Privacy Policy
Last updated: 10 July 2026
MonoChalk ("MonoChalk", "we", "us") operates a unified social media publishing API. This policy explains what personal data we process, why, and the rights you have over it. Questions or requests: [email protected].
1. Data we collect
- Account & identity: your name, email, and password hash when you sign up.
- Connected social accounts: encrypted OAuth or platform session tokens, the platform account id, and the display name for each social account you connect (Facebook, Instagram, Threads, LinkedIn, X, TikTok, YouTube, Pinterest, Bluesky). A Bluesky app password is exchanged during connection and is not stored.
- Content you publish: the text, media, and scheduling metadata you send to our publishing API.
- Operational data: API request logs, webhook delivery logs, and audit logs of account connections and API-key changes.
2. How we use it
- To authenticate you and authorize requests against your workspace.
- To publish, schedule, and manage posts on the social platforms you connect, on your behalf.
- To deliver webhooks, normalize errors, and provide post history and account health.
- To meter usage for billing (e.g. per-platform post counts).
We do not sell your personal data. We do not use the content you publish to train models.
3. How we store and secure it
- OAuth tokens are encrypted at rest using envelope encryption (a per-record data key wrapped by a key-management-service master key).
- API keys are stored only as salted hashes; the raw key is shown once and never stored.
- Webhook payloads are signed (HMAC-SHA256) and all API traffic is served over TLS.
- Access is scoped per workspace; one workspace can never access another's data.
4. Sharing with third parties
We share data only with (a) the social platforms you explicitly connect, in order to publish your content, and (b) infrastructure sub-processors (hosting, object storage, error monitoring) bound by data-processing terms.
5. Retention
We retain your data for as long as your account is active. Temporary media and old job/log records are pruned automatically. When you disconnect a social account or delete your workspace, associated tokens and data are removed (see below).
6. Your rights & data deletion
You may access, correct, export, or delete your data at any time. To request deletion, see our Data Deletion instructions or email [email protected]. For Facebook/Instagram, deauthorizing the MonoChalk app triggers our automated data-deletion callback.
7. Changes
We will update the "last updated" date above when this policy changes materially.