Privacy Policy
Last updated: October 2026
1. Introduction
Fuxux ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our social media scheduling platform at fuxux.com.
For data protection purposes, Fuxux acts as the data controller for account, billing, and product usage data described in this policy.
2. Information We Collect
We collect the following types of information:
- Account information: Name and email address when you register.
- Social account tokens: OAuth access tokens (or, for Bluesky, an app password you generate) for the social platforms you connect. These are encrypted and stored securely. See Section 5 below for exactly what account data we read from each platform.
- Content: Posts, captions, and media files you create and schedule through our platform.
- Usage data: Feature usage, page views, and interaction data to improve our service.
- Payment information: Billing details are processed by Stripe and never stored on our servers.
- Device and cookie data: Technical data such as IP address, browser type, and cookie identifiers for security, analytics, and preferences.
- Browser extension connection: If you use the Fuxux Chrome extension and click "Connect with Fuxux," the extension checks whether you're signed in at fuxux.com in that browser and creates an API key to authenticate the extension on your behalf. Your password is never shared with or accessible to the extension.
- Connected apps and AI assistants: If you connect an app such as Claude or ChatGPT to Fuxux by signing in and choosing "Allow access," that app can read your profile (name, email, plan), the names and status of your connected social accounts, and your posts, and can create, edit, schedule, publish, and delete posts on your behalf. It cannot see your password or change your plan, billing, or connected accounts. Content the app sends is stored as posts in your account. We keep a record of which apps you have connected and when they were last used. We do not receive your conversation with the assistant, only the requests it makes to Fuxux. You can remove an app at any time in Settings under Connected apps.
3. How We Use Your Information
- To provide and operate the Fuxux service.
- To publish content to your connected social accounts on your behalf.
- To generate AI captions using your provided prompts (sent to OpenAI).
- To send transactional emails (account confirmation, password reset).
- To improve the platform and fix bugs.
4. Legal Bases (GDPR)
Where GDPR applies, we process personal data under one or more of these legal bases:
- Contract: to provide the Service you request.
- Legitimate interests: to secure, improve, and maintain our Service.
- Legal obligations: for compliance with tax, accounting, or legal requests.
- Consent: where required (for example, non-essential cookies in certain jurisdictions).
5. Third-Party Processors and Subprocessors
We use service providers (processors/subprocessors) to operate Fuxux, including:
- Supabase — authentication, database, and storage.
- Vercel — application hosting and infrastructure.
- Stripe — subscription billing and payments.
- OpenAI — AI text generation for user-requested features.
- Resend — transactional email delivery.
- Sentry — error monitoring and diagnostics.
We require these providers to process personal data under contractual safeguards and only for permitted purposes.
Connected social platforms. When you connect a social account, we read only the account data needed to show you which account is connected, to publish the content you create or schedule, and — for the Unified Inbox described below — to show you the comments, mentions, and reviews on your own accounts. We never take more than that platform's API requires, and never use it for advertising, profiling, or resale. This is what each platform gives us access to:
- X (Twitter): your handle, profile photo, and public follower/following counts; the ability to read and publish tweets on your behalf.
- LinkedIn: your name and profile photo; the ability to publish posts to your profile on your behalf.
- YouTube (Google): your channel ID, channel name, and channel avatar; the ability to upload videos to that channel. See Section 5A below for Google-specific disclosures.
- Google Business Profile (Google): the business location(s) you choose to connect (name, address) and the ability to publish updates to them. If you use the Unified Inbox, also the customer reviews on those locations (reviewer name, rating, text, and time), stored so you and your workspace team can read them and reply when you choose to; disconnecting the location deletes them. See Section 5A below.
- TikTok: your TikTok display name and avatar; the ability to upload a video as a draft to your inbox, or, once you enable it, to publish a video directly to your profile.
- Meta — Facebook: the name and profile photo of the Page(s) you choose to connect, plus Page post/engagement insights; the ability to publish posts to that Page. If you use the Unified Inbox, also the comments people leave on that Page's posts (commenter name, comment text, and time), stored so you and your workspace team can read them and reply when you choose to; disconnecting the Page deletes them.
- Meta — Instagram: the username and profile photo of the Instagram business account you connect, plus content/insights data for that account; the ability to publish posts. If you use the Unified Inbox, also the comments and @mentions of that account (commenter username, text, and time), stored so you and your workspace team can read them and reply when you choose to; disconnecting the account deletes them.
