Privacy statement

How we process personal data, the rights you have and how to reach us. Transparent, GDPR-compliant and aligned with the Google API Services User Data Policy.

Version: 5 September 2026

1. About this statement

Social Media Tools ("we", "us", "Senly") provides a SaaS platform that allows marketing professionals — including agencies, social media managers, content creators, in-house marketers and freelancers — to manage their client relationships, content, scheduling, appointments, email communication, marketing and reporting. In this statement we explain which personal data we process, why, for how long, with whom we share it and which rights you have.

We act as a processor within the meaning of the GDPR. The marketing agency that uses the portal is the controller for the personal data of its own end clients. We are happy to conclude a data processing agreement (DPA) with each agency on request.

For data we collect directly from you as an agency (account, payments, support) we act as controller.

2. Which data do we process?

CategoryExamplesPurpose
Account dataName, email address, password hash, role, language, avatarAuthentication, access control, personalisation
Company dataCompany name, logo, colours, domain, contact personWhite-label portal and invoicing
End client dataCompany name, contact person, email, notes, subscription stageCRM functionality within the portal
ContentDesigns (Canva/Metricool), captions, files, posts, calendarsContent and scheduling management
Payment dataStripe customer ID, subscription status, billing address, currency (EUR/USD)Subscription billing via Stripe
OAuth tokensEncrypted access and refresh tokens from Google, Microsoft, LinkedIn, Facebook, etc.Authorised API calls on behalf of the connected user
Email dataConnected Gmail/Outlook/IMAP accounts, emails sent and received within the portal, signaturesEmail functionality in the portal
Calendar dataConnected Google/Outlook calendars, available time slots, bookings via the public booking pageAppointment management and calendars
Insights dataStatistics from Google Analytics, Search Console and Business Profile as connected by the userDashboard widgets and AI summaries
Log dataIP address, timestamp, action, user agentSecurity, debugging and audit log
Session dataJWT token, language cookie (portal_locale)Staying signed in, remembering language preference
Marketing trackingCookieless tracker (anonymised), UTM parameters, signup quiz answersInsight into which campaigns generate leads
Social session cookiesAuth cookies from LinkedIn, Facebook, TikTok, Instagram — only when you explicitly click "Connect" via the Senly ConnectorRunning automation features on behalf of your agency

3. Google API Services and the Google API Services User Data Policy

When you connect your Google account through Senly, the use of your Google data is governed by the Google API Services User Data Policy, including the Limited Use requirements. Below we explain exactly which Google services Senly accesses and what we do — and do not do — with your data.

3.1 Which Google scopes does Senly request?

  • userinfo.email — to display which Google account you are connected with.
  • drive — to fetch and display your client folders (designs, files) within the client profile. Senly only writes when you explicitly perform an upload from the portal.
  • analytics.readonly — read-only access to Google Analytics 4 reports for the property you select, to display them as dashboard widgets.
  • webmasters.readonly — read-only access to Search Console statistics (clicks, impressions, positions, queries) for the site you select.
  • business.manage — reading your own Google Business Profile statistics (search impressions, phone clicks, direction requests). Senly never modifies your Business Profile.
  • gmail.send / gmail.modify (only if you connect Gmail) — to send and read emails from within the portal on behalf of the connected account.
  • calendar (only if you connect Google Calendar) — to display available time slots on your public booking page and add bookings to your calendar.

3.2 What do we do with your Google data?

We use your Google data solely to deliver the Senly functionality you request:

  • Statistics (Analytics, Search Console, Business Profile) are shown as charts and numbers in your dashboard widgets. We do not merge Google data with other users, and we do not combine data across tenants.
  • Drive files are shown in the client profile. We never copy them to our own storage without your explicit instruction.
  • Emails (Gmail) are shown in the portal email feature for the user who connected the account.
  • Calendar data (Google Calendar) is used to read "busy" times and add confirmed bookings to your calendar.

3.3 What do we NOT do with your Google data?

  • We never use Google data for advertising or marketing purposes towards third parties.
  • We never sell or rent Google data to third parties.
  • We do not train AI models on your Google data. AI summaries are generated per request; the data is not used for model training after being sent to the AI provider (see section 5).
  • We do not share Google data with other tenants; multi-tenant isolation guarantees that agency A can never see data from agency B.
  • We do not use Google data for research or profile building beyond the specific feature you consented to.

