Privacy Policy
Last updated: 31 August 2026
Repurp AI turns one piece of source content into many content assets. This policy explains what we collect, who we send it to, how long we keep it, and how you get rid of it.
What we collect
Account data. Your name, email address, and password. The password is stored hashed by our authentication provider and we never see it in plain text.
Content you provide. YouTube URLs, uploaded video and audio, pasted transcripts, the transcripts we generate from them, images you upload or generate, and every asset generated from that source.
Brand data. The brand names, audiences, keywords, and tone settings you enter in your Brand Kit, which shape how content is generated.
Connection credentials. For each publishing integration you set up. See the three sections below for exactly what each one stores.
Usage data. Credit balances, project counts, and rate-limit counters.
Product analytics. We record how the product is used so we can see where it fails people: which screens you visit, which actions you take, how long they take, and whether they succeeded. An event records that you generated a blog post, how long the transcript was, and how long it took — never the transcript, never the generated asset, and never a publishing credential. We use PostHog for this.
We do not use advertising trackers, and we do not sell or share this data.
We do not record your screen. Session replay and automatic click capture are both switched off deliberately, in PostHog and in our error reporting. Both work by recording the page, and the page in front of you is your unpublished work.
Facebook and Instagram data
When you connect a Facebook account, we store:
- Your Facebook user ID and name.
- A long-lived access token for your Facebook account.
- The Facebook Pages you granted us access to: their IDs, names, and per-Page access tokens.
- The permissions you granted, so we can tell you when a reconnection is needed.
- For each Page that has one, the linked Instagram Business or Creator account's ID and username.
We use this only to list your Pages so you can choose one, and to publish a post when you press Publish. We do not read your feed, your messages, your followers, or your insights.
Instagram is reached through the Facebook Page it is linked to, using that Page's access token. There is no separate Instagram login and no second token.
Publishing to Instagram requires the images to be publicly reachable, because Instagram fetches them from our storage by URL. Images you attach to an Instagram post are converted to a 1080 by 1080 JPEG at publish time and stored in that converted form.
Disconnecting Facebook in your Brand Kit deletes all of the above, including the Instagram account reference.
LinkedIn data
When you connect LinkedIn, we store an access token, its expiry date, your member URN, and the URNs of any organisations you administer. We use these only to list the profiles or Pages you can post as, and to publish when you press Publish. LinkedIn access tokens cannot be refreshed, so we store the expiry date in order to warn you before it lapses.
WordPress and Mailchimp data
For WordPress we store your site URL, username, and the application password you create. For Mailchimp we store your API key and the ID and name of the audience you select. Both are credentials you generate yourself and can revoke from inside those platforms at any time.
Who we send it to
Running the product means sending parts of your content to other companies. The complete list:
| Service | What it receives | Why |
|---|---|---|
| Anthropic (Claude) | Your transcript and brand kit | Generating and editing content |
| Deepgram | Uploaded audio | Speech-to-text transcription |
| Supadata | YouTube URLs | Fetching captions when direct access is blocked |
| YouTube Data API | Search terms, video IDs | Content Discovery |
| OpenAI | Image prompts | Image generation in the editor |
| Unsplash | Image search terms | Stock photo options |
| Supabase | All account, project, and file data | Database, authentication, file storage |
| Vercel | Requests to the application | Hosting |
| PostHog | Which features you used, and when | Product analytics — never your content |
| Sentry | Error reports | Diagnosing crashes — request bodies are stripped before sending |
| WordPress, Mailchimp, Meta, LinkedIn | Only the specific asset you publish | Publishing, when you ask for it |
Your content is sent to a publishing platform only when you explicitly publish to it.
What we don't do
- We don't sell your data or share it with data brokers.
- We don't use your content to train AI models. Anthropic and OpenAI do not train on API inputs under their standard commercial terms.
- We don't post anything on your behalf that you did not press Publish on.
- We don't read your projects except where you ask us to help with a support issue.
- We don't record your screen or capture what you type. See Product analytics above.
How your data is isolated
Every database query runs as your user through Postgres row-level security, not through application-level filtering. A project belonging to another account is not merely hidden from you. It is unreadable to your session.
Credential storage
Publishing credentials are currently stored as ordinary database columns, protected by the same row-level security as the rest of your data. They are not yet encrypted at rest with a dedicated key management service. We state that plainly rather than implying stronger protection than exists. Disconnect any integration you would rather we did not hold.
Cookies
We use a session cookie to keep you signed in, and a short-lived cookie during a Facebook or LinkedIn connection to protect that flow against cross-site request forgery. Your theme preference is stored in your browser. Our product analytics sets a first-party cookie so that repeat visits from the same browser are recognised as one person rather than several.
We set no advertising cookies, and nothing here is shared with an ad network.
Retention
Your content stays until you delete it. Deleting a project deletes its transcript and generated assets. Disconnecting an integration deletes its stored credentials immediately.
Deleting your data
There are three ways to remove data, depending on how much you want gone.
Remove a single connection. Open Brand Kit and disconnect the integration. Its tokens and credentials are deleted straight away. For Facebook this also removes the linked Instagram account reference.
Remove your Facebook and Instagram data from Facebook's side. In Facebook, go to Settings and privacy, then Settings, then Apps and Websites, and remove Repurp AI. Facebook notifies us automatically, we delete the stored connection and all Page access tokens, and you are shown a confirmation code you can quote to us if you want us to verify it.
Delete your whole account. Go to Settings, then Security, and use Delete my account. You confirm by typing your email address, and the deletion happens immediately: your profile, projects, transcripts, generated assets, uploaded images, brand kits, and every stored connection are removed. There is nothing to wait for and no request to approve. If you can no longer sign in, email talk2thexora@gmail.com from your account's email address instead and we will do it for you.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict how we process it. Email us and we will action it. We will not charge you for it or treat you differently for asking.
International transfers
The services listed above are operated mainly from the United States and the European Union, so your data is processed in those places regardless of where you use Repurp AI from. Where required, transfers rely on the standard contractual clauses those providers publish.
Children
Repurp AI is not intended for anyone under 16, and we do not knowingly collect data from anyone under 16. If you believe a child has given us data, email us and we will delete it.
Security
Access is protected by row-level security in the database, all traffic is served over HTTPS, and third-party credentials are never exposed to the browser. No system is perfectly secure, so if we become aware of a breach affecting your data we will tell you.
Changes to this policy
If we change this policy in a way that materially affects you, we will update the date at the top and notify you in the app before the change takes effect.
Contact
Privacy questions or a deletion request: talk2thexora@gmail.com
