Privacy Policy
Effective date: 19 April 2026 · Last updated: 19 April 2026
This privacy policy applies to the Communitee Socials application (the “App”), accessible at https://social.communitee.ai. It explains what information the App collects, how that information is used, how Google and Meta user data is handled, and the rights you have over your information.
Communitee Socials is operated by COMMUNITEE AI - FZCO, a Free Zone Company with limited liability registered in Dubai under registration number DSO-FZCO-51546 (“we”, “us”, “our”). For any questions about this policy or your personal data, contact our Privacy Officer at privacy@communitee.ai.
The Communitee Socials App is a separate product from the communitee.ai training course website. The training website has its own privacy policy available at https://communitee.ai/privacy.
1. What the App does
Communitee Socials is a closed, invitation-only platform that helps a vetted network of affiliate creators publish compliant social media content across Facebook Pages and YouTube. The App provides content scheduling, compliance-aware caption generation with advertising disclosures, a post-approval workflow where users review and approve each post before publication, and a unified inbox for reviewing audience engagement.
Access to the App is by invitation only from the Communitee partnership team. There is no public signup.
2. Information we collect
2.1 Account information
- Your email address (used as your login identifier)
- Your name (if you choose to provide it)
- A password hash (we never see or store your password in readable form — authentication is handled through Supabase Auth)
2.2 Information you connect from Facebook (Meta Platforms)
When you choose to connect a Facebook Page to Communitee Socials, Meta asks for your permission to share the following data with us. We only receive this data after you explicitly grant these permissions, and you can revoke them at any time.
- Facebook Page list (via the
pages_show_listpermission) — so you can choose which of your Pages to connect. - Page access tokens (via the
pages_manage_postsandpages_read_engagementpermissions) — used to publish approved posts to your Page and to read engagement so we can show it to you in the unified inbox. - Page messages and conversations (via the
pages_messagingpermission) — used only when you enable the Messenger inbox feature, to display recent conversations so you can respond manually. - Posts and engagement metrics you create through the App — we store a record of what was posted, when, and basic engagement counts.
We do not collect, store or access your personal Facebook profile information, friend list, private messages unrelated to the connected Page, or any information about other users on Facebook who interact with your Page beyond the public engagement counts.
2.3 Information we receive from Google (including YouTube data)
Communitee Socials uses YouTube API Services to connect to your YouTube channel. When you choose to connect, Google asks for your permission to share the following data with us. We only receive this data after you explicitly grant permission. By connecting your YouTube channel, you also agree to be bound by the YouTube Terms of Service.
- YouTube channel information (via the
youtube.readonlyscope) — used to retrieve your channel name, ID, profile image and subscriber count so you can confirm which channel is connected and view basic channel metrics in your dashboard. - YouTube upload permission (via the
youtube.uploadscope) — used solely to upload videos that you have approved for publication inside the App. - YouTube comment access (via the
youtube.force-sslscope) — used to read comments on videos published through the App and to post replies that you compose in the engagement inbox. We only access comments on videos published through Communitee Socials. - Basic profile information (name, email, profile picture) — used to identify which Google account is connected and display it in the App's settings.
Communitee Socials' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We use Google user data only to provide and improve the App's core features (uploading approved videos to your YouTube channel).
- We do not transfer Google user data to third parties except as necessary to provide the core features, to comply with applicable law, or as part of a merger, acquisition or sale of assets where the recipient is bound by the same restrictions.
- We do not use Google user data to serve advertisements, including personalised or retargeted advertising.
- We do not allow humans to read Google user data except (a) with your explicit permission for specific messages, (b) where necessary for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) where the data has been aggregated and anonymised and is used for internal operations.
- We do not use Google user data to train or fine-tune any generalised or non-personalised AI or machine learning models.
2.4 Content you create through the App
- Draft posts and captions (including any AI-generated suggestions you review and edit)
- Advertising disclosure text automatically appended to posts (“#ad #affiliate”) as required by the ASA/CAP Code
- Scheduling information (when posts are scheduled to publish)
- Approval workflow history (which posts were approved, skipped, or edited)
- Engagement metrics for posts you publish (likes, comments, views)
2.5 Technical and usage data
- Log data (IP address, browser, device type, timestamps) used for security, debugging and abuse prevention
- Cookies and session tokens required to keep you logged in
3. How we use your information
- To give you access to the App and its features
- To publish posts and videos to your connected Facebook Pages and YouTube channels only after you have approved them
- To show you engagement data for your own Pages and channels inside the App
- To enforce advertising disclosure rules (ASA/CAP Code compliance) on posts generated through the App
- To provide customer support and respond to your requests
- To investigate and prevent abuse, fraud and security incidents
- To comply with legal obligations
We do not:
- Sell your data to anyone
- Share your data with advertisers or data brokers
- Use your Facebook or Google data to train AI models
- Post anything to your accounts without your explicit approval
- Access data from Facebook Pages or YouTube channels that you have not explicitly connected
4. Legal basis for processing (UK/EU users)
- Contract — processing is necessary to provide the service you've signed up for.
- Consent — for connecting your Facebook and Google accounts, which you grant through the OAuth permission screens and can revoke at any time.
- Legitimate interests — for security, fraud prevention and basic service analytics.
- Legal obligation — where retention or disclosure is required by law.
5. How we store and protect your data
- Where data is stored: Supabase (eu-west-2 region) and Vercel (global edge). Both providers are compliant with GDPR and apply industry-standard security controls.
- Encryption at rest: all database content is encrypted at rest.
- Encryption in transit: all communication between your browser, the App, and the Facebook/Google APIs is encrypted using TLS.
