Privacy policy
This policy explains what Influence handles, why it is needed, where it goes, how long it is kept, and the choices available to you.
1. Scope and controller
Centoria Gate Holdings Limited operates Influence and is the data controller for personal data handled to provide the service. This policy applies to the Influence website, application, support, connected social-provider features, and billing.
2. Data we handle
- Account and workspace: email address, name, authentication and session records, workspace name, role, preferences, and time zone.
- Connected providers: provider and account identifiers, display names, pages, channels, profiles, locations or boards you select, granted scopes, capabilities, connection health, encrypted access and refresh tokens when Influence holds the authorization, vendor account references when a selected publishing service holds the authorization, and token expiry or revocation state. Influence does not ask for or store your social-provider password.
- Content and delivery: campaigns, drafts, channel variants, text, links, media, alt text, publishing settings, schedules, provider responses, returned post identifiers and links, and bounded failure or reconciliation state.
- Media: files you upload, their type, size, checksum, storage state, and metadata needed to validate, transform, deliver, and remove them.
- Usage and billing: plan and entitlement state, metered publication counts, checkout and subscription references, payment status, and invoices. Stripe handles payment-card details; Influence does not store full card numbers.
- Usage and advertising measurement: website and app page categories, clicks, feature use, signup, checkout, trial and subscription events; campaign tags, referring website hostname, browser and ad-click identifiers, IP address and browser information. Matching may use a hashed version of your account email and account ID. We do not collect private content, form text, passwords or payment-card details for measurement.
- Support and operations: messages you send, safe audit records, service events, bounded error codes, queue timing, and redacted diagnostics. Authentication abuse protection also keeps a short-lived keyed digest of the normalized client IP plus the protected endpoint; its limiter table does not store the raw IP or request path. Raw IP addresses are not retained in the product audit record.
3. Why we use data
We use data to authenticate users, provide and secure workspaces, connect accounts at your request, prepare and publish the content you approve, report delivery state, prevent duplicate posts, calculate usage, provide support and billing, investigate abuse or incidents, comply with law, and improve the reliability of visible product features. We also measure website and app usage and share eligible events with Meta, X and TikTok to measure and improve our advertising.
These providers receive matching identifiers and event details through their browser pixels on public marketing pages and their server APIs. Private app activity is limited to structured events sent by our server. Hashing identifiers does not make them anonymous. Read the Meta, X and TikTok privacy policies.
We use Google Analytics to measure public website visits and signup, checkout, trial and paid subscription events. Public-page tags and server events use browser identifiers. We do not send private content, account identifiers or email addresses to Google Analytics. Google advertising signals and personalization are off. Read Google’s privacy policy.
4. Connected-provider data
Influence requests only the provider permissions needed for the feature you choose. It uses authorized data to identify selectable accounts, validate capabilities, publish or reconcile your instructions, show results, refresh the connection, and disconnect it. Content and the account information required to publish are sent to the provider you selected and are then handled under that provider's terms and privacy policy.
Some selected connections temporarily use Post for Me as a third-party account-connection and publishing processor. For those connections, Influence sends Post for Me the workspace-scoped account reference, selected provider account, approved content and media, publishing settings, and timing needed to carry out and reconcile your instruction. Post for Me holds the provider authorization for that connection and returns account and delivery status to Influence.
Influence uses YouTube API Services when you connect YouTube, select an owned channel, upload a video at your direction, and read back its delivery and processing status. For information about how Google handles information, review the Google Privacy Policy.
You can revoke Influence's Google authorization by disconnecting YouTube in Influence or through your Google security settings. When you disconnect YouTube in Influence, Influence first records the disconnect and makes the connection unusable, then requests immediate token revocation and starts bounded cleanup of the stored YouTube Authorized Data and API Data tied to that authorization. This cleanup completes within seven days and covers the YouTube account and profile fields, encrypted credentials, connection candidates, provider-returned published objects and operation references, and matching export copies for all channel connections created from that OAuth authorization flow. If you revoke access in Google security settings, Influence checks credential-bearing YouTube connections on a recurring schedule; an explicit invalid-grant result starts the same cleanup, which completes within 30 days of Google-side revocation. It does not delete user-authored campaign content, local outcome, error, or audit markers needed for reliability, external service logs, downloaded exports, backups, or content held by YouTube. For the broader removal of your Influence account and product data, use the verified account-deletion workflow in Settings or the assisted request on the data deletion page. Deleting Influence data does not delete data held by YouTube.
Use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. See the Google API Services User Data Policy. Influence does not use connected-provider data to train a general AI model, build advertising profiles, or conduct surveillance.
5. Where data goes
Data is shared only as needed with the social providers you connect, people you authorize in your workspace, and service providers that help operate Influence: Vercel for web hosting, Convex for application data, backend execution and reading public website pages during brand research, Cloudflare for media storage, Resend for transactional email, Sentry for strictly redacted operational diagnostics, Post for Me for selected provider authorization and publishing, and Stripe for billing. We may also disclose data when required by law, to protect rights and safety, or in a business reorganization subject to appropriate safeguards.
