/X, Reddit, and YouTube to perform the publishing actions you request.
- With service providers (hosting, cloud storage, logging infrastructure) under confidentiality obligations who assist us in operating SpaceAI.
- If required by law or legal process, and only to the extent necessary to comply.
4. Data Retention
- Access tokens (for all platforms) are retained only while your connected account remains active. Disconnecting immediately and permanently deletes the stored token.
- LinkedIn profile data(name, email, profile picture) is fetched at connection time and is not cached beyond 24 hours, in compliance with LinkedIn's MDP data storage requirements.
- LinkedIn organization data (Company Page name, organization ID) is retained only while the LinkedIn Page connection is active. Disconnecting deletes this data immediately.
- Publish records and audit logs (publish status, timestamps, error logs) may be retained for up to 90 days for troubleshooting and support purposes.
- Post content you create (drafts, captions, generated images) is retained until you delete the post or your SpaceAI account.
5. Security
We take security of your credentials seriously:
- All OAuth access tokens are encrypted at rest using AES-256 encryption before being stored in our database.
- All data in transit is protected with TLS encryption.
- Access to stored tokens is restricted to authorized systems and personnel only.
- We do not log or store plain-text access tokens at any point.
6. Your Choices
You have full control over your connected accounts. You may at any time:
- Disconnect your Instagram, Facebook Page, LinkedIn personal profile, LinkedIn Company Page, Twitter/X, Reddit, or YouTube account using the "Disconnect" button in your SpaceAI Connected Accounts settings. Disconnecting immediately revokes our access and permanently deletes the stored token.
- Revoke SpaceAI's access directly through the relevant platform's settings (see Section 7).
- Request deletion of your entire SpaceAI account and associated data (see Section 7).
7. Data Deletion
You can delete your connected account data in several ways:
- Disconnect in SpaceAI:Use the "Disconnect" button in your Connected Accounts settings. This immediately and permanently deletes all stored tokens and associated account data for that platform.
- Revoke via Meta/Instagram:Revoking SpaceAI's access through Instagram or Meta settings will automatically delete your data from SpaceAI via Meta's data deletion callback.
- Revoke via LinkedIn:You can revoke SpaceAI's access in your LinkedIn Settings > Data Privacy > Permitted Services. This disconnects SpaceAI from your LinkedIn account and stops any future access. We will delete stored tokens upon detecting the revocation.
- Email request: Email support@spaceai.so with the subject "Data Deletion Request" and your account details for manual deletion of your full SpaceAI account.
All deletion requests are processed immediately and permanently. We will confirm completion when requested. (See also: https://app.spaceai.so/data-deletion)
8. Platform-Specific Terms and Policies
By connecting social platforms through SpaceAI, your use of those platforms is also governed by their respective terms and policies. We encourage you to review them:
9. Contact
If you have questions about this Privacy Policy or how we handle your data, please contact us:
SpaceAI Support: support@spaceai.so