3.4 Retention of Google data

  • OAuth tokens are stored encrypted until you disconnect via Senly or revoke your consent at myaccount.google.com/permissions.
  • Statistics (GA/GSC/GBP) are cached for at most 10 minutes per time period to save quota. AI summaries are cached for 24 hours.
  • Gmail emails are displayed locally in your portal; we do not store a full copy beyond what is necessary for the feature.
  • Calendar bookings are retained for as long as you use Senly, with an audit log for 12 months.

3.5 How do you disconnect?

You can disconnect in two ways:

  • Inside Senly: go to Integrations → Website & findability (or the relevant integration page) and click "Disconnect". Tokens are removed immediately.
  • At Google: go to myaccount.google.com/permissions and remove access for Senly.

3b. Social media platform integrations (Meta, LinkedIn, X, TikTok, Pinterest, YouTube, Threads, Bluesky, Mastodon)

Within the Senly Content Planner, an agency can connect its end-client's social media accounts to schedule and publish content on their behalf. Each connection uses the official OAuth flow or API of the respective platform, and any use of the obtained data is fully subject to the applicable Platform Developer Agreement (Meta Platform Terms, LinkedIn API Terms of Use, TikTok Developer Terms, X Developer Agreement, Pinterest Developer Guidelines, YouTube API Services Terms, Threads Platform Policy, Bluesky Terms, Mastodon API Terms) as well as the GDPR. Below we explain, per platform, which permissions we request, what we do and do not do with the resulting data, how long we retain it and how you can revoke it.

3b.1 Which platforms, permissions and purpose?

CategoryExamplesPurpose
Meta — Facebook Pagespages_show_list, pages_read_engagement, pages_manage_posts, business_managementOn behalf of the agency's client, show which Pages are managed, publish scheduled posts and display publication status. We do not read DMs, ads data or perform comment moderation.
Meta — Instagram (Business account linked to a Facebook Page)instagram_basic, instagram_content_publishPublish scheduled posts, reels or stories to the client's Instagram Business account and show the account in the connections list. We do not read DMs or the comment inbox.
Meta — Threadsthreads_basic, threads_content_publishPublish scheduled Threads posts on behalf of the connected account and display the profile name. We do not process replies, mentions or trending topics.
LinkedIn — personal profilesopenid, profile, w_member_socialPublish scheduled posts to the personal LinkedIn profile of the user who approved the connection. We do not read connections, inbox or feed.
LinkedIn — Company Pages (Community Management API)w_organization_social, r_organization_social, rw_organization_adminPublish scheduled posts to the client's LinkedIn Company Page (for which the connecting user is admin), display publication status and show aggregate post performance (impressions, clicks, engagement) to the agency as part of client reporting. We do not read personal profiles of followers or connections. Use of this data is subject to the <a href="https://legal.linkedin.com/api-terms-of-use" target="_blank" rel="noopener noreferrer">LinkedIn API Terms of Use</a> and the additional Marketing Developer Platform terms.
X (Twitter)tweet.read, tweet.write, users.read, offline.accessPublish scheduled tweets on behalf of the connected account. We do not read DMs or follower lists.
TikTokuser.info.basic, video.publish, video.uploadUpload and publish scheduled videos to the connected TikTok Business account, and display the account name. We do not read personal feeds or DMs.
Pinterestpins:write, boards:read, user_accounts:readPublish Pins to boards the user selected and display the account name.
YouTubeyoutube.upload, youtube.readonlyUpload scheduled videos to the connected YouTube channel and display the channel name. We do not read comments or viewer statistics beyond what you have published.
BlueskyApp password (created by you in Bluesky settings)Publish scheduled posts to your Bluesky account via the AT Protocol. We store the app password encrypted and use it solely for publication.
MastodonPer-instance access token (via OAuth on your own instance)Publish scheduled toots to your Mastodon account on the instance you specify.

3b.2 What do we do with the platform data?

We use the obtained data solely to deliver the requested planner functionality to the agency that approved the connection:

  • Publishing: the text, images and videos entered by the agency are posted to the connected account at the client-approved time, via the platform's official publishing endpoint.
  • Display: account name, avatar and (for Meta) the list of manageable Pages/IG accounts are shown in the connections list so the agency sees what is connected.
  • Status: per scheduled post we display whether publication succeeded, failed or is still pending — including the platform's error message on failure so the agency can act on it.
  • Reporting (LinkedIn Company Pages only, aggregate metrics only): impressions, clicks and engagement per published post plus follower count of the Company Page are shown to the agency as part of client reporting.
  • Client approval: for each scheduled post the agency can send a review link to the client. The client can approve or reject the post prior to publication; only approved posts are published.

