Privacy Policy
This policy explains what data SocialFaktory collects, why, and the choices you have. SocialFaktory is operated from Switzerland. Last updated August 3, 2026.
1. What we collect
Account data (name, email, password), the content you upload (briefs, media, brand assets, cloned voices and likenesses you provide), the social accounts you connect, and usage data such as pages visited and features used. Payments are handled by our payment processor. We never store full card numbers. SocialFaktory is not directed to children under 16, and we do not knowingly collect their data.
2. How we use it
To run the service: generate your videos, publish to your connected channels, bill your subscription, prevent abuse, and improve the product. We do not sell your personal data.
3. AI processing
Your briefs and media are processed by AI infrastructure to generate video, voice, and translations. Content you upload is used to produce your output, not to train public models. Cloned voices and likenesses are processed only with your explicit consent and only to generate your content; you can delete them at any time.
4. Connected social accounts
You connect each social account yourself, through that platform's own authorisation screen, and we never ask for your platform password. From a connected account we receive an access token, the account's public profile (its name, handle, avatar and identifier), the destinations you can publish to such as pages, boards or channels, and the delivery status and public performance metrics of the posts we published for you. We send the platform only what you asked us to publish: your video or image, its caption, and the publishing options you chose. Platform data serves one purpose, which is to publish and schedule your content and report how it performed. We never use it to train AI models, never sell it, and never transfer it to advertisers, data brokers or any other third party beyond the providers that host and operate SocialFaktory. Authorisations are held inside our own infrastructure and are reachable only by the systems that publish for you; they are never shown to you or to anyone else. Disconnecting an account asks the platform to revoke the authorisation, where the platform offers a way to do that, and erases the stored credentials either way. We keep the account name and identifier on the posts already published so your history stays readable, and that record is removed when you close your account. You can also revoke our access from the platform itself at any time, which ends it immediately:
5. YouTube and Google data
SocialFaktory uses YouTube API Services. There are two separate Google authorisations and you can grant either, both, or neither. Signing in with Google is optional and only creates or identifies your SocialFaktory account: from it we receive your email address, first and last name, profile picture and Google account identifier, we store those alongside your account so you can sign in again, the sign-in token is encrypted at rest, and none of it is ever used to publish anything. Connecting a YouTube channel is the authorisation that grants publishing access, and we request exactly five permissions: your basic Google profile, your email address, read access to the channels you own, permission to upload videos to that channel on your behalf, and read access to the analytics of videos on it. We use them only to show you which channel is connected, to upload the content you asked us to publish, and to report its performance back to you. We store the authorisation and the channel identifier and title. We do not read, download or retain the videos already on your channel through YouTube API Services; if you separately paste a public video link into SocialFaktory as a creative reference, we download that specific video to work from and keep it until you delete it, which is your own action and not channel access. SocialFaktory's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never used to train AI models, never sold, and never shared with anyone except the providers that host and operate SocialFaktory, or where you ask us to or the law requires it. You can revoke SocialFaktory's access from your Google Account at any time, which ends our access immediately. Disconnecting the channel in SocialFaktory does the same from our side: we ask Google to revoke the authorisation and we erase the stored tokens, so nothing is left that could reach your channel.
6. How we protect your data
All traffic is encrypted in transit with TLS: between your browser and SocialFaktory, between our own systems, and between SocialFaktory, the AI infrastructure and the platforms we publish to. Credentials that grant access, such as the Google sign-in token and the keys that link your brands to our publishing system, are stored encrypted at rest at the application level, so they stay unreadable even with direct access to the database. Platform authorisations are held in a separate publishing system inside our own infrastructure, reachable only through those encrypted keys; the services that publish for you use them, and they are never displayed to you or to anyone else. Every request is scoped to the authenticated account, so your data is never reachable from another account, and production access is restricted to the few people who operate SocialFaktory. Full card numbers never reach our servers. If an incident ever affects your personal data, we will notify you and the competent authorities without undue delay, as required by applicable law.
7. Sharing
We share data only with service providers needed to operate SocialFaktory (hosting, payment processing, AI processing, email) and with the social platforms you explicitly connect when you publish. Providers are bound by contracts limiting use to our instructions. Our infrastructure is hosted in the United States; where your data is transferred internationally, we protect it with the safeguards required by applicable law.
8. Retention
We keep your data while your account is active. When you delete content or close your account, we delete or anonymise associated data within a reasonable period, except where law requires retention. Disconnecting a social account revokes its authorisation and erases the stored credentials straight away; the record that ties it to your published posts is removed when you close your account.
9. Your rights
You can access, correct, export, or delete your personal data, and object to or restrict certain processing. Email us and we'll act on the request within the timelines required by applicable law. If you are in the EEA or the UK, you can also lodge a complaint with your local supervisory authority. We do not sell or share your personal data as defined by the California Consumer Privacy Act.
10. Contact
Privacy questions and requests: [email protected]