Privacy Policy
Plain answers about what we collect, why we collect it, and the controls you keep. The full policy is below. The short version fits on four cards.
- No selling data
- No ad tracking
- Tokens encrypted
- Deletion requests within 30 days
- Disconnect anytime
Last updated October 7, 2026
What we collect
Your account details, the content you create, and only the platform data the features you enable actually need.
Section 2What we never do
No selling or renting data, no ad-targeting profiles, no cross-site tracking cookies following you around the web.
Section 3How it's protected
Access tokens encrypted at rest with AES-256-GCM, HTTPS everywhere, and every account's data isolated to that account.
Section 8Your controls
Request an export or deletion, revoke connections, and understand which records remain after disconnecting.
Section 10Who We Are
Social Magnum ("Social Magnum", "the App", "we", "us", or "our") is a social media management platform for scheduling, publishing, and engagement across 20+ social networks. Facebook Pages, Instagram, Threads, LinkedIn, TikTok, YouTube, Pinterest, Bluesky, Mastodon, X, Telegram, Discord, Slack, Dev.to, Tumblr, WordPress, Lemmy, Nostr, Listmonk, and Whop. The App also includes UGC Studio for content creation and Ecommerce seller tools for supported connected shops. It is operated by METAFLUX MEDIA LLC, a Wyoming limited liability company.
- Address: 30 N Gould St, Ste 23881, Sheridan, WY 82801, United States
- Contact: support@socialmagnum.com
This Privacy Policy explains what information we collect, how we use and share it, and the choices you have. By creating an account or using the App, you agree to the practices described here. Please also review our Terms of Service.
Information We Collect
2.1 Information you provide directly. When you sign up and use Social Magnum:
- Your name and email address (from signup, or from Google/Facebook sign-in if you choose it)
- Your password (stored only as a salted hash. We never see it in plain text)
- Workspace and team details you create, and members you invite
- Content you create in the App: captions, media you upload, first comments, scheduled-post settings, drafts, and RSS feeds you connect
- Billing details when you subscribe to a paid plan (see Section 6)
- Messages you send us through support or contact forms
- UGC Studio inputs and projects: brand names and website URLs, extracted website text and images, brand profiles, prompts, scripts, reference photos, demo clips, music selections, generated assets, export files and job status
- Ecommerce drafts and uploads: product descriptions, prices, quantities, category attributes, shipping and return choices, production-partner selections, images and digital files you submit
2.2 Information collected automatically. To operate and secure the service we record limited technical data. IP address, browser/device type, and basic request logs. We also retain a country-level estimate derived from a signed-in request or an existing login IP to understand where our customers use the service. This does not use precise device location and may be affected by VPNs. Essential cookies keep you signed in and secure authorization flows. Optional analytics and your cookie choices are explained in Section 11.
2.3 Information from your connected accounts. When you connect a social account. A Facebook Page, Instagram account, Threads profile, TikTok account, YouTube channel, Pinterest account, Bluesky account, Mastodon account, X account, Telegram channel or group, Discord server, Slack workspace, Dev.to account, Tumblr blog, WordPress site, Lemmy account, Nostr identity, Listmonk server, Whop community, or LinkedIn Page. We access data from that platform to provide the features you request. Connected commerce shops also provide the shop and order information described in Section 4.
How We Use Your Information
We use the information we collect to:
- Publish & schedule: create, schedule, and publish posts, reels, stories, and carousels to your connected accounts
- Analytics: show reach, impressions, engagement, follower trends, and per-post performance for social accounts you own
- UGC Studio and AI tools: read the website you submit, generate ideas and assets from your inputs, assemble videos or slides, and save exports for download or use in a post
- Ecommerce: connect authorized shops, load listing options, read and revise authorized listings, submit your new listings and files, record submission and revision results, and display order and sales summaries
- Engagement (Inbox): let you read and reply to comments and direct messages on your own accounts
- Account & workspace management: manage connected accounts, workspaces, team roles, and access
- Reliability & security: detect token expiry, prevent abuse, and keep the service secure
- Communication: send account, billing, and service notices (and, only if you opt in, product updates)
We do not sell, rent, or trade your personal information, and we do not use your data or your connected-account data for our own advertising or to build ad-targeting profiles.
Connected Accounts & Platform Data
When you connect an account, we access only the data needed for the features you enable: social publishing, scheduling, analytics and engagement, or the shop features described below, for accounts you own or manage. We store an encrypted access token so we can act on your behalf, and we use this data only to provide those features. We never sell it or share it for advertising.
