Privacy Policy

Last updated: August 6, 2026

SocialHalo ("we", "us") is a social-media analytics and AI content-intelligence service operated by Frontier Digital Marketing and available at socialhalo.io. This policy explains what data we collect, why, and the choices you have. Questions: elliot@frontierdigitalmarketing.com.

Who is responsible for your data

SocialHalo is operated by Frontier Digital Marketing LLC, a California limited liability company, at 1613 Chelsea Rd, Suite 151, San Marino, CA 91108, United States. Write to us there, or email elliot@frontierdigitalmarketing.com.

For your own account and workspace data we are the controller under the EU and UK GDPR: we decide what we collect and why, and this policy is that explanation. For the platform data and other people's content you bring into a workspace, described under Third-party data below, we act as a processor on your instructions. Our Data Processing Agreement covers that processing.

Data we collect

  • Account information — your name, email address, and a hashed password when you sign up, plus workspace names, the niche you set on a workspace, and team membership.
  • Connected social accounts — when you connect a platform (YouTube, TikTok, Instagram), we store the OAuth tokens the platform issues. Tokens are encrypted at rest (AES-256-GCM) and used only to fetch your analytics data.
  • Platform analytics data — post metadata, performance metrics, audience demographics, video transcripts, and comments retrieved from the platforms you connect, used to power your dashboards and AI analyses.
  • Content you create in SocialHalo — scheduled drafts with their captions and hashtags, ideas and scripts, and your Halo Mind conversations, meaning the questions you type and the answers you get back.
  • Competitors you track — for each competitor you add, their handle and display name, their follower count, and their public posts and metrics.
  • Product feedback — the message you send from the in-app feedback form, the page you sent it from, and your email address.
  • Payment information — handled entirely by Stripe. We never see or store your card number; we keep only your Stripe customer reference and subscription status.
  • Usage data — standard server logs (IP address, browser type, pages requested) for security and reliability, diagnostic error reports (the error, the page it happened on, and your browser and device type) so we can find and fix bugs, plus privacy-preserving product analytics (which features and pages are used, and how far you get in setup) collected without cookies to help us improve the product.

How we use your data

  • To provide analytics dashboards, scheduling, reports, and alerts for your workspaces.
  • To generate AI analyses: we send workspace content to an AI processor, either Anthropic or xAI. What that covers is set out in What we send to our AI processors below. Neither uses this data to train its models.
  • To send transactional email (account verification, password resets, invitations, billing notices).
  • To secure the service (rate limiting, fraud prevention, audit logs).

We do not sell your personal data, and we do not use it for third-party advertising.

Our legal bases for using it

If the EU or UK GDPR applies to you, we have to name a lawful basis for each thing we do with your data. Ours are:

  • Performing our contract with you, for running your account and workspaces, retrieving data from the platforms you connect, generating the analyses you ask for, storing what you write in the product, and sending you email about your account, your team, and your billing.
  • Our legitimate interests, for keeping the service secure and working (server logs, rate limiting, fraud prevention, audit logs), for diagnosing errors, for cookieless product analytics that tell us which features get used, and for clustering recent product feedback to find common themes. Our interest is in running a service that stays up and stays safe to use, and we weigh that against your privacy in each case. You can object to any processing we base on this, and we explain how below.
  • Complying with a legal obligation, for keeping billing and tax records and for responding to lawful requests from authorities.

For personal data about people other than you, such as the commenters on your posts, we are acting on your instructions rather than our own, and the lawful basis for that processing is yours to establish.

What we send to our AI processors

We send what the analysis you ran needs to answer it, drawn from your workspace. Both of our processors, Anthropic and xAI, may receive any of it: which of them runs a given analysis is a setting on our side, and changing that setting does not change what we send. Neither uses your data to train its models. The categories below are not a closed list, because they grow as we add features. Some of what they cover is not obvious:

  • Your posts — the caption as you wrote it, performance metrics, and the opening of a video's transcript, which carries the words of anyone speaking in it.
  • Comments on your posts — the comment text, whether or not a reply is involved. Sentiment analysis reads comments from across your posts, and a post deep dive reads the top comments on that post. We send the commenter's handle only when you draft a reply to their comment.
  • Drafts you have not published — when you run a Halo Check on a scheduled post, we send that draft's caption and hashtags. The draft does not have to be published for that to happen.
  • Halo Mind conversations — the question you type, word for word, and up to six earlier turns of the same conversation. Halo Mind is a free-text box, so whatever you put in it is what we send.
  • What you write in the product — the ideas you write or edit and the niche you set on your workspace go out with any analysis that builds on them, in the words you used rather than a summary. The drafts and Halo Mind questions above fall under this too; they have their own entries because they are the easiest to overlook.
  • Your own identifiers — the handle, platform, and follower count of each connected account. The weekly briefing sends these on every run.
  • Competitors you track — the display name you added, their post captions, and their public metrics.

