Privacy Policy

Last updated: September 30, 2026

This notice describes how the Lacamio service (hereinafter: “Lacamio”, the “Service”) processes the personal data of users, website visitors and newsletter subscribers, as well as data originating from the social accounts (Facebook, Instagram, TikTok) that users connect. Lacamio is a social media management and post-scheduling service. This notice is the information we provide under Articles 13 and 14 of the General Data Protection Regulation (GDPR).

Controller (operator):

  • Company name: LAKA INVEST SRL
  • Trade Register No. (Nr. Reg. Com.): J14/204/2022
  • Tax ID (CUI): RO46371899
  • Registered office: Str. Oltului 67, Sfântu Gheorghe, Covasna County, Romania
  • Email: support@lacamio.com

1. Who this notice covers and who is responsible for the data

The operator (hereinafter: “we”) is responsible as controller for the data relating to Lacamio accounts, website visits, the newsletter and customer support enquiries, and for the data from your connected social accounts that we process at your request in order to provide the Service.

Businesses, agencies and teams that use Lacamio (hereinafter: “our customers”) also use the Service to process other people’s data: people who send messages to their Facebook Page or Instagram account, who comment under their posts, who take part in their giveaways, to whom they send posts or videos for approval, and whom they invite to their team. Our customer is the controller of this data; we process it as a processor, on their behalf and on their instructions (Article 28 GDPR). This data comes from the systems of Meta (Facebook, Instagram), from our customer or — on the approval and video review portals — directly from you; sections 3 and 5 describe exactly which data is involved. If you wish to exercise your rights as such a data subject, please first contact the business you messaged, under whose post you commented or whose giveaway you took part in; if you write to us, we will forward your request to our customer and help them fulfil it.

2. Data related to your account

  • Account data: your email address; your name, username and profile picture, if you provide them; your chosen language; the time you accepted the Terms of Use (recorded, for registration with an email address, when you submit the registration form after ticking the checkbox, and for registration with an external account, when the new account is created, after the notice shown above the sign-in button); for registration with an email address, the plan you chose and whether you asked us to send you news and offers. Your password is handled by our authentication provider, Supabase, which stores it only in irreversible (hashed) form; it never reaches us in plain text.
  • Signing in with an external account: if you sign in with a Google account (or another external provider offered on the sign-in page), we receive from the provider your email address, your name, the link to your profile picture and your account ID. We do not keep the provider’s access token: we filter it out of the sign-in response, so it does not end up in your sign-in cookie either.
  • Account security: your two-factor authentication setup, if you turn it on; the list of your signed-in sessions (IP address, browser); to recognise your devices, a random device identifier (cookie), browser details, the IP address, and the time of first and last use. If you sign in from a new device, we notify you by email (with the device type and the IP address). We keep a security log of important events (e.g. password change, change of email address, sign-in from a new device, connecting and disconnecting a channel, deletion of the account), together with your email address, the IP address and browser details; we do not record the reason for deleting the account in it (see section 11).
  • Brands and team: brand details (name, colour, time zone, logo, caption tone and custom AI instructions). If you work in a team, the members of a brand can see each other’s name, username, profile picture and email address; for invitations we store the invitee’s email address and role and who invited them. The brand’s activity log records who did what (e.g. approving a post, sending a reply), without the text of the messages.
  • Questionnaire: your answers to the optional questionnaire after registration (role, number of brands, platforms used, goals, how you heard about us).
  • Subscription: your plan and its status, and the customer and subscription IDs created at Stripe. We pass your email address and your Lacamio user ID to Stripe; you enter your card details on Stripe’s payment page, and they never reach us.
  • AI credits: a monthly counter of how many AI operations you have used (per user and per brand).
  • Customer support: your tickets and messages (email address, subject, text, category). To a ticket sent from within the app we automatically attach a summary (plan, AI credits, the name and status of the brand and of the channels, the error messages of up to 5 failed posts from the last 14 days, language, app version) — never a token or password. Through the help form available without signing in, we receive your email address, the subject and the message. If you arrive from the “Stuck? Write to us” link in the sign-in or registration error message, your browser passes the email address you entered there to the form, not in the web address (see section 14).
  • Content: the texts, images and videos you provide for posts (including the cover image, the story version and the image’s alternative text), and the output of the AI features, if you use it. You do not upload audio files: we create subtitles from the video’s audio track.

3. Facebook and Instagram accounts (Meta)

If you connect your Facebook Page or your Instagram professional account, we access the data below through Meta’s official API, with your permission. Each feature works only if you grant the permission it requires and Meta has approved that permission for Lacamio.

