Overview
Africore Lab ("we", "our", "us") operates Gliiz AI (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform. Please read it carefully. By using the Service, you consent to the practices described in this policy.
Information We Collect
Account Information
When you register, we collect your name, email address, password (hashed), and profile data. We also collect billing information (processed securely by Stripe — we never store raw card details).
Platform Credentials & Tokens
When you connect social platforms (Instagram, Facebook, TikTok, LinkedIn, WhatsApp), we store OAuth access tokens on your behalf. These tokens are encrypted at rest and used solely to publish content, read analytics, and manage interactions you authorize. We never use these tokens outside the scope of your explicit actions.
Content & Usage Data
We store content you create (posts, creatives, captions), scheduling data, automation rules, and analytics data fetched from connected platforms. We also collect usage logs (feature interactions, errors) to improve the Service.
Technical Data
IP address, browser type, device identifiers, and cookies are collected automatically for security, fraud prevention, and service performance purposes.
How We Use Your Information
- To provide and operate the Service on your behalf
- To publish, schedule, and manage content on connected social platforms
- To generate AI-powered content, creatives, and automated replies
- To process payments and manage subscriptions
- To send transactional emails (account security, billing receipts, important product updates)
- To detect and prevent fraud, abuse, or unauthorized access
- To comply with legal obligations
- To improve the platform through aggregated, anonymized analytics
Third-Party Platform Integrations
Gliiz AI integrates with Meta (Facebook & Instagram), TikTok, LinkedIn, and WhatsApp Business APIs. When you connect these platforms:
- We request only the permissions strictly necessary for the features you enable
- Access tokens are stored encrypted and scoped to your account only
- We act as a data processor on your behalf — you remain the data controller for your audience data
- Data fetched from these platforms (analytics, DMs, comments) is used exclusively to power your dashboard and automations
- You can disconnect any platform at any time from Settings → Accounts, which immediately revokes our access
- Each platform's own privacy policies govern how they handle the underlying data
Data Sharing & Disclosure
We share your data only in the following circumstances:
- Service Providers: Stripe (payments), Supabase (database & auth), Vercel (hosting), Resend (transactional email), Google Gemini & Groq (AI generation — only the prompts you submit).
- Legal Requirements: If required by law, court order, or to protect the rights, property, or safety of our users or the public.
- Business Transfers: In the event of a merger or acquisition, your data may be transferred with prior notice.
- With Your Consent: Any other sharing requires your explicit, informed consent.
Data Retention
We retain your data for as long as your account is active or as necessary to provide the Service. Upon account deletion:
- Content and account data are deleted within 30 days
- Billing records are retained for 7 years to comply with accounting regulations
- Anonymized aggregated statistics may be retained indefinitely
Security
We implement industry-standard security measures including:
- Encryption in transit (TLS 1.3) and at rest (AES-256) for all sensitive data
- OAuth token encryption with rotating keys
- Role-based access controls and least-privilege principles
- Regular security audits and dependency scanning
- Two-factor authentication available for all accounts
Your Rights
Depending on your location, you may have the following rights under GDPR, CCPA, or applicable laws:
- Right to Access: Request a copy of all personal data we hold about you
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data ('right to be forgotten')
- Right to Portability: Receive your data in a structured, machine-readable format
- Right to Restriction: Limit how we process your data in certain circumstances
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: At any time, without affecting prior processing
Children's Privacy
The Service is not directed to children under 16. We do not knowingly collect personal data from minors. If you believe a minor has provided us with data, contact us immediately and we will delete it.
Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email or a prominent notice in the platform at least 14 days before taking effect. Continued use of the Service after changes constitutes acceptance.
Contact Us
For privacy-related questions, data requests, or to report a concern, contact the Africore Lab privacy team:
- Email: servicescm.pro@gmail.com
- Response time: within 30 days for standard requests, 72 hours for urgent security matters
Questions about your privacy?
Our team is here to help with any data or privacy-related questions.
Contact Privacy Team