Back

Privacy Policy

Last updated: 10 July 2026

Platform-API registration: Our app URL is https://www.heysocialfish.com and this Privacy Policy is accessible at https://www.heysocialfish.com/legal/privacy as required for TikTok, Google/YouTube, LinkedIn, X, and Meta (Facebook/Instagram) API registrations.

1. Who We Are

HeySocialFish Ltd ("we", "us", "our") is the data controller for personal data collected through the HeySocialFish platform. We are registered in England and Wales.

Website & App: https://heysocialfish.com

Contact: support@heysocialfish.com

We're a small, independent team. This policy is written to be understood, not to bury the important bits in legalese. If anything is unclear, just ask us directly.

2. What Data We Collect

Account data: Name, email address, password (hashed), subscription tier, billing information (processed via payment gateway — we do not store card details).

Content data: Content you create, upload, or generate using the platform, including posts, video analysis results, strategy plans, and campaign data.

Platform connection data: OAuth access + refresh tokens for connected social platforms (YouTube/Google, TikTok, LinkedIn, X, Instagram, Facebook) and for social sign-in providers (Google, Microsoft, LinkedIn). These are stored in encrypted secret storage. See Section 3 for a per-platform breakdown of scopes, purpose, and revocation.

Usage data: AI credit usage, feature usage, log data, session information, and error reports.

Technical data: IP address, browser type, device identifiers, and cookies (see Cookie Policy).

3. Connected Platforms — What We Access and Why

When you connect a third-party platform via the Connect page, or sign in with a social provider, we access data from that provider through their OAuth 2.0 API. We only request the scopes needed for features you have explicitly enabled in HeySocialFish. Below is a per-platform breakdown of scopes, purpose, and how you can revoke access at any time.

3.1 Publishing platforms (used when scheduling / publishing posts)

YouTube (Google): Scopes youtube.readonly + youtube.upload. We read the connected channel's name, ID, and recent uploaded video titles for display on your dashboard and in scheduling-confirmation modals. We publish videos you have composed inside HeySocialFish (uploads land as Private by default per the YouTube Data API — you promote to Public from YouTube Studio when ready). We do not access analytics, comments, DMs, or other channels. Disconnect on /connect (deletes our token immediately) or revoke at myaccount.google.com/permissions.

TikTok: Scopes user.info.basic + video.upload + video.publish. We read the connected TikTok handle for display and scheduling confirmations. We publish videos you have composed inside HeySocialFish via the Content Posting API, gated by an in-app confirmation modal naming the platform, handle, and scheduled time. TikTok data is processed in accordance with TikTok's Privacy Policy. Disconnect on /connect or revoke via TikTok's app settings.

LinkedIn (publishing): Scopes w_member_social + r_liteprofile + r_emailaddress. We read your LinkedIn name + email for display, and publish posts you have composed inside HeySocialFish to your LinkedIn feed. Disconnect on /connect or via LinkedIn's data-sharing preferences.

X (Twitter): Scopes tweet.read + tweet.write + users.read + offline.access. We read your X handle for display and publish tweets you have composed inside HeySocialFish. The offline.access scope holds a refresh token so you don't re-authenticate every few hours. Disconnect on /connect or via X's Connected Apps settings.

Facebook (Meta): Scopes pages_show_list + pages_manage_posts + pages_read_engagement. We list Pages you manage so you can select a target Page, then publish posts you have composed inside HeySocialFish to the Page you selected. Disconnect on /connect or via Facebook's Business Integrations settings.

Instagram (Meta): Scopes instagram_basic + instagram_content_publish + pages_show_list. We access your Instagram Business account (linked via a Facebook Page) and publish media you have composed inside HeySocialFish. Same revocation as Facebook — disconnect on /connect or via Meta's Business Integrations settings.

3.2 Sign-in providers (used to log in to HeySocialFish itself)

These OAuth grants are entirely separate from the publishing OAuths above. Different apps registered with each provider, different scopes, different purpose — just identifying you to create or log you into your HeySocialFish account.