  • Connection: about your Facebook user we store only an app-scoped identifier specific to Lacamio, so that we can fulfil data deletion requests arriving from Meta (see section 12); we do not request your name or email address from Facebook. For the Pages you select we store the ID, name, @username and profile picture, and for the Instagram accounts linked to them the ID, name, username and profile picture, as well as the Page access token, encrypted (see section 15). We do not save your Facebook user token in a database: it is kept only for the duration of the connection, for at most 10 minutes, in an encrypted (AES-256-GCM) cookie that scripts running in the browser cannot read and that only our server can decrypt; we delete it once you have selected your Pages, and otherwise it expires after 10 minutes.
  • Profile picture copy: we save a copy of the channel’s profile picture to our storage, because Meta’s image links expire over time. The copy can be opened only through its exact, unguessable link, is refreshed every 30 days and is deleted when the channel is disconnected.
  • Posting: on your instruction — immediately or at the time you set — we send Meta the post text, one image or one video (feed post, Reels, story), the image’s alternative text and the video’s cover image. Meta downloads the media from our storage through an unguessable link. We store the post ID, the post link and the time of publication returned by Meta.
  • Editing and deleting published posts: on your instruction (at the request of the brand’s owner or an admin), we can edit the text of a Facebook post published with Lacamio, and delete a Facebook or Instagram post published with Lacamio from the platform. Deletion on the platform is permanent; in Lacamio the post’s record is kept, marked as “deleted”.
  • Messages (Inbox): we fetch Messenger and Instagram messages from Meta when you open the Inbox page, and we do not store them: we only display the list of conversations (the participants’ name or username and platform ID, an excerpt of the last message) and the most recent messages of a conversation, up to 20 (text, time, sender, previews of attachments and story mentions). We also fetch the sender’s name and profile picture from Meta; the profile picture and the attachments load into your browser directly from Meta’s servers. We send your reply on your instruction, on behalf of your Page or account, through Meta; if more than 24 hours have passed since the last message from the person you are corresponding with, we send the reply with Meta’s “Human Agent” tag. We do not log the text of the message or the recipient, only the fact that a reply was sent (with the platform and whether it was sent with the tag).
  • New activity alerts: Meta notifies us when a new messaging event occurs on your Page or Instagram account. Of this, we store only the time of the last event per channel (so we can indicate that a refresh is worthwhile); we do not store the content of the event, the sender or the conversation ID.
  • Comments: we likewise fetch the comments under your posts (the commenter’s name or username and ID, the text and time of the comment, the number of likes, whether it is hidden) only when you open them, and we do not store them. On your instruction, on behalf of your Page or account, we reply to a comment, hide it or make it visible again, or like a comment or post or remove the like. For comment replies we log only the fact that you sent one, without its text.
  • Who sees the messages and comments: the brand’s owner, admins and editors; they can also reply to them.
  • Giveaways: if you start a giveaway for one of your posts, we read the post’s comments and, so that the draw can be verified, store a snapshot of them: the commenter’s name (on Facebook the name, on Instagram the username) and platform ID, the text, ID and time of the comment, and whether it is hidden. We store the entrants added manually by the organiser, the beginning of the post text (up to 140 characters) and its link, the conditions of the giveaway (including the excluded names), the draw record (random seed, counts, the conditions in force at the time of the draw, time, who ran the draw), and the winners and reserves. The giveaway data is visible to the brand’s team members. Retention and anonymisation are described in section 11.
  • Statistics: Meta provides the performance data of your channels and posts as non-public insights intended for the account’s manager, with your permission. On Facebook: followers, Page views, engagements, new follows and unfollows; per post, reactions, comments, shares, clicks and video views. On Instagram: followers, number of posts, reach; per post, likes, comments, reach, saves, shares, views and, for stories, the number of replies. We do not only display these figures but also store them: per post, the latest value and a time series of the figures, and per channel, one daily aggregate (fetched up to two years back when you connect the channel), so that we can show trends and reports. These are aggregate figures that do not identify third parties.
  • Reports: for the brand’s report we keep the list of the channels’ posts (the post text, link, thumbnail link, time of publication and the figures) in a cache for up to 30 days: on Instagram, all of the account’s posts (including those published before Lacamio); on Facebook — depending on the permission Meta has granted Lacamio — the posts published with Lacamio or all of the Page’s posts. The list on the Posts page is only displayed, not stored.
  • Hashtag research: if you search for a hashtag for one of your Instagram channels, we fetch from Meta the top public posts for that hashtag (the text, like and comment counts and link of other accounts’ posts, up to 9 posts) and, to calculate the weekly quota, the hashtags your account has searched recently. We only show the result, we do not store it, and we do not keep a log of searches.

