Privacy
What we hold, and why.
EkaIQ is marketing software. To do its job it stores the content you create, the brands you set up, the media you upload and the permissions needed to post on your behalf. Nothing more than that.
Last updated 2026. Questions: use the contact form.
This document is written in plain English for a beta product and is still pending professional legal review. It describes how EkaIQ actually works today and will be updated as the product changes.
Account data
Your email address, name, avatar if you add one, password credentials handled by our authentication provider, and the timestamps of your sessions. We never see your password in readable form.
Organisation and team data
Your workspace name, country, timezone, plan, team members, their roles, invitations you send and the audit trail of significant actions (who invited, approved, published or removed something, and when).
Content, media and AI
- Posts, captions, campaigns, calendars, comments and approval decisions you create.
- Files you upload - images, video, PDFs, flyers, CSV or text - stored in a private bucket that only your organisation can read.
- The prompts, briefs and uploaded document text you send to the AI, and the drafts it returns. These are used to produce your content and to debug failures; they are not used to train public models by us.
- AI generation is provided by a third-party model provider. Treat anything you paste in as data leaving your building, and do not paste material you are not allowed to share.
Social accounts and publishing
- When you connect a social account we store the account identifier, display name, page or profile reference, and the permissions granted.
- Access and refresh tokens are encrypted before storage and are only ever decrypted server-side by the publishing worker. They are never sent to your browser.
- We store what was published, when, to which account, and the response the network returned. We never ask for, receive or store your social network password.
Analytics data
Two separate things. First, performance metrics we collect from connected social accounts (reach, impressions, engagement, clicks) so your analytics page has something in it. Second, first-party product analytics: an anonymous session identifier and a small set of named events such as viewing pricing or completing onboarding. No advertising trackers, no cross-site profiling.
Enquiries and email
If you use the contact form we keep your name, email, business, website and message so we can reply. Transactional emails (invitations, notifications, password resets) are sent through an email delivery provider. We do not sell or share your details with advertisers.
Processors we rely on
- A managed database, authentication and file-storage platform (hosting your workspace data in the cloud).
- An AI model provider for content generation.
- A transactional email provider for invitations and notifications.
- The social networks you choose to connect, for publishing and metrics.
- A payment processor will be added when card payments go live; today no card details are collected or stored.
Retention
Workspace content, media and analytics are kept while your organisation exists. Deleting your organisation removes its content, media and social credentials. Audit and billing records may be retained longer where we need them for security or accounting. Contact-form enquiries are kept while relevant to the conversation.
Your rights
You can export your workspace at any time from Settings, disconnect any social account, and delete your organisation with a typed confirmation. You can also ask us for access, correction, deletion or a copy of your data, and object to processing. We follow UK GDPR and GDPR principles: only collect what the product needs, use it for the purpose you gave it, keep it secure, and delete it when it is no longer needed.
We make no claim to hold any security or privacy certification. Where we say something is encrypted or isolated, it is described honestly on the security page.
Contacting us about privacy
Use the contact form and mark your message "privacy request". We will confirm receipt and tell you what we need to verify your identity.