Privacy Policy — Adovia Pro
Last updated: July 26, 2026
Effective date: July 22, 2026
---
What We Collect
Adovia Pro collects the following data when you connect a social media account:
| Data | Source | Purpose | Stored |
|---|---|---|---|
| Social account handle, display name | YouTube / Instagram API | Display in dashboard | Yes |
| Follower count (daily snapshots) | Platform API | Analytics charts | Yes |
| Post engagement metrics (likes, comments, views, saves) | Platform API | Best-time analysis | Yes |
| Audience geography (country-level, aggregate %) | Platform API | Geography screen | Yes, aggregate only |
| OAuth access token | Google / Meta | API access | Yes, encrypted at rest |
| Your email address | Supabase Auth | Account authentication | Yes |
What we do NOT collect:
- Individual follower identities or demographics
- Private messages or DMs
- Content of your posts (only metrics)
- Any data from users who have not signed in to Adovia Pro
- Precise location data
---
How We Use Your Data
- To display your own analytics in your private dashboard
- To generate AI-powered posting-time recommendations using your own engagement history
- To identify when re-authentication is needed for a connected platform account
We do not sell your data. We do not use your data for advertising. We do not share your data with third parties except as described in the Third-Party Data Processors section below.
---
Third-Party Data Processors
Adovia Pro uses the following sub-processors to operate the service. Each is under a data processing agreement (DPA):
| Processor | Purpose | Data Shared | Location |
|---|---|---|---|
| Supabase (supabase.com) | Database, authentication, Edge Functions | All collected data — stored and processed on Supabase infrastructure | US (AWS us-east-1) |
| Anthropic (anthropic.com) | AI inference (Claude API) | Aggregated engagement metrics and post timing (no personal follower data) | US |
| Sentry (sentry.io) | Error monitoring and crash reporting | Error payloads, stack traces, anonymized session metadata | US |
| PostHog (posthog.com) | Product analytics | Page paths, anonymized events, session duration (no OAuth params, no tokens) | US |
| Vercel (vercel.com) | Web application hosting and CDN | HTTP request logs (IP, user-agent) for the web app | US / global edge |
| Google (google.com) | YouTube OAuth — authorizes read-only access to your YouTube analytics | OAuth exchange only — no ongoing data sharing beyond what you authorize | US |
| Meta (meta.com) | Instagram OAuth — authorizes read-only access to your Instagram insights | OAuth exchange only — no ongoing data sharing beyond what you authorize | US |
Google API Services User Data Policy
Adovia Pro's use of information received from Google APIs adheres to the [Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. Specifically:
- We use your YouTube data (subscriber counts, engagement metrics, audience geography) only to provide the in-app analytics dashboard to you.
- We do not share, sell, or use your Google data to train AI models.
- We do not display Google data to other users.
- We request only the minimum scopes required: `youtube.readonly` and `yt-analytics.readonly`.
---
AI Processing
Your engagement data (post times, engagement rates, aggregate audience geography) is sent to Anthropic's Claude API to generate posting-time recommendations. This data is processed only for this specific purpose and is subject to [Anthropic's usage policies](https://www.anthropic.com/policies/usage). No personal information about your followers is included in AI prompts. AI generation is capped at 3 requests per user per day.
---
Data Retention
- Social account metrics: retained while your account is active. Deleted when you disconnect an account or delete your Adovia Pro account.
- AI-generated insights: retained for 90 days after generation, then automatically purged.
- Authentication tokens: deleted immediately upon disconnecting an account or account deletion. Tokens are encrypted at rest using Supabase Vault.
- Error logs (Sentry): retained per Sentry's default retention policy (90 days).
- Product analytics events (PostHog): retained per PostHog's default retention policy.
---
Your Rights
- Access: View all data we have about you in your dashboard.
- Deletion: Delete your account and all associated data via Settings → Delete Account & Data. This is irreversible.
- Portability: Contact us to request an export of your data.
- Revocation: Disconnect any platform account at any time to stop collection and delete that account's tokens immediately.
- Meta/Facebook: You may also submit a data deletion request through your Facebook Settings → Apps and Websites.
---
Data Deletion
To delete your Adovia Pro account and all associated data:
1. In the app: Settings → Delete Account & Data
2. Or online: https://adoviapro.com/account/delete — fill out the form
We will delete all your data within 30 days. For Instagram/Facebook data specifically (required by Meta), deletion is processed within 24 hours of your request.
---
Security
- OAuth tokens are encrypted at rest using Supabase Vault (AES-256).
- Tokens are decrypted only in-memory on our servers — never sent to the client.
- All data transmission uses TLS/HTTPS.
- Row-Level Security (RLS) ensures each user can only access their own data.
- We do not log OAuth tokens, access codes, or state parameters.
---
Contact
For privacy questions or data requests: support@adoviapro.com
---
*This privacy policy is published at https://adoviapro.com/privacy (canonical URL registered with Google and Meta) and mirrored at https://adovia-pro-nine.vercel.app/privacy. Both URLs serve the same policy.*