Privacy policy
This version took effect on 22 August 2026.
1. Who we are
This service is operated by DEVIORA S.R.L., a limited liability company registered in Romania (societate cu răspundere limitată, or S.R.L.), of Calea Șerban Vodă 282, Sector 4, București 040221, Romania, holding tax identification number (CUI) 55471145 and trade register number J2026051139003, with a share capital of 500 lei. In this policy “we” and “us” mean that company, and “you” means the person using the service or the organisation they use it on behalf of.
For anything about this policy or about your data, write to hello@crestnote.com.
Where data protection law applies to you, we are the controller of the account and billing data described below, and we act as a processor on your instructions for the content you create and the social accounts you connect.
2. What we collect, and where it comes from
Your account. Your email address, your name if you give one, and a password that we never see in readable form: authentication is handled by Supabase Auth, which stores a hash rather than the password itself. We also hold the workspaces you belong to, your role in each, and the workspace name, URL slug and timezone.
The social accounts you connect. When you connect an account we receive from that platform an access token, sometimes a refresh token, the platform’s own identifier for the authorising person, the handle, display name and avatar of each account the login gives access to, the permissions actually granted, and any expiry. Tokens are stored as AES-256-GCM ciphertext under a key held outside the database, are decrypted only inside our servers at the moment they are used, and are never sent to a browser.
What you create. Drafts, captions, scheduling times, notes, and any image, video or file you upload or generate. Uploaded files are held in object storage and are addressed by a path that cannot be guessed.
What we collect on a schedule from the platforms, on your behalf. Once an account is connected, background jobs periodically read: follower counts, so the service can show a trend; posts published through us and their platform identifiers; and comments on those posts, including the commenter’s public display name, a link to their profile and the text of the comment. Comments are read so you can reply to them from here. If a figure cannot be read, we record nothing rather than recording a zero.
Competitor profiles you choose to track. If you add a public profile to follow, we record the identifier you gave and the public figures the platform publishes for it, on a schedule, so the history is there when you look. We use each platform’s own sanctioned interface for this and nothing else.
Billing. If you subscribe, payment is taken by Stripe. Card details are entered on Stripe’s systems and we never receive or store them. We hold the identifiers Stripe gives us for your customer and subscription record, and your plan.
Technical data. Ordinary server logs from our hosting provider, which include IP address, user agent, the URL requested and the time, plus error diagnostics. These are operational and are not used to profile anybody.
Cookies. Only cookies that are strictly necessary to run the service: signing you in, keeping you signed in, remembering which workspace you were in, carrying out a dismissal you asked for, and protecting the handshake when you connect a social account. There is no analytics cookie, no advertising cookie and no third-party tracker on this service. The cookie policy names every one of them and says how long it lasts. Your light or dark theme preference is kept in your own browser’s local storage and is never sent to us.
3. Why we hold it
- To run the service you asked for: publishing your posts at the times you chose, showing your figures, and letting you reply to comments. This is the performance of our contract with you.
- To keep the service working and secure: rate limits, abuse prevention, error diagnosis, backups. Our legitimate interest, and yours.
- To take payment and meet the tax and accounting obligations that follow from it.
- To contact you about the service itself: a publish that failed, a connection that expired, a change to these terms. Not marketing, unless you have asked for it, which you can stop at any time.
4. What we send to AI providers
Several features generate text or images: captions, per-platform rewrites, drafted replies to comments, and image generation. To do that we send the relevant material to a model provider over their commercial API. That material can include the draft you are writing, your brand description and tone settings, the post being replied to and the comment being replied to.
The providers we use for this are Anthropic and OpenAI. We use their commercial APIs under terms that do not permit your content to be used to train their models, and we do not opt in to any programme that would allow it. We do not send them your access tokens, your password, your payment details, or any figure collected about a competitor profile.
Generated text and images are drafts. Nothing is published to a connected account unless you or a schedule you created asked for it.
6. Where it is held
Everything we store ourselves is stored in the European Union. The database, the files you upload and the authentication records sit in Supabase’s eu-west-1 region, which is Ireland, and the application runs in Vercel’s dub1 region, which is Dublin.
Some of the processors in section 5 are outside it. Anthropic, OpenAI and Stripe are United States companies, so the material described in section 4 and the payment details you give Stripe are handled there. The social platforms you connect handle what we send them wherever they operate. Where personal data covered by UK or EU law is transferred out of that area, the transfer relies on the mechanisms in the relevant provider’s data processing terms, including the Standard Contractual Clauses where they apply.
