BrandMongo Pvt Ltd (“we”, “us”, “our”) operates the Schedule & Share platform. This Privacy Policy explains how we collect, use, store, and protect your personal data.
Last updated 2026-06-18
01Data We Collect
We collect only the data required to run the Service and to publish on your behalf. It falls into four categories.
Account data
Email address, first name, and last name
Password (stored as a bcrypt hash — never plaintext)
Authentication provider (credentials or Google OAuth)
Avatar URL (if provided via Google OAuth)
Social media platform data
Platform user IDs and usernames
OAuth access tokens and refresh tokens (encrypted at rest)
Platform-granted permission scopes
Content data
Post text, hashtags, and media file URLs
Scheduling timestamps and publishing status
Engagement metrics returned by platform APIs
Security & audit data
Audit logs of security-relevant actions
IP addresses and user agent strings (security only)
Rate limiting counters (stored temporarily)
02How We Use Your Data
We process your data for a limited set of purposes, each tied to delivering or protecting the Service.
Service delivery — authenticating you, scheduling and publishing posts to your connected platforms.
Security — protecting your account with MFA, session management, and audit logging.
Analytics — displaying engagement metrics for your published content.
Content moderation — optionally analysing content for policy compliance (opt-in per platform).
Communication — sending transactional emails such as password resets and account notifications.
03AI Features & Model Improvement
Some features use AI to help you create content — for example captions, hooks, hashtags, rewrites, and content scoring. When you use them, the text you submit is sent to our AI providers (Anthropic, OpenAI, or OpenRouter) to generate a response, over encrypted connections.
Paid plans
On paid plans, we may retain the text you submit to these AI features together with the AI-generated output in order to measure quality and to improve and train our own models. This data is stored in a private, access-controlled location and is never made public. We do not sell it, and we do not use it to train third parties’ models.
Free plan
On the free plan we do not retain your AI prompts or outputs for model improvement — they are used only to return your result and are then discarded.
Retention & your choices
Retained for up to 12 months, after which it is automatically deleted.
You can ask us to stop collecting your AI data, or to delete what we hold, at any time — contact us via the Contact page.
Deleting your account also ends this collection.
04Security Measures
We implement robust security measures to protect your data with industry-leading encryption and authentication protocols.
AES-256-GCM encryption at rest
Google Cloud KMS key management
bcrypt password hashing
TLS 1.2+ transport security
TOTP multi-factor authentication
8-hour JWT session security
Audit integrity
All security-relevant actions are logged with SHA-256 hash-chain verification for tamper detection, ensuring a complete and verifiable audit trail.
05Data Retention
We retain each class of data only as long as it is needed to operate the Service or to meet legal obligations. Retention periods are summarised below.
Data categoryRetention period
Account dataAccount lifetime + 30-day grace period
OAuth tokensUntil platform disconnected or account deleted
Post contentUser-controlled; max 2 years after publish
Audit logs1 year
Delivery logs2 years
Session data8 hours (auto-expiry)
Rate limit counters1–24 hours (auto-expiry)
AI inputs & outputs (paid plans)Up to 12 months, then auto-deleted
06Sub-Processors
We use the following trusted third-party services to process your data. Each is bound by contractual data-protection obligations.
Google Cloud PlatformCompute, storage, key managementAsia (Mumbai)
SendGrid (Twilio)Transactional emailUS
Social media platformsContent publishingUS
07Connected Social Accounts
The core of the Service is publishing on your behalf to the social platforms you connect. When you connect a social account, you authorize us — through that platform’s official OAuth flow — to access only the scopes you approve: typically to publish content you create, read engagement metrics for posts you publish, and (where you enable it) manage comments and messages. We never post without your action, and you can disconnect any account at any time from Accounts in ScheduleAndShare and from the platform’s own “apps & connections” settings.
Your use of each platform remains subject to that platform’s own terms and privacy policy. Where a platform imposes additional requirements, we comply with them — for example, our use of YouTube data follows the YouTube API Services Terms and the Google Privacy Policy, and our use of Meta (Facebook, Instagram, Threads) and WhatsApp data follows the Meta Platform Terms.
PlatformData we access (only what you authorize)Privacy policy
FacebookPublish posts; read post engagement/insights; manage commentsMeta
WhatsApp (Business & Channels)Send messages/updates to recipients you authorize; manage conversationsWhatsApp
To remove data tied to a connected account, disconnect it in ScheduleAndShare and revoke our app in the platform’s settings. See our Data Deletion & Disconnection page.
08Third-Party Integrations
ScheduleAndShare (“we”, “us”, “the Service”), operated by BrandMongo Private Limited, lets you connect optional third-party services to import content, automate workflows, and receive notifications. When you connect one of these services, you authorize us — through that service’s official OAuth authorization flow — to access only the specific data and permissions (scopes) you approve.
