Privacy policy
This policy explains what data HyperContent collects, why, how we use it, and the rights you have over it. Written in plain English — if anything is unclear, email us at contact@podiumdigital.rs.
Who we are
HyperContent is operated by PODIUM Digital, Kraljice Katarine 106, Belgrade, Serbia (MB: 68114985, PIB: 115121242). We act as the data controller for personal data processed through the HyperContent product and marketing site.
Data we collect
Account data
When you sign up, we collect your name, email address, and password hash. If you sign in through an OAuth provider, we collect the minimum profile fields that provider exposes (name, email, avatar URL).
Workspace content
We store the templates you design, the posts you compose, uploaded images, connected-account tokens, and feed items scraped from the sources you configure. This is the content of the product — we only use it to provide the service to you.
Usage data
We record basic request logs (timestamps, paths, response codes, approximate IP), rendering/publishing job metadata, and error traces. We do not sell or share this data.
Cookies
Inside the product we use first-party cookies only, strictly for authenticated sessions and for remembering a device you've verified. No advertising cookies, anywhere, ever.
This marketing site uses Google Analytics to measure which pages bring people to sign-up. It is off until you accept — analytics storage is denied by default, no analytics cookie is written and no request is sent to Google unless you choose "Accept" in the cookie notice. You can decline and the site works identically. To change your mind later, clear this site's data in your browser and the notice will ask again.
Legal basis (GDPR)
- Contract: we process your account and workspace data to deliver the product you signed up for.
- Legitimate interest: we process request logs and error traces to keep the service secure and reliable.
- Consent: we process OAuth tokens (e.g. Meta / Instagram) only after you explicitly connect those accounts.
Who we share with
We share data only with infrastructure providers strictly necessary to run the product:
- Railway — application hosting and database infrastructure.
- Cloudflare R2 / S3-compatible storage — uploaded and rendered media assets.
- Meta (Instagram, Facebook Pages, Threads) — when you publish to Instagram, Facebook, or Threads we call Meta's Graph APIs on your behalf, sending the post body, hashtags, and rendered image to Meta's servers. Meta's own privacy policy applies to what Meta does with it.
- X (Twitter v2 API) — when you publish to X we send the tweet text and any attached media to X on your behalf.
- TikTok (Content Posting API) — when you publish to TikTok we send the photo + caption to TikTok on your behalf.
- Google Analytics — marketing site only, and only if you accept analytics cookies. Nothing from inside your workspace is ever sent to it.
We never sell personal data, and we share none of it for advertising.
Connected-account data
When you link an account through Settings → Accounts we store the minimum needed to publish on your behalf and to keep the connection working over time:
- The platform user/page id (e.g. the Facebook Page id, the Instagram Business Account id, the X user id) and the public handle so you can identify which account is connected.
- The OAuth access token (and a refresh token where the platform provides one). Tokens are encrypted at rest with a key only the server holds; they're decrypted in memory at publish time and never logged.
- The set of scopes you granted. We only request scopes required by features you enable:
- Instagram:
instagram_business_basic,instagram_business_content_publish,instagram_business_manage_insights. - Facebook Pages:
pages_show_list,pages_manage_posts,pages_read_engagement,read_insights. - Threads:
threads_basic,threads_content_publish,threads_manage_insights,threads_manage_replies. - X (Twitter):
tweet.read,tweet.write,users.read,offline.access. - TikTok:
user.info.basic,video.publish,video.upload,video.list.
- Instagram:
- The remote post id of every published post (so we can fetch engagement counts after publish) and the post's permalink (so the UI can link back to the live post).
Profile analytics sync
When you click Sync now on the analytics page, HyperContent lists existing posts on your connected Instagram, Facebook Page, and Threads profiles via Meta's Graph API and stores per-post metadata (post id, permalink, caption, timestamp, reach, impressions, reactions) so the dashboard can show posts you published outside HyperContent alongside the ones you published through it. This data lives in your workspace, is wiped when you disconnect the account, and is never used for any purpose other than rendering your own analytics.
You can disconnect any linked account at any time from Settings → Accounts. On disconnect we mark the connection inactive and stop using its token; the token entry is wiped within 30 days. Meta users can also remove the app from Facebook → Settings → Apps and Websites or request deletion via Meta's settings — both fire a callback to us, we verify Meta's signed_request, mark the connection disconnected immediately, and you can verify that processing happened at the confirmation URL we return.
Retention
Account data is kept for the life of your account. If you delete your workspace, all workspace content is removed within 30 days. Request logs and error traces are retained for 30 days. Backups are retained up to 30 days and then rotated.
Your rights
If you're in the EU, you have the right to:
- access the personal data we hold about you
- correct inaccurate data
- request deletion (subject to legal retention obligations)
- receive your data in a portable format
- object to or restrict specific processing
- lodge a complaint with a supervisory authority in your member state
To exercise any of these rights, email contact@podiumdigital.rs — we'll respond within 30 days.
Security
All traffic is HTTPS. Passwords are hashed with scrypt. OAuth tokens and other secrets are encrypted at rest with AES-256-GCM. Access to production systems is role-based and logged, and sign-ins from an unrecognised device require a second factor. See our security overview for more.
Children
HyperContent is not directed at children under 16 and we do not knowingly collect personal data from children.
Changes
We may update this policy when the product changes or the law requires. Material changes will be announced via email to workspace admins at least 14 days before they take effect.
Contact
Email contact@podiumdigital.rs for any privacy question, request, or complaint.