4. TikTok accounts

You connect your TikTok account through TikTok’s official login; what we can access is determined by the permissions you grant on TikTok’s authorisation screen. We process TikTok data in accordance with TikTok’s developer terms and policies, solely for the features you use.

  • Connection: the TikTok account ID, display name, @username (if you grant permission for it), the access and refresh tokens (encrypted), and the list of permissions actually granted. We save a copy of the profile picture to our storage (it can be opened only through its exact, unguessable link and is refreshed every 30 days). While the channel is connected, we renew access automatically about once a day, even if you are not using it at the time. The security log records the connection (together with your TikTok @username, if you grant permission for it).
  • Posting: you can send a video or a photo post (one image) to TikTok on your instruction, immediately or scheduled (for a scheduled post, our system starts the sending at the time you set). TikTok downloads the media from our storage through an unguessable link. The post is sent either as a draft or by direct publishing; the Channels page and the composer show which mode your channel posts in. When sent as a draft, the post lands in your TikTok account’s notifications (inbox), and you finish it in the TikTok app: you also choose the privacy level and the other settings there, and we do not receive them. In this case, for a video we do not send the caption; for a photo we do send the description. In Lacamio, such a post is marked “Sent as draft”. In both modes, we store TikTok’s publish ID (publish_id), the status of the sending (e.g. processing, sent as draft, published, failed), the time of the last check and any error message. Because TikTok processes the post after it has been sent, we keep querying TikTok for its status afterwards, counted from the sending: the processing for up to 24 hours, the public post ID for up to 48 hours, and what happened to a draft (whether you finished it in the TikTok app or discarded it) for up to 7 days; if TikTok rejects the post afterwards, within this period (for a draft: before it reaches the TikTok app), it is shown as failed in Lacamio. If TikTok provides the post’s public ID (typically only for posts visible to everyone), we store that too. TikTok posts cannot be deleted or edited from Lacamio.
  • Direct publishing (if your channel posts in this mode; for the post to go out, TikTok must also allow this for Lacamio and for your account): the post goes directly to your TikTok profile. When the TikTok panel appears in the composer (and also in the Planner if you replace the video of a post intended for direct publishing), we fetch from TikTok your account’s nickname, username and profile picture, the available privacy levels, whether comments, Duet and Stitch are turned off on your account, and the maximum video length. On the panel, you choose for each post the privacy level, whether to allow comments, Duet and Stitch (for a photo, comments only), the commercial content disclosure and, for a photo, whether to add recommended music. The privacy level has no default value: you must choose it yourself; allowing comments, Duet and Stitch, the commercial disclosure and adding music are off by default and are turned on only if you tick them. We store your choice with the post — together with which Lacamio user made it and when — and at every sending — for an immediate, scheduled or queued post, and on a retry — this is what we send to TikTok, together with the caption and, for a video, the cover image position (if you chose a cover image). At the moment of sending, we fetch the above account data again: if there is no valid choice, or your account’s settings have changed in the meantime so that your choice can no longer be sent (e.g. the chosen privacy level is no longer available, or you have turned off the interaction you requested), we do not send the post to TikTok (it may still go out to its other channels), we do not adjust the settings on your behalf, and an error message indicates this. We do not store the fetched account data. With direct publishing, a post can go to only one TikTok account, cannot be recurring and cannot go through approval (a post that has gone through approval, including on the client portal, or that is retried by a team member other than the brand’s owner or an admin, goes to TikTok as a draft). The brand’s team can see the stored settings in the Planner.
  • Statistics (if TikTok grants Lacamio permission for this and you grant it too): we also show your account’s follower count on the dashboard: when you open it, we fetch the count from TikTok at most once every 15 minutes and keep the latest value in a cache. In addition, we store it daily, and it also counts towards the brand’s aggregate follower change and the reports. For your posts sent with Lacamio for which TikTok provides the public ID, during the 30 days after sending we fetch and store as a time series the number of views, likes, comments and shares, and we also store the latest value in the post’s target-channel records. When such a post is opened in the Planner, we refresh this latest value after the 30 days too (without continuing the time series), and if we do not have the post’s link yet, we also fetch and save it.
  • Video list (if TikTok grants Lacamio permission for this and you grant it too): on the Posts page and in reports we may display the list of your TikTok videos (title, description, cover image link, video link, time of publication, and the number of views, likes, comments and shares). We keep the list in a cache for the report for up to 30 days; otherwise we do not store it. If Lacamio requests this permission but your channel has not yet granted it, the interface suggests reconnecting the channel.

