Legal
Privacy Policy
Last updated 9 October 2026
SaySo helps agencies plan social media posts, get a client's approval through a review link, and publish to the accounts the client has connected. This page explains what that takes in personal data, and nothing more. SaySo is operated by VTS, based in India, which is responsible for the data described here.
What we collect
When you create an account
- Your full name, username and email address.
- Your password, stored only as a one-way hash (bcrypt). We cannot read it, and neither can anyone who sees the database.
- A profile photo, if you upload one, your timezone and your theme setting.
- For each signed-in device: the browser it reports, its IP address, and when it was last used — so you can see your devices in Settings and sign them out.
- The date you accepted these terms, and which version you accepted.
When you work in SaySo
- The clients you set up (company name, brand colour), the posts, captions and media you upload for them, schedules, tasks, comments and the team members you invite (their name, email and role).
- A security log of important actions — who did what, when, from which IP address and browser. It is how a team can answer “who changed this?” and how we look into misuse.
When a client opens a review link
Clients do not need an account. When they answer, we keep the name they type, their approval or change request, and any comment. If the agency chooses to email the link, we keep the client email addresses it was sent to (at most five per link), so reminders can go to them.
When you ask for early access
The early-access form on this website asks for your name, work email and agency, and, if you choose to tell us, how many clients you manage and a note. It is emailed to our inbox and not stored anywhere else. We use it only to set up your access and to reply to you.
When you connect Facebook or Instagram
If you connect a Facebook Page or an Instagram professional account through Facebook Login, we receive from Meta, and store:
- The Page or Instagram account's ID, name, username and profile picture link.
- The Instagram account's follower and media counts.
- The ID of the Facebook user who connected it, and the permissions they granted.
- Access tokens that let us publish and read insights on your behalf. These are encrypted (AES-256-GCM) before they are stored, and are never shown to anyone, including you.
Post insights (reach, likes and similar numbers) are fetched from Meta when you open them and are not stored. We use Meta data only to show you the accounts you connected, publish the posts you approve to them, and show you how those posts performed. We do not sell it, use it for advertising, or combine it with data about anyone else.
How we use it
- To run the service: sign you in, show your work to your team, publish what you approve.
- To send email you or your team triggered: review links, reminders about posts still waiting for an answer, team invitations, and task updates.
- To keep the service secure and to investigate misuse.
We do not sell personal data, show advertising, or use tracking or analytics cookies. The only cookies SaySo sets are the ones that keep you signed in.
Who handles data for us
These companies process data on our behalf, only to provide the service:
- MongoDB, Inc. (MongoDB Atlas) — our database, where everything above is stored, including the data received from Meta.
- Cloudinary — stores the images and videos you upload, and profile photos.
- Google (Gmail) — sends our emails, so it sees each email's recipient and content.
- Vercel — hosts this website and passes early-access requests on to our inbox without storing them. It also counts visits to this website (pages viewed, rough location and device type) without cookies or anything that identifies you. It does not receive account data.
- Meta — receives the posts you publish to Facebook and Instagram, under Meta's own terms.
Some of them store data outside India. We will update this list before adding a new one.
How long we keep it
- Account and workspace data: for as long as your account exists.
- Early-access requests: until your access is set up, or until you ask us to delete the request.
- Disconnecting a Facebook Page or Instagram account in SaySo deletes its access tokens straight away.
- Removing SaySo from your Facebook settings does the same, automatically, for every account you connected.
- Signing a device out removes that session. Old sessions are dropped once an account has too many.
Deleting your data
Facebook and Instagram data
Go to Facebook → Settings & privacy → Settings → Apps and websites, find SaySo, and remove it. Then choose to send a deletion request. We erase the tokens, names, usernames, profile pictures, follower counts and your Facebook user ID for every account you connected, and Facebook gives you a confirmation code you can use to check the status of the request.
Everything else
Email hello@saysohub.com from the address on your account and ask for it to be deleted. We will confirm and delete your account, and the personal data tied to it, within 30 days. Posts and comments you made inside a client's workspace belong to that workspace; we remove your name from them or delete them, as you prefer.
Your rights
You can ask us for a copy of your personal data, to correct it, or to delete it, by emailing hello@saysohub.com. Most of it you can also change yourself in Settings. Depending on where you live (for example under India's Digital Personal Data Protection Act, 2023, or the GDPR) you may have further rights, and you can complain to your data protection authority.
Requests from public authorities
If a government or public authority asks us for personal data, we:
- check that the request is lawful before doing anything with it;
- challenge it if we believe it is not lawful;
- disclose only the minimum the request lawfully requires;
- keep a record of the request, our response and the reasoning behind it.
Security
Connections are encrypted (HTTPS). Passwords are hashed and platform tokens are encrypted. Each request is checked on the server against the clients you belong to, so a team member cannot reach another agency's work. Review links can be revoked at any time. No system is perfectly secure; if we learn of a breach that affects your data, we will tell you.
Children
SaySo is a tool for businesses and is not meant for anyone under 18. We do not knowingly collect data from children.
Changes
When this policy changes, the date at the top changes. If the change matters, we will tell you by email or in the app before it applies.
Contact
VTS, India — hello@saysohub.com