Privacy Policy
Last updated: June 29, 2026
Monarchly ("Monarchly", "we", "us") operates a social-media management platform at monarchly.net. This policy explains what data we collect, why, how we use it, and the choices you have. We collect the minimum needed to run the service and never sell your personal data.
1. Information we collect
Account data
- Your name, email address, and hashed password (or the identifier from a Google/GitHub single sign-on).
- Workspace and team membership, role, and subscription tier.
Connected social accounts
- When you connect a social account (X/Twitter, Instagram, Facebook, TikTok, YouTube, LinkedIn, Discord) we receive an OAuth access token, refresh token, and your public profile identifiers (handle, display name, account/page ID). Tokens are encrypted at rest with AES-256-GCM.
- Content and metrics you ask us to manage on your behalf: posts, captions, media you upload, schedules, comments/messages you reply to, follower counts, and engagement statistics retrieved from each platform's API.
Usage & technical data
- Log data (IP address, request IDs, timestamps, errors) used for security and debugging.
- AI usage metering (token counts) used to bill AI features accurately.
- Payment records are processed by Stripe; we store only a customer ID and subscription status, never card numbers.
2. How we use your data
- To publish, schedule, and analyze content on the social accounts you connect.
- To provide AI features you invoke (caption/hashtag generation, growth analysis). Your content is sent to our AI providers only when you trigger those features.
- To authenticate you, enforce subscription limits, and protect against abuse.
- To send transactional email (verification, password reset, billing) via Resend.
3. How we share data
We share data only with the service providers needed to run Monarchly, and only as required:
- The social platforms you connect, to publish and retrieve content you request.
- Supabase (database & auth), Stripe (payments), Resend (email), Sentry (error monitoring), Upstash (rate limiting/cache), and our hosting providers.
- AI providers (Anthropic, OpenAI, Perplexity): only the content you submit to an AI feature, only at the moment you use it.
We do not sell personal data. We disclose data to law enforcement only when legally required.
4. Platform-specific data & API compliance
When you connect a third-party platform, we access only the data that platform's API returns for the features you use, and we use it solely to operate those features on your behalf. We do not use platform data to train AI models, and we never sell it.
TikTok
- With your authorization we access, via the TikTok API, your basic profile (open ID, display name, avatar), your videos and their metrics, and the ability to publish content you create in Monarchly. Access tokens are encrypted at rest (AES-256-GCM).
- We use this data only to schedule and publish your posts, show your analytics, and manage engagement at your request. We comply with the TikTok Developer Terms of Service, the TikTok API Services Agreement, and the TikTok Community Guidelines.
- Revoking access: disconnect TikTok inside Monarchly (Accounts → Disconnect), which deletes the stored tokens immediately, and/or revoke Monarchly directly in TikTok at Settings & privacy → Security & permissions → Manage app permissions. You may also request deletion via our data deletion instructions.
Meta (Facebook & Instagram), Google/YouTube, X, LinkedIn, Discord
The same principles apply to every other connected platform: we access only what their API returns for the features you invoke, use it only to provide those features, and honor each platform's developer terms (including the Meta Platform Terms and the Google API Services User Data Policy, including its Limited Use requirements). Disconnecting an account in Monarchly deletes its tokens immediately, and you can also revoke access from that platform's own app-permissions settings.
5. Data retention
We keep your data while your account is active. You can disconnect a social account at any time, which deletes its stored tokens immediately. If you delete your account, we erase your personal data and disconnect all social accounts within 30 days, except where retention is legally required (e.g. billing records).
6. Your rights
- Access / export: download a copy of your data from Settings, or email us.
- Deletion: delete your account from Settings, or follow the data deletion instructions.
- Correction: update your profile in Settings.
- EU/UK and California residents have additional GDPR/CCPA rights, which we honor.
7. Security
Platform credentials are encrypted with AES-256-GCM. Passwords are hashed with bcrypt. Access is scoped per workspace, all API traffic is rate-limited, and critical operations are written to a security audit log. No system is perfectly secure, but we follow current best practices.
8. Children
Monarchly is not directed to anyone under 16, and we do not knowingly collect their data.
9. Changes
We will post any changes here and update the date above. Material changes will be emailed to you.
Questions? Email support@monarchly.net.