Privacy Policy
Last updated: August 2026
1. Scope and introduction
Signesis is a social media management platform, operated from Switzerland, that allows content creators, and businesses to plan, schedule and publish content across the social accounts they own or are authorized to manage. Running several online identities means entrusting a tool with the keys to them, and this policy is written to be read rather than skimmed past: it sets out, in plain terms, exactly what personal data Signesis holds, why it is held, who else ever sees it, how long it is kept, and how to get it back or have it erased. The guiding principle is restraint - no data is collected that the product does not genuinely need, nothing is sold, and no advertising or tracking is embedded anywhere in the service. Signesis alone decides why and how the data described below is processed, and is therefore responsible for it in law and answerable for it to you. Questions about this policy, or about the data held about you, can be raised through the contact page.
2. Data collected
- Account details - your email address and a securely hashed password, or, if you sign in with Google, the email address and name Google returns.
- Profile details you choose to provide - your name, timezone, and a profile photo.
- Connected social accounts - the account's handle and display name, its follower and subscriber counts, and an access token permitting Signesis to act on that account on your behalf.
- Content you create - captions, images and videos you upload, and the schedule you set for them.
- Billing details - your plan and subscription status. Card details are handled entirely by Stripe and are never seen or stored by Signesis.
- Support requests submitted from within the application.
3. Connected social accounts
Connecting a social account sends you to that platform to sign in and authorize Signesis; your password for that platform is never seen or received by Signesis. The platform returns an access token, which is used strictly for the purposes you have authorized: reading your public profile - the handle and follower or subscriber counts displayed in your workspace - and publishing the posts you schedule. Direct messages are not read. Nothing is published that you have not created and scheduled yourself. Access tokens are held in a database table that is unreachable from the browser and readable only by server-side functions.
4. Google user data
When you connect a YouTube channel, Signesis accesses data through Google's APIs - your channel's public identity and subscriber count, and, so that it can publish on your behalf and show you your own analytics, permission to upload videos and to read your channel and video statistics. This Google user data is used only to provide those features to you. It is not sold, is not used for advertising, and is not shared with anyone other than the infrastructure processors listed in section 10 (and only as needed to operate the service) and Google itself. It is retained only as described in section 13, and is deleted when you disconnect the account or delete your Signesis account.
5. Limited Use of Google user data
Signesis's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Signesis does not use Google user data to train, develop or improve any generalized or non-personalized artificial-intelligence or machine-learning models.
6. Purposes of processing
- Operating the service - storing your content and publishing it to your connected accounts at the times you choose.
- Displaying your own figures, such as follower counts retrieved from the connected platform.
- Sending account emails (password reset, billing) and, where enabled, a digest of your upcoming posts.
- Responding to support requests.
- Maintaining the security, integrity and reliability of the service.
7. Legal basis
Processing necessary to deliver the service you have signed up for - storing and publishing your content, connecting your accounts, billing - is carried out on the basis of performance of a contract. Security, abuse prevention and service reliability rest on legitimate interests. To prevent abuse of the service and to comply with the law, uploaded media is automatically scanned to detect unlawful content - in particular child sexual abuse and exploitation (CSAM) - which is carried out using a specialist child-protection organisation's detection service, to which the media is transmitted for that purpose; any content identified as unlawful, together with the associated account information, may be preserved and disclosed both to that organisation and to the competent authorities. Optional features, such as the upcoming-posts digest and the AI writing assistant, are processed on the basis of your consent, which you may withdraw at any time by turning the feature off. Records required for tax and accounting are retained to comply with a legal obligation.
8. Images and videos
Media you upload is stored at a public, unlisted URL. This is a technical requirement of publishing: certain platforms retrieve the image or video from that URL in order to post it. The URLs are long and not guessable, and are neither listed nor indexed by Signesis - but anyone holding the URL can open the file, and uploaded media should therefore be treated as public.
9. AI writing assistant
Where you use the AI assistant to draft a caption, the text and context you supply are sent to a third-party AI provider to generate the suggestion, and that provider's handling of the content is governed by its own terms. The providers currently used can be identified on request through the contact page. The assistant is entirely optional: if you would prefer that no content leave Signesis, do not use it - every other feature operates without it.