Shopify shops
You authorize access on Shopify. We do not ask for your Shopify password. We store encrypted access and refresh tokens, the shop identifier, myshopify.com domain, name, currency, granted permissions and connection status. We use this information to connect your shop to the Social Magnum workspace you confirm.
We read product categories, collections, inventory locations and sales channels to prepare products. When you submit a product, we send the descriptions, images, options, prices, inventory and other product details you choose to Shopify. Publishing to a sales channel is a separate permission and action. We retain product drafts, staged images and submission identifiers to show results and avoid duplicate submissions.
We query recent order identifiers, dates, totals, currency and payment and fulfillment status for the orders page and overview. We do not request customer names, email addresses, phone numbers or delivery addresses in these queries. Order summaries are fetched on demand and are not stored as a customer database. They may cover only a limited number of recent orders.
Shopify data is used to provide the shop-management and overview features you request. We do not sell it, use it for advertising or unsolicited messages, send it to UGC generation, or use it to train AI models. We process shop data on the merchant's instructions, using our hosting, database and storage providers to operate the service. Shopify handles data under its Privacy Policy.
Etsy shops
You authorize Etsy access on Etsy's OAuth screen; we do not ask for your Etsy password. We store encrypted access and refresh tokens, your Etsy user and shop identifiers, shop name, currency and connection status. With your permission, we read listing details and shop options such as categories, shipping profiles, processing times, return policies, shop sections and production partners; send the listing text, images and digital files you choose; and read back submission results.
Etsy order responses are processed on our server to produce limited summaries: receipt identifiers, dates, amounts, currency and payment/shipping status. Responses can contain buyer details, but our order endpoint strips names, email addresses, delivery addresses and buyer messages before returning summaries to the App. We do not request buyer-email access or store a buyer contact directory. Shop records, your drafts, staged files and submission history are stored to provide the integration.
We act on the seller's instructions as a service provider for shop data. We do not use Etsy order or buyer data for advertising, unsolicited messages, sale to others or AI-model training, and the Ecommerce integration does not send that data to UGC generation. Etsy handles information under its Privacy Policy. Platforms marked Coming soon cannot be connected; test integrations are explicitly labeled Sandbox or development.
eBay seller accounts
Social Magnum provides seller tools for creating and revising supported listings, reading orders and viewing summaries for your own authorized shops. It is not a buyer shopping or checkout service. You sign in and grant access on eBay's own screen; we never ask for your eBay password. We store encrypted access and refresh tokens, a hashed account identifier, seller display name, connection status and granted permissions. Sandbox connections and test results are labeled and kept separate from production.
With your permission, we read categories, item specifics, conditions, shipping/payment/return policies and inventory locations; send the listing content and photos you select; and store drafts, submission receipts and revision-operation identifiers/statuses. New-draft photos are stored privately by us and transferred to eBay Picture Services when preparing a listing. Photos added while revising an existing offer are normalized and uploaded to eBay directly; saving the revision applies the selected photos to the offer. Published images and listings are then handled under eBay's Privacy Notice. Optional policy setup requires an additional eBay account-management permission.
Order responses are processed temporarily on our server. Only order identifiers, dates, amounts, currency and payment, fulfillment or cancellation status are returned to your authorized workspace. Buyer names, contact details, addresses and messages are excluded from those summaries, and we do not keep an eBay buyer database or persist raw order responses. Dashboard figures describe a limited recent sample for your own connected shops; they are not market-wide statistics, competitor benchmarks, complete accounting records or payouts.
We use eBay data only for the authorized seller workflow, support and security. We do not sell it, use it for advertising or unsolicited messages, feed it to UGC/AI generation, train AI models with it, or expose another seller's private data. Disconnect under E-commerce Shops to clear our credentials, or revoke access in eBay's Third-party app access settings. See eBay data deletion for removal of saved records and account-closure notifications.
Facebook Pages
Via the Meta Graph API, we access: Page name, Page ID, category, follower count, and profile picture; your published posts and their content; Page insights (impressions, reach, engagement, video views); and comments on your posts. We do not access Facebook Page messages or Messenger conversations. Where a Page is owned by a Business Manager, we read your business's Page listing for the sole purpose of showing you the Pages you manage. We do not access your business's other assets, ad accounts, or billing information.
Via Instagram's API (Instagram Business Login), we access: your Instagram account ID, username, name, profile picture, and follower count; your media and captions; comments; account and media insights (including aggregate audience demographics); and, if you enable the Inbox, Instagram direct messages, so you can read and reply to them in the App.
Threads
Via the Threads API, we access: your Threads user ID, username, and profile; your posts and replies; mentions; and post/profile insights (views, likes, replies), so you can publish and manage engagement in the App. At your request, the App can also delete posts and replies it published on your behalf. We only ever delete content when you ask us to.
