Last updated: April 16, 2025
Privacy Policy
This Privacy Policy explains how Kontuur, operated by About Social Media ("we", "us", "our"), collects, uses, and protects your information when you use our platform at kontuur.io.
1. Information We Collect
We collect the following categories of information:
- Account information: name, email address, and password when you register.
- Agency and client data: client names, brand details, and content briefs you enter into the platform.
- Social media access tokens: OAuth tokens issued by Meta (Facebook / Instagram) when you connect accounts to Kontuur. These are used solely to publish, schedule, and retrieve analytics for content you manage through the platform.
- Generated content: captions, images, and post data created or managed within the platform.
- Usage data: pages visited, features used, browser type, IP address, and timestamps, collected automatically via server logs.
2. Meta and Instagram Data
When you connect an Instagram or Facebook account, Kontuur requests only the permissions required to perform the functions you authorise:
- Reading your Instagram business profile and page information.
- Publishing content (photos, videos, captions) on your behalf.
- Retrieving post-level insights and analytics.
- Scheduling content to be published at a future time.
We do not access private messages, contacts, or any data beyond what is required for the above functions.
Meta-derived data (profile details, media, and analytics) is stored securely in our database to power the dashboard and reports you see. We never sell, share, or use this data for advertising purposes. Access tokens are encrypted at rest and in transit.
You can revoke Kontuur's access to your Meta accounts at any time from your Facebook Settings → Apps and Websites. Revoking access will remove the connection from Kontuur within 24 hours.
To request deletion of all Meta-derived data we hold about you, visit our Data Deletion page.
3. How We Use Your Information
- To provide, maintain, and improve the Kontuur platform.
- To generate AI-powered social media content on your behalf.
- To publish and schedule posts to connected social media accounts.
- To display analytics and performance data in your dashboard.
- To send transactional emails (post approvals, account notifications).
- To respond to support requests and communicate service updates.
- To detect and prevent abuse, fraud, or security incidents.
4. Third-Party Services
Kontuur uses the following sub-processors that may have access to your data as necessary to provide their services:
- Supabase — database and authentication infrastructure. Data is stored in EU data centers.
- Vercel — hosting and edge delivery.
- Anthropic (Claude AI)— AI model used to generate content suggestions. Content prompts are sent to Anthropic's API; Anthropic's privacy policy governs their handling of API data.
- Resend — transactional email delivery.
- Meta Platforms — the Instagram Graph API and Facebook Marketing API used to publish and retrieve data for connected accounts.
5. Data Retention
We retain your account data for as long as your account is active. Generated posts and analytics are retained for the duration of your subscription plus a 30-day grace period after cancellation.
You may request deletion of your account and all associated data at any time by contacting us at the address below. We will process deletion requests within 30 days.
6. Data Security
We implement industry-standard security measures including encrypted storage, HTTPS transport, and access controls. OAuth tokens are stored encrypted and scoped to the minimum permissions required. Despite these measures, no transmission over the internet is 100% secure.
7. Your Rights (GDPR)
If you are located in the European Economic Area, you have the following rights regarding your personal data:
- Access: request a copy of the personal data we hold about you.
- Rectification: request correction of inaccurate data.
- Erasure: request deletion of your data.
- Portability: receive your data in a structured, machine-readable format.
- Restriction / objection: restrict or object to certain processing activities.
To exercise any of these rights, contact us at privacy@kontuur.io.
8. Cookies
Kontuur uses only strictly necessary cookies for session management and authentication. We do not use advertising or tracking cookies. A full cookie policy is available on request.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date above and notify active users by email if the changes are material.
10. Contact
For privacy-related questions or requests, please contact:
About Social Media
Email: privacy@kontuur.io