Simino Social legal
Privacy Policy
This Privacy Policy explains how Simino Social collects, uses, stores, discloses and protects personal information when you use our website, mobile application, scheduling tools, media library and social publishing services.
Effective Date: 22 August 2026 · Last Updated: 22 August 2026
1. Introduction
Simino Social lets you compose a post once, attach a photo or video, choose which of your connected Facebook Pages, Instagram Business accounts and YouTube channels should receive it, and publish immediately or at a scheduled time.
In this policy, “Simino Social”, “Company”, “we”, “us” or “our” refers to SIMINO LABTEST PRIVATE LIMITED. The product is built by its AI product studio Smartnetra, which also owns the domain this site is served from. “You” means a visitor, account holder, workspace member or other user of the platform.
Related documents: Terms of Service, Delete your data and Security.
2. Information We Collect
Account information: the email address you sign in with, your user identifier, workspace name, workspace membership and role, and your communication preferences.
Content you create: post captions, titles, descriptions, scheduled publish times, target account selections, and the delivery status of each post.
Media you upload: the photo and video files you add to a post, together with technical facts we read from them such as file size, MIME type, image dimensions, video duration, aspect ratio and a content checksum.
Connection information: the identifiers, display names and profile images of the social accounts you connect, and the encrypted credentials described in section 4.
Device and usage data: browser and device type, operating system, IP address, pages viewed, session activity, and diagnostic or error records generated while you use the service.
Support information: messages, attachments and account details you send us when you contact support.
3. Information From Connected Accounts
When you connect a social account, we receive only the information needed to list the account and publish on your behalf:
- Facebook: the Pages you administer, and for each Page its Page ID, name, profile picture and a Page access token.
- Instagram: the Instagram Business or Creator account linked to a Page you administer, and its account ID, username and profile picture.
- YouTube: the channels on your Google account, and for each channel its channel ID, title and thumbnail.
We also store the identifier and permalink that a platform returns after a successful publish, so we can show you where a post went and avoid publishing the same post twice.
We do not read your inbox, direct messages, friends list, contact list, follower list or private posts. We do not download your existing photo or video library from any platform.
4. Access Tokens and Passwords
We never see, receive or store your Facebook, Instagram or Google password. When you connect an account, we send you to the platform’s own website. You type your password there, on their domain, over their connection. The platform then returns an access token to us — a revocable key scoped to the specific permissions you approved.
Those tokens are protected by four independent measures:
- They are encrypted with AES-256-GCM before being written to storage.
- The encryption key is held in our server-side function environment, never in the database, so a copy of the database alone does not reveal a usable token.
- They are stored in a private database schema that is not exposed through our public API and cannot be selected by any signed-in user, including you.
- Row-level security is enabled on that storage with no policy that grants access, so ordinary application credentials are refused even if the other layers were bypassed.
Tokens are decrypted only inside the server-side function that is publishing your post, for the duration of that call. They are never sent to your browser or mobile app.
You can disconnect an account inside Simino Social at any time, which deletes the stored token. You can also revoke our access directly from Facebook Business Integrations or your Google security settings, without visiting our site at all.
5. Media You Upload
Photos and videos you upload are held in a private storage bucket. They are not public, not indexed and not listable. Access is restricted to the workspace that uploaded them.
Facebook and Instagram publish media by fetching it from a URL rather than accepting a file upload. To publish to those platforms we generate a short-lived signed link to your file, valid for a limited period (two hours by default) and unguessable, and pass it to Meta. The link expires on its own; it is not reused and is not shared with anyone else.
YouTube requires the file itself. Videos destined for YouTube are uploaded from your browser or mobile app directly to Google’s upload endpoint. Those bytes do not pass through our servers.
We do not run facial recognition, biometric analysis or content-based advertising profiling on your media.
6. How We Use Information
- Create, authenticate and manage your account and workspace.
- Store drafts, media and schedules until you publish them.
- Check a file against each platform’s published limits before publishing, and tell you in plain language when it will be rejected.
- Publish your posts to the accounts you selected, at the time you chose.
- Retry a failed delivery, and record why a platform refused it.
- Show you the status, platform identifier and link for each delivery.
- Diagnose faults, prevent abuse and keep the service reliable and secure.
- Send service messages such as delivery failures, security alerts and policy notices.
- Comply with legal, tax, regulatory and business obligations.
We do not sell personal information. We do not use your content or platform data to train machine-learning models. We do not use it for advertising or to build advertising profiles.
7. Facebook and Instagram Data
Our use of information received from Meta APIs adheres to the Meta Platform Terms and Developer Policies, including the limited-use requirements.
