1. Who we are
BulBul Social (“the Service”, “we”, “us”) is operated by [COMPANY LEGAL NAME], registered at [REGISTERED ADDRESS], registration number [REGISTRATION NUMBER]. You can reach us at support@bulbul.asia.
2. Scope
This policy explains what personal data we collect, how we use it, the legal basis for processing, with whom we share it, how long we keep it, and your rights. It applies to the web application available at https://social.bulbul.asia and the supporting backend at https://api.bulbul.asia.
3. What we collect
3.1 Account data (you)
- Your email address, display name, profile picture and Google account ID — obtained when you sign in with Google.
- Authentication cookies and session tokens issued by our service.
3.2 Connected platform data (Meta platforms)
When you connect a Threads, Instagram, Facebook Page or WhatsApp Business account:
- OAuth access tokens issued by Meta, encrypted at rest using AES-128 in CBC mode (Fernet).
- Account identifiers: user ID, username, page ID, Instagram Business Account ID, WhatsApp Business Account ID, phone number ID.
- Public profile data: display name, profile picture URL, biography.
- Content you publish through the Service: post text, images, videos, scheduled publish time, and the resulting platform post ID.
- Engagement data we fetch on your behalf: comments and replies on your posts, direct messages addressed to your accounts (Instagram, WhatsApp), insights (impressions, reach, likes, replies).
3.3 Technical data
- IP address, user-agent, request timestamps (kept in application logs for 30 days).
- Error reports and diagnostic events.
4. Why we collect it (purposes & legal basis)
| Purpose | Data used | Legal basis |
|---|---|---|
| Authenticate you | Google account ID, email, session cookies | Performance of contract |
| Publish content to your Meta accounts on your instruction | OAuth tokens, post content, account identifiers | Performance of contract |
| Fetch comments, replies and messages for the in-app inbox | OAuth tokens, message metadata, message bodies | Performance of contract |
| Generate AI draft text suggestions | Your prompt, optional sample posts you select | Performance of contract |
| Detect abuse, prevent fraud, debug | IP address, logs, error reports | Legitimate interest |
5. Third parties we share data with
We only share the minimum data needed for the Service to function. We do not sell your personal data.
- Meta Platforms, Inc.— when you publish content, fetch insights, or interact with Instagram / Facebook / WhatsApp / Threads, your data is transmitted to Meta’s Graph API. Their handling is governed by Meta’s Privacy Policy.
- OpenAI, L.L.C.— when you ask the Service to generate draft post text, the prompt (which may include text from posts you selected) is sent to OpenAI’s API. Per OpenAI’s API terms, this data is not used for model training. See OpenAI Privacy Policy.
- Google LLC — for sign-in (OAuth). See Google Privacy Policy.
- Infrastructure providers — Vercel (frontend hosting), our own servers hosted in [HOSTING REGION] for the backend and database.
6. Where data is stored
All personal data is stored in PostgreSQL and MinIO object storage on servers located in [HOSTING REGION]. Database backups are encrypted at rest. OAuth access tokens are additionally encrypted at the application layer using a symmetric key (Fernet, AES-128-CBC + HMAC-SHA256) before being written to the database.
7. How long we keep data
- Account & connected accounts: for as long as you keep the account active.
- Published posts and fetched insights: 24 months, then aggregated and anonymised.
- Messages and comments: 90 days, unless you mark them for retention.
- Application logs: 30 days.
- Backups: 35 days rolling.
- When you delete an account, all of the above is removed within 30 days, except where we are legally required to retain it.
8. Your rights
You have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Delete your account and all associated data via our data deletion page.
- Disconnect a Meta account at any time from the dashboard — we will delete the OAuth token and stop fetching new data immediately.
- Export your data in a machine-readable format (on request).
- Lodge a complaint with your local data protection authority.
9. Security
We use HTTPS everywhere, encrypt OAuth tokens at rest, restrict database access to application servers, rotate secrets regularly, and require two-factor authentication for all team members with production access. We notify affected users within 72 hours of becoming aware of any data breach that may affect them.
10. Children
The Service is not directed to children under 16. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. Material changes will be communicated by email and via an in-app notice at least 14 days before they take effect.
12. Contact
Questions, requests or complaints about this policy or your data: write to support@bulbul.asia.
Краткое содержание на русском
BulBul Social — сервис для управления соцсетями (Facebook, Instagram, WhatsApp, Threads). Мы храним токены доступа к вашим аккаунтам Meta в зашифрованном виде, контент, который вы публикуете через сервис, и метаданные комментариев/сообщений, которые мы получаем по вашему поручению.
Мы передаём ваши данные только в Meta (для выполнения ваших действий — публикации, чтения комментариев), в OpenAI (если вы используете AI-генерацию текстов), в Google (для входа) и нашему хостинг-провайдеру. Мы не продаём ваши данные.
Вы можете удалить аккаунт в любой момент на странице удаления данных. Все данные будут удалены в течение 30 дней. По любым вопросам — support@bulbul.asia.