Legal

Privacy Policy

Last updated: July 2026

1. Scope and introduction

Signesis is a social media management platform, operated from Switzerland, that allows content creators, and businesses to plan, schedule and publish content across the social accounts they own or are authorized to manage. Running several online identities means entrusting a tool with the keys to them, and this policy is written to be read rather than skimmed past: it sets out, in plain terms, exactly what personal data Signesis holds, why it is held, who else ever sees it, how long it is kept, and how to get it back or have it erased. The guiding principle is restraint — no data is collected that the product does not genuinely need, nothing is sold, and no advertising or tracking is embedded anywhere in the service. Signesis alone decides why and how the data described below is processed, and is therefore responsible for it in law and answerable for it to you. Questions about this policy, or about the data held about you, can be raised through the contact page.

2. Data collected

  • Account details — your email address and a securely hashed password, or, if you sign in with Google, the email address Google returns.
  • Profile details you choose to provide — your name, timezone, and a profile photo.
  • Connected social accounts — the account's handle and display name, its follower and subscriber counts, and an access token permitting Signesis to act on that account on your behalf.
  • Content you create — captions, images and videos you upload, and the schedule you set for them.
  • Billing details — your plan and subscription status. Card details are handled entirely by Stripe and are never seen or stored by Signesis.
  • Support requests submitted from within the application.

3. Connected social accounts

Connecting a social account sends you to that platform to sign in and authorize Signesis; your password for that platform is never seen or received by Signesis. The platform returns an access token, which is used strictly for the purposes you have authorized: reading your public profile — the handle and follower or subscriber counts displayed in your workspace — and publishing the posts you schedule. Direct messages are not read. Nothing is published that you have not created and scheduled yourself. Access tokens are held in a database table that is unreachable from the browser and readable only by server-side functions.

4. Purposes of processing

  • Operating the service — storing your content and publishing it to your connected accounts at the times you choose.
  • Displaying your own figures, such as follower counts retrieved from the connected platform.
  • Sending account emails (password reset, billing) and, where enabled, a digest of your upcoming posts.
  • Responding to support requests.
  • Maintaining the security, integrity and reliability of the service.

5. Legal basis

Processing necessary to deliver the service you have signed up for — storing and publishing your content, connecting your accounts, billing — is carried out on the basis of performance of a contract. Security, abuse prevention and service reliability rest on legitimate interests. Optional features, such as the upcoming-posts digest and the AI writing assistant, are processed on the basis of your consent, which you may withdraw at any time by turning the feature off. Records required for tax and accounting are retained to comply with a legal obligation.

6. Images and videos

Media you upload is stored at a public, unlisted URL. This is a technical requirement of publishing: certain platforms retrieve the image or video from that URL in order to post it. The URLs are long and not guessable, and are neither listed nor indexed by Signesis — but anyone holding the URL can open the file, and uploaded media should therefore be treated as public.

7. AI writing assistant

Where you use the AI assistant to draft a caption, the text and context you supply are sent to a third-party AI provider to generate the suggestion, and that provider's handling of the content is governed by its own terms. The providers currently used can be identified on request through the contact page. The assistant is entirely optional: if you would prefer that no content leave Signesis, do not use it — every other feature operates without it.

8. Service providers

Personal data is never sold, and is never shared for advertising. A limited number of processors are engaged solely to operate the service: providers of database, authentication and file storage; hosting; payment processing; transactional email; and the AI assistant. A current list is available on request. Content is, necessarily, also transmitted to whichever social platform you have instructed Signesis to publish it to.

9. International transfers

Some of the providers described above process data outside Switzerland and the European Economic Area. Where that is the case, the transfer is made under appropriate safeguards, such as the European Commission's standard contractual clauses or an equivalent recognised mechanism.

10. Security

Data is transmitted over encrypted connections. Records are isolated per user at the database level, so one account cannot read another's. Platform access tokens are held separately from application data, are not exposed to the browser under any circumstances, and are accessible only to server-side functions. No system is perfectly secure, but access to personal data is restricted to what is necessary to run the service.

11. Retention

Your account and content are retained until you delete them. Media attached to a published post is deleted automatically once the post passes your plan's analytics window — 7, 30, 90 or 365 days, depending on the plan — while the post record itself is retained. Access tokens are deleted as soon as an account is disconnected.

12. Disconnection and deletion

  • Disconnect an account — remove it from the project's Accounts tab; its access token is deleted immediately.
  • Revoke from the platform — Signesis can also be removed from within the platform's own settings, usually under connected or authorized applications. Where the platform sends notice of this, the token is deleted on receipt.
  • Request deletion through a platform — the data held for that connected account is then deleted, comprising its token, its cached follower count and the posts scheduled to it, and a confirmation code is issued which can be checked at signesis.com/data-deletion. Your Signesis account and any other connected accounts are unaffected.
  • Delete everything — make the request through the contact page and the account and all of its content will be erased.

13. Your rights

Signesis extends the same core rights to every user, wherever they are located: the right to access the personal data held about you, to have it corrected, to obtain a copy of it, to have it erased, and to object to or restrict how it is processed. Requests may be made through the contact page and will be answered within one month. Exercising these rights never results in a degraded service or a different price.

14. Regional rights

Users in the European Economic Area and the United Kingdom hold these rights under the GDPR and UK GDPR, and users in Switzerland under the Federal Act on Data Protection; each may also lodge a complaint with their national supervisory authority. California residents hold equivalent rights under the CCPA/CPRA — including the right to know what is collected and to have it deleted — and note that Signesis does not sell personal information, does not share it for cross-context behavioural advertising, and does not process sensitive personal information for the purpose of inferring characteristics. Residents of other US states and of countries with comparable data protection laws may exercise the same rights set out above.

15. Cookies

Only the functional cookies required to operate the service are used: keeping you signed in and, while Signesis remains in private beta, recognising a preview link. No advertising or tracking cookies are used, and no third-party analytics are embedded.

16. Age

Signesis is not intended for children. You must be at least 18 years old to hold an account, and accounts are not knowingly created for anyone below that age. This mirrors the minimum age set out in the Terms of Service.

17. Amendments

  • This policy may be updated from time to time by publishing a new version on this website.
  • Please check this page from time to time to ensure you are content with any changes.
  • Significant changes will be notified by email, and the date shown above always reflects the most recent revision.
Questions? Get in touch through the contact page.