5. Approval and video review for our customers’ clients

We process this data on behalf of our customer (the team that sent the link), as a processor; please direct requests concerning it primarily to them.

  • Post approval portal: if a team sends you posts for approval through a private link, we process your email address provided for notifications, the name you enter on the portal (your browser remembers it in a cookie for 180 days), your decisions and your notes.
  • Video review: if a team sends you videos for approval through a private link, we process the recipient’s email address, the name you provide, your decisions and your notes (with timecodes). The link is valid for 30 days from sending or resending; the team can extend it to a maximum of 90 days and can revoke it at any time. Your browser stores the name you enter and your unsent notes locally. We use your IP address only to limit abuse and do not save it. We send the emails about the batch; the reply-to address is the email address of the team member who sent it. If the team creates a post from an approved video, the video is moved to the post storage, whose links are unguessable but public, and from then on the rules for post media apply (see section 11).
  • There is no analytics on the approval and video review portals.

6. Newsletter

  • If you subscribe to Lacamio updates on the website, we save your email address and the place and time of subscription in a spreadsheet belonging to our Google account (Google Apps Script and Google Sheets). The purpose is to inform you by email about notable Lacamio updates; the legal basis is your consent.
  • When you register, you can indicate separately and voluntarily whether you would like to receive news and offers from us, and you can later turn this on or off at any time on the Settings page; we store this flag with your account, together with the time of the latest change, and we also record the change in the security log (for 365 days). We send such emails only to people who have consented to them.
  • You can withdraw your consent (unsubscribe) at any time, without giving reasons and free of charge: every newsletter and offer we send contains an unsubscribe link, you can turn off the flag recorded with your account yourself on the Settings page, and you can also ask at support@lacamio.com; we then delete your address from the list or turn off the flag recorded with your account. Withdrawal does not affect the lawfulness of processing before the withdrawal. We keep your newsletter address until you unsubscribe.
  • People who signed up for the early access notification (waitlist) before the newsletter was introduced will receive only one email from us, about the launch, which includes the option to subscribe to the newsletter; they will receive the newsletter only if they subscribe there. If they do not subscribe, we delete their email address within 30 days of the notification.

7. What we use the data for, and on what legal basis

  • Performance of a contract (Article 6(1)(b) GDPR): operating your account and the Service — connecting channels; creating, scheduling, publishing, editing and deleting posts; managing messages and comments; giveaways; statistics and reports; AI features at your request; teamwork, approval and video review; the related system messages (e.g. confirming registration, invitations, approval notifications); subscription and customer support.
  • Legitimate interests (Article 6(1)(f)): the security of the Service and of accounts (security log, device recognition and new-device alerts, IP-based abuse limiting, error logs); the summary attached to support tickets; persistent display of the channels’ profile pictures; product development and plan recommendations based on the optional questionnaire; statistics on the reasons for account deletions. You can object to these (see section 13).
  • Consent (Article 6(1)(a)): analytics (see section 14), the newsletter, and sending news and offers (see section 6).
  • Legal obligation (Article 6(1)(c)): invoicing and accounting records, and fulfilling and documenting data protection requests (including data deletion requests arriving from Meta).
  • For data processed on behalf of our customers (see section 1), our customer is responsible for the legal basis; we act on their instructions.

We do not sell your data, we do not use it for advertising profiling, and we use data received from social platforms only for the feature for which we requested it.

8. AI features and automated decision-making

  • Subtitles: if you request subtitles, Deepgram downloads the video from an unguessable link in our storage and creates a timestamped transcript. We return the transcript and the SRT subtitles created from it to your browser and do not store them on the server. We opt our requests out of Deepgram’s model improvement programme: according to Deepgram, it therefore does not use the audio to improve its own models, and retains it only for as long as necessary to process the request.
  • Caption suggestions: Anthropic (Claude) receives the transcript, the chosen language, the brand’s caption tone and custom AI instructions and, when you ask again, the previous suggestions.
  • AI hashtag suggestions: Anthropic receives the text of the post in the composer — with the names of the winners of your giveaways filtered out (see below) — and the interface language.
  • Giveaway rules: Anthropic receives the giveaway title, the prize, the brand’s name and tone, the language, the platform and a summary of the conditions — not the entrants, the comments or the excluded names.
  • We do not send to AI providers the messages, comments, entrant lists and statistics that we fetch from your Meta and TikTok accounts. The AI receives only the text for which you explicitly request a suggestion; if that text contains a name originating from a platform (e.g. in a winner announcement), we filter it out as described below, subject to the limitations set out there. Before requesting hashtag suggestions, we remove from this text the winner lines of the draft winner announcement, as well as the winners and reserves of your brands’ giveaways (their names, their @usernames — longer names also in inflected forms — and the IDs of their comments), wherever they appear in the text; if we cannot fully load the list of winners, we do not send the text. The filtering is automated and only knows the winners we can still identify, so it is not flawless: for example, it does not remove other names that you have typed into the text. For a draft winner announcement created in Lacamio (and for a copy made with Duplicate), we do not send the edited text at all when you request hashtag suggestions, only the giveaway’s title and prize.
  • AI output is only a suggestion: you decide whether to use it. We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. The giveaway draw is a random selection started by the organiser (our customer) according to the conditions they set.