Sign in with Google: Scopes openid + email + profile. We read your Google display name and email address to create or link your HeySocialFish account. We do not access YouTube, Drive, Gmail, or any other Google service via this scope. Revoke at myaccount.google.com/permissions.

Sign in with Microsoft: Scopes openid + email + profile + User.Read. We read your Microsoft display name and email for account creation/linking. We do not access Outlook, OneDrive, Teams, or any other Microsoft service via this scope. Revoke at account.live.com/consent/Manage or, for work/school accounts, via your Entra tenant admin.

Sign in with LinkedIn: Scopes openid + email + profile. We read your LinkedIn display name and email for account creation/linking. This is a distinct LinkedIn OAuth app from our publishing integration above — no content-write scope. Revoke via LinkedIn's data-sharing preferences.

3.3 OAuth token storage and deletion

All OAuth access + refresh tokens are stored in encrypted secret storage. They are never exposed in plaintext, cannot be retrieved via the application interface, and are not shared with any third party beyond the intended platform integration. On disconnect, we delete the token record from that secret store within the same request. If you delete your HeySocialFish account, all connected platform tokens are purged as part of the standard 90-day account deletion (see Section 9).

What we don't do: We do not store copies of your published content beyond a short-term cache used for retry logic on failed publishes. We do not read your DMs, private messages, or non-public content on any connected platform. We do not share your OAuth token with any third party. We do not use OAuth data to train AI models.

3.4 Google API Services User Data Policy compliance

HeySocialFish's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we use YouTube API data only to power the features described in Section 3.1 (display the connected channel + publish user-composed videos). We do not use it for advertising. We do not sell it. We do not use it to train generalised AI models. We allow humans to read it only where required for security, to comply with law, or with your explicit permission.

3.5 Disclosure: who we share Google user data with

To be explicit about disclosure of data received from Google APIs (including YouTube Data API v3 and Google Sign-In):

  • We do not sell Google user data. We do not sell any user data, ever, to anyone.
  • We do not share Google user data with advertisers, ad networks, data brokers, or analytics providers. HeySocialFish contains no third-party advertising trackers.
  • We do not transfer Google user data to any third party outside the list below. Every named processor is engaged strictly to deliver HeySocialFish's stated features; each operates under a Data Processing Agreement and is bound by their own privacy policy.

Categories of processor that may handle Google user data:

  • Our cloud infrastructure provider (UK data residency) — hosts our application, encrypted database, and secure token storage. Google OAuth tokens are held in encrypted secret storage; profile fields (email, display name, picture URL) and YouTube channel metadata (channel id/title, uploaded video ids and their metadata for scheduling/analytics) are held in our encrypted database. No cross-border transfer of Google user data outside the UK/EEA.
  • OpenAI — receives only content you deliberately submit to an AI feature (e.g. a caption you asked Copilot to help write, a transcript for the Video Splitter). We do not send raw Google user profile data or YouTube listing data to OpenAI. OpenAI processes prompts under its enterprise privacy commitments and does not use API content to train shared models.
  • Stripe and GoCardless — payment processors. They receive billing details (name, email, address, card/DD data submitted on their hosted forms). They never receive Google user data or YouTube data.
  • Brevo — transactional email provider. Receives only recipient email address + the transactional message body (verification, password reset, receipts). Never receives Google user data or YouTube data.
  • Google (YouTube Data API v3, Google Identity) — the originating platform. We call Google's own APIs to read the channel state and publish videos you have composed in HeySocialFish. This is not a "transfer to a third party" — it is fulfilling the purpose Google authorised the token for.
  • Operational tooling (error monitoring, uptime checks) — receives only sanitised technical metadata (route, status code, timing). Personal identifiers, OAuth tokens, and API content are stripped before submission. Never receives Google user data or YouTube data content.