TikTok
Via the TikTok API, we access: your TikTok open ID, username, display name, avatar, and profile link; your follower, following, likes and video counts; the list of videos you have posted, with their thumbnails and links; and your account's posting eligibility (for example whether your account is private, and which audience settings are available to you), which TikTok requires us to check immediately before each publish. We use video.publish only to post the content you create in the App, and never post without your explicit action.
YouTube
Via YouTube API Services, we access: your channel ID, title, custom URL, thumbnail, and subscriber, view and video counts; and the list of your recent uploads, so you can see them in the App. We use the upload permission solely to publish the videos you create in the App, with the title, description and visibility you choose. We do not read, edit, or delete videos we did not publish for you, and we do not access your comments, playlists, or watch history.
Via the Pinterest API, we access: your account username and profile picture; your boards and their names, so you can pick where a Pin is published; and the Pins the App creates on your behalf, together with their basic analytics.
Bluesky & Mastodon
For Bluesky we store the app password you generate and the handle it belongs to; for Mastodon we store your instance address and an OAuth token. In both cases we access your profile, your handle, and the posts the App publishes for you. Both credentials are encrypted at rest and are used only to publish and read back what you post through the App.
X
Via the X API with OAuth, we store an encrypted token pair and access: your account ID, username, and profile picture; and the posts the App publishes for you, so you can see and, at your request, delete them. We do not read your timeline, followers, or direct messages.
Telegram
You connect Telegram by adding our bot to a channel or group you administer. We store the chat's ID, title, and type. No personal Telegram credentials are involved. The bot receives only the updates Telegram sends it (the connection code you post and its own membership changes); we do not read your chat history. The bot publishes the messages you compose and can delete the ones it sent, at your request.
Discord
You install our bot into a server you manage and pick a channel. We store the server's ID and name and the channel's ID and name. The bot publishes the messages you compose to that channel and can delete the ones it sent. We do not read message history or member lists.
Slack
When you install the App into a Slack workspace, we store an encrypted bot token together with the workspace and channel names and IDs you select. The bot joins the channels you pick and publishes the messages you compose there. We do not read channel history, files, or member profiles.
Dev.to
You connect Dev.to by pasting an API key you generate, which we store encrypted. We access your profile (username, name, and profile picture) and use the key only to publish the articles you write in the App. Dev.to's API does not allow deleting articles, so removal happens on Dev.to itself.
Tumblr
Via Tumblr's OAuth, we store an encrypted token pair and access: the list of blogs on your account (name, title, and avatar), so you can pick where to publish; and the posts the App publishes for you, which we can delete at your request. We do not read your dashboard, likes, or followers.
Listmonk
Listmonk is newsletter software you host yourself. You connect it with your server's URL plus an API user and token you create in its admin; we store the token encrypted and use it only to read your list names and create and send the campaigns you compose here. Your subscribers and their addresses stay on your server — we never read or store them. Revoke access any time by deleting the API user in your Listmonk admin.
Whop
Whop is a community platform where creators run memberships with their own forums. You connect yours by pasting an API key you create in Whop's developer settings; we store it encrypted and use it only to read your forum names and publish the forum posts you compose here. We never touch your members, payments, or payouts. Whop's API offers no way to delete a post, so removing one is done in Whop itself. Revoke access any time by deleting the API key in your Whop dashboard.
You connect LinkedIn through LinkedIn's own OAuth screen and choose which Company Pages you administer to connect. We store the resulting access token encrypted and use it only to list the pages you administer, publish the posts you compose here, show you the posts published through the App, and delete a post when you ask. We do not read your connections, messages, or feed. Revoke access any time from LinkedIn's Permitted services settings, or by disconnecting the page here.
Nostr
Nostr has no accounts anywhere — your identity is a cryptographic keypair. You either paste your existing private key or we mint a fresh one for you (shown to you exactly once and never stored in plaintext). We keep the key encrypted and use it only to sign the notes you write here and, at your request, signed deletion requests; we also store your public key, display name, and the relay list your notes publish to. Disconnecting erases our encrypted copy — the identity itself remains yours, and the same key keeps working in any Nostr app.
Lemmy
You connect Lemmy by signing in on your own instance (with your two-factor code if you use one). The password is sent to your instance once to create a session and is never stored by us; we keep only the encrypted session token, your username, your instance address, and the communities you pick (name, title, and icon). We use the token only to publish the posts you write and, at your request, delete them. Changing your password on the instance revokes our access instantly. We do not read your subscriptions beyond the picker, your votes, or your messages.