7. How long we keep it
Content, connections and collected figures are kept while your workspace exists, because the history is the product: a follower trend cannot be rebuilt after it is deleted, and no platform will hand back the period before you started measuring.
Deleting a workspace is something you ask us to do rather than something you can press: write to hello@crestnote.com from the address you signed up with, and we delete its content, media, connections, comments and collected history. Access tokens are destroyed as soon as a connection is removed or revoked, not on a schedule, and that part you can do yourself at any time.
Two things deliberately outlive the rest. Invoices and payment records are kept for as long as tax law requires. A record that a deletion request was made and completed, and on what date, is kept as evidence that we honoured it. That record keeps one piece of personal data with it, indefinitely: the identifier the platform gives us for the person who asked. We cannot drop it and still answer the status page that platform hands you, tell a repeat of the same request from a new one, or show anybody that the deletion happened. Section 9 describes what that identifier is and what it is not.
8. Your rights
Depending on where you live you may have the right to a copy of your data, to have it corrected, to have it deleted, to take it elsewhere, to object to some processing, and to restrict it. Write to hello@crestnote.com and we will answer within the period the applicable law allows, at no cost.
If you are in the UK or the EU and you think we have handled your data badly, you may complain to your supervisory authority. Ours is the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), at www.dataprotection.ro.
If you are in California, we do not sell or share personal information as those terms are defined by the CCPA, and we do not discriminate against anybody for exercising a right under it.
9. Deleting data connected through Facebook or Instagram
There are two different things you can do, and they have different consequences. This distinction matters most to agencies, where the person who connected an account is often not the person who owns the content.
Removing our app from your Facebook settings ends the connection. Facebook tells us, and we immediately mark those connections as revoked and destroy every access token derived from that login, in every workspace it was used in. The workspace keeps its own posts, media, comments and figures, and can reconnect later.
Requesting deletion of your data goes further. You can start it from Facebook, under Settings, then Apps and Websites, by choosing this app and requesting that your data be deleted; or you can write to hello@crestnote.com and ask us directly. When the request arrives we delete the records tied to you as a person, which are your name, your handle, your profile picture and the platform’s identifier for you, and we destroy every credential derived from your login. One copy of that identifier survives, in the record of the request itself, described at the end of this section. It survives nowhere else.
We do not delete the workspace’s own content in response to that request: its posts, its uploaded media, the comments on its posts and its follower history belong to the organisation, not to the person who connected the account, and one employee leaving must not erase a company’s archive. To delete a workspace and everything in it, an owner of that workspace should ask us.
A deletion request started from Facebook returns a confirmation code and a link to a page where you can check its progress at any time. We keep the record of that request as evidence that we honoured it, and we keep it indefinitely. It holds four things: the identifier Facebook gives us for you, the date the request arrived, the date it completed, and how many records were removed. Nothing else about you is stored with it, and the identifier is never shown on the status page or anywhere else in the product.
We are explicit about that identifier because keeping it is the one part of this that is not erasure. It is app-scoped: Facebook mints a different one for every app, so it is not your Facebook username, your account number, or anything that identifies you to us or to anybody else once your other records are gone. Holding it is what lets the status page keep answering you, lets us recognise a repeat of the same request rather than running it twice, and lets us demonstrate to you or to a regulator that the deletion happened and when. If you would rather we did not keep even that, write to hello@crestnote.com and say so, and we will weigh your objection against those reasons and tell you the outcome.
10. How it is protected
- Access tokens are encrypted with AES-256-GCM before they reach the database, under a key the database does not hold, and are decrypted only inside our servers.
- Ciphertext lives in a part of the database that the public interface cannot reach at all, so no browser can request it, whatever else goes wrong.
- Every table is protected by row-level security keyed to workspace membership, so one customer’s query cannot return another customer’s rows.
- Everything is served over TLS. Passwords are stored only as hashes.
- Error messages stored for you to read are stripped of anything credential-shaped before they are written.
No service can promise it will never be breached. If one happens and it affects you, we will tell you and the relevant regulator within the time the law requires.
11. Children
This is a business tool and is not directed at children. Do not use it if you are under sixteen, or under the age at which you can agree to this in your own country if that age is higher. If we learn that we hold a child’s data we will delete it.
12. Changes to this policy
When this policy changes, the date at the top changes with it. If a change materially affects what we do with your data, we will tell you inside the product or by email before it takes effect, rather than relying on you to notice.
13. Contact
DEVIORA S.R.L., Calea Șerban Vodă 282, Sector 4, București 040221, Romania. Telephone +40 725 680 625. Data protection enquiries, and everything else: hello@crestnote.com.