9. Who receives the data

To operate the Service we use the following providers (processors), strictly to the extent necessary:

  • Supabase — database, authentication (sign-in, two-factor authentication, sessions, sending authentication emails — delivered by Resend) and image storage (profile pictures, brand logos, copies of the channels’ profile pictures). The encrypted tokens, the statistics and the giveaway entries are also stored here.
  • Vercel — running the application (hosting): every request, including fetching messages and comments, passes through its servers; server and error logs are generated here. With your consent, Vercel also performs the analytics (Vercel Web Analytics).
  • Sentry — error monitoring: reporting the application’s errors. Error reports may contain technical identifiers (e.g. the IDs of the Lacamio user, the brand, the post, the Facebook Page and the Instagram account), the location of the error, and error messages from the platforms and our providers; for an error in sending an email, also the email’s subject and the email provider’s response, which may include the recipient’s email address. We do not send tokens or passwords.
  • Cloudflare R2 — storage of post media: the files are accessible through unguessable but public links so that Meta, TikTok and Deepgram can download them. Videos sent for video review are kept in a separate, non-public store and can be opened only through signed links valid for 60–90 minutes.
  • Resend — sending system messages by email (e.g. welcome, team invitation, new-device alert, customer support, approval and video review emails), and delivering Supabase’s authentication emails (e.g. sign-up confirmation, sign-in link, password reset, email address change).
  • Stripe — online payment and subscription management. Stripe processes payment data partly as an independent controller, under its own privacy policy.
  • Deepgram — converting the video’s audio to text (subtitles).
  • Anthropic (Claude) — AI suggestions (caption, hashtag, giveaway rules). We filter out the names of giveaway winners before requesting hashtag suggestions; the limitations of the filtering are described in section 8.
  • Google — storing newsletter subscriptions (Google Apps Script, Google Sheets).

Independent controllers to whom we send data on your instruction, or from whom we receive data: Meta (Facebook, Instagram) and TikTok — they receive the published content, the replies and your actions, and process them under their own rules; and Google (or another external sign-in provider) if you sign in with an external account. The brand’s team members see the brand’s data according to their role, and content sent for approval is also seen by the client.

10. Transfers outside the European Economic Area

Some of our providers (e.g. Vercel, Supabase, Sentry, Cloudflare, Resend, Stripe, Deepgram, Anthropic and Google) are US companies or may also process data in the United States. In such cases the transfer is based on the European Commission’s adequacy decision (the EU–US Data Privacy Framework) where the provider participates in it, and otherwise on the standard contractual clauses (SCCs) adopted by the European Commission. You can ask at support@lacamio.com which safeguard applies to which provider, and for a copy of the safeguards (e.g. the standard contractual clauses).

