LEGAL

Privacy Policy

Effective: August 24, 2026

1. What We Collect

Account information (email, name) provided at registration. OAuth tokens for connected platforms (Facebook, Instagram, YouTube, LinkedIn, TikTok) stored encrypted with per-tenant key isolation. Content you create or schedule through Reach. Engagement metrics retrieved from connected platforms. Usage telemetry (feature interactions, session duration) for service improvement.

2. How We Use Your Data

To provide the DeeCi intelligence service and Reach content distribution. To retrieve and display engagement analytics from your connected platforms. To improve service quality through anonymized usage patterns. We never sell your data. We never use your content to train models. Your intelligence outputs belong to you.

3. Data Architecture

DeeCi operates a sovereign-first architecture. All data is encrypted at rest (AES-256-GCM) and in transit (TLS 1.3). Per-tenant database isolation ensures no cross-tenant data access. OAuth tokens are encrypted with tenant-specific keys managed through AWS KMS. No data is stored in commercial browser memory.

4. Third-Party Platforms

When you connect a social media account, we store an encrypted OAuth token to access that platform on your behalf. We only request permissions necessary for content publishing and engagement retrieval. You can revoke access at any time from within the connected platform or by contacting us.

5. Data Retention

Account data is retained while your account is active. Content queue history and engagement metrics are retained for 24 months. OAuth tokens are retained until you disconnect the platform or delete your account. You may request complete data deletion at any time.

6. Your Rights

Access: Request a copy of all data we hold about you. Correction: Update inaccurate personal information. Deletion: Request complete erasure of your data (see our Data Deletion page). Portability: Export your data in standard formats. Objection: Opt out of non-essential data processing.

7. Security

Tested against 5,250 attack vectors with zero breaches. 8 defense layers including host allowlisting, network membrane, token authentication, and SCIF-grade audit logging. Full security posture details available on our Security page.

8. Changes

We will notify you of material changes to this policy via email. Continued use after notification constitutes acceptance of the updated policy.
Contact
For privacy inquiries or data requests: privacy@thedeeci.com