Legal

Privacy Policy

This is a draft and is not in force. Satat has no registered legal entity yet, so every field identifying the data controller is marked unfilled below.

Do not submit this document to Meta, LinkedIn, TikTok or any other platform review until those fields are completed and the policy has been reviewed by a lawyer qualified in Indian data protection law.

Effective date: [NOT YET IN FORCE]

1. Who we are

Satat is an autonomous content pipeline that plans, produces and publishes social media content on behalf of its users. The data controller responsible for the personal data described in this policy is [LEGAL ENTITY NAME], registered at [REGISTERED ADDRESS], India.

You can reach us about anything in this policy at [CONTACT EMAIL].

2. What we collect

  • Account data. Your email address, and your name and profile picture if you sign in with Google. Authentication is handled by Supabase Auth; we never see or store your password.
  • Workspace and brand data. What you enter about your business — brand name, category, tone, audience, region, languages, logo, colours, content pillars, guardrails and posting cadence.
  • Connected platform credentials. When you connect a social account we store OAuth access and refresh tokens, encrypted at rest. We never ask for, accept or store a social media password.
  • Content you create. Scripts, captions, rendered images and video, and the schedule they are published on.
  • Public data we read for you. When you run a scan, we read publicly available posts from the profiles you nominate, through official platform APIs only.
  • Billing data. Subscription and payment records. Card details are handled by our payment processor and never reach our servers.
  • Operational logs. Job records, errors and audit entries showing who changed what and when.

3. What we do not do

  • We do not sell personal data, and we do not share it for advertising.
  • We do not use browser automation or unofficial APIs to access any platform on your behalf. Official APIs only.
  • We do not post to any account you have not explicitly connected and authorised.
  • We do not message anyone who has not opted in, on any channel, regardless of instruction.

4. Why we process it

To operate the service you asked for: to run the pipeline, publish to the accounts you connect, bill you accurately, keep the service secure, and meet legal obligations. Our basis for processing is the performance of our contract with you, your consent where you have given it, and our legitimate interest in securing and improving the service.

5. Who we share it with

We use a small number of processors, each handling only what their function requires:

  • Supabase — database, authentication and file storage.
  • Vercel and Railway — application and worker hosting.
  • Anthropic — the reasoning model that writes strategy, scripts and captions. Content sent for generation is not used to train their models.
  • Razorpay — payment processing and invoicing.
  • Resend — transactional email.
  • The platforms you connect — we send them the content you have approved for publishing, and read back the metrics they expose.

Some of these operate outside India. Where that is the case, transfers are made under the safeguards those providers offer, and only as far as running the service requires.

6. How long we keep it

Account, workspace and content data is kept while your account is open. Delete your account and we remove it, including files in storage, and revoke the platform tokens you granted us. Billing and invoice records are retained for as long as Indian tax law requires. Operational logs are kept for [RETENTION PERIOD].

7. Your rights

Under the Digital Personal Data Protection Act, 2023 you may ask us to give you a copy of your personal data, correct it if it is wrong, erase it, or tell you who we have shared it with. You may withdraw consent at any time; where processing depended on that consent, we will stop. Write to [CONTACT EMAIL] and we will respond within the period the Act allows.

If we do not resolve your concern, you may complain to the Data Protection Board of India.

8. Grievance officer

As required by Indian law, our grievance officer is [GRIEVANCE OFFICER NAME], reachable at [GRIEVANCE OFFICER EMAIL].

9. Security

Every workspace is isolated at the database level, so one customer's data cannot be read by another even if the application is wrong. Platform tokens are encrypted at rest and are readable only by the background worker that needs them — never by a browser. Access to production systems is limited to those who require it.

10. Children

Satat is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18.

11. Changes

If we change this policy in a way that materially affects you, we will tell you by email before the change takes effect.