Privacy Policy

Last updated 2026-06-09 (v2)

Plain-English summary

We collect the minimum we need to run Svmmon. We never sell your data. You can export everything or delete your account from Settings at any time. EU and California residents get the same rights everyone else does. They're built into the product, not bolted on.

What we collect

  • Email address. Used to sign you in. We never collect a password.
  • Content you create. Profiles, hook prompts, slideshows, images, automations, saved research.
  • Post performance you log. View counts, likes, platform handles. Powers the marketing intelligence loop. Only what you enter.
  • Linked social usernames. Your TikTok / Instagram / YouTube handle if you connect them. We do not pull anything you didn't explicitly authorize.
  • Billing info. Our payment processor holds card numbers, billing addresses, and invoice history. We never see card numbers. We store only the customer + subscription IDs.
  • IP addresses and user-agent strings. Written to security logs for fraud and abuse prevention. Retained up to 180 days, then purged.
  • Consent records. When you agreed to which version of this policy. Required by GDPR / CCPA.
  • Encrypted AI provider API key. Only if you opt into BYOK on the Unlimited tier. Stored encrypted at rest; we never log the plaintext.

What we do NOT collect

  • No third-party advertising trackers, marketing pixels, or session-replay tools.
  • No analytics beyond what is essential to operate the product.
  • No keystroke logging.
  • No card numbers. Our payment processor handles all payment data.
  • No phone numbers (we don't do SMS).
  • No biometric data.

Who we share data with

We share the minimum needed to run the service:

  • Payment processor. Billing and subscription management.
  • AI provider. Slideshow and hook generation. Per its API terms, your inputs are not used to train models.
  • Cloud hosting. Database, file storage, and authentication.
  • Messaging provider. Only if you opt in for export delivery or admin alerts.
  • Research providers. When you use research features. Only public content and your search queries go through these services.
  • Social platforms you connect. Only when you explicitly authorize OAuth, and only the data their APIs require to post on your behalf.

We do not sell your data. We never share data for advertising.

The full, versioned sub-processor list lives at /subprocessors with each provider's purpose, location, and policy link. EU and UK customers, see also our Data Processing Addendum.

Your rights

  • Export your data. Settings → Privacy & data → Download my data. Produces a JSON file with every row we hold about your account. Link is valid 24h.
  • Delete your account. Settings → Privacy & data → Delete my account. Your data is soft-deleted for 7 days (sign in to undo) then permanently purged.
  • Correct your data. Edit your profile, settings, and connected accounts anytime.
  • Withdraw consent. Some functionality requires consent (e.g. you can't use the product without agreeing to the Terms). Reach out at support@svmmonapp.com for anything beyond that.
  • Lodge a complaint with your local data protection authority (UK ICO, your EU country's DPA, etc.).

Retention

  • Account data. Kept while your account is active. Deleted within 7 days of you requesting deletion (sign in during that window to keep your account). Residual copies in encrypted backups are purged within 90 days.
  • Security logs (IP / user-agent). Up to 180 days.
  • Data-export downloads. Signed link expires 24 hours after generation. The underlying file is purged on the next daily cleanup.
  • Billing records. Our payment processor's retention applies. Typically 7 years for tax and audit purposes.
  • Consent records. Kept indefinitely while you have an account. Hard-deleted with your account.

Cookies

We use a strictly-necessary authentication session cookie. We do not use marketing, advertising, or analytics cookies. The one exception is affiliate attribution, described next, which loads only after consent in the EU, EEA, and UK.

Affiliate attribution (Affiliateo)

Our marketing site (svmmonapp.com) uses Affiliateo to credit the affiliate who referred you. Once it loads, it stores persistent identifiers in your browser's localStorage (affiliateo_ref, affiliateo_visitor_id, and affiliateo_campaign_id) and sends your IP address, browser user agent, and approximate geolocation to affiliateo.com to track clicks and conversions. Affiliateo acts as a data processor for this; their data-processing terms are at affiliateo.com/dpa. In the EU, EEA, and UK, this tracker loads only after you accept the cookie banner. If you decline, it never loads and none of these identifiers or data are sent. In other regions, where prior consent is not legally required, it loads automatically. You can contact us to have it disabled.

International transfers

Our processors operate from the United States and other regions. When EU personal data is transferred, transfers rely on the Standard Contractual Clauses (SCCs) where applicable.

Contact

For any privacy question, data request, or complaint: support@svmmonapp.com. We aim to respond within 7 days and resolve within 30 (GDPR timeline).

Privacy Policy · Svmmon