Shoutly AI — Data Security & Privacy Policy
Effective date: August 20, 2026
•Last updated: August 20, 2026
Shoutly AI is operated by Qubixel Technologies Private Limited ("Shoutly AI," "we," "us," or "our"), a company incorporated under the Companies Act, 2013, with its registered office at:
371 Royal County Kothnoor, JP Nagar 8th Phase, Gottigere, Bangalore South, Bangalore – 560083, Karnataka, India.This Policy explains what information we collect, how we use it, how we protect it, and the choices you have — including the specific rules that apply when you connect a third-party social media account to our platform.
1. Scope
This Policy applies to:
- The Shoutly AI website (shoutlyai.com) and web application
- Our API and any integrations built on it
- Data obtained through third-party platform APIs when you connect a social media account (Google/YouTube, Meta/Facebook/Instagram/Threads, TikTok, LinkedIn, Pinterest, X, Bluesky, and Google Business Profile) to Shoutly AI
It does not apply to the privacy practices of the third-party platforms themselves (Google, Meta, TikTok, etc.), which are governed by their own privacy policies.
2. Information We Collect
2.1 Information you provide directly
- Account information: name, email address, password (hashed, never stored in plain text), business/organization name, billing address, phone number.
- Business profile information: industry, brand voice preferences, logos, brand assets you upload.
- Content: text prompts, drafts, images, and videos you create, upload, or generate using Shoutly AI, and the captions/hashtags/schedules you configure.
- Payment information: processed by our payment processor; we do not store full card numbers on our own servers.
- Support communications: anything you send us via email, chat, or contact forms.
2.2 Information we collect automatically
- Log data (IP address, browser type, device identifiers, pages visited, timestamps)
- Usage analytics (features used, posts created, error events) for product improvement
- Cookies and similar technologies (see Section 11)
2.3 Information from connected social media accounts
When you connect a third-party social account, we request only the access needed to provide the specific features described in Sections 3 and 5 below — we do not request broader access "for future use." Depending on the platform, this may include:
- Basic profile information (name, username, avatar, profile link)
- The ability to publish, schedule, or draft posts on your behalf
- Read-only access to metrics needed to power your analytics dashboard (impressions, reach, engagement, follower counts, comment counts)
- Media you explicitly choose to upload or generate through Shoutly AI for publishing
We never request access to your private messages, contacts, or any data unrelated to content publishing and performance reporting.
3. How We Use Your Information
We use the information described above to:
- Provide the core service: generate content, schedule posts, and publish to the social accounts you've connected, on your instruction.
- Display connected-account identity (name, avatar) so you can confirm which account is linked before publishing.
- Show analytics and reporting for your own connected accounts inside your Shoutly AI dashboard.
- Operate, maintain, secure, and improve the platform (debugging, fraud prevention, performance monitoring).
- Communicate with you about your account, billing, support requests, and material changes to our service or this Policy.
- Comply with legal obligations.
We do not use data obtained through connected social accounts to serve ads, build advertising profiles, sell to data brokers, determine creditworthiness, or train general-purpose AI models on your connected-platform data without your explicit, separate consent.
4. How We Share Your Information
We do not sell your personal data or the data obtained through connected social platforms. We share data only in the following circumstances:
- Service providers: infrastructure, hosting, and API providers that process data on our behalf under contractual confidentiality and security obligations (for example, our hosting providers and the Outstand unified social API, which we use to route publishing requests to social networks).
- With your direction: when you instruct us to publish content to a connected account.
- Legal requirements: to comply with applicable law, regulation, legal process, or governmental request.
- Business transfers: in connection with a merger, acquisition, or sale of assets, with prior notice to you and continued protection of your data under an equivalent policy.
- Security and abuse prevention: to investigate and prevent fraud, abuse, or security incidents.
We do not permit humans to read your connected-platform content or data except where necessary for security investigation, legal compliance, or with your affirmative, specific consent.
5. Platform-Specific Disclosures
The sections below describe exactly how each connected platform's data is used, in line with each platform's developer policies.
5.1 Google (YouTube Data API, Google Business Profile API)
Scopes requested: youtube.upload, youtube.readonly, business.manage.
youtube.uploadis used solely to publish a scheduled video directly to the YouTube channel you connected, at the time you scheduled it.youtube.readonlyis used solely to (a) display the connected channel's name and thumbnail back to you after authorization, and (b) check the processing/publish status of a video you uploaded so we can show accurate status in your dashboard.business.manageis used solely to publish updates, posts, and respond to information on the Google Business Profile listing(s) you connect, on your instruction.
Google API Services User Data Policy — Limited Use disclosure: Shoutly AI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for serving advertisements, and we do not allow humans to read this data except: (1) with your affirmative consent for specific messages, files, or data; (2) for security purposes such as investigating abuse; (3) to comply with applicable law; or (4) where the data has been aggregated and anonymized for internal operations.