3b.3 What do we NOT do with the platform data?

  • We never use platform data for advertising or to target any audience other than the owner's own audience.
  • We never sell, rent or share platform data with third parties or between tenants. Multi-tenant isolation guarantees that agency A can never see agency B's data, and that page X of client 1 is not visible to client 2 within the same agency.
  • We do not train AI models on platform data. AI caption suggestions are generated per-request based on user-supplied prompt input; the resulting posts and analytics are never sent as training data to an AI provider (see section 5).
  • We do not read personal inbox messages, DMs or private content. The requested scopes are strictly limited to publishing and (for LinkedIn Company Pages) aggregate page analytics.
  • We do not build personal profiles based on follower lists, likes or other behavioural data; we do not request those scopes.
  • We do not use platform data for research or any purpose outside the specific publication and reporting function you consented to.

3b.4 Retention of platform data

  • OAuth tokens (access + refresh): stored encrypted with per-tenant AAD (AES-256-GCM). Retained until you disconnect within Senly, until the platform signals deauthorization via our webhook, or until the token expires and can no longer be refreshed.
  • App passwords / instance tokens (Bluesky, Mastodon): stored encrypted until you disconnect.
  • Publication history (scheduled posts, timestamps, media URLs, publication status, external post id): retained as long as the agency uses Senly, unless the user deletes a post. Deleted posts and events older than 90 days are automatically pruned by our retention cron.
  • LinkedIn Company Page analytics: raw metrics are cached for a maximum of 24 hours; aggregated reporting figures are retained as long as the agency uses Senly.
  • Page and account metadata (name, avatar, page-id/IG-id): retained until disconnect.

3b.5 Deauthorization and data deletion

  • Meta webhook: when you deauthorize Senly from your Facebook settings or submit a data deletion request, our webhook at https://app.senly.io/api/planner/webhooks/meta receives the signal and we remove all associated tokens, page metadata and publication data for the affected account within 30 days. A confirmation code is available on request.
  • LinkedIn: token revocation via linkedin.com/psettings/permitted-services immediately invalidates token access. On the next publication attempt we clean up the expired connection and, on request, delete all associated stored data.
  • Threads / Instagram / X / TikTok / Pinterest / YouTube: similar deauthorization flows are available via each platform's own account settings. Upon a valid deauth signal or explicit deletion request we remove all associated stored data.
  • Individual deletion request: you can always manually request deletion of all platform data for a specific connection by disconnecting inside Senly (Manage connections → × next to the connection) or by contacting us at info@senly.io.

3b.6 How do you disconnect?

3c. YouTube API Services

Senly uses the YouTube API Services for the YouTube integration in the Content Planner. By connecting your YouTube account through Senly, you agree that your use of YouTube data is subject to the YouTube Terms of Service and the Google Privacy Policy. Senly complies with the YouTube API Services Developer Policies, including the Limited Use requirements and the prohibition on unauthorized transfer of YouTube data.

  • Scopes: youtube.upload (used only to upload the videos you schedule) and youtube.readonly (used only to display the channel name, avatar and public channel statistics in your reporting).
  • What we do: upload the videos you schedule to the connected channel and display public channel/video statistics in the agency dashboard.
  • What we do NOT do: we do not fetch viewer data, watch history, comments or personal recommendations; we do not sell, rent or transfer YouTube data to third parties; we do not train AI models on YouTube data; we do not share data between tenants.
  • Retention: encrypted OAuth tokens (AES-256-GCM, per-tenant AAD) and public channel metadata (name, avatar, statistics). Tokens are deleted immediately upon disconnect and publication history within 30 days upon request.
  • Revoking access: you can revoke Senly's access to your YouTube account at any time via the Connections modal in Senly, or directly at myaccount.google.com/permissions. For full deletion of stored YouTube data please contact info@senly.io.
  • Google Privacy Policy: in addition to this statement, the Google Privacy Policy also applies to data processed through the YouTube API.

