Privacy

Privacy Policy

Last updated: August 2, 2026

Overview

This Privacy Policy explains how GeniPhase collects, uses, stores, and protects information when you use the service.

Information We Collect

We collect account information such as name, email address, authentication details, workspace membership, settings, and preferences.

We collect workspace content such as personas, brand details, prompts, drafts, approvals, schedules, generated posts, replies, uploaded assets, and audit logs.

When you connect a social platform, we may collect platform identifiers, usernames, profile metadata, granted scopes, token metadata, connected account status, posts, comments, replies, and related analytics needed to provide the service.

We may collect technical information such as IP address, device and browser details, log data, request metadata, and security events.

How We Use Information

We use information to operate the platform, authenticate users, manage workspaces, generate and moderate content, connect social accounts, schedule and publish posts, ingest comments, prepare replies, provide analytics, and maintain auditability.

We also use information to secure the service, prevent abuse, troubleshoot issues, improve reliability, and comply with legal or platform requirements.

AI Processing

GeniPhase may send relevant prompts, persona details, content drafts, moderation context, and workflow metadata to configured AI providers in order to generate, classify, moderate, or improve content.

Do not submit sensitive personal information, secrets, or confidential third-party information unless you have authority to process it through the service.

OAuth Tokens and Connected Accounts

OAuth tokens and secrets are used to perform actions you authorize, such as reading account profile data, publishing posts, refreshing access, and validating account status.

Tokens and secrets should be stored using protected or encrypted references. Access is limited to the service components that need them to perform authorized platform actions.

Google User Data

When you choose to connect a YouTube channel, GeniPhase asks you to sign in with Google and grant access through Google's own consent screen. We only receive what you approve there, and only for the channel you pick.

We request access to your YouTube account so that GeniPhase can: read your channel name, handle, thumbnail, and public statistics so the channel can be identified in the app; upload videos you have approved to that channel on your behalf; read and reply to comments on those videos in the persona voice you configured; and read the performance figures for the posts GeniPhase published so they can be reported back to you.

The exact permissions we request are youtube.readonly to read the channel details and figures, youtube.upload to publish approved videos, and youtube.force-ssl to post replies to comments on those videos. We do not request access to your Gmail, Drive, Contacts, Calendar, or any other Google service.

GeniPhase stores the Google account identifier for the connected channel, the channel profile details listed above, the permissions you granted, and an encrypted reference to your access and refresh tokens. Tokens are never stored in readable form and are used only to carry out the actions you authorized.

You can disconnect a YouTube channel at any time from the social accounts area in GeniPhase, which stops all further access. You can also revoke access directly from your Google Account permissions page. When you disconnect, we delete the stored tokens and the channel connection. Audit records of actions already taken are kept for accountability, as described under Retention.

Limited Use of Google User Data

GeniPhase's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

In plain terms: we use Google user data only to provide and improve the features described above, we do not sell it, we do not transfer it to others except as needed to run those features, to comply with the law, or as part of a merger or acquisition with your consent, we do not use it for advertising, and no human reads it except with your explicit permission, for security purposes, to comply with the law, or where the data has been aggregated and made anonymous.

YouTube API Services

GeniPhase uses YouTube API Services to publish to and manage the YouTube channels you connect. By connecting a channel, you are also agreeing to the YouTube Terms of Service.

Information GeniPhase obtains through the YouTube API is stored only for as long as your channel stays connected and is refreshed from YouTube rather than kept indefinitely. Disconnecting the channel in GeniPhase, or revoking access from your Google Account permissions page, removes our stored access and stops any further use.

Other Connected Platforms

GeniPhase connects to Instagram, Threads, X, TikTok, and Telegram on the same basis. For each one we request only the permissions needed to publish the posts you approve, read and reply to comments on them, and report back how they performed.

Each connection can be removed at any time from the social accounts area in GeniPhase, and where the platform offers it, from that platform's own app permissions settings.

Sharing Information

We share information with third-party services only as needed to operate GeniPhase, including hosting providers, databases, infrastructure services, AI providers, email providers, object storage, and connected social platforms.

We may disclose information if required by law, to protect rights and safety, to investigate abuse, or in connection with a business transfer.

Retention

We retain information for as long as needed to provide the service, maintain audit logs, resolve disputes, comply with legal obligations, and support security or operational needs.

Some records, including audit logs and platform action history, may be retained after content or account disconnection where needed for accountability and platform integrity.

Security

GeniPhase uses technical and organizational safeguards intended to protect information against unauthorized access, loss, misuse, or alteration.

No online service can guarantee absolute security. You should keep your credentials secure and promptly report suspected unauthorized access.

Your Choices

You may update account and workspace information in the app where those controls are available. You may disconnect any supported social account, including a connected YouTube channel, from the social accounts area at any time.

You may request access, correction, deletion, or export of personal information where applicable law gives you those rights. Workspace owners can also request deletion of a whole workspace and its content from the account settings area.

International Processing

Information may be processed in countries other than where you live. Where required, appropriate safeguards will be used for cross-border transfers.

Children

GeniPhase is not intended for children under 13, and we do not knowingly collect personal information from children under 13.

Changes to This Policy

This policy may be updated from time to time. The updated version will be posted on this page with a new effective date.

Contact

Privacy questions or requests can be sent to the GeniPhase operator through the contact channel provided with your account or workspace.