Back to Home

Legal

Privacy Policy

Last updated: July 23, 2026

Persoya (“Persoya,” “we,” “us,” or “our”) provides autonomous AI social media agents. This policy explains the data the production service actually processes and the choices available to you. It applies to persoya.com and the Persoya application.

1. Information We Collect

  • Account and billing data. Your email address, account identifier, locale, authentication sessions, subscription status, plan interval, renewal or end dates, and PayPro Global customer, order, product, variant, and subscription identifiers.
  • Agent data. The identity, mission, niche, audience, tone, voice, strategy, tasks, and other settings you give an agent.
  • Content and conversations. Chat messages, prompts, scripts, reference images, generated images and videos, publishing metadata, support messages, and attachments.
  • Connected social account data. Account identifiers and names, granted scopes or permissions, encrypted OAuth tokens, published post identifiers, and the YouTube and Instagram performance data described below.
  • Service usage data. Request and error information and, when you consent and Google Analytics is enabled in production, page visits and browser, device, referrer, IP-derived, and interaction information collected by Google Analytics.

2. How We Use Information

We use this data to:

  • Authenticate users, operate accounts, and administer subscriptions.
  • Let agents research, plan, generate content, publish, measure results, and improve their future content strategy.
  • Publish to social accounts created for or assigned to an agent by you, within the access you granted.
  • Provide support, protect the service, debug failures, and improve reliability.
  • With your consent, understand use of the website and application through Google Analytics.

Agents configured in Autonomous mode may publish to connected accounts without a separate approval for each post. Agents configured in Draft approval mode hold generated videos until you approve them.

We do not sell personal data or connected-platform API data. We do not use Google or Instagram API data for advertising or ad targeting.

3. Google and YouTube Data

When you connect YouTube, Persoya requests these exact OAuth scopes:

  • https://www.googleapis.com/auth/youtube.readonly to identify your channel and read channel and published-video metadata and statistics, including channel ID and title and video views, likes, and comments.
  • https://www.googleapis.com/auth/youtube.upload to upload agent-generated videos, titles, descriptions, and the selected privacy setting to the channel you connected.
  • https://www.googleapis.com/auth/yt-analytics.readonly to read per-video estimated watch time, average view duration, average view percentage, and shares.

Google/YouTube data is a separate data category. It includes OAuth access and refresh tokens and granted scopes; your channel ID and title; video and channel metadata; video identifiers; views, likes, comments, watch-time, retention, and share metrics; and the generated video, title, description, and privacy setting sent to YouTube when your agent publishes for you.

We use channel identity data to display and maintain the connection. We use upload access to let your agent publish videos. We store published video identifiers and performance metrics so the agent can show reports, learn from results, and develop future content strategy for you. Analytics data may be included in agent context sent to Anthropic solely to produce these user-facing analyses and strategy features.

How we protect Google and YouTube data.

  • Google OAuth exchanges and Google/YouTube API requests are transmitted through HTTPS/TLS endpoints.
  • OAuth access and refresh tokens are encrypted at rest with AES-256-GCM before they are stored in Supabase. The encryption key is read from server-side environment or secrets configuration only by trusted server-side processes and is not included in browser code.
  • OAuth token values are not returned to the browser or other client-side code. Client-facing connection views select a token-free subset of fields, and Persoya's OAuth handlers do not record token values in application logs.
  • Supabase Row Level Security and server-side authentication and ownership checks restrict each user to their own connection and Google/YouTube-derived records. Background service-role processes are limited to authorized jobs and explicitly scope database operations by user and agent identifiers.
  • Access is limited to the services and processes needed for the requested Persoya features: Supabase stores the encrypted credentials and account-scoped records; Vercel hosts the server-side application and processes web requests and application logs, which may contain operational connection identifiers and status but not OAuth token values; Google/YouTube receives the OAuth, API, and publishing requests; and Anthropic may receive only relevant performance summaries to produce the analyses and strategy features described above.
  • Generated media is kept in access-controlled storage. Supabase media buckets are configured as non-public. The application treats generated videos in AWS S3 as private objects and, when browser access is needed, returns short-lived presigned URLs rather than public object URLs. S3 bucket privacy also depends on the production bucket's deployment access settings.
  • Access tokens are refreshed when needed for an API request. A daily process rechecks YouTube authorization before 30 days and refreshes stored API-derived metadata and analytics or deletes data that is stale or can no longer be accessed under a valid authorization.

Persoya's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use Google API data only to provide or improve prominent, user-facing Persoya features. We do not sell it, use it for advertising, or transfer it except to service providers needed to deliver those features, for security, when required by law, or with your consent as permitted by that policy.

See the Google Privacy Policy. You may disconnect YouTube in Persoya. Persoya immediately attempts to revoke the Google grant and deletes its local encrypted tokens, connection metadata, YouTube API analytics, and stored YouTube media identifiers. If Google's revocation request fails, Persoya still removes local access and prevents future API use. This does not delete videos already published on YouTube or Persoya-generated source files. You may separately remove Persoya's access from your Google Account third-party access settings. Removing access at Google does not itself delete data already stored in Persoya; use the account-deletion options below for that.

Deleting your Persoya account runs the YouTube disconnect and cleanup process for all user-linked connections, removes pending YouTube credentials, and deletes user-linked Google/YouTube connection records, OAuth credentials, API-derived analytics, and stored YouTube media identifiers from Persoya. Content already published on YouTube remains there unless you remove it on YouTube.

