Privacy Policy
Effective 2026-08-11
1. Who controls your data
Silver Gorilla Group LLC, 3 Chevy Dr. #1034, E. Syracuse, NY 13057, United States ("Publishly", "we", or "us") operates the service. This policy covers our website, API, dashboard, automation integrations, and connected social-platform features.
2. Information we collect
- Account and workspace data, including your name, email, memberships, roles, invitations, account groups, and tags.
- Content and instructions you provide, including drafts, captions, schedules, media, platform settings, webhook URLs, and support messages.
- Connected-platform data you authorize us to access, such as profile or Page identifiers, display names, avatars, authorization tokens, posting capabilities, posts, comments, direct messages and conversations the connected account has received, and account or post analytics supported by that platform.
- Reliability and security data, including delivery receipts, classified errors, retry attempts, connection health, audit events, IP address, device/browser information, and service logs.
- Subscription and transaction status from Stripe. We do not store complete payment-card numbers.
3. How we use information
We use this information only as needed to:
- authenticate users and provide the workspace, publishing, scheduling, analytics, receipt, webhook, and health features they request;
- send content to a selected platform, independently confirm delivery, classify failures, retry safe failures, and warn about expiring or unhealthy connections;
- secure, troubleshoot, monitor, and improve the service;
- administer subscriptions, enforce usage limits, answer support requests, and comply with law.
We do not sell personal information. We do not use connected social-platform data for advertising, data-broker profiles, or training general-purpose artificial intelligence models. Optional AI features process only the prompts and content a user deliberately submits to that feature.
4. Google and YouTube user data
When you connect YouTube, Publishly requests the minimum Google scopes shown on our platform review page to identify your channel, upload a video you schedule, confirm that video through an independent read, and show your YouTube Analytics. Publishly's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We do not transfer Google user data to advertising platforms, use it to determine creditworthiness, allow humans to read it except with your affirmative support consent or when necessary for security/legal compliance, or use it to train generalized AI models.
5. Meta and Instagram user data
When you connect Instagram, Publishly uses the Instagram API with Instagram Login and requests only the permissions shown on our platform review page: to identify the professional account you chose, publish the post you scheduled and read back its media id and permalink to confirm it is live, read and reply to the comments on your own media, read the direct-message conversations that account has received so you can answer them in Publishly, and show the account and post insights that belong to you.
Direct messages are the most sensitive of these. Publishly reads a conversation only for the connected account that received it, shows it only to members of your workspace, and sends a reply only inside the response window Instagram permits — outside that window the reply is disabled rather than attempted. We do not use message, comment, or insights data to train generalized AI models, do not transfer it to advertising platforms, and do not allow humans to read it except with your affirmative support consent or where necessary for security or legal compliance.
Disconnecting an Instagram account deletes the stored authorization for it. Meta's deauthorization and data deletion callbacks are honoured automatically, and you can request deletion yourself at any time through our data deletion page. Publishly reads and writes nothing on Facebook Pages.
6. When information is shared
- With the social platform you chose, to perform the action you requested.
- With infrastructure, storage, email, monitoring, support, payment, and optional AI subprocessors under contracts that limit processing to providing their service to us.
- With workspace members according to their role and your workspace configuration.
- When required by law, to protect users or the service, or as part of a business transaction with notice and appropriate safeguards.
We do not give a connected platform's data to another platform unless you explicitly choose that destination and the transfer is necessary to publish your content there.
7. Security
Provider tokens and per-user app credentials are encrypted with authenticated AES-256-GCM before database storage. API keys are scope-limited, revocable, shown once, and stored as hashes. We also apply tenant isolation, audit logging, bounded retries, SSRF controls, and least-privilege provider scopes. No internet service can promise absolute security; report a suspected issue to [email protected].
8. Retention, revocation, and deletion
We retain workspace content and delivery history while your workspace remains active or as needed to provide the service, resolve disputes, enforce agreements, and satisfy legal obligations. Disconnecting a channel attempts provider-side revocation where the platform supports it and removes stored authorization credentials and provider-derived connection data. Deleting a workspace starts removal of its content and connections. Encrypted backups age out through the normal backup lifecycle and are not restored except for disaster recovery.
Google/YouTube authorized data is removed as soon as it is no longer necessary and, after revocation or a valid deletion request, no later than seven days unless retention is required for security or law. Posts already published on a third-party platform remain there until you delete them on that platform. See the data-deletion instructions.
9. Your controls and rights
You can disconnect individual accounts, revoke API keys, export workspace data, or request workspace deletion in the product. You can also revoke access directly in a platform's settings, including Google Account third-party access. Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal data. We verify requests before acting on them.
10. Cookies, children, and international processing
We use essential cookies for sessions, security, preferences, and checkout, plus configured privacy-conscious service analytics. Publishly is a business service not directed to children under 13, and we do not knowingly collect their data. Data may be processed where we and our subprocessors operate; we use legally required transfer safeguards where applicable.
11. Changes and contact
We will update the effective date and provide appropriate notice before material changes take effect. Privacy and deletion questions may be sent to phliq5215@gmail.com.