Privacy Policy
Last updated 5 July 2026
Who we are
Social Freak Ltd (company no. 14659411), Unit 82A, James Carter Road, Mildenhall, Bury St Edmunds, IP28 7DE, UK, operates Social Fetch. We are the data controller for personal information described in this policy. For privacy questions, contact support@socialfetch.dev.
What this policy covers
This policy applies when you visit socialfetch.dev, create an account, use our API, dashboard, documentation, or free tools, or contact support (collectively, the “Services”). It covers personal information we process as data controller. It does not cover third-party websites, social platforms whose data you fetch through the API, or how you use API outputs in your own products.
Information we collect
We may collect:
- Account data: name, email address, organisation, authentication identifiers, and optional profile details when you register or sign in.
- Billing data: payment and invoice metadata processed by our payment provider, including saved payment methods used to process subscription renewals and authorized automatic auto-refill charges. We do not receive or store full card numbers.
- Usage and API logs: endpoints called, timestamps, status codes, credits consumed, request metadata, response previews, and related operational metadata.
- Support and communications: content you send when you contact us or respond to surveys or feedback.
- Technical data: IP address and user agent on sign-in sessions for security and abuse prevention; cookies and similar technologies for session management, billing currency preference (`geo_currency`, GBP/USD/EUR, about one year, shared across our marketing site and app in production), and, in production, product analytics (which may use cookies). We obtain consent where required by applicable law.
API requests
The API returns publicly available data from third-party platforms at request time. That data is returned to you and is governed by those platforms’ terms. We do not sell customer API request data or response content, do not use it to train machine-learning models, and do not share it except with subprocessors that help us operate the Services under appropriate safeguards. Each API call creates a database row with the endpoint, HTTP method and path, status code, credits charged, request parameters, response previews, and any error code. Rows are not a permanent archive of platform content. We retain operational API logs for approximately 30 days, including request metadata and response previews, for support, billing, and reliability, then delete them. We do not permanently store platform content as an archive on your behalf.
Analytics and email
We use subprocessors for hosting, payments, email delivery, product analytics, and error monitoring. In production this includes Stripe for payments, SendGrid for transactional email, PostHog for product analytics, and Sentry for error tracking. These providers process data on our instructions and only for the purposes described in this policy. We obtain consent for non-essential cookies and similar technologies where required by law.
Documentation AI
Ask AI and documentation chat send your questions to third-party AI services so we can answer from our documentation. These features are for documentation help only; they are not a channel for submitting API requests or customer data for processing. We do not sell customer API request data or response content, do not use it to train machine-learning models, and do not share it except with subprocessors that help us operate the Services under appropriate safeguards.
How we use information
We use personal information to:
- Provide, operate, and improve the Services;
- Authenticate users, enforce limits, and protect against abuse;
- Process payments and send service-related messages;
- Analyse usage in aggregate to improve reliability and design;
- Comply with law and respond to lawful requests.
We do not sell personal data or customer API request data. Marketing email is sent only where permitted and you can opt out.
Legal bases
Where UK GDPR, the Data Protection Act 2018, or EU GDPR applies, we rely on appropriate legal bases including: performance of a contract (providing the Services); legitimate interests (security, analytics, product improvement) balanced against your rights; consent where required (for example, certain cookies); and legal obligations.
Sharing and service providers
We use trusted third-party providers for hosting, payments, email, and analytics. Stripe processes payments. A detailed subprocessor list is available on request for security reviews. Service providers may only use data as instructed by us and subject to appropriate safeguards. We may also disclose information if required by law, to protect rights and safety, or in connection with a business transfer (for example, a merger), in line with applicable law.
International transfers
Our hosting and database providers may process data in the United States and other countries outside the UK and EEA. Where UK or EU law requires it, we use appropriate safeguards such as standard contractual clauses approved by regulators.
Retention
We retain account and billing information while your account is active and as needed to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements. We retain operational API logs for approximately 30 days, including request metadata and response previews, for support, billing, and reliability, then delete them. Aggregated or anonymised statistics may be kept longer for operations and reporting.
Your rights
Depending on your location, you may have rights to access, rectify, erase, or export personal information; object to or restrict certain processing; withdraw consent where processing is consent-based; and lodge a complaint with a supervisory authority (in the UK, the Information Commissioner’s Office). To exercise these rights, contact support@socialfetch.dev. We may need to verify your request.
Security
We use technical and organisational measures to protect personal information, including TLS for data in transit, hashed API key storage, and optional two-factor authentication. No method of transmission or storage is completely secure. See our Security page for an overview of our practices.
Children
The Services are not directed at children under 16. We do not knowingly collect personal information from children.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version here and adjust the “Last updated” date. For material changes, we will provide additional notice where appropriate (for example, by email or in-product notice).
Contact
Privacy inquiries: support@socialfetch.dev.