Privacy Policy
Last updated: October 9, 2026
1Who we are
SocialLoopy is a social media planning, automation, analytics and AI content platform operated by SocialLoopy B.V. in the Netherlands ("SocialLoopy", "we", "us" or "our"). We process personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable privacy laws.
Privacy contact: via our contact form
This policy explains how we collect, use, store, share and delete personal data when you use SocialLoopy, including our social media integrations, Google integrations, YouTube API Services and AI features.
2Personal data we collect
Account and profile data
Name, email address, password hash, profile image, authentication provider identifiers, workspace and team settings.
Connected platform data
Platform account IDs, usernames, page or channel IDs, profile images, OAuth access tokens, refresh tokens, token expiry dates, permissions and scopes.
Content and scheduling data
Posts, captions, hashtags, media files, links, calendar dates, publication status, platform publication IDs and error logs.
Messages and analytics
When enabled, comments, inbox items, public metrics, engagement data, reach, impressions and other analytics made available by connected platforms.
Billing and subscription data
Plan, subscription status, Mollie customer and transaction identifiers, invoices and payment-related metadata. We do not store full card details.
Technical and usage data
IP address, device and browser information, log files, security events, cookies, analytics events and pages visited.
AI feature inputs
Prompts, post drafts, uploaded media, transcripts, brand voice examples and other content you submit to AI tools.
Advertising data (Ads)
Brand and product details from websites you scan, ad texts, images, videos and presenter avatars you create, and, when you connect an ad account: ad account, Page, Instagram and pixel IDs, campaign settings and budgets, review feedback and daily results such as spend, impressions, clicks and conversions.
Support communications
Messages you send us, support requests, bug reports and related account context needed to help you.
3Social media and platform API data
SocialLoopy uses official OAuth and API integrations so you can connect accounts and publish or manage content from one dashboard. We never ask for or store your social media passwords.
Depending on the platform and permissions you grant, we may access account identifiers, profile names, profile images, pages, business accounts, channels, boards, posts, comments, publication status and analytics. We use this data only to provide the connected features you choose to use: account linking, scheduling, publishing, analytics, inbox management, calendar syncing and troubleshooting.
You can disconnect a social account in the SocialLoopy dashboard. You can also revoke access directly from the relevant platform settings, such as Meta/Facebook app settings, Pinterest settings or Google account permissions.
4Google, Google Calendar and YouTube API Services
SocialLoopy uses Google API Services for Google Sign-In, Google Calendar syncing and YouTube account connection features. When you connect YouTube, we use YouTube API Services to identify your YouTube channel and provide YouTube-related scheduling or publishing features that are visible in your SocialLoopy dashboard.
SocialLoopy's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data or YouTube API Data for ads, retargeting, personalized advertising, surveillance, credit decisions, resale or data broker purposes.
We do not download YouTube videos, collect YouTube login credentials, or use undocumented Google or YouTube APIs. Human access to Google or YouTube data is limited to cases where you ask for support, where access is needed for security or legal reasons, or where data is aggregated for internal operations.
By using YouTube-related features, you also agree to the YouTube Terms of Service. You can review Google's privacy practices in the Google Privacy Policy. You can revoke SocialLoopy's access to your Google account at any time from Google security settings.
5How and why we use personal data
| Purpose | Legal basis |
|---|---|
| Create and manage your SocialLoopy account | Contract |
| Connect social media accounts through OAuth | Contract and consent |
| Create, schedule, publish and analyze social posts | Contract |
| Sync scheduled posts with Google Calendar when you choose to connect it | Contract and consent |
| Provide AI-assisted content generation and optimization | Contract and legitimate interests |
| Create, launch, pause and report on ad campaigns in the ad accounts you connect, and give optimization advice | Contract |
| Show public ads of advertisers you choose to follow, from the Meta Ad Library | Contract and legitimate interests |
| Process subscriptions, payments, invoices and tax records | Contract and legal obligation |
| Protect the service, prevent abuse and debug errors | Legitimate interests |
| Send service messages and respond to support requests | Contract and legitimate interests |
| Improve product performance and usability | Legitimate interests |
| Comply with laws, platform policies and regulator requests | Legal obligation |
6AI features
If you use AI features, the text, images, audio, video, URLs, brand voice examples or other inputs you provide may be sent to our AI provider to generate captions, ideas, summaries, translations, transcripts or other requested outputs. We use these inputs only to provide or improve the user-facing AI features in SocialLoopy and to keep the service safe and reliable.
Do not submit content to AI tools unless you have the rights and permissions needed to use that content.
7Advertising (Ads)
With Ads you create ads with AI and, if you choose, run them in your own Meta or TikTok ad account. SocialLoopy never handles your ad spend: the advertising platform bills you directly, and we charge no fee over your budget.
