Privacy Policy

Last updated 27 July 2026

This policy explains what data SocialGrid (the “Service”), operated by Exen Labs, handles and why. The Service is an operator tool: it is used by the person who runs the connected social media accounts, not by the public, and it is not designed to collect data about anyone else.

What we handle

  • Connected account details.When you connect a social media account, we store the account identifier and basic profile information the platform returns — such as the open ID, display name and avatar — so the interface can show which account is connected and attach scheduled posts to the right one.
  • Access and refresh tokens. Required to publish on your behalf. These are encrypted at rest using AES-256-GCM and are never displayed in the interface or included in logs.
  • Content and source media. Videos you upload or link, the files generated from them, transcripts, captions, scripts and the settings attached to each job.
  • Operational records. Job status, timestamps, and error messages produced when something fails, kept so failures can be diagnosed.

The Service has no public sign-up, runs no advertising, sets no advertising or analytics cookies, and does not build profiles of end users of the connected platforms.

How platform data is used

Data obtained from a connected platform is used only to operate the features you asked for: identifying the connected account, and publishing content you have approved. It is not sold, rented or shared for advertising, and it is not used to train any AI model. We request only the permissions those functions need, and each platform’s own privacy policy continues to govern the data it holds about you.

Third-party processors

To run, the Service passes data to a small number of providers:

  • DigitalOcean— application hosting, the database, and object storage for media files.
  • CometAPI— AI text generation, image generation, and transcription of the audio extracted from your source video.
  • ElevenLabs— text-to-speech for generated voiceover.
  • The platforms you connect— such as YouTube and TikTok, which receive the content you publish.

These providers process data to deliver their part of the Service and are subject to their own terms and privacy policies.

Retention

Source media, generated output and job records are kept until you delete them or the Service is decommissioned. Transcripts are retained per job so a retry does not have to pay to produce them again. Disconnecting an account deletes its stored tokens and revokes the Service’s access; content already published to that platform is unaffected and remains under that platform’s control.

Security

Refresh tokens are encrypted at rest. The database is firewalled to the application. Media is stored in a private-by-default object store, with individual files made publicly readable only where a destination platform requires a reachable URL to fetch them. All traffic is served over HTTPS.

Your choices

You can disconnect any connected account at any time from the settings page, which removes its stored credentials. You can delete jobs and their associated media from the interface. For any request about data held by the Service, contact us at the address below.

Children

The Service is a business tool and is not directed at children. We do not knowingly collect data from anyone under 13.

Changes

We may update this policy as the Service changes. The date at the top of this page reflects the current version.

Contact

Questions or requests about your data: [email protected].