3d. Other integrations (tasks, design, email, meetings, storage, CRM and invoicing)

In addition to the social media platforms and Google services in sections 3, 3b and 3c, Senly offers optional integrations with a range of external tools. Every integration is created by you explicitly via OAuth or an API key; we store tokens/keys encrypted (AES-256-GCM, per-tenant AAD) and use them only for the requested function. We never sell platform data, do not share it between tenants and do not train AI models on it.

Tasks and project management

Monday.com, ClickUp, Asana, Notion, Linear, Jira (Atlassian), Basecamp, Todoist, Teamwork, Trello, Wrike: connect via OAuth or API token to import your assigned tasks/issues as Senly tasks. We only read what the connecting user is allowed to see; we do not write tasks back unless you explicitly enable that.

Design and content assets

Canva: fetch designs via OAuth to display them in the client profile. Figma, Adobe Express: connect design files. Google Drive, Dropbox, OneDrive, iCloud: optional connection to display client folders; we do not copy files to our own storage unless you explicitly upload.

Email and calendar

Gmail (Google), Outlook (Microsoft Graph), IMAP/SMTP: connect via OAuth or username+password to send and read emails from the portal on behalf of the connected account. Google Calendar, Outlook Calendar: display available times on your public booking page and add bookings to the calendar. IMAP/SMTP passwords are stored encrypted.

Meetings and notifications

Slack, Microsoft Teams, Discord: connect your workspace/server and pick a channel for notifications (e.g. new lead, published post). We only receive a webhook URL or OAuth token and post messages to the channels you choose; we do not read existing conversations.

CRM and leads

HubSpot, Pipedrive, Salesforce, GoHighLevel, Typeform: optionally connect to import contacts and form submissions as leads into Senly. We only read the fields you select at contact/deal level and only write back if you explicitly activate a sync.

Invoicing and payments

Moneybird, Xero, QuickBooks, Mollie: connect your accounting to display invoices and payments in Senly. We read invoice metadata (number, client, amount, status). Stripe: Senly uses Stripe for our own subscriptions and Stripe Connect for affiliate payouts (see section 8).

Email marketing

Mailchimp, Klaviyo: connect your audiences and campaigns so you get an overview in Senly. We only read aggregate figures and list names; we do not send emails through your account unless you activate a specific workflow.

Website analytics

Google Analytics (GA4), Google Search Console, Google Business Profile: see section 3 above for scopes and retention.

Alternative social planners (proxy)

Metricool, Buffer, Hootsuite, Later, Sprout Social: optionally connect when using Senly alongside an existing planner. We only read what is needed to display your connected accounts and publications; we do not post through these tools without an explicit instruction.

How to disconnect any of these integrations

You can disconnect each integration within Senly via Integrations or Manage connections. On disconnect the token/API key and cached metadata are removed immediately; historical sync records (e.g. imported tasks) remain until you delete them yourself. You can also always revoke access at the platform level (e.g. in the connected tool's account settings). For full deletion of stored data for a specific integration, contact info@senly.io.

4. Senly Connector Chrome extension

When you install the optional Senly Connector Chrome extension and manually click "Connect" within a client profile, the extension reads the session cookies of the relevant social media platform (LinkedIn, Facebook, TikTok or Instagram) from your own browser and sends them encrypted to our server.

  • Encryption: AES-256-GCM with a per-tenant scoped key. Cookies from agency A cannot be read by agency B.
  • Purpose: solely to be able to run automation features (growth tools, invite tools) on the server on behalf of your agency, without you having to share passwords.
  • Collection: only after an explicit user action ("Connect" button). Never silently in the background.
  • Retention: until you click "Disconnect" or the cookies are invalidated by the platform itself.
  • No passwords: the extension does not read passwords, only already-active session tokens. Your client passwords never enter our system.

5. AI functionality (Gemini, Groq, Cerebras and others)

Senly offers AI-assisted features such as caption suggestions, brand checks, note suggestions and weekly Insights summaries. We use a tiered AI fallback ladder:

  • Google Gemini (first choice, with data processing terms confirmed by Google — data is not used for model training).
  • If Gemini is down: Groq, Cerebras, Cloudflare Workers AI, GitHub Models, OpenRouter, xAI Grok and OpenAI — depending on which API keys are configured at platform level or per agency.

We send only the minimum data necessary to the AI provider to fulfil the request. AI summaries of your Insights data contain only numbers and top-N lists — no personal data of your end clients.

Agencies can optionally set their own Gemini API key in Integrations → AI; in that case the AI request goes directly via your own account.

