Privacy Policy
Last updated 30 July 2026
Personify is run by one operator. We collect the minimum needed to plan and generate your content: an email address, the brand details you give us, and the content we produce for you. We do not sell personal data and we do not run advertising trackers.
1. Who we are
Personify (“Personify”, “we”) is an independently operated software service that plans a month of social content for a brand and generates the posts. For privacy purposes we are the data controller for your account and brand data, and we act as a processor for the content we generate on your instruction. Questions, requests, and complaints go to hello@personify.app.
2. What we collect
- Account data. Your email address and an authentication record held by Supabase Auth. Passwords are salted and hashed by Supabase; we never receive or store your plaintext password. If you sign in with Google we receive your email address, name, and profile image from Google instead of a password.
- Brand inputs. Whatever you give us to work from: your website URL, brand description, audience, tone, offers, reference images, and uploaded media.
- Generated content. The plans, captions, images, and videos we produce for you, plus the prompts used to produce them.
- Connected accounts. If you connect a social account, we store the access and refresh tokens needed to publish on your behalf, plus the account handle and ID. We do not read your direct messages or your follower list beyond aggregate counts.
- Billing data. When paid plans launch, Stripe will process your payment details. We will receive a customer ID, plan, subscription status, and the last four digits and brand of the card. We never receive your full card number.
- Technical logs. Request logs, error traces, IP address, and coarse device information generated by our host and by our own error reporting.
We do not ask for, and ask that you do not upload, special-category data (health, biometric, political, or similar) or anyone else's personal data that you do not have the right to share. Avatars created from a real person's likeness require that person's consent.
3. Why we use it
- To create and secure your account, and to sign you in.
- To generate the plan, copy, images, and videos you ask for.
- To schedule and, where you have connected an account, publish your posts.
- To take payment and manage your subscription.
- To debug failures, prevent abuse, and keep the service up.
- To send transactional email — confirmation, password reset, and delivery notices.
Where the GDPR or UK GDPR applies, our legal bases are performance of a contract (running the service you signed up for), legitimate interests (security, abuse prevention, service improvement), consent (optional integrations such as connecting a social account), and legal obligation (tax and accounting records).
4. Third parties that process your data
Personify is assembled from hosted services. Each one below receives only what its job requires, and each acts as our processor or sub-processor:
- Supabase — authentication, Postgres database, and file storage for your brand data and generated media.
- Vercel — application hosting, edge routing, and request logs.
- OpenRouter — routes our text and image prompts to the underlying models (currently Anthropic Claude and Google Gemini families) for personas, plans, captions, and slide imagery.
- fal.ai — image and video generation, including lip-synced avatar video, speech synthesis, and image-to-video rendering.
- HeyGen — avatar and voice catalogues for avatar-led video, where you select from that library.
- Resend — delivery of transactional email.
- Stripe — payment processing and subscription billing (once paid plans are live). Stripe is an independent controller for payment data.
- Google — only if you choose Google sign-in, for authenticating you.
- Instagram / TikTok — planned. If you connect an account, we will exchange tokens with that platform and send it the posts you approve. Those platforms handle that data under their own policies.
Prompts we send to AI providers include the brand details and reference material needed for that generation. We send them through paid API endpoints, which those providers operate as processors on our behalf, and we do not authorise them to use your content to train general-purpose models. We do not sell personal data or share it for cross-context behavioural advertising.
5. How long we keep it
- Account and brand data — for as long as your account is open, then up to 30 days after you ask us to delete it, so that an accidental deletion can be reversed.
- Generated content and media — until you delete it, or 12 months after your account closes, whichever comes first.
- Social access tokens — until you disconnect the account or the token expires. Disconnecting deletes ours immediately.
- Technical logs — up to 90 days.
- Billing records — as long as tax and accounting law requires, typically seven years.
6. Your rights and how to delete your data
Subject to your local law, you can ask us for a copy of your data, correct it, delete it, restrict or object to how we use it, or withdraw consent for an optional integration. To exercise any of these, email hello@personify.appfrom the address on your account with the word “privacy” in the subject.
Deletion requests are actioned within 30 days. We delete your account record, brand data, generated content, and stored media, and we instruct our processors to do the same. Backups roll off within a further 30 days. Records we must keep for tax or fraud-prevention purposes are retained and nothing else. We will confirm by email when the deletion is complete.
If you are in the EEA or UK you may also complain to your local data protection authority.
7. Cookies
We set only the cookies needed to keep you signed in and to protect the session — they come from Supabase Auth. There is no advertising, retargeting, or cross-site tracking in Personify. Clearing them signs you out.
8. Security
Data is encrypted in transit. Database rows are isolated per user with row-level security, so one account cannot read another's. Service credentials are held as server-side environment variables and are never exposed to the browser. No service is perfectly secure; if a breach affects you, we will notify you and any required regulator without undue delay.
9. International transfers
Our processors operate in the United States and other countries. Where data leaves the EEA or UK, the transfer relies on the receiving provider's standard contractual clauses or an equivalent safeguard in its data processing agreement.
10. Children
Personify is a business tool and is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has created an account, email us and we will remove it.
11. Changes to this policy
If we change how we handle personal data we will update this page and move the “last updated” date. For material changes affecting existing accounts we will email you before the change takes effect.
12. Contact
Privacy questions, data requests, and complaints: hello@personify.app.