When you use AI text planning, we send the information needed for that request to Google through Vercel AI Gateway. This can include public website text, your confirmed brand profile and guidelines, your campaign brief, selected account details, and images or videos you choose. Google processes these requests through Vertex AI with zero data retention requested. We do not send your social-account passwords or access tokens to the model.
When you generate or edit an image, we send your prompt and selected reference images to OpenAI through Vercel AI Gateway. A reference image is optional. These requests are not used to train the provider’s models. OpenAI may retain prompts, images and related information in abuse-monitoring logs for up to 30 days, or longer when required by law or necessary to protect its services or others from harm. Image generation does not use the zero-retention route used for text planning. Read OpenAI’s data controls.
You review the suggested content before it is scheduled. AI output can be wrong, so check names, claims and dates before approving it. Your saved brand information, guidelines and plans are part of your workspace data and follow the export and deletion options below.
6. Security and token handling
Provider credentials that Influence stores are encrypted before storage and decrypted only inside the bounded server path that performs an authorized provider action. Credentials held by a selected publishing service stay within that service's connection boundary and are used only for the provider action you request. Influence uses least-privilege access, short-lived transfer links, authenticated ownership checks, redacted operational events, and audited security mutations. No system can guarantee absolute security; report a suspected issue privately to hello@influence.so.
7. Retention and deletion
We keep account, workspace, connected-provider, campaign, and media data while needed to provide the service, resolve delivery state, meet security or legal obligations, and enforce agreements. A generated export and its download record expire after 24 hours. The final privacy-minimized keyed account and media deletion markers expire after 30 days. Those markers contain digests rather than the email address, storage bucket, or storage key and prevent recreation or restoration while a 28-day disaster-recovery snapshot could still contain an earlier copy. The anonymous completion audit is subject to a 90-day cutoff. A provider-side copy may follow that provider's separate retention or a legal requirement. An older snapshot will not be used to reactivate a deleted account or media object.
You can disconnect a provider or start export and account deletion from Settings. Deleting Influence does not delete posts already sent to a social provider; manage those on the provider. Full instructions are on the data deletion page.
Retained visit and event records have a 365-day expiry date. Associated visitor and preference records have an expiry date no later than 400 days. A bounded cleanup job removes expired records; removal may follow the expiry date. Account deletion may remove them sooner, and account-bound records are included in your export and deletion options.
For Post for Me-managed connections, account deletion removes supported draft or scheduled vendor records, disconnects Post for Me-held credentials, and deletes an empty Post for Me account record only after each step is confirmed. If Post for Me still reports a publication as processing or processed, automated deletion pauses rather than discarding delivery evidence; contact support to resolve the retained record and then re-request deletion. Deletion also pauses if required cleanup configuration is unavailable or unsafe, before any Post for Me request is made. This cleanup does not delete content already delivered to the social provider, the social-provider account itself, or prove that the provider revoked its underlying grant.
8. Cookies and local storage
Essential cookies keep you signed in, secure the service and remember privacy choices. Optional cookies support usage and advertising measurement. In regions where our public-site settings require a choice, this waits until you select Accept all cookies. Elsewhere it starts by default. Accept only essential cookies turns optional measurement off.
A new successful signup or sign-in activates usage and advertising measurement under the policies shown at sign-in, including after an earlier essential-only public-site choice. You can change this again using Cookie choices in the footer, privacy pages or app policies. Global Privacy Control keeps advertising sharing off. Changes stop future collection and unsent sharing; they cannot recall events already delivered.
Our first-party preference cookie lasts up to 400 days. Google Analytics, Meta, X and TikTok cookies have provider-controlled lifetimes. Your browser can also block or delete cookies; the service remains usable without optional tracking.
9. International processing
Influence is operated by a Hong Kong company and uses providers in multiple regions, so data may be processed outside your country. Where required, we use contractual or other safeguards and apply data-minimization, security, retention, and access controls to those transfers.
10. Your choices and rights
Subject to applicable law, you may request access, correction, export, deletion, restriction, or information about our handling of your personal data. You may revoke provider access in Influence or at the provider. Contact hello@influence.so from your account email so we can verify the request without asking for a password or token.
11. Age and changes
Influence is for users who are at least 18 and able to enter a binding agreement. We may update this policy when the service, providers, or law changes. Material changes will be identified by a new effective date and, where required, a notice or renewed consent before a new use begins.
Company details
- Operator and data controller
- Centoria Gate Holdings Limited
- Hong Kong company number
- 79414238
- Incorporated
- 17 December 2025
- Contact
- hello@influence.so
- Registered address
- Unit 2A, 17/F, Glenealy Tower, No.1 Glenealy, Central, Hong Kong S.A.R.