11. How long we keep the data

  • Account, profile, brands, questionnaire answers, invitations, AI counters: until the account or the brand is deleted.
  • Posts (text, media, approval notes): until the post is deleted or until the post’s author deletes their account. Deleting a brand does not delete its posts: they remain with their author as posts without a brand. The post’s target-channel records (the IDs received from the platform, the link and the latest value of the post’s figures; for TikTok, the stored settings together with the user who chose them and the time, the publish ID and the status of the sending) are deleted together with the post, and also when the channel is disconnected (see section 12); we track the status of a TikTok sending for up to 7 days, and the records remain with the post after that too.
  • Post media: the media of drafts and scheduled posts is kept until publication or until the post is deleted. If the post has been sent successfully to all target channels, we delete the media; if TikTok had not yet downloaded the media at the time of sending, we keep tracking the download and delete the media afterwards. It is, however, kept if sending to any channel failed or only partly succeeded (so that it can be retried), if Facebook did not confirm downloading the video, if TikTok had not yet downloaded the media at the time of sending and tracking of the download was not started (this is the case for TikTok posts sent before the update of 27 September 2026), or if the TikTok channel ceased to exist (because it was disconnected, or because the person who connected it deleted their Lacamio account) before we could delete the media after tracking the download, and for the next occurrences of recurring posts; in these cases at most until the post or the account is deleted. Uploads not used in a post may also be kept until the account is deleted. A video uploaded to the Media & subtitles tool is deleted after processing. If processing does not take place because of a temporary rate limit, the file is kept so that you can retry; if you do not retry, your browser requests its deletion, and if that does not happen (e.g. because you close the tab), the file may be kept until the account is deleted.
  • Channel data, tokens, profile picture copies and the latest channel figures kept in the dashboard cache (e.g. the follower count): for as long as the channel is connected (until it is disconnected or the account is deleted).
  • Statistics: the time series of post figures for 400 days, the daily channel aggregates for 3 years (1,095 days), but in either case no longer than until the channel is disconnected; the report cache for up to 30 days, and it is deleted immediately when the channel is disconnected.
  • Giveaway entries: we anonymise the data of the imported comments immediately when the channel is disconnected or upon a Meta data deletion request, and at the same time we also delete the post excerpt stored with the giveaway (the beginning of the post text) and the post link (the post’s platform ID is kept); if this step fails, the daily clean-up makes up for it. If the channel ceases to exist because the person who connected it deleted their Lacamio account, the daily clean-up does the same. Independently of this, we anonymise all entries (including manually added ones) 90 days after the giveaway’s last draw (a redraw restarts the clock), and for giveaways that were never drawn, after 180 days of inactivity. On anonymisation, the name, the platform ID and the comment’s text, ID and time are deleted; the rows, the counts and the draw record are kept, but they no longer identify the entrants. The following are not anonymised: the draft winner announcement (an ordinary post, which you can edit or delete), excluded names entered manually in the conditions (both in the giveaway conditions and in the draw record), and the ID of the team member who ran the draw: these are kept until the post or the giveaway is deleted. While the channel is connected, the post excerpt and the post link are also kept until the giveaway is deleted (the 90-day and 180-day anonymisation does not affect them). The owner or an admin can delete the giveaway at any time, together with all its entries.
  • Logs: the brand’s activity log for 180 days (entries for draws before 24 September 2026 may also contain the winners’ names; these are also deleted after 180 days). Security log entries for 365 days from when they were recorded — even after the account is deleted, together with the email address, the IP address and browser details, because they are needed for the subsequent investigation of security events. Recognised devices for 365 days after their last use; the record of Meta data deletion requests for 365 days. We keep the reason given when deleting an account (one of the options offered) only as anonymous statistics, without any reference to your account, for 365 days; the deletion entry of the security log does not contain the reason (it may still appear in the entries for account deletions made before this notice took effect; these are also deleted after 365 days).
  • Customer support: tickets and messages for 365 days from the last message.
  • Video review: we store the videos in the private store for up to 90 days after the batch is closed or archived; for an open batch, until the link has been expired for at least 60 days and there has been no activity for 60 days. The team receives a warning email 7 days before deletion; when a batch is deleted, its videos are deleted too. The reviewer’s name, decisions and notes, and the recipient’s email address, are kept with the batch until our customer deletes the batch, the brand or their account.
  • Approval portal: the recipient’s email address and the notes until the brand or the post is deleted.
  • Not stored: Messenger and Instagram messages; comments (except the snapshot imported for a giveaway, see section 3 and above); hashtag results; the TikTok account data fetched before posting and at the time of sending (nickname, profile picture, available settings); transcripts; AI suggestions, unless you put them into a post, and except for the AI-generated draft giveaway rules, which we save with the giveaway and which are deleted together with it.
  • Newsletter: until you unsubscribe.
  • Invoicing: we keep the invoices for paid subscriptions and the data on them (e.g. name, email address, amount, date) for the period required by accounting and tax law (in Stripe’s system), even after the account is deleted. On the payment page, Stripe records your acceptance of the Terms of Use and your request for the subscription to start immediately (right of withdrawal, see section 8 of the Terms of Use) with the payment; with the subscription, we store the version and the language of the checkbox text. Card details are handled by Stripe and never reach us.
  • Backups and server logs: deleted data may remain in our hosting provider’s automatic backups until those backups expire, and in our manual database backups until those backups are deleted. We use backups only for restoration, and we do not restore deleted data from a backup. Vercel deletes server and error logs, and Sentry deletes error reports, according to their own retention periods.