6. Marketing and analytics tracking

Senly uses a proprietary cookieless visitor tracker on the marketing website (senly.io). It hashes IP addresses and User-Agent strings into a 24-hour identifier without storing personal data. We do not place third-party tracking cookies (Facebook Pixel, Google Ads, etc.) on the website.

When you sign up for a trial, we optionally ask about your role, challenge and platforms (signup quiz) to personalise your onboarding. These answers are stored in your own account and used to improve Senly's marketing — your personal answers are never shared publicly.

7. Client review portal (public page)

Agencies can submit content to their end clients for approval via a unique review link (senly.io/review/[token]). We do not store personal data of end clients who open this link — only an aggregate of approve/reject actions per token. We do not place tracking cookies on this page.

8. Payments via Stripe

Subscriptions are billed via Stripe. Stripe is an independent controller for your payment data. We only receive a Stripe customer ID, invoice status and the chosen currency (EUR or USD, automatically detected based on your IP address and adjustable until the first payment).

For the affiliate programme Senly uses Stripe Connect to automatically process payouts to partners. Affiliates are paid directly from Stripe.

9. Legal basis for processing

  • Performance of the contract — delivering the SaaS service.
  • Consent — when you connect a Google/Microsoft/social account via OAuth.
  • Legitimate interest — security, fraud prevention, technical stability and product improvement.
  • Legal obligation — tax retention duties and requests from supervisory authorities.

10. Retention periods (summary)

  • Account data: for as long as the subscription is active + up to 30 days afterwards.
  • End client and content data: for as long as the agency does not delete it via the portal.
  • OAuth tokens (Google, Microsoft, social): until disconnection or token revocation at the provider.
  • Insights cache (GA/GSC/GBP/AI): 10 min (data) up to 24 hours (AI summary).
  • Log data (audit, SyncLog): up to 12 months.
  • Stripe link: for as long as the subscription is active; financial records 7 years (tax).
  • After cancellation: full deletion within 30 calendar days of request (unless otherwise required by law).

11. Sub-processors

We share data only with sub-processors that are necessary for the service:

  • Railway / PostgreSQL — hosting and database (United States).
  • Stripe — payments and Connect payouts.
  • Google Cloud (Workspace APIs) — Drive, Analytics, Search Console, Business Profile, Gmail, Calendar.
  • Microsoft (Graph API) — Outlook calendar, Outlook mail.
  • Resend / SMTP — transactional emails (welcome, password reset, notifications).
  • AI providers — Gemini, Groq, Cerebras, Cloudflare, GitHub Models, OpenRouter, xAI, OpenAI (only to answer the concrete request; no training).
  • Metricool — content planning and analytics.
  • Canva — fetching designs.
  • GoHighLevel (optional) — tasks and CRM sync when enabled.

We never sell or rent personal data to third parties.

12. Security

  • Encrypted connections (HTTPS/TLS) for all communication.
  • Passwords stored as bcrypt hash (never readable).
  • OAuth tokens encrypted at rest (AES-256-GCM, per-tenant key derivation).
  • Strict multi-tenant isolation: each agency only sees its own data.
  • Rate limiting on login attempts and API routes to block brute-force attacks.
  • Audit log of critical actions (SyncLog).
  • JWT sessions with a maximum validity of 30 days.
  • Automatic error monitoring with anonymised stack traces.

13. Your rights

As a data subject you have the right under the GDPR to access, rectification, erasure, restriction, portability and objection. Please direct your request in the first instance to the agency you work with. Agencies can handle these requests via the portal or contact us at info@senly.io.

You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

14. Data breaches

In the event of a data breach that poses a risk to data subjects, we will inform the relevant agency without undue delay (within 24 hours of discovery). The agency is responsible for notifying the Data Protection Authority within 72 hours if required.

15. International transfers

Our primary hosting and data storage runs via Railway in the United States. Some sub-processors (Stripe, Google, Microsoft, AI providers) also process data outside the EU. For these transfers outside the EU we rely on the EU Standard Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework. We keep track of which processor processes which data outside the EU and can explain this on request. A current overview of our sub-processors is available at /subverwerkers.

16. Contact

For privacy questions you can reach us via:

Social Media Tools
Nieuwlandsedijk 66, Lage Zwaluwe
info@senly.io

17. Changes

We may amend this statement. For material changes we will inform agencies via the portal or by email. The date at the top indicates when the statement was last updated. We keep earlier versions internally for reference.