Privacy Policy
Last updated: 24 August 2026
Socialiser App Ltd (“Soclo”, “we”, “us”), company number 17243028, is the controller of personal data described in this policy for the Soclo public website, web app, mobile apps, Soclo Pages and related services. This policy explains what we process, why, who receives it and the rights available to you.
1. Information we collect
- Account information: name, email, authentication identifiers, plan, credits, settings and account activity.
- Business and brand information: business name, address or area, industry, description, offers, audience, tone, brand colours, approved assets and other information you choose to add or allow Soclo to scan.
- Content and projects: prompts, posts, captions, images, videos, audio, scripts, edits, schedules, website design and page content.
- Connected-platform information: encrypted access tokens, connected profiles and the content or performance information required for the feature you select.
- Customer interaction information: supported message and conversation previews, leads, enquiries, bookings, reviews and the identifiers needed to follow up.
- Website and domain information: website address, design, publish state, custom-domain registration and DNS information, renewal state and availability.
- Payment and billing information: plan status, credit purchases, merchant-account status and transaction references. Soclo does not store full customer card numbers.
- Advertising measurement information: only if you explicitly enable Measure Meta campaigns, the mobile app can share app interactions such as install or launch and completed registration, plus subscription or purchase outcomes, with Meta. Device or advertising identifiers are available to this measurement only where the platform permits them; on iOS, IDFA collection additionally requires Apple’s App Tracking Transparency permission. Soclo does not put your name, email, authentication token, prompts, brand content or customer content into these Meta event parameters.
- Technical and safety information: device, app version, approximate region, diagnostics, security events, moderation decisions, reports and records needed to investigate misuse.
2. How we use information
- Provide the features you choose, including content creation, publishing, websites, customer work, analytics, bookings and payments.
- Use your approved business context to make drafts, designs, plans and suggestions more relevant.
- Carry out Autopilot work according to the permissions, instructions and credit limit you set.
- Authenticate users, process purchases, maintain website entitlement, prevent fraud and provide support.
- With your separate opt-in, measure installs and outcomes from advertisements for Soclo, attribute those outcomes and improve Soclo’s advertising campaigns.
- Secure, debug and improve Soclo, enforce the Terms and meet legal and provider obligations.
- Send service notices and, where you agree, product or marketing messages.
3. Legal bases
Depending on the activity, we rely on performance of a contract, legitimate interests in operating and securing the Service, consent, and legal obligations. Meta advertising measurement is off by default and relies on your explicit in-app consent. That choice is bound to the signed-in account and is cleared on sign-out or account switch rather than inherited by another account on the device. You can withdraw that consent at any time in Settings → Privacy → Measure Meta campaigns; withdrawal disables future Meta App Events and advertising-identifier collection from Soclo. Apple’s ATT choice is a separate additional control on iOS. A customer who uses a real person in generated material must have that person’s current permission and confirm it in the dedicated real-person flow. Where applicable law treats the processing as special-category biometric information, we also require an appropriate Article 9 UK GDPR condition and complete any required impact assessment.
4. AI features and model providers
When you choose an AI feature, prompts and instructions, selected photos, videos or audio, captions, relevant brand and business context, and customer messages or reviews when AI replies are enabled can be sent to the provider used for that task. Soclo uses providers that can include Anthropic, OpenAI, BytePlus/ByteDance ModelArk, fal.ai (including ElevenLabs audio) and AssemblyAI. The exact provider depends on the feature and availability.
Soclo does not use information obtained through connected Google or other platform APIs to train or fine-tune general-purpose AI models. Soclo does not offer voice cloning. Preset text-to-speech does not create or retain a clone of your voice.
5. Facial and likeness information
Soclo keeps real people separate from synthetic actors. A real person can only be added through the dedicated named-permission flow.
- Collection: the real-person route requires the person’s name, an un-ticked permission declaration and source material supplied by the authorised account. Soclo can create additional reference angles to keep that person visually consistent. Provider-authorised asset routes can use an opaque provider identifier rather than image bytes.
- Purpose: only to create the actor-led content the account requests, keep the authorised identity consistent and investigate safety or rights concerns.
- Permission: permission must be specific, current, recordable and withdrawable. The uploader must be able to demonstrate authority; a depicted person can contact Soclo directly even if they are not the customer.
- Storage and disclosure: the permission record is kept in a private database. Source and generated reference images are kept with the customer’s account and are not listed as assets for other customers. The necessary actor material or identifier is sent over encrypted connections to the selected generation provider so it can perform the requested job. Soclo does not sell it.
- Retention: source and generated actor-reference images are kept while that actor remains selected. Removing the actor or withdrawing permission stops reuse, removes the current reference pack and records the withdrawal. Account deletion removes the account’s actor images and permission record. Limited generation, moderation or serious-incident evidence can be retained for the periods described below where needed for safety, legal claims or another legal obligation.
- Rights: access, correction, restriction, objection, withdrawal and erasure requests can be made through the public report route. A depicted person does not need an account.
6. Connected social and Google platforms
When you connect a platform, Soclo stores an encrypted access token and uses the permitted data only for the features you choose. You can disconnect a supported account. The third party also processes information under its own policy.
