Privacy Policy
What we collect
- Your email, on the account and in support.
- Access tokens for the networks you connect — through each platform's official flow, never a password typed into Fanout.
- Content (text, image, video) you send to publish or schedule.
- Subscription data, charges, and transaction identifiers from Stripe.
- Technical logs, audit events, and what we need for security and support.
How we use it
Only to run the product: publish what you sent to the networks you connected, at the time you set. We don't sell or share your data with third parties for advertising.
Where it's stored
In a database hosted on Supabase (US), restricted to server-side routes — network credentials never reach the browser.
How long we keep it
- Account, workspaces, content, and media: while the account is active.
- Archived media: automatic deletion after 30 days.
- Network tokens: until you disconnect or the workspace is deleted.
- Technical logs: up to 180 days.
- Billing, consent, and audit records: up to 5 years after closure when law or fraud prevention requires it.
- Backups: technical cycle up to 90 days.
After a valid deletion request, active data is erased or anonymized within 30 days. We may keep only the minimum required by law, with restricted access.
Your rights
You can request confirmation of processing, access, correction, portability, information about sharing, objection, withdrawal of consent, and deletion where it applies. You can also disconnect networks in the product.
YouTube API Services
Fanout uses YouTube API Services to publish to YouTube. That use is also subject to the YouTube Terms of Service and Google Privacy Policy. You can revoke Fanout's access to your Google data at myaccount.google.com/permissions.
Agents and API
When an AI agent uses Fanout through MCP or REST, we only receive what the tool sends (caption, media, time, accounts). We never receive your full conversation with the assistant.