Privacy Policy
What we collect, how we use it, and the rights you have over your data at CircleDiary.
1. Introduction
CircleDiary ("CircleDiary", "we", "our", or "us") provides an AI-powered social media automation platform that helps creators and teams plan, generate, schedule, and analyze content across multiple networks. Your privacy is fundamental to that mission.
This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices and rights you have. It applies to our website, web application, mobile experiences, browser extensions, and APIs (together, the "Service").
2. Information We Collect
Information you provide
- Account data: name, email, password hash, profile picture, time zone, language.
- Billing data: plan, billing address, VAT/tax IDs, and the last four digits of your card. Full payment details are handled by our PCI-compliant processor (Stripe) — we never see or store your card number.
- Connected accounts: OAuth tokens, public profile data, page IDs, and posting permissions for networks you connect (e.g. Instagram, LinkedIn, X, TikTok, YouTube, Facebook, Threads, Pinterest).
- Content: drafts, captions, media assets, prompts, brand guidelines, comments, and AI training inputs you submit.
- Support & communications: messages you send us, survey responses, and feedback.
Information collected automatically
- Device & log data: IP address, browser type, OS, device identifiers, referrer, and crash logs.
- Usage data: pages viewed, features used, posts scheduled, click events, and approximate location derived from IP.
- Cookies & SDKs: see our Cookie Policy for the full list.
Information from third parties
When you authenticate with a social platform or sign in via Google, that provider shares profile fields, account IDs, and the scopes you approved. We may also receive engagement metrics for posts you publish through the Service (impressions, reach, comments, clicks).
3. How We Use Your Information
We process your information to:
- Provide, operate, secure, and improve the Service.
- Authenticate you and protect against fraud, abuse, and unauthorized access.
- Generate AI content, captions, and recommendations based on your prompts and brand inputs.
- Schedule, publish, and report on posts across your connected networks.
- Personalize dashboards, notifications, and product suggestions.
- Process payments, manage subscriptions, prevent chargebacks, and meet tax obligations.
- Send transactional messages, product updates, and — with your consent — marketing.
- Conduct research, troubleshoot issues, and develop new features.
- Comply with legal obligations and enforce our Terms of Service.
Legal bases (EEA / UK users)
We rely on contract performance (delivering the Service), legitimate interests (securing and improving the product), consent (marketing, optional cookies, certain AI features), and legal obligation (tax, accounting, responding to lawful requests).
4. AI Processing & Model Training
CircleDiary uses a combination of in-house and third-party large language and image models (including providers such as OpenAI, Anthropic, and Google) to generate captions, images, and recommendations.
- Prompts and outputs are processed to deliver the AI feature you requested.
- We do not use your prompts, brand assets, or generated content to train foundation models for other customers.
- Sub-processors are contractually prohibited from training on your data.
- You can opt out of optional product-improvement analytics in Settings → Privacy.
- You are responsible for reviewing AI output before publishing — outputs may be inaccurate, biased, or out of date.
6. Data Sharing and Disclosure
We share information only as needed to operate the Service:
- Sub-processors: hosting (AWS, Cloudflare), email (Resend, Postmark), payments (Stripe), analytics (PostHog), error monitoring (Sentry), AI providers, and customer-support tools.
- Connected networks: content you choose to publish is sent to the relevant social platform.
- Workspace members: content, schedules, and analytics are visible to other users in your workspace based on their role.
- Legal & safety: when required by law, subpoena, or to investigate fraud, abuse, or violations of our Terms.
- Business transfers: in the event of a merger, acquisition, or asset sale — you will be notified.
We never sell your personal information and do not share it for cross-context behavioral advertising.
7. Data Security
We protect your data with controls aligned to SOC 2 and ISO 27001 best practices:
- TLS 1.2+ in transit and AES-256 encryption at rest.
- Hardware-backed key management and least-privilege access controls.
- Mandatory MFA for staff, single sign-on, and just-in-time production access.
- Continuous monitoring, vulnerability scanning, and annual third-party penetration tests.
- Documented incident-response plan with breach notification within 72 hours where required by law.
No system is perfectly secure — please use a strong, unique password and enable two-factor authentication on your account.
8. International Data Transfers
CircleDiary is operated from the United States and processes data in the US and EU. When we transfer personal data out of the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses, the UK Addendum, or equivalent safeguards. You can request a copy of the relevant transfer mechanism by contacting us.
9. Your Privacy Rights
Depending on where you live (GDPR, UK GDPR, CCPA/CPRA, LGPD, and similar laws), you may have the right to:
- Access, correct, or delete your personal data.
- Export a portable copy of your content and account data.
- Restrict or object to certain processing, including profiling.
- Withdraw consent for marketing or optional features at any time.
- Lodge a complaint with your local supervisory authority.
- Opt out of "sale" or "sharing" of personal information (California) — we do not sell or share as defined by the CCPA.
Most actions are self-serve in Settings → Privacy. For everything else, email privacy@circlediary.com and we will respond within 30 days.
10. Data Retention
We retain personal data only as long as needed for the purposes it was collected:
- Account data: until you delete your account, then purged within 30 days (90 days for encrypted backups).
- Content & schedules: for the life of your workspace, or until you delete them.
- Billing records: up to 7 years to comply with tax and accounting laws.
- Support tickets: 24 months from the last interaction.
- Security logs: 12 months in hot storage.
11. Children's Privacy
The Service is intended for users aged 16 and older (13+ in the United States with verifiable parental consent where required). We do not knowingly collect personal information from children under those thresholds. If you believe a child has provided us data, contact privacy@circlediary.com and we will delete it.
12. Changes to This Policy
We may update this Privacy Policy to reflect product, legal, or regulatory changes. Material changes will be announced in-app and by email at least 14 days before they take effect. The "Last updated" date at the top always reflects the current version.
13. Contact Us
For privacy questions, data-subject requests, or to reach our Data Protection Officer:
- Email: privacy@circlediary.com
- Mail: CircleDiary, Inc. — Attn: Privacy, 123 AI Street, San Francisco, CA 94105, USA
- EU representative: available on request
Have questions about this policy?
privacy@circlediary.com
5. Social Media Account Access
When you connect a social account, we use OAuth 2.0 — your credentials are never shared with us. We request the narrowest scopes required to publish and read analytics on your behalf.