We request only the permissions the publishing feature needs:
pages_show_list— to list the Pages you administer so you can choose one.pages_read_engagement— to read a Page’s name and picture, and to obtain the Page access token used for publishing.pages_manage_posts— to create the photo or video post you composed.instagram_basic— to identify the Instagram Business account linked to your Page.instagram_content_publish— to publish the media container you composed to that account.
We do not transfer Meta platform data to data brokers, advertising networks or monetisation partners. We do not combine it with data from other sources to build profiles. We do not use it for any purpose other than operating the features you asked for.
If you remove Simino Social from your Facebook Business Integrations, the token becomes invalid immediately and any pending posts to that account will fail rather than publish.
8. YouTube API Services and Google Data
Simino Social uses YouTube API Services. By connecting a YouTube channel you agree to be bound by the YouTube Terms of Service. Google’s Privacy Policy describes how Google handles data it receives.
We request two Google scopes:
youtube.upload— to upload the video you composed to the channel you selected.youtube.readonly— to list your channels so you can choose one, and to read the title and thumbnail we display.
Simino Social’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We store your channel identifier, channel title, channel thumbnail, an encrypted refresh token and the identifier of each video we upload for you. We store nothing else from your Google account.
You can revoke our access to your YouTube data at any time from the Google security settings page at myaccount.google.com/permissions, or by disconnecting the channel inside Simino Social. To request deletion of the YouTube data we hold, follow the steps in Delete your data.
11. Service Providers and Hosting
We rely on a small set of infrastructure providers:
- Supabase — authentication, the application database and private media storage.
- Cloudflare — website delivery and the scheduler that triggers posts at their appointed time.
- Meta Platforms, Inc. and Google LLC — the destination platforms, which receive only what you chose to publish.
These providers process data on our instructions and are not permitted to use it for their own purposes.
12. Data Retention
Posts, media and delivery records are retained while your account is active so you have a history of what was published where.
When you disconnect a social account, the stored credential for it is deleted at once. When you delete your account, we delete your posts, media, connections and credentials as described in Delete your data.
Limited records may be retained longer where necessary to resolve disputes, prevent fraud or abuse, enforce our agreements, or meet legal, tax and accounting obligations. Content already published to Facebook, Instagram or YouTube lives on those platforms and must be deleted there.
13. Deleting Your Data
You can request deletion of your data at any time. There are three routes, all described step by step on the Delete your data page:
- Self-service: disconnect an account in Simino Social to delete its stored credential, or delete individual posts and media.
- Full account deletion: email SiminoSocial@smartnetra.com from your registered address with the subject “Delete my account”. We action verified requests within 30 days and confirm by email when it is done.
- Revoke at the platform: remove Simino Social from your Facebook Business Integrations or your Google security settings.
14. Your Rights
Subject to applicable law, including India’s Digital Personal Data Protection Act, 2023, you may request access to your personal data, correction of inaccurate data, deletion, withdrawal of consent, and grievance redressal.
To exercise these rights, contact SiminoSocial@smartnetra.com. We may ask you to verify control of your registered email address before acting on a request.
15. Security
We use administrative, technical and organisational safeguards including encrypted transmission, encryption of credentials at rest, row-level access control that scopes every record to its workspace, private storage buckets, short-lived signed links, and separation of the credential store from the public API. Our Security page describes these in more detail.
No internet service can guarantee complete security. Protect your email account, since it is what signs you in, and disconnect social accounts you no longer use.
16. International Transfers
Our infrastructure providers operate globally, so your information may be processed outside your country of residence. Where required, we rely on appropriate safeguards and on the contractual commitments those providers make about how they handle data on our behalf.
17. Children
Simino Social is intended for adults operating business or creator accounts. It is not directed at children, and we do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact SiminoSocial@smartnetra.com and we will delete it.
18. Changes to This Policy
We may update this Privacy Policy from time to time. The updated policy will be posted on this page with a revised Last Updated date. Where changes are material we will also notify you by email or in the application.
19. Contact Us
Simino Social
SIMINO LABTEST PRIVATE LIMITED
At Plot -1, Forest Park, Near Sishuvawan Square, Bhubaneswar, Odisha, India
Email: SiminoSocial@smartnetra.com
Phone: +91-90400-11908
20. Grievance Redressal
For privacy complaints, access requests, correction requests, deletion requests or other data-related queries, contact the Grievance Officer at SIMINO LABTEST PRIVATE LIMITED.
Email: SiminoSocial@smartnetra.com
Phone: +91-90400-11908
This Privacy Policy is governed by the laws of India. Disputes will be subject to the jurisdiction of competent courts in Bhubaneswar, Odisha, India.