NewOne place, every account.See how
Legal

Privacy Policy

What we collect, why, how we keep it safe, and what you can ask us to do with it. Written to be readable — not to hide anything.

Last updated September 4, 2026

Draft notice. This policy is written to be honest and accurate to how we actually run the service today. It has not been reviewed by a lawyer. If you need a legally-vetted version before signing a contract, contact us and we'll expedite that.

TL;DR

  • You give us an email and a password. We hash the password with bcrypt and never see it in the clear.
  • You connect social accounts. We store the OAuth tokens encrypted with AES-256-GCM and only use them to publish and read metrics for your posts.
  • We host everything on our own infrastructure in the United States. No third-party analytics track you across the web from our site.
  • We don't sell your data, ever. We don't use your posts to train AI models.
  • You can export or delete your data any time. Deletion is honoured within 30 days.

Who we are

ManageSM is operated by the ManageSM team based in Canada. When this policy says “we”, “us”, or “ManageSM” it means the operator of the service at www.managesm.com. For any privacy-related questions, contact us at hello@managesm.com.

What we collect

Information you give us

  • Account details. Your first name, last name, email address, and a password (stored as a bcrypt hash, never in the clear).
  • Workspace and brand details. Names, descriptions, brand voice notes, and any other setup information you enter.
  • Content you create. Posts you draft, images and videos you upload, approval comments, saved replies, and everything else you type into the app.
  • Payment information (once billing launches). Handled by Stripe — we never see your card number. We keep your Stripe customer ID and the last four digits of your card for support.

Information from social networks you connect

  • OAuth tokens for each connected account. Encrypted at rest with AES-256-GCM. Only used to (a) publish posts you scheduled, (b) read engagement numbers on posts you published through us.
  • Account handle, display name, and avatar so we can show you which account is which.
  • Metrics on posts you published through us — likes, replies, impressions, clicks. We do not pull your full account history, DMs, or contacts.

Information we collect automatically

  • Server logs. IP address, browser user-agent, and the URL of every request, kept for 30 days to help us debug problems and detect abuse.
  • Activity records. Timestamps of the things you do in the app — logins, posts published, approvals granted, settings changed — so you and your team have a full history.

Why we collect it

  • To run the service you asked us to run. Publishing your posts, showing you your data.
  • To keep the service secure. Detecting suspicious logins, preventing abuse.
  • To give you support. When you email us we need to know who you are.
  • To improve the service. Understanding which features people use and which are broken.
  • To meet legal obligations. Tax records, responding to legal orders.

We do not use your data to train AI models, sell it to anyone, or share it with advertisers.

If you're in the European Economic Area or the UK, we process your personal data under the following legal bases:

  • Contract. To provide the service you signed up for.
  • Legitimate interests. Security, fraud prevention, product improvement — balanced against your rights.
  • Legal obligation. Tax records, court orders.
  • Consent. Only where required (e.g., marketing emails to non-customers). Withdrawable at any time.

Who we share it with

We share your data only with the following third parties (called subprocessors), and only for the purposes listed:

SubprocessorWhat they doWhere
Contabo GmbHHosting our server infrastructureUSA
Anthropic PBCAI drafting (Claude) — only the text of your post drafts is sent, when you use AI featuresUSA
SocialAPI.aiOAuth broker and unified API for Facebook, Instagram, Threads, TikTok, YouTube, Google Business Profile, LinkedIn, and Bluesky. Holds your network access tokens (encrypted) on our behalf and relays your posts and inbound comments/DMs.USA
The social networks you connectPublishing posts and reading metrics on your behalfPer each network
Stripe (once billing launches)Payment processingUSA

We may also share data if legally required (court order, subpoena) or to protect our rights and safety. We'll always try to notify you first unless legally prevented from doing so.

How long we keep it

  • Account data: as long as your account is active.
  • Deleted accounts: purged within 30 days of your deletion request, except where we're legally required to keep records (e.g., tax invoices — 7 years).
  • Server logs: 30 days.
  • Backups: nightly backups retained for 30 days.
  • Activity records: life of the workspace, so you always have the full audit trail.

Your rights

You can, at any time:

  • Access the data we hold about you — request a copy.
  • Correct anything wrong — most of it you can edit yourself in Settings.
  • Delete your account and all associated data.
  • Export your data in a portable format (CSV or JSON).
  • Restrict or object to processing.
  • Withdraw consent where consent was the basis.
  • Complain to a supervisory authority (e.g., ICO in the UK, CNIL in France, OPC in Canada).

To exercise any of these, email us at hello@managesm.com. We respond within 30 days, typically within 3 business days.

Security

What we have in place today:

  • TLS 1.2+ for every connection to the service (Let's Encrypt certificates, auto-renewed).
  • OAuth tokens and other secrets encrypted at rest with AES-256-GCM.
  • Passwords hashed with bcrypt (cost factor 10).
  • Role-based access control per workspace.
  • Nightly database backups with 30-day retention.
  • Full activity history so you can trace who did what.
  • Session cookies with the HttpOnly, Secure, and SameSite=Lax flags.

No system is 100% secure. If you notice something we should know about, please email hello@managesm.com with “Security” in the subject.

Cookies

We use one strictly-necessary cookie — the session cookie that keeps you logged in (authjs.session-token). It's HttpOnly, Secure, and SameSite=Lax. We don't set marketing or advertising cookies, and we don't use third-party trackers.

If we add product analytics in the future (Plausible or similar), it will be cookie-less and privacy-friendly. We'll update this policy before turning anything on.

International transfers

Our infrastructure is in the United States. If you access ManageSM from outside the US, your data will be transferred to and processed in the US. For EEA and UK users, we rely on the Standard Contractual Clauses adopted by the European Commission as the transfer mechanism.

Children

ManageSM is a business tool. It's not designed for or directed at children. You must be at least 16 years old to use it (18 in some jurisdictions). If you believe a child has provided us data, contact us and we'll delete it.

Changes to this policy

We'll update this policy if we change how we handle data. Material changes will be announced in-app and by email to your account address at least 30 days before they take effect. The date at the top of the page shows the last revision.

Contact

For any privacy question, request, or complaint: hello@managesm.com. We'll get back to you within 3 business days.

See also our Terms of Service and Data Processing Agreement.