Orbelyra

Legal

Privacy Policy

Version 1.0 - Effective [Effective date not configured]

Privacy Policy

Effective Date: [Effective date not configured] Version: 1.0 Company: AJTech LLC Address: [Business address not configured] Privacy Contact: privacy@example.com Support: support@example.com

This Privacy Policy is a production legal draft intended for review by qualified counsel before launch.

1. Introduction

This Privacy Policy explains how AJTech LLC collects, uses, stores, shares, protects, retains, and deletes information when users access the Orbelyra platform, including customer workspaces, media uploads, staff collaboration workflows, social account integrations, publishing features, billing features, email verification, and related services.

2. Scope

This policy applies to the web application, backend API, workflow features, social publishing integrations, account authentication, notifications, support communications, and public legal pages. It does not replace the privacy policies of Meta, Facebook, Instagram, TikTok, Google, YouTube, Stripe, hosting providers, media storage providers, email providers, or other third-party services that users choose to use with the platform.

3. Information We Collect

We collect information that users provide, information generated through use of the Service, information created by workflow participants, information received from connected social platforms with user authorization, and operational information needed to secure and operate the Service.

4. Account and Profile Information

We may collect name, email address, display name, account status, email verification status, password hash, workspace role, platform staff role, invitation status, session status, and account lifecycle records. We do not store plaintext passwords.

5. Business and Workspace Information

We may collect workspace name, business information, workspace settings, timezone, subscription status, entitlements, staff assignments, asset assignments, connected social account status, and workflow configuration. Customer workspace data is tenant-scoped and protected by role authorization and database isolation controls.

6. Uploaded Images, Videos, and Media

Customers retain ownership of uploaded content. Uploaded media may be stored, processed, scanned, previewed, versioned, reviewed, downloaded by authorized assigned workflow participants, scheduled, and published only as instructed through the Service. Media may be stored in cloud media storage or local development storage depending on environment configuration.

7. Media Versions and Approvals

The Service maintains immutable media asset versions, checksums, master storage keys, proxy preview keys, processing status, uploader identity, upload timestamps, approval history, revocation history, change requests, and publishing snapshots. Version history supports workflow integrity, legal review, operational troubleshooting, publishing idempotency, and audit logging.

8. Workflow Comments and Chat

We collect comments, chat messages, change-request instructions, publishing instructions, system messages, timestamps, and participant identifiers. Customer Users may communicate with assigned Editors and Uploaders. Operations Admins may view assigned customer workflow discussions when permitted for operational support. Unassigned staff may not access unrelated customer chats.

9. Publishing Instructions

We may collect captions, titles, descriptions, hashtags, first-comment text, thumbnails, privacy settings, disclosure settings, scheduling times, timezone information, connected account choices, and platform-specific metadata needed to prepare, schedule, or publish approved content.

10. Authentication and Session Information

We process secure session identifiers, CSRF tokens, login events, password reset tokens, email verification tokens, staff invitation tokens, account deletion confirmations, session revocation records, and related security metadata. Raw tokens are stored only in transient delivery channels where necessary; persistent token records use hashes where applicable.

11. Device, Browser, and Log Information

We may collect IP-derived security information where lawful and needed, user-agent summaries, request identifiers, trace identifiers, error codes, service names, timing information, security events, and operational logs. Logs are designed to redact passwords, OAuth tokens, authorization headers, cookies, SMTP credentials, Stripe secrets, KMS plaintext data keys, and signed media URLs.

12. Social Account Data

When a Customer User connects a supported social account, the Service receives only the data authorized by that provider and required for implemented publishing functionality. We do not receive social platform passwords. Connected account data may include safe account identity, account or channel identifiers, granted scopes, connection status, publishing eligibility, post identifiers, upload identifiers, publishing status, and provider error metadata.

13. Meta, Facebook, and Instagram Data

Depending on the configured Meta architecture and granted permissions, the Service may access Facebook Page identity, Page metadata needed to locate a linked Instagram professional account, Instagram professional account identity, username or display metadata, media container identifiers, post identifiers, publishing status, and publishing eligibility information. The Service uses this data to show the connected account, verify publishing capability, publish approved content, reconcile results, and troubleshoot failures.

14. TikTok Data

Depending on granted scopes and account eligibility, the Service may access TikTok creator identity, nickname or avatar where returned, creator posting capabilities, available privacy options, maximum video duration, required interaction or disclosure settings, publish identifiers, log identifiers, and publication status. The Service uses this data to display the target account, enforce current privacy choices, apply unaudited SELF_ONLY restrictions where required, publish approved content, and reconcile posting status.

15. Google and YouTube Data

When YouTube functionality is authorized, the Service may access authorized Google account identity, YouTube channel identity, upload authorization, resumable upload metadata, video identifiers, selected visibility, upload status, and publication status. The application uses YouTube API Services. Users connecting YouTube functionality are also subject to the YouTube Terms of Service and the Google Privacy Policy.

16. OAuth Access and Refresh Tokens

OAuth access and refresh tokens are stored encrypted and are used only to perform authorized integration actions, such as refreshing access, validating account status, uploading approved media, publishing approved content, or polling publishing results. OAuth tokens are not shown in the user interface, are not exposed to workspace staff, and must not be logged. When a social account is disconnected, usable local OAuth credentials are revoked where supported or invalidated and deleted according to the disconnect workflow.