WordPress
Two ways to connect, your choice. For a self-hosted site, you paste an application password you create in wp-admin (not your login password); we store it encrypted along with your username and the site's URL, name, and icon, and use it only to upload the images you attach and publish the posts you write. For a WordPress.com site, we store an encrypted OAuth token scoped to the one site you pick on WordPress.com's own consent screen. In both cases, deleting a post from the App sends it to your site's own Trash, where you can still restore it. We do not read your pages, comments, users, or plugins.
Our use of information received from Meta's APIs adheres to the Meta Platform Terms and Developer Policies, including their data-use and Limited Use requirements. Specifically:
- We request only the permissions necessary for the App's stated features
- We do not sell platform data or disclose it to data brokers. Disclosures are limited to providing the features you authorize, necessary service providers, and legal or security obligations, subject to the platform's data-use restrictions. See the separate disclosures for agents you connect in Section 5 and service providers in Section 6
- We do not use platform data for surveillance, or to discriminate against any person or group
- You can disconnect any account or revoke our access at any time (see Section 10)
YouTube & Google
Social Magnum uses YouTube API Services. By connecting a YouTube channel you agree to be bound by the YouTube Terms of Service, and Google's handling of your information is described in the Google Privacy Policy. You can review and revoke Social Magnum's access to your Google account at any time via the Google security settings page, as well as from within the App.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google user data to serve advertising or sell it. Transfers are limited to purposes permitted by that policy; we do not use it to train generalised AI or machine-learning models, and no human reads it except where you expressly ask us to, where it is necessary for security, or where the law requires it.
TikTok
Our use of information received from the TikTok API adheres to the TikTok Developer Terms of Service. We request only the scopes the App's stated features require, we do not sell TikTok data or disclose it for unrelated purposes, and we do not use it for advertising, surveillance, or profiling. Content is published only when you choose to publish it.
AI Agents & the MCP Connector
You can optionally connect a third-party AI agent. Claude, ChatGPT, Cursor, Codex or any other client that speaks the Model Context Protocol. To your Social Magnum account. Nothing is connected until you approve it yourself, signed in, on our consent screen.
What an approved agent can read. A connected agent can request the same data you can see in the App for the workspace it is working in: your connected accounts and their status, scheduled and published posts and their captions, analytics figures, your media library and drafts, comments and Instagram direct messages on your posts, your workspaces, and the names, email addresses and roles of the people in workspaces you own.
That data leaves our systems. When an agent reads something, the answer is sent to the agent's provider. Anthropic, OpenAI, Google or whoever operates the client you connected. And is handled under their privacy policy, not ours. We do not control how long they keep it, whether they use it to train models, or who at that company can see it. Read the privacy policy of any agent before you connect it.
- The MCP connector sends data in response to requests from an agent you approved. Native AI and UGC features separately process your inputs as explained in Section 6.
- Comments and messages include other people's words. An agent reading your inbox reads what your audience wrote, including their display names. Connecting an agent means that information reaches the agent's provider too.
- No credential is ever shared. An agent never receives your password, your social-network access tokens, or the keys we hold for connected accounts. It holds only its own revocable credential for our API.
- We record when a connection was made and last used, so you can spot activity you did not cause. We do not store the content of the conversations you have with your agent.
Withdrawing access. Every connected agent is listed on the Agents & CLI page, with a Disconnect button for each and one to disconnect them all. Revoking takes effect immediately. The credential stops working on its next request. It does not reach into the agent provider's systems and delete what they already received; for that you would need to use their own controls.
Data Retention
- Connections: disconnecting a shop clears our stored shop credentials and stops new API access. It does not automatically erase its shop record, saved listing drafts, staged media or submission history. Social-account removal and full deletion are explained on our Data Deletion page.
- Social drafts and Media Library: social drafts expire 30 days after their last edit; library uploads expire 30 days after upload. Files still referenced by a post, draft or saved design may remain while needed for that feature.
- UGC videos: saved video records expire 30 days after creation. Referenced media may remain where another saved item still needs it. Brand profiles and job/project records are separate from this media window. Download exports you need to keep.
- Ecommerce: listing drafts, staged images/PDFs and submission records are not subject to the Media Library's automatic 30-day sweep. They remain for the shop workflow until removed or included in a verified deletion request. Order summaries are fetched from the connected platform rather than kept as a separate buyer database. Shopify installation handoffs expire after one hour; expired encrypted grants are removed by our scheduled cleanup. Uninstalling Social Magnum in Shopify revokes access, and our uninstall handler clears stored credentials. When Shopify sends a shop-redaction request, we remove the applicable shop records, product drafts and staged files. A later reinstallation is treated as a new authorization. We promptly remove eBay personal data when it is no longer needed, when the affected user or eBay requests deletion, or when our API participation ends; we do not retain it simply because a draft still exists.