A complete, current list of sub-processors is maintained internally and available to users on request at support@heysocialfish.com.

Legal disclosure only: Google user data may be disclosed to law-enforcement or regulators where legally required (e.g. a valid UK court order or a lawful information notice from the ICO). We will notify affected users unless legally prohibited from doing so.

Merger, acquisition, or change of control: If HeySocialFish Ltd is acquired or merged, we will notify users in advance via email and give at least 30 days to export or delete data. The acquirer must honour these terms or offer a comparable protection level; a link to the successor privacy policy will be published here.

Any change to who we share Google user data with will be reflected in this section and communicated by email to active users at least 14 days before it takes effect.

4. How We Use Your Data

  • To provide, maintain, and improve the Service
  • To personalise AI Copilot guidance and content suggestions
  • To process subscription payments and manage your account
  • To send service-critical notifications (account, billing, security alerts)
  • To send product updates and hints (you can opt out any time)
  • To investigate abuse, fraud, or policy violations
  • To comply with legal obligations

We do not sell your data to third parties. We do not use your content to train AI models shared with other customers.

5. Legal Basis (UK GDPR)

  • Contract: Processing necessary to provide the Service under our Terms of Service
  • Legitimate interest: Security monitoring, fraud prevention, service improvement
  • Consent: Marketing communications (opt-in)
  • Legal obligation: Compliance with applicable law

6. Data Storage, Security & Workspace Protection

All data is stored on cloud infrastructure with UK data residency. We apply encryption at rest and in transit, role-based access controls, and regular security reviews.

Workspace isolation: Each user account operates within a private, isolated workspace. Your workspace data — plans, content, analytics, AI interactions — is stored separately and is not accessible to any other user of the platform. No cross-user data queries are possible through normal or API-level use of the Service.

Connected platform credentials: OAuth tokens for connected social platforms (TikTok, LinkedIn, Instagram, X, YouTube, Facebook) are stored in encrypted secret storage. They are never exposed in plaintext, cannot be retrieved via the application interface, and are not shared with any third party beyond the intended platform integration.

Staff access: HeySocialFish staff do not access workspace content in the normal course of operations. Access may occur only where strictly necessary for technical support you have requested, or to comply with a legal obligation — and only with appropriate authorisation and logging.

Your responsibility: While we protect your data on our end, you are responsible for the security of the devices and credentials used to access your account. If you choose to share your login with others, you accept responsibility for their actions within your workspace. We cannot protect your account from risks you introduce yourself.

7. Third-Party Processors

We use the following third-party processors under Data Processing Agreements. Each is engaged for a narrow, defined purpose and is bound by their own privacy policy and (where applicable) UK GDPR standard contractual clauses:

  • Cloud infrastructure provider — hosts our application, encrypted database, object storage, and secret storage. UK data residency. Named on request.
  • OpenAI — sole AI provider for HeySocialFish. Powers the Copilot, Content Plan Generator, Post Composer, Video Splitter moment selection + captions, and Text Repurposer via GPT language models, plus Video Analysis + Video Splitter transcription via Whisper. Content sent to OpenAI is not used to train their models (per their enterprise privacy commitments). If we add additional AI providers in future we will update this page and the AI Disclaimer before starting to route your content to them.
  • Stripe — card payment processing. Card details are entered on Stripe's hosted form; we never see or store card numbers. Stripe operates under their own privacy policy and is authorised by the FCA under FRN 900461.
  • GoCardless — Direct Debit payment processing for UK subscribers who prefer bank-debit. Bank details are not stored by us; GoCardless operates under their own privacy notice and is authorised by the FCA under the Payment Services Regulations 2017 (FRN 597190).
  • Brevo (formerly Sendinblue) — transactional email delivery (verification, password reset, team invitations, beta welcome, billing confirmations). Brevo processes email delivery under their own privacy policy.
  • Connected platform providers — TikTok, Google/YouTube, LinkedIn, X, Meta (Facebook/Instagram). We interact with these via their public OAuth 2.0 APIs when you have explicitly connected them (see Section 3). We are not a "processor" for these providers — each is the controller of its own data on its own platform.