17. Payment and Subscription Information

When billing is enabled, payment and subscription processing may be handled by Stripe or another payment processor. We may store customer identifiers, subscription identifiers, plan status, billing period dates, entitlement status, invoice status, payment issue state, and webhook processing records. Payment processors handle payment card or payment instrument data under their own terms and privacy policies.

18. Email and Notification Information

We may use email addresses and notification preferences to send verification messages, password reset links, staff invitations, workflow notifications, publishing status alerts, subscription notices, and security messages. Transactional email is sent from backend services, not frontend code.

19. How Information Is Used

We use information to provide and secure accounts, create workspaces, process media, support editing and review workflows, enforce role permissions, generate proxy previews, maintain immutable version history, record approvals, support chat, connect social accounts, publish approved content, reconcile publishing results, manage subscriptions, send transactional emails, audit important actions, detect abuse, troubleshoot failures, and comply with legal or platform obligations.

20. How Information Is Shared

We do not sell customer personal information or uploaded media. Information may be shared with authorized users within the relevant workspace, assigned Operations Admins, assigned Editors, assigned Uploaders, Platform Super Admins for audited platform administration, service providers, social platforms selected by the Customer, payment processors, legal authorities when required, or parties involved in a business transfer subject to appropriate safeguards.

21. Service Providers

We use service providers to host the application, operate databases and queues, store media, manage encryption keys, deliver transactional email, process payments, monitor errors and system health, maintain backups, and provide infrastructure support. Service providers may process information only as needed to provide their services to us.

22. Cloud Storage

Uploaded media, proxy previews, thumbnails, derivatives, metadata, and processing outputs may be stored with configured cloud media storage providers. Master media URLs are protected through tenant authorization and signed access workflows. The Service should not expose unrestricted permanent master-file URLs.

23. Email Provider

Transactional email may be sent through a configured provider such as Resend SMTP or through the console provider in local development and tests. Email messages may include verification links, reset links, invitation links, and workflow notices. They must not include passwords, password hashes, OAuth tokens, KMS secrets, SMTP credentials, or database credentials.

24. Payment Processor

Stripe or another payment processor may receive billing contact information, customer references, subscription details, tax information, and payment metadata necessary to process subscriptions, renewals, invoices, failures, cancellations, refunds, and customer portal access. We do not store full payment card numbers in the application database.

25. Social-Platform Providers

When a user publishes or connects an account, information needed for that action may be sent to Meta, Facebook, Instagram, TikTok, Google, YouTube, or another supported provider. This may include approved media, captions, titles, descriptions, hashtags, thumbnails, privacy settings, disclosure settings, publishing schedule information, and provider-specific metadata selected by the user.

26. Security

The Service uses technical and organizational safeguards designed to protect data, including secure authentication, session controls, CSRF protection, tenant-scoped database access, PostgreSQL Row-Level Security, role authorization, platform staff assignments, structured logging with redaction, audit logs, immutable media versions, token encryption, backup and restore procedures, and operational monitoring.

27. Credential Encryption

Sensitive OAuth credentials are encrypted at rest using the configured credential vault architecture. Production deployments should use a cloud key-management system or equivalent KMS-backed envelope encryption. Plaintext OAuth tokens should exist only briefly in backend process memory when needed for authorized provider calls.

28. Data Retention

We retain information for as long as needed to provide the Service, maintain security, comply with law, satisfy billing and tax obligations, preserve audit logs, troubleshoot publishing history, enforce agreements, and honor platform policy requirements. Retention periods may differ for account data, media files, proxy previews, audit logs, billing records, OAuth credentials, publication history, backups, and security logs.

29. Account Deletion

Users may request account deletion through authenticated settings where available or by contacting privacy support. Account deletion may disable login, revoke sessions, remove or anonymize eligible profile data, invalidate social credentials, cancel eligible future jobs, and delete eligible content according to contractual and legal requirements. See the Data Deletion Policy for more detail.

30. Social-Account Disconnect and Revocation

Users may disconnect connected social accounts from the Connections page where available or revoke authorization directly with the provider. Disconnect attempts provider revocation where supported, invalidates local encrypted credentials, marks the account disconnected, prevents future publishing with that connection, and preserves safe historical publication and audit records where required.

31. User Rights

Depending on location and applicable law, users may have rights to access, correct, delete, export, restrict, object to, or withdraw consent for certain personal information. Requests may require identity and authority verification. We will not delete data solely because an unauthenticated person enters an email address.

32. Cookies

The Service uses necessary cookies and browser storage for authentication, CSRF protection, session continuity, local demo sessions, selected workspace state, and application preferences where implemented. See the Cookie Policy for details.

33. International Transfers

Information may be processed in countries other than the user's country, including where our hosting, storage, email, payment, monitoring, or social platform providers operate. Where required, transfers should be protected by appropriate contractual or legal safeguards.

34. Children

The Service is intended for business users and is not directed to children. Users must be legally able to enter into the applicable agreement and authorized to act for their business or assigned platform role.

35. Changes to This Privacy Policy

We may update this Privacy Policy as the Service changes. If a material update expands data use, changes legal rights, or is otherwise legally significant, we may provide notice and require acceptance before newly covered uses occur.

36. Contact Information

Privacy requests: privacy@example.com

Support requests: support@example.com

Legal entity: AJTech LLC

Business address: [Business address not configured]