10. Service providers
Personal data is never sold, and is never shared for advertising. A limited number of processors are engaged solely to operate the service, each with access only to the data it needs for its function:
- Supabase - database, authentication and file storage.
- Cloudflare - application hosting.
- Stripe - payment processing.
- Resend - transactional email.
- Anthropic - the optional AI writing assistant.
- A specialist child-protection organisation - automated content-safety scanning of uploaded media, as described in section 7.
These processors act on Signesis's instructions and are not permitted to use the data for their own purposes. Content is, necessarily, also transmitted to whichever social platform you have instructed Signesis to publish it to. No other sharing, transfer or disclosure of personal data takes place, except where required by law.
11. International transfers
Some of the providers described above process data outside Switzerland and the European Economic Area. Where that is the case, the transfer is made under appropriate safeguards, such as the European Commission's standard contractual clauses or an equivalent recognised mechanism.
12. Security
Data is transmitted over encrypted connections. Records are isolated per user at the database level, so one account cannot read another's. Platform access tokens are held separately from application data, are not exposed to the browser under any circumstances, and are accessible only to server-side functions. Two-factor authentication is available and can be enabled from your account settings. Where it is turned on, the authenticator secret and your one-time recovery codes are stored server-side, are never exposed to the browser, are excluded from the data export, and are deleted with your account. The recovery codes are held only in hashed form. No system is perfectly secure, but access to personal data is restricted to what is necessary to run the service.
13. Retention
Your account and content are retained until you delete them. Media attached to a published post is deleted automatically once the post passes your plan's analytics window - 7, 30, 90 or 365 days, depending on the plan - while the post record itself is retained. Access tokens are deleted as soon as an account is disconnected.
14. Disconnection and deletion
- Disconnect an account - remove it from the project's Accounts tab; its access token is deleted immediately.
- Revoke from the platform - Signesis can also be removed from within the platform's own settings, usually under connected or authorized applications. Where the platform sends notice of this, the token is deleted on receipt.
- Request deletion through a platform - the data held for that connected account is then deleted, comprising its token, its cached follower count and the posts scheduled to it, and a confirmation code is issued which can be checked at signesis.com/data-deletion. Your Signesis account and any other connected accounts are unaffected.
- Delete everything - from Settings, under Account, use Delete account to permanently erase your Signesis account and all of its content, including your projects, connected accounts, posts, media and profile. This also cancels any active subscription and cannot be undone.
15. Your rights
Signesis extends the same core rights to every user, wherever they are located: the right to access the personal data held about you, to have it corrected, to obtain a copy of it, to have it erased, and to object to or restrict how it is processed. Two of these can be exercised directly from your account at any time: in Settings, under Account, Download my data provides a copy of your Signesis data in a portable, machine-readable format, and Delete account permanently erases your account and all of its content. For the remaining rights, or if you are unable to use these tools, requests may be made through the contact page and will be answered within one month. Exercising any of these rights never results in a degraded service or a different price.
16. Regional rights
Users in the European Economic Area and the United Kingdom hold these rights under the GDPR and UK GDPR, and users in Switzerland under the Federal Act on Data Protection; each may also lodge a complaint with their national supervisory authority. California residents hold equivalent rights under the CCPA/CPRA - including the right to know what is collected and to have it deleted - and note that Signesis does not sell personal information, does not share it for cross-context behavioural advertising, and does not process sensitive personal information for the purpose of inferring characteristics. Residents of other US states and of countries with comparable data protection laws may exercise the same rights set out above.
17. Cookies
Only the functional cookies required to operate the service are used: keeping you signed in and, while Signesis remains in private beta, recognising a preview link. No advertising or tracking cookies are used, and no third-party analytics are embedded.
18. Age
Signesis is not intended for children. You must be at least 18 years old to hold an account, and accounts are not knowingly created for anyone below that age. This mirrors the minimum age set out in the Terms of Service.
19. Amendments
- This policy may be updated from time to time by publishing a new version on this website.
- Please check this page from time to time to ensure you are content with any changes.
- Significant changes will be notified by email, and the date shown above always reflects the most recent revision.