Privacy Policy

Last updated: March 25, 2026

1. Data We Collect

Account data: Email address (used for authentication via OTP).

Connected services: Twitter/X OAuth tokens, Figma OAuth tokens. These are stored securely and used only to operate the service on your behalf.

Content: Design images and SVGs you upload, AI-generated captions, and scheduled post data.

Usage data: Post creation counts and feature usage for subscription billing purposes.

Payment data: Processed by Polar. We do not store credit card numbers or payment details directly.

2. How We Use Your Data

Your data is used exclusively to provide the AutoPost service: generating post images, creating AI captions, scheduling and publishing tweets, and managing your subscription. We do not sell, rent, or share your personal data with third parties for marketing purposes.

3. Third-Party Services

AutoPost integrates with the following services that may process your data according to their own privacy policies:

  • Twitter/X — posting content and fetching analytics
  • Figma — accessing design files and frames
  • Polar — payment processing and subscription management
  • Anthropic (Claude) — AI caption generation (design images are sent for analysis)
  • Resend — sending OTP authentication emails

4. Data Storage & Security

Data is stored in a SQLite database on secure infrastructure (Render). Authentication uses HTTP-only secure cookies. OAuth tokens are stored encrypted at rest. All connections use HTTPS.

5. Data Retention

Your data is retained for as long as your account is active. Generated images are stored for the duration of your subscription. Upon account deletion, all data is permanently removed within 30 days.

6. Cookies

We use a single HTTP-only authentication cookie (auth_session) to maintain your login session. We do not use tracking cookies, analytics cookies, or third-party advertising cookies.

7. Your Rights

You have the right to: access your personal data, request correction of inaccurate data, request deletion of your data, disconnect third-party services at any time, and export your data. To exercise these rights, contact us at hello@refinestudio.io.

8. Changes

We may update this policy from time to time. We will notify you of significant changes via email.

9. Contact

Refine Studio — hello@refinestudio.io