Privacy Policy
Last updated: 25 September 2026
Socialiser App Ltd (“Soclo”, “we”, “us”), company number 17243028, is the controller of personal data described in this policy for the Soclo public website, web app, mobile apps, Soclo Pages and related services. This policy explains what we process, why, who receives it and the rights available to you.
1. Information we collect
- Account information: name, email, authentication identifiers, plan, credits, settings and account activity.
- Business and brand information: business name, address or area, industry, description, offers, audience, tone, brand colours, approved assets and other information you choose to add or allow Soclo to scan.
- Content and projects: prompts, posts, captions, images, videos, audio, scripts, edits, schedules, website design and page content.
- Connected-platform information: encrypted access tokens, connected profiles and the content or performance information required for the feature you select.
- Customer interaction information: supported message and conversation previews, leads, enquiries, bookings, reviews and the identifiers needed to follow up.
- Your buyers’ order information: when somebody buys through your Soclo website, the order, the items, the amount and the contact or delivery details they gave. Soclo processes this so it can show it to you in Orders & customers. It is shown only to your own account, is never sold, and is never used to advertise to your buyers.
- Website and domain information: website address, design, publish state, custom-domain registration and DNS information, renewal state and availability.
- Payment and billing information: plan status, credit purchases, merchant-account status and transaction references. Soclo does not store full customer card numbers.
- Advertising measurement information: only if you explicitly enable Measure Meta campaigns, the mobile app can share app interactions such as install or launch and completed registration, plus subscription or purchase outcomes, with Meta. Device or advertising identifiers are available to this measurement only where the platform permits them; on iOS, IDFA collection additionally requires Apple’s App Tracking Transparency permission. Soclo does not put your name, email, authentication token, prompts, brand content or customer content into these Meta event parameters.
- App install measurement: only if you choose Allow measurement in the mobile app, or turn on Settings → Privacy → Measure app installs, the app lets AppsFlyer, our measurement provider, work out which of our adverts led to your install. AppsFlyer then receives your app install and app opens, technical information about your device and connection such as your IP address, the device identifiers your phone allows, and your Soclo account ID (a random code, not your name or email). On iOS, the advertising identifier (IDFA) is used only if you also allow tracking in Apple’s prompt. With the same choice, RevenueCat, which runs our in-app subscriptions, receives your AppsFlyer ID and those device identifiers, and if we switch on purchase measurement it can send your purchase and subscription events, including the amount paid, to AppsFlyer. This is a separate choice from Measure Meta campaigns.
- Technical and safety information: device, app version, approximate region, diagnostics, security events, moderation decisions, reports and records needed to investigate misuse.
2. How we use information
- Provide the features you choose, including content creation, publishing, websites, customer work, analytics, bookings and payments.
- Use your approved business context to make drafts, designs, plans and suggestions more relevant.
- Carry out Autopilot work according to the permissions, instructions and credit limit you set.
- Authenticate users, process purchases, maintain website entitlement, prevent fraud and provide support.
- With your separate opt-in, measure installs and outcomes from advertisements for Soclo, attribute those outcomes and improve Soclo’s advertising campaigns.
- Secure, debug and improve Soclo, enforce the Terms and meet legal and provider obligations.
- Send service notices and, where you agree, product or marketing messages.
3. Legal bases
Depending on the activity, we rely on performance of a contract, legitimate interests in operating and securing the Service, consent, and legal obligations. Meta advertising measurement is off by default and relies on your explicit in-app consent. That choice is bound to the signed-in account and is cleared on sign-out or account switch rather than inherited by another account on the device. You can withdraw that consent at any time in Settings → Privacy → Measure Meta campaigns; withdrawal disables future Meta App Events and advertising-identifier collection from Soclo. Apple’s ATT choice is a separate additional control on iOS. A customer who uses a real person in generated material must have that person’s current permission and confirm it in the dedicated real-person flow. Where applicable law treats the processing as special-category biometric information, we also require an appropriate Article 9 UK GDPR condition and complete any required impact assessment.
App install measurement with AppsFlyer is also off by default and relies on your consent. If you choose Not now, the app remembers that answer for your account on that device and does not ask again; you can still turn it on later in Settings → Privacy → Measure app installs. If you said yes, that permission is cleared when you sign out or switch accounts, so another account on the device never inherits it. You can withdraw at any time in the same place: the app then stops AppsFlyer measurement and removes the AppsFlyer ID and device identifiers it gave RevenueCat. Withdrawing does not delete what AppsFlyer has already received; to ask for that, contact privacy@soclo.app. Apple’s tracking choice is a separate, additional control on iOS.
