Privacy Policy
Plain answers about what we collect, why we collect it, and the controls you keep. The full policy is below. The short version fits on four cards.
- No selling data
- No ad tracking
- Tokens encrypted
- Delete within 30 days
- Disconnect anytime
Last updated August 10, 2026
What we collect
Your account details, the content you create, and only the platform data the features you enable actually need.
Section 2What we never do
No selling or renting data, no ad-targeting profiles, no cross-site tracking cookies following you around the web.
Section 3How it's protected
Access tokens encrypted at rest with AES-256-GCM, HTTPS everywhere, and every account's data isolated to that account.
Section 7Your controls
Export what we hold, disconnect any account instantly, and have everything deleted within 30 days of asking.
Section 9Who We Are
Social Magnum ("Social Magnum", "the App", "we", "us", or "our") is a social media management platform for scheduling, publishing, and engagement across eight social networks. Facebook Pages, Instagram, Threads, TikTok, YouTube, Pinterest, Bluesky, and Mastodon. The App is operated by METAFLUX MEDIA LLC, a Wyoming limited liability company.
- Address: 30 N Gould St, Ste 23881, Sheridan, WY 82801, United States
- Contact: support@socialmagnum.com
This Privacy Policy explains what information we collect, how we use and share it, and the choices you have. By creating an account or using the App, you agree to the practices described here. Please also review our Terms of Service.
Information We Collect
2.1 Information you provide directly. When you sign up and use Social Magnum:
- Your name and email address (from signup, or from Google/Facebook sign-in if you choose it)
- Your password (stored only as a salted hash. We never see it in plain text)
- Workspace and team details you create, and members you invite
- Content you create in the App: captions, media you upload, first comments, scheduled-post settings, drafts, and RSS feeds you connect
- Billing details when you subscribe to a paid plan (see Section 5)
- Messages you send us through support or contact forms
2.2 Information collected automatically. To operate and secure the service we record limited technical data. IP address, browser/device type, and basic request logs. We use only an essential session cookie to keep you signed in (see Section 10).
2.3 Information from your connected accounts. When you connect a social account. A Facebook Page, Instagram account, Threads profile, TikTok account, YouTube channel, Pinterest account, Bluesky account, or Mastodon account. We access data from that platform to provide the features you request. This is detailed in Section 4.
How We Use Your Information
We use the information we collect to:
- Publish & schedule: create, schedule, and publish posts, reels, stories, and carousels to your connected accounts
- Analytics: show reach, impressions, engagement, follower trends, and per-post performance for accounts you own
- Engagement (Inbox): let you read and reply to comments and direct messages on your own accounts
- Account & workspace management: manage connected accounts, workspaces, team roles, and access
- Reliability & security: detect token expiry, prevent abuse, and keep the service secure
- Communication: send account, billing, and service notices (and, only if you opt in, product updates)
We do not sell, rent, or trade your personal information, and we do not use your data or your connected-account data for advertising or to build ad-targeting profiles.
Connected Social Accounts & Platform Data
When you connect an account, we access only the data needed for the features you enable: publishing, scheduling, analytics, and engagement for accounts you own or manage. We store an encrypted access token so we can act on your behalf, and we use this data only to provide those features. We never sell it or share it for advertising.
Facebook Pages
Via the Meta Graph API, we access: Page name, Page ID, category, follower count, and profile picture; your published posts and their content; Page insights (impressions, reach, engagement, video views); and comments on your posts. We do not access Facebook Page messages or Messenger conversations. Where a Page is owned by a Business Manager, we read your business's Page listing for the sole purpose of showing you the Pages you manage. We do not access your business's other assets, ad accounts, or billing information.
Via Instagram's API (Instagram Business Login), we access: your Instagram account ID, username, name, profile picture, and follower count; your media and captions; comments; account and media insights (including aggregate audience demographics); and, if you enable the Inbox, Instagram direct messages, so you can read and reply to them in the App.
Threads
Via the Threads API, we access: your Threads user ID, username, and profile; your posts and replies; mentions; and post/profile insights (views, likes, replies), so you can publish and manage engagement in the App. At your request, the App can also delete posts and replies it published on your behalf. We only ever delete content when you ask us to.
TikTok
Via the TikTok API, we access: your TikTok open ID, username, display name, avatar, and profile link; your follower, following, likes and video counts; the list of videos you have posted, with their thumbnails and links; and your account's posting eligibility (for example whether your account is private, and which audience settings are available to you), which TikTok requires us to check immediately before each publish. We use video.publish only to post the content you create in the App, and never post without your explicit action.
YouTube
Via YouTube API Services, we access: your channel ID, title, custom URL, thumbnail, and subscriber, view and video counts; and the list of your recent uploads, so you can see them in the App. We use the upload permission solely to publish the videos you create in the App, with the title, description and visibility you choose. We do not read, edit, or delete videos we did not publish for you, and we do not access your comments, playlists, or watch history.
Via the Pinterest API, we access: your account username and profile picture; your boards and their names, so you can pick where a Pin is published; and the Pins the App creates on your behalf, together with their basic analytics.
Bluesky & Mastodon
For Bluesky we store the app password you generate and the handle it belongs to; for Mastodon we store your instance address and an OAuth token. In both cases we access your profile, your handle, and the posts the App publishes for you. Both credentials are encrypted at rest and are used only to publish and read back what you post through the App.
