Privacy Policy
Last updated 20 September 2026
This policy explains what Publishly collects, why, and how long we keep it. We collect as little as the service needs and we never sell personal data.
What we collect
Account: your name, email address and profile picture from Google sign-in. Workspace: agency and company names, logos, timezones, team members and roles, post drafts, captions, schedules, approvals and internal notes. Connected accounts: the platform, account name, avatar and a provider account ID — never the platform password or access token. Leads: contact details you type or confirm from conversations (name, phone, email, request). Technical: server logs, IP address for rate limiting and security, and anonymous usage counts.
What we deliberately do not store
Media files are uploaded straight to our publishing provider (Zernio) and are not stored on Publishly’s servers. Direct messages and comments are read live from the platforms when you open the inbox and are not stored; we keep only handling metadata (assigned teammate, done/unread, the sender’s public name and picture, and ad attribution when a platform sends it).
How we use it
To run the service you asked for: publishing, scheduling, approvals, client review links, inbox replies and analytics. To send transactional email such as invitations and notifications. To keep the service secure, prevent abuse and bill subscriptions. We do not use your content to train models and we do not show advertising.
Who we share it with
Zernio (publishing, media and inbox access to the platforms you connect), Supabase (database and authentication hosting), Vercel (application hosting), Paddle (payments, as Merchant of Record — Paddle receives your billing details, we do not see your card number), Resend (email delivery), and Google (sign-in). Each processes data only to provide its service. We disclose data when the law requires it.
Client review pages
Public review links show selected posts to the people you share them with. We log when a link is opened (time, IP, browser) and the decisions made, so you can see who approved what.
Retention and deletion
Workspace data is kept while your agency exists. Deleting a company or agency removes its data from our database; published posts remain on the social platforms. Logs and rate-limit records are kept for a short period for security. You can request a copy or deletion of your data at hello@publishly.now.
Cookies
We use only strictly necessary cookies: your sign-in session and small preferences such as the sidebar state. No advertising or cross-site tracking cookies.
International transfers and your rights
Our providers may process data in the EU and the United States under standard contractual safeguards. Depending on where you live you may have rights to access, correct, export or delete your data, or to object to processing; contact us and we will respond within 30 days.
Contact
Publishly · hello@publishly.now. We will post updates to this policy here and note the date at the top.
Questions? Email hello@publishly.now.