When you connect an ad account, we receive an access token from Meta or TikTok. We store it encrypted (AES-256-GCM) and use it only to do what you ask in SocialLoopy: list your ad accounts, Pages and pixels, create campaigns (always paused first), switch them on or off within the budget limits you set, and fetch their results. We only manage campaigns created in SocialLoopy and do not read or change your other campaigns. Your ad data is never used for our own advertising, never sold and never shared with other customers.
If you follow other advertisers, we fetch their public ads from the Meta Ad Library. That library is public under the EU Digital Services Act; we show these ads with a link to the library and do not copy their texts into your ads.
AI-made images and videos get a machine-readable "made with AI" mark (IPTC metadata) and, by default, a visible label. If you upload a photo of a real person as a presenter, you confirm that you have their consent; we store that confirmation with the photo. Read more on our AI transparency page.
You can disconnect an ad account in the dashboard or remove the app in your Facebook or TikTok settings. When you remove the SocialLoopy Ads app in Facebook, Meta tells us and we delete the connection and its data automatically; you then get a confirmation code with a link to this page.
8Sharing and subprocessors
We do not sell personal data. We share data only when needed to provide SocialLoopy, comply with the law, protect the service, or complete an action you requested.
- Hosting, database and storage providers used to run SocialLoopy
- Mollie for payments and subscription processing
- Email providers for transactional email and support communication
- OpenAI and Anthropic for AI-assisted text and image features when you use those tools
- fal.ai for AI video (talking presenters, lip sync and product videos) when you use those tools
- ElevenLabs for voice-overs and voice cloning when you use those features
- Meta Marketing API and Ad Library, and the TikTok Business API, when you connect an ad account or follow an advertiser
- Google, YouTube and Google Calendar APIs when you connect Google services
- Meta/Facebook/Instagram, TikTok, LinkedIn, Pinterest, X/Twitter, Bluesky and other platforms when you connect or publish to them
- Analytics and security tools used to understand service usage and protect the platform
When data is transferred outside the European Economic Area, we use appropriate safeguards where required, such as contracts, data processing agreements and standard contractual clauses.
9Retention and deletion
| Data type | Retention |
|---|---|
| Account data | Kept while your account is active, then deleted or anonymized after account deletion unless retention is legally required. |
| OAuth tokens | Kept only while the relevant account is connected. Deleted when you disconnect the account or delete your SocialLoopy account. |
| Google/YouTube authorized data | Deleted when no longer needed for the connected feature, after disconnect/revocation, or when tokens can no longer be refreshed, unless retention is legally required. |
| Ad account connections and tokens | Kept while connected. Deleted when you disconnect, delete your SocialLoopy account, or remove the SocialLoopy Ads app in your Facebook settings. |
| Campaign records and ad results | Kept while the ad account is linked, so you can see your history. Deleted when you unlink the ad account or delete your SocialLoopy account. |
| Avatar photos of real people | Kept until you delete the avatar, which also deletes the photo. Stored together with the consent you confirmed. |
| Posts, media and schedules | Kept until you delete them or close your account, subject to backups and legal obligations. |
| Billing and tax records | Kept for the legally required accounting period. |
| Security and server logs | Kept only as long as needed for security, diagnostics and legal compliance. |
| Backups | Removed on a rolling schedule; deleted data may remain briefly in encrypted backups until the backup expires. |
To request deletion, contact us via our contact form from the email address linked to your account. We normally respond within 30 days. Platform connection records and tokens are removed when you disconnect an account or delete your SocialLoopy account.
10Security
We use administrative, technical and organizational measures designed to protect personal data, including HTTPS/TLS in transit, encryption of platform access tokens at rest (AES-256-GCM), access controls, logging, monitoring and restricted team access. No online service can be guaranteed to be perfectly secure, but we work to protect data against unauthorized access, loss, misuse and disclosure.
11Your choices and rights
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your data, subject to legal retention duties.
- Restrict or object to certain processing.
- Receive a portable copy of your data where applicable.
- Withdraw consent for connected platform access at any time.
- Lodge a complaint with your local data protection authority. In the Netherlands, this is the Autoriteit Persoonsgegevens.
You can exercise these rights by reaching out via our contact form. We may need to verify your identity before processing a request.
12Cookies and analytics
We use cookies and similar technologies for login sessions, security, preferences, analytics and product performance. Our cookie details are available in the Cookie Policy. You can control cookies through your browser settings, but disabling essential cookies may prevent the service from working correctly.
13Children
SocialLoopy is not intended for children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided personal data to SocialLoopy, contact us so we can delete it where required.
14Changes to this policy
We may update this policy when our services, integrations, legal obligations or data practices change. If a change materially affects how we use data from Google APIs, YouTube API Services or other connected platforms, we will update this page and, where required, ask users to consent again before using the data in a new way.