Our use of information received from Meta's APIs adheres to the Meta Platform Terms and Developer Policies, including their data-use and Limited Use requirements. Specifically:
- We request only the permissions necessary for the App's stated features
- We do not sell platform data, and we do not transfer it to data brokers or to any third party of our own accord. The single exception is an AI agent you connect and approve yourself, which receives only what it asks for on your behalf. See "AI agents you connect" in Section 5
- We do not use platform data for surveillance, or to discriminate against any person or group
- You can disconnect any account or revoke our access at any time (see Section 9)
YouTube & Google
Social Magnum uses YouTube API Services. By connecting a YouTube channel you agree to be bound by the YouTube Terms of Service, and Google's handling of your information is described in the Google Privacy Policy. You can review and revoke Social Magnum's access to your Google account at any time via the Google security settings page, as well as from within the App.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google user data to serve advertising, we do not sell or transfer it, we do not use it to train generalised AI or machine-learning models, and no human reads it except where you expressly ask us to, where it is necessary for security, or where the law requires it.
TikTok
Our use of information received from the TikTok API adheres to the TikTok Developer Terms of Service. We request only the scopes the App's stated features require, we do not sell or transfer TikTok data to any third party, and we do not use it for advertising, surveillance, or profiling. Content is published only when you choose to publish it.
AI Agents & the MCP Connector
You can optionally connect a third-party AI agent. Claude, ChatGPT, Cursor, Codex or any other client that speaks the Model Context Protocol. To your Social Magnum account. Nothing is connected until you approve it yourself, signed in, on our consent screen.
What an approved agent can read. A connected agent can request the same data you can see in the App for the workspace it is working in: your connected accounts and their status, scheduled and published posts and their captions, analytics figures, your media library and drafts, comments and Instagram direct messages on your posts, your workspaces, and the names, email addresses and roles of the people in workspaces you own.
That data leaves our systems. When an agent reads something, the answer is sent to the agent's provider. Anthropic, OpenAI, Google or whoever operates the client you connected. And is handled under their privacy policy, not ours. We do not control how long they keep it, whether they use it to train models, or who at that company can see it. Read the privacy policy of any agent before you connect it.
- We do not send your data to any AI provider on our own initiative. It moves only in response to a request from an agent you approved.
- Comments and messages include other people's words. An agent reading your inbox reads what your audience wrote, including their display names. Connecting an agent means that information reaches the agent's provider too.
- No credential is ever shared. An agent never receives your password, your social-network access tokens, or the keys we hold for connected accounts. It holds only its own revocable credential for our API.
- We record when a connection was made and last used, so you can spot activity you did not cause. We do not store the content of the conversations you have with your agent.
Withdrawing access. Every connected agent is listed on the Agents & CLI page, with a Disconnect button for each and one to disconnect them all. Revoking takes effect immediately. The credential stops working on its next request. It does not reach into the agent provider's systems and delete what they already received; for that you would need to use their own controls.
Data Retention
- Connected-account data & tokens: kept while the account is connected; cleared when you disconnect it.
- Content & scheduled posts: retained until you delete them or close your account.
- Media files & drafts: stored on Cloudflare R2 to power publishing and your Media Library; library uploads and drafts are also swept automatically 30 days after their last use (said right on those pages), and everything is deleted when you remove it or close your account.
- Account data: retained until you request deletion or your account is removed.
- Logs & billing records: retained for a limited period for security and legal/accounting obligations.
After a deletion request, we remove or anonymize your data within 30 days, except where retention is required by law.
Data Security
- Token encryption: all platform access tokens are encrypted at rest with AES-256-GCM, using a key stored separately from the database.
- Encryption in transit: all traffic is served over HTTPS/TLS, with HSTS and strict security headers.
- Tenant isolation: every account's data is scoped to that account; workspace roles (owner, admin, member) control who can see and manage which accounts.
- Least privilege: access to production data is limited to personnel who need it.
No method of transmission or storage is 100% secure, but we work to protect your information using industry-standard measures.
GDPR (EU/UK Users)
For personal data of individuals in the EEA and UK, you are the data controller for the content and audience data you manage through Social Magnum, and Social Magnum acts as a data processor: we process that data only to provide the features you enable. We follow a privacy-by-default approach and collect only what is needed to run the service. Where data is transferred internationally, we rely on recognized safeguards such as Standard Contractual Clauses (see Section 11).
Your Rights & Choices
You can:
- Access, correct, or export the data we hold about you. Email support@socialmagnum.com
- Delete your data. See our Data Deletion page
- Disconnect any connected account at any time in Social Accounts, which stops all data collection for that account
- Revoke our access from the platform directly. Via Facebook Settings → Business Integrations, your Instagram apps & websites settings, your Threads account settings, TikTok's Security settings (Apps and websites), the Google security settings page for YouTube, Pinterest's Connected apps settings, by deleting the app password in Bluesky, or your Mastodon instance's Authorized apps settings
- Opt out of product/marketing emails using the unsubscribe link (account and billing notices still apply)
Depending on where you live (e.g., EEA/UK, California, Virginia, Colorado), you may have additional rights and the right to lodge a complaint with your local data protection authority.
International Data Transfers
We and our sub-processors may process data in the United States and other countries. Where we transfer personal data out of the EEA/UK, we rely on appropriate safeguards, including Standard Contractual Clauses, to ensure an adequate level of protection.
Children's Privacy
Social Magnum is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 13 (or under 16 in the EU). If you believe a child has provided us personal data, contact us and we will delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be posted here with a new "Last updated" date and, where appropriate, communicated by email. Continued use of the App after changes take effect constitutes acceptance.
Contact Us
For privacy questions or data requests:
- Email: support@socialmagnum.com
- Mail: METAFLUX MEDIA LLC, 30 N Gould St, Ste 23881, Sheridan, WY 82801, United States

Questions about your data?
Privacy questions and data requests go to the people who actually built the product, and we answer for real. Deleting everything is a right, not a negotiation. The data-deletion page walks through it, and requests complete within 30 days.