Privacy Policy
Last updated: June 17, 2026
This Privacy Policy explains how Altus Entertainment LLC ("we", "us", "our") collects, uses, shares, and protects personal data when you use Social Director(the "Service") or visit our website. Altus Entertainment LLC is the data controller for the personal data processed in connection with the Service.
1. Personal data we collect
- Account data — name, email address, password hash, profile photo, time zone.
- Connected-platform data — OAuth tokens and basic profile information from social platforms you connect (e.g. Instagram, TikTok, X), and the posts, captions, media, and metrics processed to provide the Service.
- Content you provide — text prompts, uploaded photos and video, brand assets, and AI-generated drafts.
- Support data — messages, attachments, and other information you send when contacting us.
- Usage and device data — pages visited, features used, IP address, browser type, device identifiers, log timestamps, and approximate location derived from IP.
- Payment data — handled directly by Paddle (see "Payments" below). We receive limited information such as your billing email, country, last four digits of the payment method, plan, and transaction status.
2. How we use personal data
- create and manage your account and authenticate you;
- provide, operate, and improve the Service, including generating, scheduling, and publishing posts on your behalf;
- process payments and manage your subscription (via Paddle);
- communicate with you about your account, security alerts, and product updates;
- respond to support requests;
- monitor, prevent, and investigate fraud, abuse, and security incidents;
- analyze usage to improve features and reliability;
- comply with legal obligations and enforce our Terms.
3. Legal bases (UK/EEA users)
- Performance of a contract — to provide the Service you signed up for.
- Legitimate interests — to secure, maintain, and improve the Service, prevent fraud, and run our business.
- Consent — for optional cookies and any marketing emails where consent is required; you may withdraw consent at any time.
- Legal obligation — for tax, accounting, and responding to lawful requests.
4. Payments
Payments are processed by Paddle.com Market Limited, our Merchant of Record. When you make a purchase, your payment details are collected and processed directly by Paddle under its own Privacy Policy. We do not store full card numbers.
5. How we share personal data
- Service providers / subprocessors — hosting, database, email delivery, analytics, error tracking, customer support, and AI model providers used to generate content. These providers process data on our behalf under written agreements.
- Paddle — as Merchant of Record for payments, subscription management, tax compliance, and invoicing.
- Connected social platforms — content you schedule is transmitted to the platforms you authorize.
- Professional advisers — lawyers, accountants, and auditors as needed.
- Authorities — where we are required to disclose by law, court order, or to protect rights, property, or safety.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to standard confidentiality.
We do not sell your personal data.
6. AI processing
When you ask the Service to draft or rewrite content, your prompts and any associated context (e.g. previous posts you have shared with us) are sent to our AI provider(s) to generate the output. We do not authorize our AI providers to train their public foundation models on your content.
7. International transfers
We are based in the United States and our subprocessors may be located in the United States, the EEA, the UK, and other countries. Where personal data is transferred outside the UK/EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, or on adequacy decisions where applicable.
8. Data retention
We keep personal data for as long as your account is active and for a reasonable period afterwards to comply with legal obligations, resolve disputes, and enforce our agreements. When data is no longer needed, we delete or anonymize it. Billing records retained by Paddle follow Paddle's own retention schedule.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict, or object to processing of your personal data; to data portability; to withdraw consent; and to lodge a complaint with your local data protection authority. To exercise any of these rights, email hello@socialdirector.app. We will respond within one month or as required by applicable law.
California residents have additional rights under the CCPA/CPRA, including the right to know, the right to delete, the right to correct, and the right to opt out of "sharing" for cross-context behavioral advertising. We do not sell or share personal data as those terms are defined under California law.
10. Security
We use industry-standard technical and organisational measures to protect personal data, including encryption in transit, encrypted credential storage, access controls, and audit logging. No system is perfectly secure; you are responsible for keeping your account credentials confidential.
11. Cookies
We use strictly necessary cookies to keep you signed in and to remember your preferences. We may also use limited first-party analytics cookies to understand how the Service is used and improve it. Where required by law, we will ask for your consent to non-essential cookies and provide controls to manage them in your browser.
12. Children
The Service is not directed to children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
13. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through the Service.
14. Contact us
Altus Entertainment LLC (data controller)
Email: hello@socialdirector.app