A Halo Mind request that goes to xAI also carries a one-way hash of the conversation id, which lets xAI route it to a warm cache. That hash is a routing key only: it contains no message content and no account, workspace, or member details.

Product feedback

When you send feedback from inside the app, we periodically cluster recent messages to find common themes. That run pools feedback from every customer rather than only yours, so your message is read alongside other people's, and it goes to the same AI processors. We send the message text, the date, the page you sent it from, and the category we filed it under. We deliberately leave out your email address, which we store but never put in the request. The box is free text, so anything you paste into it goes with it.

Service providers

We share data only with the processors required to run the service:

  • Vercel (application hosting) and Railway (background processing)
  • Supabase (database and file storage)
  • Anthropic and xAI (AI analysis processing)
  • Stripe (payments and billing)
  • Resend (transactional email)
  • PostHog (privacy-preserving product analytics, configured in cookieless mode)
  • Sentry (error monitoring and diagnostics)
  • Google (YouTube), TikTok, and Meta APIs (data retrieval for accounts you connect)

The current list, with each provider's purpose and location, is kept at socialhalo.io/legal/subprocessors. We'll update it before adding a new subprocessor.

Where your data is processed

We are a United States company, and we and every provider listed above store and process your data in the United States. Each provider's location is listed on socialhalo.io/legal/subprocessors.

If you are in the United Kingdom, the European Economic Area, or Switzerland, that means your data leaves your country. For those transfers we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the UK GDPR applies. Email us at the address above and we will send you a copy of the clauses we use. We do not rely on the EU-US Data Privacy Framework, because we have not self-certified to it.

YouTube API Services

SocialHalo uses YouTube API Services. By connecting a YouTube account you agree to the YouTube Terms of Service, and Google's Privacy Policy applies to data Google processes. You can revoke SocialHalo's access to your YouTube data at any time via Google security settings or by disconnecting the account in SocialHalo Settings. We refresh stored YouTube data periodically and delete it when you disconnect the account or delete your workspace.

TikTok and Meta platform data

Data retrieved from TikTok and Meta (Instagram) APIs is used solely to display your analytics and generate insights inside your workspace, is retained only while the account remains connected, and is deleted when you disconnect the account or delete your workspace, consistent with each platform's developer terms.

Third-party data

Some of what we process describes people other than you:

  • People who comment on your posts — their handle and the text of their comment.
  • Competitors you track — the display name you entered, their public posts and captions, and their metrics.
  • Anyone speaking in your videos — their words reach us in the transcript, whether or not they are the account holder.

We process this to run your comments inbox and competitor comparisons and to generate the analyses you ask for. It goes to our AI processors as described above, and neither of them uses it to train its models. We act as a processor on behalf of you, the account holder.

Comment data is automatically purged 180 days after the comment was posted, and sooner if you disconnect the account, delete the underlying post, or delete your workspace. A competitor's stored posts are deleted when you stop tracking that competitor or delete the workspace.

Cookies

We use only essential cookies: a session cookie to keep you signed in and short-lived cookies during OAuth connection flows. We do not use advertising or cross-site tracking cookies. Our product analytics runs in a cookieless mode and sets no cookies or persistent browser storage.

Data retention and deletion

We keep workspace data while your account is active. You can delete an entire workspace or your whole account yourself at any time from Settings → Danger zone; disconnecting a single social account instead removes just that account's stored tokens and platform data. Deletion removes the associated data from our production systems immediately, and backups age out on a rolling schedule within 30 days. Comment data is additionally purged on the 180-day schedule described above, and Halo Mind conversations can be deleted individually from the Halo Mind history. To request deletion or a copy of your data, you can also email elliot@frontierdigitalmarketing.com.

Your rights (GDPR / CCPA)

Depending on where you live, you may have the right to access, correct, export, restrict the processing of, or delete your personal data, and the right not to be discriminated against for exercising those rights. We honor these requests for all users regardless of region — contact us at the email above and we'll respond within 30 days.

If you are in the UK or the EEA you also have the right to object to any processing we base on our legitimate interests, listed above, and the right to complain to a data protection supervisory authority. In the UK that is the Information Commissioner's Office at ico.org.uk. In the EEA it is the authority for the country you live in, the country you work in, or the country where you think the problem happened. We would rather you came to us first, but you do not have to.

Security

All traffic is encrypted in transit (TLS). Social OAuth tokens are encrypted at rest. Access to production systems is restricted and audited. No method of storage is 100% secure. If we learn of a breach affecting your personal data we will tell you without undue delay, and in any event within 48 hours of becoming aware of it, along with what you need to meet your own reporting obligations. That is the same 48-hour commitment we make in our Data Processing Agreement.

Changes

We'll post any changes to this policy here and update the date above. Material changes will be announced by email to account holders.