4. AI features and model providers
Soclo shares data with third-party AI providers only when you choose to use an AI feature, and choosing that feature is your permission for that sharing. When you do, prompts and instructions, selected photos, videos or audio, captions, relevant brand and business context, and customer messages or reviews when AI replies are enabled can be sent to the provider used for that task. If you do not use an AI feature, none of that is sent. Soclo uses providers that can include Anthropic, OpenAI, BytePlus/ByteDance ModelArk, fal.ai (including ElevenLabs audio), AssemblyAI and TypeSafe. The exact provider depends on the feature and availability.
If Soclo’s main planner cannot choose a format or creative guide for an advert you asked for, Soclo can ask TypeSafe, an AI decision service, to make that choice instead. TypeSafe receives the details of that advert request: your brief and any direction you gave, script lines and production notes, the names and descriptions of the people or characters you chose, and the Brand Kit and website details used for it. It returns only the choice; it does not write or make the advert.
Soclo does not use information obtained through connected Google or other platform APIs to train or fine-tune general-purpose AI models. Soclo does not offer voice cloning. Preset text-to-speech does not create or retain a clone of your voice.
5. Facial and likeness information
Soclo keeps real people separate from synthetic actors. A real person can only be added through the dedicated named-permission flow.
- Collection: the real-person route requires the person’s name, an un-ticked permission declaration and source material supplied by the authorised account. Soclo can create additional reference angles to keep that person visually consistent. Provider-authorised asset routes can use an opaque provider identifier rather than image bytes.
- Purpose: only to create the actor-led content the account requests, keep the authorised identity consistent and investigate safety or rights concerns.
- Permission: permission must be specific, current, recordable and withdrawable. The uploader must be able to demonstrate authority; a depicted person can contact Soclo directly even if they are not the customer.
- Storage and disclosure: the permission record is kept in a private database. Source and generated reference images are kept with the customer’s account and are not listed as assets for other customers. The necessary actor material or identifier is sent over encrypted connections to the selected generation provider so it can perform the requested job. Soclo does not sell it.
- Retention: source and generated actor-reference images are kept while that actor remains selected. Removing the actor or withdrawing permission stops reuse, removes the current reference pack and records the withdrawal. Account deletion removes the account’s actor images and permission record. Limited generation, moderation or serious-incident evidence can be retained for the periods described below where needed for safety, legal claims or another legal obligation.
- Rights: access, correction, restriction, objection, withdrawal and erasure requests can be made through the public report route. A depicted person does not need an account.
6. Connected social and Google platforms
When you connect a platform, Soclo stores an encrypted access token and uses the permitted data only for the features you choose. You can disconnect a supported account. The third party also processes information under its own policy.
Meta App Events
The Meta App Events SDK in the mobile app measures advertising for Soclo itself; it is separate from any Facebook or Instagram account you connect for publishing. It is disabled until you turn on Measure Meta campaigns. After opt-in, Meta can receive the event categories and permitted device identifiers described in sections 1–3 for advertising measurement, attribution and campaign optimisation. Automatic SDK events cover consented lifecycle signals such as app launch; Soclo sends completed purchase and subscription outcomes through one durable manual route, while Meta's automatic in-app-purchase logging is disabled to avoid duplicate value. You can withdraw in the Privacy screen at any time.
AppsFlyer app install measurement
AppsFlyer helps us see which of our adverts bring people to Soclo. It measures Soclo’s own advertising only and has nothing to do with the accounts you connect for publishing. It stays switched off until you allow it. If we switch on reporting to advertising networks, AppsFlyer can tell the network that showed you our advert that it led to an install. Purchase and subscription results reach AppsFlyer only from RevenueCat, never from the app itself. You can withdraw in Settings → Privacy → Measure app installs at any time.
YouTube and Google Business Profile
Soclo can use YouTube API Services to upload approved videos to your channel and read the public performance of that content. Google Business Profile access can publish approved posts and read supported performance signals. Use of Google API information follows the Google API Services User Data Policy, including Limited Use. Google API information is not sold, used for advertising or used to train general AI models. You can revoke Google access from Google security settings.
Snapchat
If you connect Snapchat, Soclo can use the permissions you approve to publish or schedule supported Story content, read supported Public Profile and advertising results, and manage advertising you explicitly approve. “Share to Snapchat” sends a local copy of your chosen image or video to Snapchat’s own preview, where you decide whether and where to post it; opening the preview is not an automatic publication.
Snapchat sales measurement is off by default. If you deliberately enable it and confirm that you have a lawful basis, Soclo can send minimised purchase events to Snapchat’s Conversions API to measure advertising. Customer email addresses or phone numbers used for matching are normalised and irreversibly hashed before transmission. Soclo keeps a delivery ledger containing event status and non-identifying operational facts, not the raw email address or phone number. You can disable measurement or disconnect Snapchat at any time.