5.2 Meta (Facebook, Instagram, Threads)
Scopes requested: pages_read_user_content, business_management, pages_show_list, pages_manage_posts, pages_read_engagement, pages_manage_engagement, read_insights, plus Instagram- and Threads-equivalent publishing and insight scopes.
These scopes are used exclusively to let you publish and schedule content to Pages, Instagram professional accounts, and Threads profiles you manage, and to display engagement and reach metrics for those same accounts inside your dashboard. We comply with the Meta Platform Terms and Developer Policies.
5.3 TikTok
Scopes requested: user.info.basic, user.info.profile, user.info.stats, video.publish, video.upload, video.list.
Used to authenticate your TikTok account, publish or draft videos you create in Shoutly AI to your connected account, and display your follower/engagement statistics and recently published videos inside your analytics dashboard. We comply with TikTok's Developer Terms of Service and Content Posting API policies.
5.4 LinkedIn
Used to publish content on your behalf to the personal profile or organization Page you connect, and to retrieve basic profile/organization identity to confirm the connection.
5.5 Pinterest
Used to publish pins to boards you select, and to list/create boards on your connected Pinterest account.
5.6 X (Twitter)
Used to publish posts to your connected X account and retrieve basic account identity and engagement metrics.
5.7 Bluesky
Bluesky does not use OAuth. You provide an app-specific password (generated separately in your Bluesky settings, never your main account password) directly into our connection form. It is transmitted once to establish a session and is not stored by Shoutly AI in plain text.
6. Data Security
We take the following technical and organizational measures to protect your information, including data obtained through connected platform APIs:
- Encryption in transit: all data transmitted between your browser, our servers, and connected platform APIs is encrypted using TLS/HTTPS.
- Encryption at rest: stored credentials (OAuth tokens, API keys) and personal data are encrypted at rest.
- Access controls: access to production systems and user data is restricted to authorized personnel on a need-to-know basis, protected by authentication and role-based permissions.
- Credential isolation: connected-platform OAuth tokens are stored server-side only and are never exposed to the browser or to third parties outside the scope of publishing your content.
- Monitoring & logging: we monitor for unauthorized access attempts and unusual account activity.
- Vendor security: infrastructure providers we rely on maintain independent security certifications (e.g., SOC 2, ISO 27001 as applicable to each provider).
- Incident response: in the event of a data breach affecting your personal information, we will notify affected users and relevant authorities in accordance with applicable law, without undue delay.
- Least-privilege scope requests: we request only the narrowest set of platform permissions required for the specific features described above and do not request scopes for hypothetical future functionality.
No method of transmission or storage is 100% secure; we cannot guarantee absolute security, but we continuously work to protect your information using industry-standard practices.
7. Data Retention & Deletion
- We retain account information for as long as your account is active and for a reasonable period afterward to comply with legal, accounting, and dispute-resolution obligations.
- Connected-platform OAuth tokens and cached platform data are retained only for as long as the connection remains active. If you disconnect an account, we delete the associated access tokens and cached profile/metrics data within 30 days, except where retention is required by law.
- Content you generate but never publish is retained in your account until you delete it or close your account.
- You may request deletion of your account and associated data at any time by contacting us (Section 13) or, where available, using in-app account deletion.
- Upon account deletion, we delete or anonymize your personal data within 30 days, except data we are legally required to retain (e.g., billing records for tax purposes).
8. Your Rights & Choices
Depending on your location, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data
- Object to or restrict certain processing
- Data portability
- Withdraw consent for a connected platform at any time by disconnecting it in your dashboard or revoking access directly from the platform's own settings (e.g., Google Account permissions, Facebook Business Integrations)
To exercise these rights, contact us using the details in Section 13. Region-specific rights are detailed further below:
9. Children's Privacy
Our platform workspace does not engage with variables or profiles relating to individuals under the age of 18. Suspect profiles are deleted instantly.
10. International Data Transfers
As an India-incorporated company serving customers globally, your data may be processed in India and in the jurisdictions where our infrastructure and service providers operate. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for cross-border transfers.
11. Cookies & Similar Technologies
We employ simple system storage flags to cache local interface settings and stay signed in across active browser loops. Check our Cookie Policy.
12. Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will notify you via email or an in-product notice before the changes take effect. The "Last updated" date at the top of this page reflects the most recent revision.
13. Contact Us
If you have questions about this Policy or wish to exercise your data rights, contact:
Qubixel Technologies Private Limited
371 Royal County Kothnoor, JP Nagar 8th Phase, Gottigere, Bangalore South, Bangalore – 560083, Karnataka, India