12. Disconnection, deletion and revoking access

  • Disconnecting a channel: on the Channels page, only the brand’s owner can disconnect a channel, and only one that they connected themselves. Disconnection immediately deletes on our side the channel’s data and token, the posts’ target-channel records (with the IDs, links and statistics), the statistics time series, the profile picture copy and the brand’s report cache, anonymises the imported entries of giveaways run on the channel, and deletes the post excerpt and post link stored with the giveaways. For a Facebook Page, we also unsubscribe from Meta’s notifications if the Page is not used by anyone else in Lacamio. Your posts (text and media), the anonymised giveaways and the log entries are kept for the periods set out in section 11. Deleting a brand does not disconnect its channels: disconnect them separately.
  • Access on the platform: after a TikTok channel is disconnected, we also revoke Lacamio’s access on TikTok if the same TikTok account is no longer used by any other channel in Lacamio (e.g. one belonging to another user or brand); if it is still in use, we do not revoke access, so as not to interrupt that channel’s operation. The revocation takes place in the background after disconnection; if TikTok is unavailable at the time or responds with an error, if a technical error occurs on our side, or if we cannot establish with certainty that the account is not used by anyone else, it does not take place, and we do not make up for it later. You can also revoke access on TikTok yourself at any time in the app, under Settings and privacy → Security → “Manage app permissions”. For Facebook and Instagram channels, disconnecting deletes data only on our side: you can revoke access on the platform yourself, in the “Business integrations” (or “Apps and websites”) section of Facebook Settings — we connect your Instagram account through your Facebook Page, so you also revoke its access there.
  • If you revoke access only on the platform (on TikTok, or on Facebook without a data deletion request), the channel will not work in Lacamio, but the data we hold about it (name, profile picture copy, tokens, statistics) is kept until it is disconnected. So please also disconnect the channel in Lacamio, or write to support@lacamio.com and we will delete it.
  • Data deletion request through Facebook: if you remove Lacamio in your Facebook settings and request the deletion of your data, Meta notifies us. We then delete all Facebook and Instagram channels that were connected to Lacamio with your Facebook user (in any Lacamio account), together with the tokens, the posts’ target-channel records and the statistics; we delete the profile picture copies and the report cache of the affected brands, anonymise the imported entries of giveaways run on those channels, and delete the post excerpt and post link stored with the giveaways. We give you a confirmation code, and you can track the status of the request at lacamio.com/api/meta/data-deletion?id=[code], in Hungarian, English or Romanian according to your browser’s language. If a channel was connected without its Facebook ID being recorded, we check and complete the request manually. This request does not delete your Lacamio account or your posts — to do that, delete your account or write to us.
  • Deleting your account: you can permanently delete your account on the “Account settings” page. This immediately deletes your account and your profile; your own brands, together with their members, invitations, activity log and video review batches (the batches’ videos are deleted from storage shortly afterwards); all posts you wrote (including in other people’s brands); your channels and tokens; your devices; the customer support tickets linked to your account; the giveaways you created; the media you uploaded; and the profile pictures and logos. Posts written by your team members in your brands are not deleted: they remain with their author, without a brand, until the author deletes them or their account. In other brands, the text of the approval notes you wrote is kept (without the author). If you chose the TikTok settings of a post written by someone else (see section 4), your deleted account’s identifier is kept in that post’s target-channel records as the user who made the choice, at most until the post is deleted or the channel is disconnected. The following are kept for the periods set out in section 11: the security log entries (e.g. sign-in from a new device, channel changes and the deletion itself, with the email address, the IP address and browser details, for up to 365 days from when they were recorded), the anonymous deletion statistics (including the reason given), customer support messages sent without signing in, the newsletter subscription (unsubscribe from it separately), and the invoicing data and Stripe’s records.
  • Subscription and access when deleting your account: as the first step of the deletion, before your data is deleted, we close any of your payments at Stripe that are still open (unfinished) and immediately cancel all of your subscriptions that would still be charged; after that, we do not charge any further fees. At Stripe we record only that the subscription ended because the Lacamio account was deleted; we do not pass on the reason for the deletion. If closing the open payments or the cancellation fails, we do not delete your account: in that case, cancel your subscription on the “Plan & billing” page using the “Manage subscription” button, or write to support@lacamio.com, and try deleting again. If the deletion itself fails after the cancellation, your subscription remains cancelled (we tell you so on the page) and we do not charge any further fees; by then, your uploaded media may already have been deleted. In that case, try deleting again or write to us. Fees already paid are not refunded automatically (see section 8 of the Terms of Use). After a successful deletion, we also unsubscribe your Facebook Pages from Meta’s notifications if the Page is not used by anyone else in Lacamio (if this does not happen, we store nothing from notifications that arrive afterwards). Likewise, after a successful deletion we also revoke Lacamio’s access on TikTok for your TikTok channels, subject to the condition and limitations described for disconnection. On Facebook and Instagram, deleting your account does not revoke Lacamio’s access: you can do that in the place described above.