- OAuth tokens: access tokens and refresh tokens we receive from Facebook and Google are stored encrypted in our database and are only used server-side. They are never exposed to your browser.
- Access controls: only a small number of authorised staff can access production systems, and only for support and security purposes.
- Row-level security: the App uses Supabase Row-Level Security policies to ensure each user can only see their own data.
6. How long we keep your information
- While you are an active user — we keep your account data, connected tokens and post history for as long as your account is active.
- After you disconnect a platform — we delete the associated access tokens and revoke our access. If you disconnect via the App, associated platform data (comments, engagement metrics) is deleted within 7 days. If you revoke access via Google or Facebook's security settings, we delete the associated data within 30 days.
- YouTube data — video metadata, comment data and engagement metrics retrieved from the YouTube API are refreshed from the API on each access and are not cached beyond 30 days. When you disconnect your YouTube channel, all stored YouTube data is deleted in accordance with the timelines above.
- After you delete your account — we delete your account and associated personal data within 30 days, except where we are required by law to retain specific records.
- Logs and security records — kept for up to 12 months.
- Aggregated, anonymised usage statistics — may be kept indefinitely.
7. Your rights
If you are in the UK or EU, you have the following rights over your personal information:
- Right of access — request a copy of the data we hold about you
- Right to rectification — ask us to correct inaccurate data
- Right to erasure — ask us to delete your data (the “right to be forgotten”)
- Right to restrict processing — limit how we use your data
- Right to data portability — receive your data in a machine-readable format
- Right to object — object to certain types of processing
- Right to withdraw consent — disconnect any platform at any time
To exercise any of these rights, email privacy@communitee.ai. We will respond within one month.
You also have the right to complain to a supervisory authority. In the UK, that is the Information Commissioner's Office (ICO) at ico.org.uk.
8. How to disconnect or delete your data
- Disconnect a platform — go to Platforms from the sidebar navigation and click Disconnect next to the platform you want to remove. This immediately revokes our access tokens for that platform and deletes them from our database.
- Delete your account entirely — email support@communitee.ai from the email address associated with your account with “Delete my account” in the subject line. This removes your account, all connected tokens, post history and profile information within 30 days.
For full details, see our Data Deletion Instructions.
You can also revoke our access directly from the platform providers at any time:
- Facebook: Settings → Business Integrations → Communitee Socials → Remove
- Google: https://myaccount.google.com/permissions → Communitee Socials → Remove access
8.1 Removing access via Facebook or Google
You can also revoke our access directly from the platform providers at any time, without logging in to Communitee Socials:
- Facebook: Go to your Facebook Settings → Business Integrations → Communitee Socials → Remove
- Google: https://myaccount.google.com/permissions → Communitee Socials → Remove access
If you revoke access via Facebook or Google, please also email support@communitee.ai so we can ensure all associated data is removed from our systems within 30 days.
9. International data transfers
Communitee Socials is operated by COMMUNITEE AI - FZCO, which is established in the United Arab Emirates. If you are accessing the App from the United Kingdom, the European Economic Area, or another jurisdiction with data protection laws, your personal data will be transferred to, processed and stored in countries outside your own — including the UAE (where the controller is based) and the countries where our sub-processors operate (see Section 9a).
The UAE is not currently the subject of a UK or EU “adequacy decision”. Where personal data is transferred from the UK or EEA to the UAE or to any other country not covered by an adequacy decision, we rely on appropriate safeguards to protect your data, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- The UK International Data Transfer Addendum to the EU SCCs, or the UK International Data Transfer Agreement (IDTA), where the transfer is from the UK;
- Additional technical and organisational measures such as encryption in transit and at rest, access controls, and minimisation of data shared with each sub-processor.
You can request a copy of the safeguards we rely on for a specific transfer by emailing privacy@communitee.ai.
9a. Sub-processors and service providers
We use a limited set of trusted third-party service providers (“sub-processors”) to operate the App. Each sub-processor is contractually bound to protect your data and to process it only on our instructions.
- Supabase, Inc. — database, authentication, file storage (EU, eu-west-2, Ireland).
- Vercel Inc. — application hosting and edge network (United States and global edge network).
- Anthropic, PBC — AI caption generation (large language model inference) (United States).
- Meta Platforms, Inc. — receiving Facebook Page connections and publishing approved posts (as per Meta Platform Terms).
- Google LLC (incl. YouTube) — receiving YouTube channel connections and uploading approved videos (as per Google Terms).
We may update this list from time to time. Where a change is material, we will update this page and notify active users by email at least 14 days before the new sub-processor begins processing your data.
10. Children
Communitee Socials is not directed at children under 18. We do not knowingly collect personal information from anyone under 18. If you believe we have collected information from a child, please contact privacy@communitee.ai and we will delete it.
11. Third-party platforms
Communitee Socials connects to Facebook (Meta Platforms) and YouTube (Google). When you use those connections, your activity is also subject to those platforms' own privacy policies:
- Meta Privacy Policy: https://www.facebook.com/privacy/policy
- Google Privacy Policy: https://policies.google.com/privacy
- YouTube Terms of Service: https://www.youtube.com/t/terms
12. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the “Last updated” date and notify active users by email at least 14 days before the changes take effect.
13. Contact us
If you have any questions about this privacy policy, or to exercise any of your rights:
- Data Protection Contact: privacy@communitee.ai
- General Support: support@communitee.ai
- Postal Address: COMMUNITEE AI - FZCO, Premises No 53892 001, IFZA Business Park DDP, Dubai Silicon Oasis, PO Box 342001, Dubai, United Arab Emirates
- Registration: DSO-FZCO-51546 (Dubai Integrated Economic Zones Authority)
- App URL: https://social.communitee.ai
See also: our Terms of Service.