Privacy Policy
Last updated: 2 August 2026
Who We Are
Solofy (“we”, “us”, “our”) is a social media content tool for solopreneurs.
Contact: solofy.support@gmail.com
What We Collect
Account information
- Your email address, and your name if you sign in with Google
- If you sign up with a password, it is stored only as a salted hash by our authentication provider (Supabase). We never see or store the password itself
- If you sign in with Google, we do not receive or store your Google password
Connected platform credentials
- When you connect your X (Twitter) account, we store your OAuth access tokens
- These are encrypted at rest using industry-standard encryption (Fernet/AES-128)
- We never store your X password
Content you create
- Posts, threads, drafts, and templates you create within Solofy
- Images you upload to attach to posts
- Personas and categories you configure
Usage data
- Basic analytics about your posting activity (streak, post counts)
- Optional anonymous page-view analytics, only after consent: route, referrer domain, coarse device, browser, and operating system
- We do not use advertising, cross-site tracking, Google Analytics, or Meta Pixel
- The browser storage described in our Cookie Policy is used only for sign-in, requested interface preferences, and functional caching
How We Use Your Data
- To provide the Solofy service: generating, scheduling, and publishing your content
- To authenticate you and keep your account secure
- To show you your own analytics and posting history
- We do not sell your data to anyone
- We do not use your content to train AI models
- We do not share your data with third parties except as described below
Third Parties We Use
| Service | Purpose | Privacy policy |
|---|---|---|
| Supabase | Database and authentication | supabase.com/privacy |
| OpenAI | AI content generation | openai.com/privacy |
| X (Twitter) | Publishing your posts | twitter.com/privacy |
| Railway | Hosting | railway.app/legal/privacy |
OpenAI: Your post content and persona prompts are sent to OpenAI’s API to generate content. OpenAI’s API data usage policy applies. As of our last update, OpenAI does not use API data to train models by default.
Data Storage and Security
- Your data is stored in Supabase (hosted on AWS)
- Platform credentials (X OAuth tokens) are encrypted before storage
- Images are stored in Supabase Storage
- We use HTTPS for all data in transit
Your Rights
You have the right to:
- Access your data: everything is visible within the app
- Export your data: contact us and we will provide a full export
- Delete your account and all associated data, available in Settings → Account
- Disconnect connected platforms at any time from Settings
GDPR (EU users): We process your data based on contract performance (providing the service you signed up for). You may contact us to exercise your rights under GDPR.
CCPA (California users): We do not sell your personal information.
Data Retention
- Active account data is retained while your account is active
- If you delete your account, your data is permanently deleted within 30 days: posts, drafts, threads, personas, categories, templates, schedule, connected accounts and usage history
- Backups may retain data for up to 90 days after deletion
What We Keep After You Delete
There is one deliberate exception to the above, and we'd rather state it plainly than bury it.
The free plan includes a monthly allowance of AI generations. Because that allowance resets each month, deleting an account and immediately creating a new one would be a way to reset it early. To prevent that, when an account is deleted we keep a small record containing:
- a one-way hash of your email address, not the address itself, and it cannot be reversed back into your email by us
- the identifier of the X account that was connected, if there was one
- how much of that month's generation allowance had been used, and which month it was
If you create a new account later, that usage carries over for the remainder of the same month, and then resets normally. It is used for nothing else, not marketing, not analytics, not profiling, and it is never shared.
Legal basis and retention: we rely on legitimate interests (preventing abuse of a free service). These records are deleted after 12 months. If you would like this record removed sooner, contact us at solofy.support@gmail.com and we will remove it, though we may then be unable to distinguish a returning account from a new one.
Children
Solofy is not intended for users under 13. We do not knowingly collect data from children.
Changes to This Policy
We will notify you of significant changes via email or an in-app notice. Continued use after changes constitutes acceptance.
Contact
For privacy questions or data requests: solofy.support@gmail.com