8. Data Retention

We retain your data for as long as your account is active. On account closure, we delete personal data within 90 days, except where we are required to retain it for legal or financial compliance purposes (typically 7 years for financial records under UK law).

8b. Your Contacts' Data — CRM Features (Improver & Pro)

HeySocialFish Improver and Pro tiers include CRM-style contact management features (the "Contacts" section of the Sales Hub). These features allow you to store names, email addresses, and engagement notes about your own contacts — people you are communicating with in your business.

You are the data controller for your contacts' data. HeySocialFish acts only as a data processor on your behalf for this data. Your contacts have rights under UK GDPR that you are responsible for honouring:

  • Right to be forgotten: If one of your contacts requests erasure of their data, you must delete them from the Contacts section. Use the Delete action on their record, or export and purge their data.
  • Unsubscribe requests: If a contact no longer wishes to receive email from you, you must respect that. Use the Unsubscribed tag on their contact record and do not include them in future mail sends. HeySocialFish does not add automated unsubscribe footers to mail sent from the Sales Hub — this is your responsibility.
  • Consent: You should only store contacts for whom you have a legitimate reason to hold data (e.g. they are a business contact, a customer, or have opted in to hear from you). Do not use the Contacts feature to store data obtained without a lawful basis.
  • Data portability: Use the Export CSV button to provide a contact with a copy of their data if requested.

HeySocialFish stores your contact data on the same secure cloud infrastructure as your other workspace data. Contact data is workspace-isolated and never shared with other users. We do not use your contacts' data for any purpose beyond providing the CRM feature to you.

If a contact of yours contacts us directly requesting erasure or unsubscription, we will forward that request to you as the controller. We cannot act on it without your instruction unless legally required to do so.

9. Your Rights (UK GDPR)

You have the following rights regarding the personal data we hold about you as a HeySocialFish user:

  • Access — request a copy of the data we hold about you
  • Rectification — correct inaccurate data
  • Erasure ("right to be forgotten") — request deletion of your account and all associated personal data
  • Restriction — limit how we use your data
  • Portability — receive your data in a machine-readable format (JSON/CSV)
  • Object — object to processing based on legitimate interest
  • Withdraw consent — at any time, for processing based on consent
  • Unsubscribe from marketing — use the unsubscribe link in any marketing email, or use the button below
Exercise your rights

To request erasure, a data export, or unsubscription — email us with your registered email address and the action requested. We will respond within 30 days.

✉ Submit a GDPR request
Or write to: HeySocialFish Ltd — support@heysocialfish.com — subject line: GDPR Request

You may also lodge a complaint with the ICO (Information Commissioner's Office) at ico.org.uk.

10. Cookies

We use cookies and similar tracking technologies. See our Cookie Policy for full details.

11. Changes to This Policy

Material changes will be notified via email or in-app notification. The latest version is always available at: https://www.heysocialfish.com/legal/privacy.

11b. Your Responsibilities as a User

When you use the Sales Hub CRM and mail features, you take on responsibilities as a data controller for your contacts' personal data. These include:

  • Ensuring you have a lawful basis for holding and contacting each person in your CRM
  • Honouring unsubscribe and erasure requests promptly
  • Not using the platform to send unsolicited bulk email (spam)
  • Keeping contact data accurate and up to date

HeySocialFish provides the tooling; the legal responsibility for how you use it rests with you. Our Terms of Service reflect this responsibility.

12. A Note to Early Adopters

If you're one of our early users — thank you. Your data protection matters to us, and so does your trust. We will never do anything unexpected with your data, and we welcome questions or concerns at support@heysocialfish.com. Early adopters have a direct line to the team and a real say in how the platform develops. Use it.

Terms of Service →Cookie Policy →AI Disclaimer →Data Deletion →