Sosial · Egate Worldwide

Privacy Policy

Last updated: September 18, 2026

Sosial ("the app") is a personal social media companion developed by Egate Worldwide ("we", "us"). This policy explains what information the app handles and how it is protected. Contact: support@sosial.app.

1. What lives where

Your creative work stays on your device: post designs, captions, scheduled posts and settings are stored locally, and the access tokens for your connected social channels stay in your device's secure storage (Section 2). Separately, if you create a Sosial Cloud account in the app, we store your account and workspace on our servers so your identity, team name and notification preferences survive reinstalls and follow you across devices.

Our servers are provided by Supabase and hosted in Singapore. The only personal data we hold there is what your cloud account needs to work:

Passwords are stored only as irreversible hashes by our authentication provider — never in readable form — and database rules (row-level security) ensure each account can see only its own rows. We hold no post designs, captions, photos or videos on our servers.

Optional cloud publishing: each connected channel has a per-channel Cloud publishing switch (off by default). Turning it on stores an encrypted copy of that channel's access tokens in our token vault (Supabase Vault, Singapore) so our worker can publish for you when the app is closed. The plaintext is never readable by other users or by us through any normal interface; only the publish worker can decrypt it at publish time. Turning the switch off — or disconnecting the channel — deletes the cloud copy and its secrets immediately. Your device always keeps its own copy regardless.

2. Connected social accounts

To publish on your behalf, the app connects to third-party platforms using their official login flows. You connect each account yourself, one at a time, and each connection asks your permission first. Login happens in your browser through an intermediate page on this website (sosial.app/auth.html), which only forwards the login code back to the app — it stores nothing.

Access tokens granted during login are kept in your device's secure storage (iOS Keychain / Android Keystore via the operating system) and are used only to (a) publish posts you explicitly create or schedule, and (b) read statistics for posts and accounts you choose to view. If you enable Cloud publishing for a channel, an encrypted copy is additionally held in our Singapore vault as described in Section 1 — never otherwise. We never access accounts you have not connected, and we never publish anything you did not authorise. Each platform's handling of your data is governed by that platform's own privacy policy.

2.1 Facebook Pages — via the Facebook Graph API

2.2 Instagram — via the Instagram Graph API

2.3 Threads — via the Threads API

2.4 TikTok — via TikTok Login Kit and the Content Posting API

2.5 X (Twitter) — via the X API v2

2.6 Bluesky — via the AT Protocol

2.7 LinkedIn — via the LinkedIn API

2.8 Mastodon — via the Mastodon REST API

2.9 Pinterest — via the Pinterest API (v5)

2.10 YouTube — via the YouTube Data API (v3)

2.11 Photos shared via temporary links

Some channels (Instagram, Threads, TikTok photo posts) can only fetch photos from a public web address. For those, the app uploads your photo to a temporary file host so the platform can pull it for publishing. These links are short-lived, carry no account information, and are never used for anything except delivering your photo to the platform you chose.

3. Sosial Cloud sign-in options

You can create your cloud account with an email address and password, or with Sign in with Google. If you choose Google, Google shows you a consent screen and shares your name, email address and profile picture with us; we store the name and email as your account identity. Authentication itself is handled by Google and Supabase — we never see or store your Google password. You can use email + password without ever touching Google, and vice versa.

4. What we collect

Beyond the cloud-account data in Section 1, we do not collect, transmit or store personal data on our systems. The app contains no third-party analytics or advertising SDKs. This website (sosial.app) is a static site with no tracking, cookies or accounts. All traffic between the app and our servers is encrypted in transit. If you email us for support, we receive only what you choose to include in your message.

5. Sharing

We do not sell, rent or share your information with anyone. Our infrastructure provider (Supabase, hosting in Singapore) processes your cloud-account data solely to operate the service. Content you publish goes directly from your device to the social platforms you selected, under those platforms' own privacy policies.

6. Data deletion

You can delete your data at any time:

Content already published lives on the platforms under their policies — delete it there (or ask us how at support@sosial.app). To request deletion of anything you sent us by email (e.g. a support message), write to support@sosial.app and we will delete it within 30 days.

7. Children

Sosial is not directed at children under 13, and we do not knowingly handle data from children under 13.

8. Changes to this policy

If this policy changes, the updated version will be posted at this address with a revised date before the change takes effect. If we begin storing new categories of data (for example post content for server-side scheduling), this policy will be updated first to describe exactly what is stored and why.

9. Contact

Questions about this policy, or any data-protection request (access, correction, deletion): Egate Worldwide — support@sosial.app.