- Account, security and billing: account records remain until deletion; necessary security and accounting records may be retained to meet legal obligations. Restricted backup copies may remain until their normal rotation and are not used for ordinary product access.
We handle verified deletion requests within 30 days, removing or anonymizing the data in scope except records we must retain by law. We explain any applicable exception. For stored YouTube API data, deletion after a request or authorization revocation is handled as soon as possible and within seven calendar days. Any shorter applicable legal or platform deadline takes precedence. Disconnecting does not remove content already published on a marketplace or a social network, or copies downloaded by others.
Data Security
- Token encryption: all platform access tokens are encrypted at rest with AES-256-GCM, using a key stored separately from the database.
- Encryption in transit: all traffic is served over HTTPS/TLS, with HSTS and strict security headers.
- Tenant isolation: every account's data is scoped to that account; workspace roles (owner, admin, member) control who can see and manage which accounts.
- Least privilege: access to production data is limited to personnel who need it.
No method of transmission or storage is 100% secure, but we work to protect your information using industry-standard measures.
GDPR (EU/UK Users)
For personal data of individuals in the EEA and UK, you are the data controller for the content and audience data you manage through Social Magnum, and Social Magnum acts as a data processor: we process that data only to provide the features you enable. For our own account administration, billing, security and support, METAFLUX MEDIA LLC acts as controller, relying on contract performance, legal obligations, legitimate interests or consent as applicable. We collect only what is needed to run the service. Where data is transferred internationally, we rely on recognized safeguards such as Standard Contractual Clauses (see Section 12).
Your Rights & Choices
You can:
- Access, correct, or export the data we hold about you. Email support@socialmagnum.com
- Delete your data. See our Data Deletion page
- Disconnect any connected account at any time in Social Accounts or E-commerce Shops, which stops new access through that connection
- Revoke our access from the platform directly. Via Facebook Settings → Business Integrations, your Instagram apps & websites settings, your Threads account settings, TikTok's Security settings (Apps and websites), the Google security settings page for YouTube, Pinterest's Connected apps settings, by deleting the app password in Bluesky, your Mastodon instance's Authorized apps settings, X's Connected apps settings, by removing the bot from your Telegram channel or Discord server, by removing the app from your Slack workspace, by revoking the API key in your Dev.to settings, Tumblr's Apps settings, by deleting the application password in your WordPress profile, WordPress.com's connected-applications settings, or by changing your password on your Lemmy instance (which invalidates our session token), or for Nostr by disconnecting the identity here — that erases our encrypted copy of the key, which is the only access we ever had — and for Listmonk by deleting the API user in your server's admin, and for Whop by deleting the API key in your Whop dashboard's developer settings, and for LinkedIn under Settings → Data privacy → Permitted services
- Shopify: uninstall Social Magnum through Shopify Admin to revoke access. For a copy or deletion of our stored shop data, contact us with your workspace and shop domain. We also process Shopify's mandatory customer-data and shop-redaction requests. We do not retain customer contact records.
- Etsy: revoke Social Magnum in Etsy's account settings under connected apps. For deletion of our saved drafts, files or history, email us with the workspace and shop name. Never send passwords or tokens.
- Opt out of product/marketing emails using the unsubscribe link (account and billing notices still apply)
Depending on where you live (e.g., EEA/UK, California, Virginia, Colorado), you may have additional rights and the right to lodge a complaint with your local data protection authority.
International Data Transfers
We and our sub-processors may process data in the United States and other countries. Where we transfer personal data out of the EEA/UK, we rely on appropriate safeguards, including Standard Contractual Clauses, to ensure an adequate level of protection.
Children's Privacy
Social Magnum is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 13 (or under 16 in the EU). If you believe a child has provided us personal data, contact us and we will delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be posted here with a new "Last updated" date and, where appropriate, communicated by email. Continued use of the App after changes take effect constitutes acceptance.
Contact Us
For privacy questions or data requests:
- Email: support@socialmagnum.com
- Mail: METAFLUX MEDIA LLC, 30 N Gould St, Ste 23881, Sheridan, WY 82801, United States

Questions about your data?
Privacy questions and data requests go to the people who actually built the product, and we answer for real. The data-deletion page explains how to request removal, what remains on external platforms, and any legal retention exceptions. We handle verified requests within 30 days or an applicable shorter deadline.