For other connected networks, access and message availability depend on that network's API and the permission you grant. Permission to publish does not automatically grant Autopilot permission to contact customers.
7. Payments, subscriptions, websites and domains
Apple, Google, Stripe and other selected payment infrastructure can process subscription, credit and merchant-payment information. Soclo receives status, references and information needed to provide support, prevent fraud and show business activity. Full card details are handled by the payment provider.
For a purchased domain, registration information and the data required to manage DNS and renewal are sent to the registrar and infrastructure provider. A custom domain may legally need registrant information. The website editor is available to every customer, and a site becomes public only when you press Publish. Renewal charging is not switched on, so the renewal and suspension lifecycle is not running; the applicable terms will be shown before it starts.
8. Service providers and disclosures
Soclo does not sell personal data. Soclo shares only what a feature needs, and only with service providers — including analytics tools, advertising networks, third-party software development kits, AI model providers and any parent, subsidiary or other related entity with access to user data — whose own published terms and data-processing terms commit them to protect personal data and to use it only to provide their service to Soclo, to a standard comparable to this policy. Providers can include Cloudflare, Supabase, publishing and social-integration infrastructure, Apple, Google, Meta, Stripe, RevenueCat, AppsFlyer, PostHog, Sentry, TypeSafe, Anthropic, OpenAI, BytePlus/ByteDance ModelArk, fal, AssemblyAI and ElevenLabs. They receive only the information needed for their role under contract, for the consented advertising-measurement purpose described above, or their direct relationship with you.
We can also disclose information to comply with law, protect people, investigate misuse, enforce rights, complete a corporate transaction or notify a model/platform provider about an incident, using a pseudonymous user reference where that is sufficient.
9. Retention
Account and business information is generally retained while the account is active. On verified deletion, live account data is deleted or anonymised promptly and encrypted backup copies are purged within 30 days. After that Soclo keeps only an anonymous note that an account was deleted, together with the reason if one was given, and the safety, content-report and likeness records described below and in section 5. Payment receipts are held by Apple, Google or Stripe, not by Soclo.
AppsFlyer keeps measurement data under its own terms and retention settings. The app keeps a note on your device of the accounts that chose Not now, so it does not ask them again; deleting your account or uninstalling the app clears it from the current installation, unless your phone restores the app's data from a backup.
The app keeps a bounded on-device delivery ledger and durably reserves an attempted completed-registration or purchase conversion before handing it to Meta. This gives at-most-one SDK submission attempt across a restart: if the app stops after reservation, a measurement signal can be omitted rather than submitted twice. The ledger contains opaque account or store-transaction identifiers, not event content, and is cleared with the app’s local data on account deletion or uninstall. It is local to that installation and does not survive reinstall or move to another device, unless your phone restores the app's data from a backup. Meta retains App Events under its applicable business tools terms and retention controls. Content-report decisions can be retained for 24 months and serious incident records for six years. The likeness-specific periods are in section 5.
10. International transfers
Some providers process information outside the UK or EEA. Where UK transfer law requires a safeguard, Soclo uses an appropriate transfer mechanism such as the UK International Data Transfer Agreement, the UK Addendum to approved contractual clauses, adequacy regulations or another lawful mechanism. The same safeguards apply when a selected generation provider processes authorised real-person material.
11. Your rights
Depending on the law that applies, you may have rights to access, correct, erase, restrict, object, receive a portable copy and withdraw consent. Contact privacy@soclo.app. You can complain to the UK Information Commissioner’s Office at ico.org.uk or your local authority.
12. Account and data deletion
Delete from Settings → Privacy → Delete my account in the app, or use the web deletion route if you no longer have the app. Deletion removes your content, brand, connected accounts and history from Soclo, and takes any published website down. Soclo keeps only an anonymous note that an account was deleted, plus the reason if you gave one. Payment receipts stay with Apple, Google or Stripe, and a store subscription must be cancelled there separately. A depicted person can use the content report route without deleting or owning the customer account.
13. Security
Soclo uses encrypted transport, encryption at rest where provided by the storage system, separately protected access tokens, access controls and least-privilege practices. No system is perfectly secure. Report a vulnerability through the contact on the Security page.
14. Cookies and website tracking
The public marketing website currently uses no advertising or analytics cookies. Account areas use the essential cookies or secure tokens needed to sign you in and protect the session. See the Cookie notice.
15. Children
Soclo is not directed at children, and we do not knowingly collect personal data from children under 13. If you believe a child under 13 has given us personal data, contact privacy@soclo.app and we will delete it. Anybody under 18 must have a parent or guardian agree to the Terms for them and supervise their use. Content involving children is subject to the strict content-safety and legal rules in the Terms.
16. Contact
Socialiser App Ltd
Company No. 17243028
Privacy and data rights: privacy@soclo.app
General support: hello@soclo.app