Privacy Policy
Last updated: 26 July 2026
GODEYE is an AI marketing tool. You connect your own social media accounts, GODEYE helps you write and schedule posts, and it publishes them to those accounts on your instruction. This policy explains exactly what we store, why, and how to get rid of it.
Who we are
GODEYE (“we”, “the service”) is operated by Tyson Mulwa. For any privacy question or request, contact tysonmulwa25@gmail.com.
What we collect
Account information
Your name and email address, and a cryptographic hash of your password, we never store the password itself. If you enable two-factor authentication, the TOTP secret is stored encrypted.
Business profile
Whatever you choose to tell us about your business or creator profile: description, industry, audience, location, website, products and services. This is used as context so the AI writes relevant content. You provide it; you can change or remove it at any time.
Connected social accounts
When you connect a platform (Facebook, Instagram, Telegram, Reddit, LinkedIn, X, Discord) we store the access tokens that platform issues, plus the account or page name and its ID so we can show you what is connected.
All platform tokens are encrypted at rest using AES-256-GCM. They are decrypted only at the moment we make a request you asked for, publishing a post you scheduled, or reading back that post’s engagement figures.
Content and media
The posts you write or generate, your hashtags and variants, images you upload or generate, and your scheduling calendar.
Performance data
For posts published through GODEYE, we retrieve public engagement counts (likes, comments, shares) from the platform so we can show you how a post performed.
Operational logs
A record of significant account actions (sign-ins, connecting or disconnecting an account, publishing) for security and troubleshooting.
What we do NOT do
- We do not sell your data, and we never have.
- We do not use your content or your audience’s data for advertising.
- We do not train AI models on your content.
- We do not read your private messages, your friends list, or anyone else’s personal data. We request only the permissions needed to list your pages and publish to them.
- We do not post anything you did not create or schedule.
Meta Platform data (Facebook & Instagram)
If you connect Facebook or Instagram, we request only these permissions, each for a single purpose:
pages_show_list, to show you which Pages you can post to.pages_manage_posts, to publish the posts you schedule.pages_read_engagement, to read back likes and comments on those posts.business_management, to list Pages held in your Business Manager.
Instagram is connected separately, through Instagram Login, and grants two further permissions:
instagram_business_basic, to identify the Instagram account you connected and show its username next to your scheduled posts.instagram_business_content_publish, to publish the posts you schedule to Instagram.
Meta Platform data is used solely to provide these features to you, is never transferred to a data broker or ad network, and is deleted when you disconnect the account or delete your GODEYE account.
Where your data lives
The database and file storage are hosted on Supabase (Amazon Web Services, Canada Central). The web application runs on Cloudflare; the API and background workers run on Railway. Content generation uses Anthropic’s Claude API; the text of your brief and business profile is sent to Anthropic to produce the draft, and per Anthropic’s API terms it is not used to train their models. Anthropic does not receive your connected accounts’ access tokens or other Meta Platform Data.
How long we keep it
Your data is kept while your account is open. Disconnect a social account and its tokens are deleted immediately. Delete your account and everything associated with it is removed within 30 days, except where we must retain a record to comply with the law.
Your rights
You can access, correct, export or delete your data at any time. Most of it is available directly in the app, and anything else by emailing us. See Data deletion for how to remove your data. If you are in the EU or UK, you also have the right to object to processing and to lodge a complaint with your data protection authority.
Security
Passwords are hashed with Argon2id. Platform tokens are encrypted with AES-256-GCM. All traffic runs over HTTPS. Access to your workspace is limited to the members you invite, with the role you assign them.
No system is perfectly secure. If we discover a breach affecting your data, we will tell you and the relevant authority without undue delay.
Children
GODEYE is not intended for anyone under 18, and we do not knowingly collect their data.
Changes
If we change this policy we will update the date above, and for material changes we will notify you in the app or by email.
Contact
Questions or requests: tysonmulwa25@gmail.com