For every integration below, the following principles apply:
You are in control. We access a connected account only after you explicitly authorize it, and only for the scopes shown on the consent screen.
Least privilege. We request the minimum permissions needed to provide the feature.
Purpose limitation. We use data obtained from a connected service solely to provide the Service to you (e.g., to create, import, schedule, publish, or notify).
No sale of data. We do not sell, rent, or share your connected-service data with third parties for advertising or independent purposes.
Revocable. You can disconnect any integration at any time, from within ScheduleAndShare and from the third-party service’s own “connected apps” settings. See our Data Deletion & Disconnection page.
Retention. We retain data from connected services only as long as needed to deliver the feature you requested, or as required by law, after which it is deleted.
Your use of each third-party service is also governed by that service’s own privacy policy. We encourage you to review them.
Notion
When you connect Notion, we use Notion’s OAuth flow to access the specific pages and databases you select. We read the content of those selected items so you can import it into ScheduleAndShare and turn it into scheduled posts. We do not access your entire Notion workspace, and we do not modify your Notion content unless you explicitly direct us to. Imported content is stored only as needed to create and deliver your scheduled posts. You can revoke access at any time in Notion under Settings → Connections. Notion’s privacy policy.
Google Drive
When you connect Google Drive, we use Google’s OAuth flow with the drive.file scope, which allows us to save and export your posts and media to your Google Drive, and import files you explicitly open with our app from Google Drive. This scope only grants access to files that our app creates or that you choose to open with Schedule & Share — we cannot browse or access any other files in your Drive. Exported content is saved to your chosen folder. Our use of Google user data complies with the Google API Services User Data Policy, including its Limited Use requirements. You can revoke access at any time in your Google Account under Security → Third-party access. Google’s privacy policy.
Dropbox
When you connect Dropbox, we use Dropbox’s OAuth flow to let you select files and folders to import as media (images and videos) for your posts. We request read access only to the files you choose; we do not browse or access files you have not selected. Imported media is stored only as needed to schedule and publish your content. Our use of the Dropbox API complies with the Dropbox API Terms of Service and Developer Policies. You can revoke access at any time in Dropbox under Settings → Connected apps. Dropbox’s privacy policy.
Zapier
When you connect Zapier, you enable automated workflows (“Zaps”) that pass data between ScheduleAndShare and other applications you have connected in your Zapier account. We send and receive only the data fields you configure in your Zaps (for example, post content or scheduling triggers). Data routed through Zapier is also processed under Zapier’s privacy policy and the policies of any other app you connect through it. You can disconnect at any time from your Zapier account or from within ScheduleAndShare. Zapier’s privacy policy.
Canva
When you connect Canva, we use the Canva Connect OAuth flow to let you export or import the specific designs you select, for use as media in your posts. We request access only to the designs you choose to bring into ScheduleAndShare. Imported designs are stored only as needed to schedule and publish your content. You can revoke access at any time in your Canva account settings under connected apps. Canva’s privacy policy.
Slack
When you connect Slack, we use Slack’s OAuth flow to post notifications and/or content to the Slack workspaces and channels you authorize. We request only the scopes needed to deliver notifications or publish to the channels you select. We do not read message history beyond what is necessary for the feature you enable. You can revoke access at any time in Slack under Settings & administration → Manage apps, or by removing the app from your workspace. Slack’s privacy policy.
Data we access, how we use it, and how to remove it
Your data may be transferred to and processed in countries outside the European Economic Area. Where such transfers occur, we rely on Standard Contractual Clauses (SCCs) adopted by the European Commission to ensure an adequate level of protection for your data.
10Your Rights (GDPR)
If you are in the European Economic Area, you have the following rights under the General Data Protection Regulation.
Access
Article 15
Export all your data via Settings → Privacy → Export Data.
Rectification
Article 16
Update your profile via Settings.
Erasure
Article 17
Delete your account via Settings → Privacy → Delete Account.
Restriction
Article 18
Request restriction of processing by contacting us.
Portability
Article 20
Download your data in machine-readable JSON format.
Objection
Article 21
Opt out of analytics tracking via Settings.
To exercise any of these rights, or to learn how deletion works end-to-end, see our data deletion page.
11Cookies
We use essential cookies required for the Service to function, as well as consent-gated analytics cookies.
If you accept our cookie banner, we use Google Analytics (with anonymized IP addresses) to understand how users interact with our platform. Google Analytics cookies are only set after you give explicit consent, and you can withdraw consent at any time by clearing your cookies.
For the full breakdown of categories and durations, read our Cookie Policy.
12Children's Privacy
Our Service is not intended for children under 16. We do not knowingly collect personal data from children under 16. If you believe we have collected data from a child, please contact us immediately so we can remove it.
13Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the “Last updated” date. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
14Contact Us
For any privacy-related questions or to exercise your rights, reach our privacy team directly.