Skip to content

Privacy policy

Last updated 22 September 2026

Cosmic Social is operated by Cosmic LLC, a limited liability company in Wisconsin, United States. This policy explains what we collect, why, and what you can ask us to do about it.

Who this covers

Two kinds of people use Cosmic Social: the agencies and social media managers who hold an account with us, and the people they invite to approve posts for a client. This policy applies to both.

If you are a customer of one of our agencies and a post about your business was scheduled here, the agency is the one who decided what to publish. We process that content on their instructions.

What we collect

  • Account details. Your email address, and a password if you set one. If you sign in with Google we receive your email address, name and profile picture from Google — not your Google password.
  • Client and brand information. Whatever you enter about the businesses you manage: name, brand voice, facts about the business, content themes, topics to avoid, posting schedule.
  • Social account connections. When you connect a Facebook Page, Instagram account or LinkedIn organisation, we store the access tokens those platforms issue, along with the account identifier and name. Tokens are encrypted before they are written down and are never sent to your browser.
  • Content we generate and publish. Drafts, reviewer notes, your edits, approval decisions, the final text, and the identifier the platform returns for a published post.
  • Performance data. Public metrics for posts we published on your behalf — impressions or reach, engagement, clicks — read back from the platform’s own reporting.
  • Billing details. Handled by Stripe. We keep a customer and subscription identifier and never see your full card number.
  • Operational records. Sign-in times, IP address, browser, and a log of what the posting engine did, for security and for support.

How we use it

  • To generate, review, schedule and publish posts you have asked us to.
  • To show you what was published, what failed, and how it performed.
  • To take payment, and to enforce the limits of your plan.
  • To keep the service working and secure: detecting abuse, diagnosing failures, and telling you when a connected account needs reconnecting.

We do not sell your data. We do not use the content of your posts or your clients’ brand information to train our own models, and the AI providers we use are engaged under terms that do not permit them to train on it either.

Who we share it with

Only the providers we need to run the service, each for a specific job:

  • Supabase — database, authentication and file storage.
  • Vercel — application hosting.
  • Anthropic — generating and reviewing post copy. Your brand information and draft text are sent for this purpose.
  • Resend — sending email, if you have switched email on.
  • Stripe — payments.
  • Meta, LinkedIn and any other platform you connect — receiving the posts you have approved, on your instruction.

We may also disclose information where the law requires it, or to protect our rights, safety or property.

Platform data

Data we receive from Meta and LinkedIn is used only to provide the features you asked for — publishing to your accounts and reporting on those posts. We do not transfer it to a data broker, use it for advertising, or combine it with data from other sources to build profiles of individuals. Our use of information received from Google APIs follows Google’s API Services User Data Policy, including the Limited Use requirements.

How long we keep it

Account and client records are kept while your account is open. Posting history and performance data are kept while your account is open, because they are what the reporting is made of. Access tokens are deleted when you disconnect an account, and are replaced whenever a platform issues a new one.

When you close your account we delete your data within 30 days, except where we must keep records for tax or legal reasons. Backups are overwritten on a rolling basis and are fully cycled within 90 days.

Your choices

  • You can see and edit everything about a client from inside the app.
  • You can disconnect any social account at any time, which deletes its tokens.
  • You can ask for a copy of your data, or for it to be corrected or deleted: how to delete your data.
  • Depending on where you live you may have rights under the GDPR, the UK GDPR or US state privacy laws, including the right to object to processing and to complain to a regulator. We honour these regardless of where you live.

Write to privacy@usecosmicsocial.com and we will respond within 30 days. For deletion, see privacy@usecosmicsocial.com.

Security

Social account tokens are encrypted with AES-256-GCM before storage and are decrypted only on our servers, for the length of a single call to the platform. Every table enforces tenant isolation in the database itself, so one agency cannot read another’s data even if the application has a bug. Access to production systems is limited to people who need it.

No system is perfectly secure. If we discover a breach affecting your data we will tell you and the relevant regulators as the law requires.

Children

Cosmic Social is a business tool and is not directed at anyone under 18. We do not knowingly collect information from children.

International transfers

We operate from the United States, and our providers may process data in the United States and elsewhere. Where personal data is transferred out of the European Economic Area or the United Kingdom, we rely on the European Commission’s standard contractual clauses.

Changes

If we change this policy we will update the date at the top, and for a material change we will tell you in the app before it takes effect.

Contact

Cosmic LLC, Wisconsin, United States. privacy@usecosmicsocial.com