13. Your rights

  • Access: you can see most of your data in your account; you can also request a copy of the data we process about you.
  • Rectification: you can change your data in your account or ask us to correct it.
  • Erasure: you can disconnect a channel, delete your account (see section 12) or request the erasure of your data.
  • Restriction of processing in the cases set out in the GDPR.
  • Data portability: on request, we send you the data you provided in a machine-readable format (the Service has no self-service export).
  • Objection: you can object to processing based on legitimate interests on grounds relating to your particular situation, and to the newsletter and to news and offers at any time.
  • Withdrawal of consent: at any time, without affecting the lawfulness of processing before the withdrawal; for analytics, using the “Cookie settings” button (see sections 6 and 14).
  • Complaint: you can lodge a complaint with the Romanian supervisory authority (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal — ANSPDCP, www.dataprotection.ro), or with the supervisory authority of your habitual residence, your place of work or the place of the alleged infringement (in Hungary: Nemzeti Adatvédelmi és Információszabadság Hatóság, www.naih.hu).

Please send your requests to support@lacamio.com. We respond without undue delay and within one month at the latest; where justified, this period may be extended by two further months, in which case we will inform you. We may verify your identity before fulfilling a request.

Do you have to provide your data? Registration requires your email address (and a password or an external sign-in); without it we cannot create an account. Connecting a channel and using each feature require the corresponding permission on the platform. Everything else (name, profile picture, questionnaire, newsletter, analytics) is voluntary.

14. Cookies and data stored in your browser

  • Cookies necessary for operation: keeping you signed in (Supabase); the device recognition security cookie (2 years); the active brand (1 year); the language (until the browser is closed); temporary cookies while a channel is being connected (for up to 10 minutes: verifying the request, the brand being connected, the return address, for Facebook the user token, for TikTok the login verification code); on the approval portal, the name you entered (180 days).
  • Your browser’s local storage: your cookie choice, the theme (light or dark), post composer drafts, pending deletions, your email address during registration (until the browser tab is closed), the email address you entered when you click the help link in the sign-in or registration error message (we delete it when the help form opens; otherwise it is kept until the browser tab is closed), and on the video review portal the name you entered and your unsent notes.
  • Analytics: Vercel Web Analytics loads only if you choose the “Accept” button on the cookie banner; it measures both on the website and in the app. According to Vercel, it does not use cookies and records the address of the page visited, the referring page, the country, and the type of device, operating system and browser. It does not measure on the approval and video review portals or on the email confirmation page, even with consent. Your choice is stored by your browser. You can change or withdraw it at any time using the “Cookie settings” button in the website footer or, in the app, in the account menu: this reopens the cookie banner, which also shows your current choice. After you choose “Necessary only”, measurement stops immediately and does not take place on further pages or visits; this only changes your stored choice and does not delete any other data.
  • We do not use advertising or third-party tracking cookies, or tracking pixels.

15. Security

  • We store the social platforms’ access tokens with AES-256-GCM encryption, in a table that only the server can access. We decrypt stored tokens only on the server, immediately before calling the platform, and we do not send them to the browser. During the Facebook connection process, the Facebook user token is kept for up to 10 minutes in a cookie that is encrypted in the same way, cannot be read by scripts running in the browser, is transmitted over HTTPS and can be decrypted only by the server (see section 3).
  • Row-level security (RLS) in the database ensures that a user can access only their own data and the data of their brands.
  • Two-factor authentication can be turned on; we send an email about sign-ins from a new device; we keep a security log of important events.
  • Video review videos are kept in private storage and can be accessed only through short-lived signed links; we store the secret code of video review client links only as a hash and as an encrypted copy.

However, no internet service can guarantee complete security.

16. Children

The Service is intended for people aged 18 or over (see the Terms of Use). We do not knowingly process the account data of anyone under 18; if we become aware that such an account has been created, we delete it.

17. Changes to this notice

We may update this notice from time to time. We will inform you of material changes on this page (by changing the “Last updated” date) and, where appropriate, by email.

18. Contact

For privacy questions: support@lacamio.com.