Privacy Policy
Unsocial — getunsocial.app · Last updated: 18 July 2026
1. Introduction
Unsocial Pty Ltd ("Unsocial", "we", "us", "our"), a company registered in South Africa, operates the Unsocial social media scheduling platform available at getunsocial.app (the "Service"). This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and the rights you have over it.
This Policy is written to comply with South Africa's Protection of Personal Information Act 4 of 2013 ("POPIA"). If you access the Service from outside South Africa, other privacy laws (such as the EU/UK GDPR) may also apply to you; we've reflected similar principles throughout this Policy regardless of where you're based.
By using the Service, you agree to the collection and use of information as described here. If you don't agree, please don't use the Service.
2. Who We Are
Unsocial Pty Ltd, a private company registered in South Africa. You can reach us, including our Information Officer, at support@getunsocial.app for any privacy-related question or request.
3. Information We Collect
3.1 Information you give us directly
- Account details: your name, email address, and password (unless you sign in with Google or Apple)
- Billing details: name and email used for invoicing — your card details are handled directly by Paystack; we never see or store your full card number
- Content you create: captions, images, video, hashtags, and scheduling information for your posts, reels and stories
- Anything you submit through our help chat or feedback board (provided via Featurebase)
3.2 Information from connected social media accounts
When you connect Facebook, Instagram or Threads — and, as we roll out support, TikTok, YouTube, X/Twitter, Pinterest and LinkedIn — we receive the following via each platform's official API:
- OAuth access and refresh tokens that let us publish posts on your behalf
- Basic profile information (e.g. page/account name, profile picture, account ID)
- Post performance data (likes, comments, shares, reach, impressions) used to generate your analytics and posting-time suggestions
We only request the specific permissions needed to schedule posts and read analytics for the accounts you connect. You can revoke this access at any time from Settings → Connected Accounts within Unsocial, or directly from the relevant platform's own security settings.
3.3 Information collected automatically
- Usage data via PostHog — pages visited, features used, clicks and session activity — to help us understand and improve the product
- Device and browser data (e.g. IP address, browser type, operating system) for security and troubleshooting
- Cookies and similar technologies — see Section 8
3.4 Information from other tools we use
- Featurebase: processes anything you post to our feedback board or share via live chat
- AWS SES / SNS: used to send transactional emails and track delivery, bounce and complaint status, so we stop emailing addresses that reject our messages
4. How We Use Your Information
We use your information to:
- Create and manage your account
- Publish your scheduled posts to the platforms you've connected, at the times you choose
- Generate analytics and suggest better posting times, based on your own historical post performance
- Process subscription payments and manage billing, via Paystack
- Send transactional emails — publish failures, expiring platform tokens, your first successful post, and onboarding nudges if you haven't connected an account or posted yet
- Provide customer support and respond to feedback
- Monitor, secure and improve the Service
- Comply with legal obligations, such as tax and financial record-keeping
We do not sell your personal information, and we never use your post content or connected-account data to train AI models or share it with advertisers.
5. Legal Basis for Processing
Under POPIA, we process your information because it's necessary to perform our contract with you (running the Service, posting, billing); you've given consent (e.g. connecting a social account, opting into marketing emails); we have a legitimate interest in improving and securing the Service; or we're required to by law (e.g. tax records).
6. Notifications & Your Communication Preferences
We send transactional and service emails via AWS SES, including:
- Post publish failure alerts
- Social media token expiry reminders
- First-post success confirmation
- Once-off onboarding nudges
You can turn off non-essential notifications at any time from Settings → Notifications. We use AWS SNS with automatic suppression, so if an email bounces or is marked as spam, we stop emailing that address to protect deliverability for everyone. Some emails — for example critical security or billing notices — may still be sent regardless of your notification preferences, where legally necessary.
7. Who We Share Information With
We only share data with the service providers needed to run Unsocial, each acting as our operator/processor under POPIA:
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Database hosting & user authentication (incl. Google/Apple sign-in) | All account, content and connected-platform data |
| Amazon Web Services (Lambda, SES, SNS) | Running the scheduled publishing job, sending transactional emails, suppressing bounced/complained addresses | Post content, email address, delivery/bounce status |
| Paystack | Payment processing and billing | Billing name/email; Paystack holds your card details, not us |
| PostHog | Product usage analytics to improve the Service | Usage and interaction data |
| Featurebase | Feedback board and live-chat support | Content of your feedback/support messages |
| Facebook, Instagram, Threads (and, as added: TikTok, YouTube, X/Twitter, Pinterest, LinkedIn) | Publishing your posts and retrieving performance analytics via official APIs | Content you schedule, OAuth tokens, post performance data |
We do not sell, rent or trade your personal information to third parties for their own marketing purposes.
8. Cookies & Tracking
We use essential cookies to keep you signed in and to secure your session (via Supabase Auth), and analytics cookies/identifiers via PostHog to understand product usage. You can control non-essential cookies through your browser settings; blocking essential cookies may prevent the Service from working properly.
9. International Data Transfers
Some of our service providers (including AWS, Supabase, PostHog, Paystack, and the social media platforms themselves) may process or store data on servers outside South Africa. Where this happens, we rely on those providers' own safeguards — such as standard contractual clauses or equivalent protections — to keep your data protected to a standard consistent with POPIA.
10. Data Retention & Account Deletion
- While your account is active, we retain your data to provide the Service.
- If you disconnect a social media platform, we immediately stop pulling data from it and delete the stored access tokens for that platform. Historical post data already created through Unsocial may remain part of your account history unless you delete your account entirely.
- If you delete your account, we delete your personal data — profile, content, connected-platform tokens, and analytics tied to you — from our active systems within 30 days, with residual copies purged from backups on our standard backup cycle.
- We retain a minimal, anonymised record of your subscription and payment transactions (amount, date, and payment reference — with no name or contact details attached) for as long as South African tax and financial record-keeping law requires (currently up to five years). This record cannot be used to re-identify or contact you.
11. Your Rights Under POPIA
You have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate or outdated information
- Request deletion of your personal information (see Section 10)
- Object to processing based on our legitimate interest
- Withdraw consent where processing relies on it (e.g. disconnect a social account, unsubscribe from marketing)
- Lodge a complaint with the Information Regulator of South Africa if you believe we've mishandled your information
To exercise any of these rights, email support@getunsocial.app. You can contact the Information Regulator at inforegulator.org.za or complaints.IR@justice.gov.za.
12. Children's Privacy
Unsocial is intended for business and professional use by people 18 years or older. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we'll delete it.
13. Security
We use industry-standard measures — including encryption in transit, access controls, and secure hosting via Supabase and AWS — to protect your information. No system is completely secure, and we can't guarantee absolute security.
14. Changes to This Policy
We may update this Policy as the Service evolves — for example, when we add support for new platforms like TikTok, YouTube, X, Pinterest or LinkedIn. We'll post the updated version here with a new "Last updated" date, and notify you of material changes by email.
15. Contact Us
Unsocial Pty Ltd