Privacy Policy
Last updated 7 September 2026
Who we are
Social Freak Ltd (company no. 14659411), Unit 82A, James Carter Road, Mildenhall, Bury St Edmunds, IP28 7DE, UK, operates Social Fetch. We are an independent data controller for account, billing, fraud and security, legal-compliance, and direct customer-relationship information described in this policy. For personal data in customer-instructed API requests and results, we act as the customer’s processor under our Data Processing Addendum. For privacy questions, contact support@socialfetch.dev.
What this policy covers
This policy applies when you visit socialfetch.dev, create an account, use our API, dashboard, documentation, or free tools, or contact support (collectively, the “Services”). It primarily covers personal information we process as controller and explains our separate processor role for customer API workloads. It does not govern third-party websites, social platforms whose data you fetch through the API, or how you use API outputs in your own products.
Information we collect
We may collect:
- Account data: name, email address, organisation, authentication identifiers, and optional profile details when you register or sign in.
- Billing data: payment and invoice metadata processed by our payment provider, including saved payment methods used to process subscription renewals and authorized automatic auto-refill charges. We do not receive or store full card numbers.
- Usage and API logs: request IDs, endpoints called, timestamps, status codes, credits consumed, and related operational metadata. Under standard retention this also includes request parameters, target URLs, and limited response previews; zero-retention accounts do not durably store those payload fields.
- Support and communications: content you send when you contact us or respond to surveys or feedback.
- Technical data: IP address and user agent on sign-in sessions for security and abuse prevention; cookies and similar technologies for session management, billing currency preference (`geo_currency`, GBP/USD/EUR, about one year, shared across our marketing site and app in production), and, in production, product analytics (which may use cookies). We obtain consent where required by applicable law.
API requests
The API returns publicly available data from third-party platforms at request time. That data is returned to you and is governed by those platforms’ terms. For personal data in customer-instructed API requests and results, Social Freak Ltd acts as the customer’s processor; the customer remains controller and is responsible for its instructions and lawful basis. We do not sell that data or use it to train machine-learning models, and disclose it only as needed to provide, secure, and support the Services, including through authorised subprocessors. Each API call creates a database row containing minimal operational fields such as the endpoint, HTTP method and path, status code, credits charged, and any error code. Under standard retention, the row also contains request parameters and limited response previews; those payload fields are not durably stored for zero-retention accounts. Rows are not a permanent archive of platform content. We retain standard operational API logs for approximately 30 days, including request metadata and limited response previews, for support, billing, abuse prevention, and reliability, then delete them. Accounts can opt into zero retention: live upstream processing still occurs, but we do not durably store request parameters, target URLs, or response previews; minimal operational, billing, security, and reliability metadata remains. Hosted screenshots and similar short-lived media artifacts are retained for approximately 7 days. Where a customer explicitly opts into hosted social-media originals, those objects are retained for approximately 90 days. Objects are then deleted automatically; customers needing longer retention should download and store the bytes themselves. When you call GET /v1/web/ask, the target URL, retrieved page text, and your question are sent to our AI provider to produce the requested answer. We do not permanently store platform content as an archive on your behalf.
Analytics and email
We use providers for email delivery, product analytics, and error monitoring. In production this includes SendGrid for transactional email, PostHog US Cloud for product analytics, and Sentry’s US ingest service for error tracking. Stripe handles payments and may act independently for regulated payment and fraud functions. Provider roles and data scope are listed in our public register. We obtain consent for non-essential cookies and similar technologies where required by law.
Documentation AI
Ask AI and documentation chat send documentation questions to third-party AI services so we can answer from our documentation. These features are for documentation help only; they are not a channel for submitting API request payloads or retrieved customer API content.
How we use information
We use personal information to:
- Provide, operate, and improve the Services;
- Authenticate users, enforce limits, and protect against abuse;
- Process payments and send service-related messages;
- Analyse usage in aggregate to improve reliability and design;
- Comply with law and respond to lawful requests.
We do not sell personal data or customer API request data. Marketing email is sent only where permitted and you can opt out.
Legal bases
Where UK GDPR, the Data Protection Act 2018, or EU GDPR applies, we rely on appropriate legal bases including: performance of a contract (providing the Services); legitimate interests (security, analytics, product improvement) balanced against your rights; consent where required (for example, certain cookies); and legal obligations.
Sharing and service providers
We publish at /subprocessors a concise, non-exhaustive register of material service providers we publicly identify. Additional diligence information may be available on reasonable request where legally permitted and subject to applicable confidentiality and contractual restrictions. Our DPA requires us to impose appropriate data-protection obligations on providers that act as our subprocessors. Some payment, authentication, and source-platform services act independently for their own legal purposes. We may also disclose information if required by law, to protect rights and safety, or in connection with a business transfer (for example, a merger), in line with applicable law.
International transfers
We are established in the UK. EEA-to-UK transfers currently benefit from the European Commission’s renewed UK adequacy decision through 27 December 2031. Providers may process data in the United States and other countries. For onward restricted transfers we use the approved mechanism applicable to the vendor and service configuration; see the public register or contact us for information about the applicable mechanism where legally permitted and subject to applicable confidentiality and contractual restrictions.
Retention
We retain account and billing information while your account is active and as needed to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements. We retain standard operational API logs for approximately 30 days, including request metadata and limited response previews, for support, billing, abuse prevention, and reliability, then delete them. Accounts can opt into zero retention: live upstream processing still occurs, but we do not durably store request parameters, target URLs, or response previews; minimal operational, billing, security, and reliability metadata remains. Hosted screenshots and similar short-lived media artifacts are retained for approximately 7 days. Where a customer explicitly opts into hosted social-media originals, those objects are retained for approximately 90 days. Objects are then deleted automatically; customers needing longer retention should download and store the bytes themselves. Aggregated or anonymised statistics may be kept longer for operations and reporting.
Your rights
Depending on your location, you may have rights to access, rectify, erase, or export personal information; object to or restrict certain processing; withdraw consent where processing is consent-based; and lodge a complaint with a supervisory authority (in the UK, the Information Commissioner’s Office). To exercise these rights, contact support@socialfetch.dev. We may need to verify your request.
Security
We use technical and organisational measures to protect personal information, including TLS for data in transit, hashed API key storage, and optional two-factor authentication. No method of transmission or storage is completely secure. See our Security page for an overview of our practices.
Personal data breaches
We notify affected customers without undue delay and, where feasible, within 72 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data, providing available information in phases where necessary. The DPA describes the information and assistance provided to affected customers.
Children
The Services are not directed at children under 16. We do not knowingly collect personal information from children.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version here and adjust the “Last updated” date. For material changes, we will provide additional notice where appropriate (for example, by email or in-product notice).
Contact
Privacy inquiries: support@socialfetch.dev.
Related documents
Data Processing Addendum · Service Provider Register · Terms of Service