Meta App Events
The Meta App Events SDK in the mobile app measures advertising for Soclo itself; it is separate from any Facebook or Instagram account you connect for publishing. It is disabled until you turn on Measure Meta campaigns. After opt-in, Meta can receive the event categories and permitted device identifiers described in sections 1–3 for advertising measurement, attribution and campaign optimisation. Automatic SDK events cover consented lifecycle signals such as app launch; Soclo sends completed purchase and subscription outcomes through one durable manual route, while Meta's automatic in-app-purchase logging is disabled to avoid duplicate value. You can withdraw in the Privacy screen at any time.
YouTube and Google Business Profile
Soclo can use YouTube API Services to upload approved videos to your channel and read the public performance of that content. Google Business Profile access can publish approved posts and read supported performance signals. Use of Google API information follows the Google API Services User Data Policy, including Limited Use. Google API information is not sold, used for advertising or used to train general AI models. You can revoke Google access from Google security settings.
Snapchat
If you connect Snapchat, Soclo can use the permissions you approve to publish or schedule supported Story content, read supported Public Profile and advertising results, and manage advertising you explicitly approve. “Share to Snapchat” sends a local copy of your chosen image or video to Snapchat’s own preview, where you decide whether and where to post it; opening the preview is not an automatic publication.
Snapchat sales measurement is off by default. If you deliberately enable it and confirm that you have a lawful basis, Soclo can send minimised purchase events to Snapchat’s Conversions API to measure advertising. Customer email addresses or phone numbers used for matching are normalised and irreversibly hashed before transmission. Soclo keeps a delivery ledger containing event status and non-identifying operational facts, not the raw email address or phone number. You can disable measurement or disconnect Snapchat at any time.
For other connected networks, access and message availability depend on that network's API and the permission you grant. Permission to publish does not automatically grant Autopilot permission to contact customers.
7. Payments, subscriptions, websites and domains
Apple, Google, Stripe and other selected payment infrastructure can process subscription, credit and merchant-payment information. Soclo receives status, references and information needed to provide support, prevent fraud and show business activity. Full card details are handled by the payment provider.
For a purchased domain, registration information and the data required to manage DNS and renewal are sent to the registrar and infrastructure provider. A custom domain may legally need registrant information. Soclo Pages remains an owner-only preview, so its public renewal, suspension and retention lifecycle is not active. The applicable domain and website-lifecycle terms will be shown before public activation opens.
8. Service providers and disclosures
Soclo does not sell personal data. Providers can include Cloudflare, Supabase, publishing and social-integration infrastructure, Apple, Google, Meta, Stripe, RevenueCat, PostHog, Sentry, Anthropic, OpenAI, BytePlus/ByteDance ModelArk, fal, AssemblyAI and ElevenLabs. They receive only the information needed for their role under contract, for the consented advertising-measurement purpose described above, or their direct relationship with you.
We can also disclose information to comply with law, protect people, investigate misuse, enforce rights, complete a corporate transaction or notify a model/platform provider about an incident, using a pseudonymous user reference where that is sufficient.
9. Retention
Account and business information is generally retained while the account is active. On verified deletion, live account data is deleted or anonymised promptly and encrypted backup copies are purged within 30 days, except limited records required for tax, fraud, legal claims, safety incidents or another legal obligation.
The app keeps a bounded on-device delivery ledger and durably reserves an attempted completed-registration or purchase conversion before handing it to Meta. This gives at-most-one SDK submission attempt across a restart: if the app stops after reservation, a measurement signal can be omitted rather than submitted twice. The ledger contains opaque account or store-transaction identifiers, not event content, and is cleared with the app’s local data on account deletion or uninstall. It is local to that installation and does not survive reinstall or move to another device. Meta retains App Events under its applicable business tools terms and retention controls. Payment and tax records can be retained for the period required by law. Content-report decisions can be retained for 24 months and serious incident records for six years. The likeness-specific periods are in section 5.
10. International transfers
Some providers process information outside the UK or EEA. Where UK transfer law requires a safeguard, Soclo uses an appropriate transfer mechanism such as the UK International Data Transfer Agreement, the UK Addendum to approved contractual clauses, adequacy regulations or another lawful mechanism. The same safeguards apply when a selected generation provider processes authorised real-person material.
11. Your rights
Depending on the law that applies, you may have rights to access, correct, erase, restrict, object, receive a portable copy and withdraw consent. Contact [email protected]. You can complain to the UK Information Commissioner’s Office at ico.org.uk or your local authority.
12. Account and data deletion
Delete from Settings → Privacy → Delete my account in the app, or use the web deletion route if you no longer have the app. Store subscriptions can require separate cancellation through Apple or Google. A depicted person can use the content report route without deleting or owning the customer account.
13. Security
Soclo uses encrypted transport, encryption at rest where provided by the storage system, separately protected access tokens, access controls and least-privilege practices. No system is perfectly secure. Report a vulnerability through the contact on the Security page.
14. Cookies and website tracking
The public marketing website currently uses no advertising or analytics cookies. Account areas use the essential cookies or secure tokens needed to sign you in and protect the session. See the Cookie notice.
15. Children
Soclo is a business service for people aged 18 and over. We do not knowingly create accounts for children. Content involving children is subject to the strict content-safety and legal rules in the Terms.
16. Contact
Socialiser App Ltd
Company No. 17243028
Privacy and data rights: [email protected]
General support: [email protected]