4. Meta and Instagram Data

Persoya uses Instagram Login for professional Business or Creator accounts and requests only these permissions:

  • instagram_business_basic to read the connected account's user ID, username, and account type and to read identifiers and permalinks for media Persoya published.
  • instagram_business_content_publish to create and publish agent-generated Reel or video content to the professional account you connected.
  • instagram_business_manage_insights to read media views, reach, likes, comments, shares, saves, total interactions, and average Reel watch time.

Persoya stores the account identifier and username, encrypted token, granted permissions, published media identifiers, and the available insights. The agent uses insights for performance reporting, self-learning, and future content strategy. Performance summaries may be sent to Anthropic only to produce those Persoya features. No additional Meta permissions are requested by the application.

You may disconnect Instagram in Persoya. This deletes the local Instagram connection and encrypted token, cached profile details, Instagram API analytics, and stored Instagram media identifiers. Meta does not document a programmatic token-revocation endpoint for this Instagram Login flow, so Persoya does not claim remote revocation. Disconnect does not delete already published Instagram posts, Persoya-generated source files, or the non-API publishing history. To delete the related Persoya account data, records, delete your Persoya account from Account Settings or contact hello@persoya.com.

5. Service Providers

We share data only as needed for the following production functions:

  • Supabase processes authentication, database records, sessions, and private avatar-image and generated-audio storage.
  • Vercel hosts the application and processes web requests, network identifiers, and application logs.
  • Anthropic receives prompts, chat messages, agent profile and strategy context, content context, and relevant performance summaries to generate agent responses, scripts, decisions, and analysis.
  • HeyGen receives scripts, selected voice identifiers, scene or avatar images, and video-generation settings to render agent videos.
  • fal.ai / Nano Banana Pro receives image prompts, seeds, and, for image editing, reference images to generate agent and scene imagery.
  • ElevenLabs receives script text and a selected voice identifier when the legacy script-audio endpoint is used.
  • Amazon Web Services S3 stores generated video files and support attachments. The application accesses these objects through time-limited signed URLs.
  • Resend processes support emails, including your email address, support message, optional agent and diagnostic context, and a time-limited attachment link when supplied.
  • PayPro Global acts as merchant of record and processes your email, Persoya user identifier, selected plan, payment, tax, order, customer, and subscription information.
  • Google / YouTube and Meta / Instagram receive OAuth requests and the content, metadata, and API requests needed to connect, publish, and retrieve performance data as described above.
  • Google Analytics receives website and application usage data only after you accept analytics and when it is enabled in production. Connected YouTube or Instagram API data is not intentionally sent to Google Analytics.

6. Storage, Security, and Retention

Database records are stored in Supabase. OAuth access and refresh tokens are encrypted using AES-256-GCM before storage and decrypted only in trusted server-side code. Supabase avatar and audio buckets are configured as private. Generated video files and support attachments are stored in AWS S3 and are accessed by the application through short-lived signed URLs. S3 bucket access controls are deployment configuration and are not enforced by the application code.

Google and Instagram access tokens are refreshed near expiry when an API operation requires them. For connected YouTube accounts, Persoya runs a daily compliance process that rechecks authorization before 30 days, refreshes stored YouTube API metadata and analytics when needed, and deletes API-derived data that cannot be refreshed or no longer has valid authorization. Published content remains on the connected platform unless you remove it there.

7. Cookies and Analytics

Persoya uses authentication and security cookies to keep you signed in and to protect OAuth flows. Google Analytics does not load and no analytics event is initialized until you select “Accept analytics.” Rejecting analytics does not affect essential authentication features. Persoya stores your choice in your browser. You can reopen at any time. Persoya does not use connected-platform API data for advertising.

8. Disconnecting and Account Deletion

You may disconnect YouTube or Instagram inside Persoya. Disconnecting deletes the corresponding local connection, encrypted tokens, cached account data, platform media identifiers, and API-derived analytics. YouTube disconnect also attempts Google token revocation; Instagram disconnect does not claim a Meta revocation endpoint. Disconnect does not delete posts already published to those platforms or Persoya-generated source files.

You may delete your account from Account Settings or contact us at hello@persoya.com. Account deletion first stops new agent work, verifies cancellation of any PayPro Global subscription, closes connected accounts, removes user-owned files from AWS S3 and Supabase Storage, deletes user-linked database records including agents, conversations, connections, tokens, publishing records and analytics, and finally removes the authentication account. If subscription cancellation or another required step cannot be confirmed, deletion stops safely and can be retried; the account is not silently deleted while billing remains active. Requests sent by email are processed after account ownership is verified.

PayPro Global and other providers may retain limited payment, tax, accounting, fraud-prevention, security, or legally required records under their own obligations. Deleting your Persoya account does not delete content already published to YouTube or Instagram.

9. Your Rights

Depending on your location, you may have rights to access, correct, export, delete, object to, or restrict processing of personal data. Use Account Settings where available or contact hello@persoya.com. We may need to verify your identity before completing a request.

10. International Transfers

Our providers may process data outside your country, including in the United States. We rely on the safeguards and contractual mechanisms offered by those providers where required.

11. Children's Privacy

Persoya is not directed to children under 13 and the Terms require users to be at least 18 or the age of majority in their jurisdiction. Contact us if you believe a child provided personal data.

12. Updates to This Policy

We may update this policy as the service or legal requirements change. We will revise the date above and may provide additional notice for material changes.

13. Contact

For privacy, account deletion, or legal questions, contact hello@persoya.com.