- Meta — Threads: your Threads username and profile photo, plus insights for posts you publish; the ability to publish posts on your behalf. If you use the Unified Inbox, also the replies to your Threads posts and the posts that @mention your account (author username, text, and time), stored so you and your workspace team can read them and reply when you choose to; disconnecting the account deletes them.
- Pinterest: your username; the boards on your account; the ability to create pins.
- Reddit: your username and avatar; the ability to submit posts to subreddits you choose, using your account.
- Discord: the name and icon of the single channel webhook you create when connecting — Discord's webhook flow does not give us access to your personal Discord profile or any other server data; the ability to post messages to that one channel.
- Bluesky: the handle and app password you provide directly (an AT Protocol app password, not your main account password) — used only to publish posts to your account via the Bluesky/AT Protocol API.
We do not sell, rent, or share the data described above — in raw or in any aggregated or anonymized form — with advertisers, data brokers, or any other third party for their own purposes, and we do not use it to train AI/ML models. You can disconnect any platform at any time from Settings, which revokes our access to it.
5A. Google User Data
Fuxux uses Google APIs for two separate features, and accesses only the Google user data needed to operate the one(s) you actually use:
- YouTube: your channel ID, channel name, and profile picture (to show you which channel is connected), and the ability to upload videos to that channel on your behalf when you publish or schedule a post to YouTube.
- Google Business Profile: the name, address, and other listing details of the business location(s) you choose to connect, and the ability to publish updates/posts to that listing on your behalf. If you use the Unified Inbox, we also read the customer reviews on that listing and, when you click Send, post your reply to a review. Reviews are used only to show them to you and your workspace team.
What we share, and with whom. We do not sell, rent, or share your Google user data — in raw form or in any aggregated or anonymized form — with advertisers, data brokers, or any other third party for their own purposes. The only parties that ever process this data are the infrastructure processors listed in Section 5 above (for example, Supabase to store your encrypted access token, and Vercel to run the server that calls the YouTube API when you publish) — each acting solely to provide the Fuxux service back to you, under the contractual safeguards described in Section 5. We do not use Google user data to serve ads, and we do not use it to develop, improve, or train generalized AI/ML models.
Your Google OAuth access and refresh tokens are encrypted at rest and are used only to call the YouTube Data API and/or the Google Business Profile API on your behalf, depending on which you've connected. You can revoke Fuxux's access at any time from your Google Account permissions page or by disconnecting the account from Fuxux's Settings, either of which immediately stops any further access.
Fuxux's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. International Data Transfers
Because some providers are located outside the European Economic Area, your data may be transferred internationally (including to the United States). Where required, we rely on appropriate safeguards such as Standard Contractual Clauses and equivalent transfer mechanisms.
7. Cookies and Tracking Technologies
We use essential cookies for login, security, and core functionality. We may also use analytics or similar technologies to understand product usage and improve performance.
For users in the EEA/UK, non-essential cookies (such as analytics) are set only after you consent via our first-party cookie banner. You can withdraw or change consent at any time.
Reopen preferences anytime from "Cookie settings" in the site footer or your account menu.
8. Data Retention
We retain your data for as long as your account is active. You may delete your account at any time from the Settings page, which will permanently remove all your data from our systems. We may retain limited records where required by law (for example, tax and accounting obligations) or for legitimate security and fraud-prevention purposes.
9. Security
We use industry-standard security practices including encrypted connections (HTTPS), Row-Level Security on our database, and encrypted storage of OAuth tokens. However, no method of transmission over the internet is 100% secure.
10. Your Rights and Request Process
Depending on your location, you may have rights to access, correct, delete, restrict, port, or object to certain processing of your personal data. You can disconnect social accounts in the app and request account deletion from Settings.
To submit a rights request, email privacy@fuxux.com. We may ask for reasonable identity verification before fulfilling your request, and we generally respond within 30 days where legally required.
11. Children's Privacy
The Service is not intended for children under 13, and we do not knowingly collect personal data from children under 13.
12. US State Privacy Notices
If you are a resident of certain US states (such as California), you may have additional privacy rights. We do not sell personal information as that term is commonly defined in US state privacy laws.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through the app. Continued use of the service after changes constitutes acceptance of the updated policy.
14. Contact
If you have questions about this Privacy Policy, please contact us at privacy@fuxux.com.