Privacy Policy
What SocioRep collects, how we use it, and who else sees it.
Version 2026-08-10 · Effective 10 August 2026
Who we are & about this policy
This Privacy Policy explains what personal information SocioRep collects, how we use it, who we share it with, and the choices you have. It applies to the SocioRep service — the website, application and related communications. In this policy, "you" means the business using SocioRep — the owner or authorised user of a SocioRep account, and also anyone using SocioRep without an account, which parts of the service allow. "Your customers" means the people your own business serves. Where something applies only to people using SocioRep without an account, we say so, and the section "Using SocioRep without an account" sets it out in one place.
SocioRep is operated by Sajel Saxena under LabTech, GSTIN 23BBFPS9664D1ZF, at DHV 3/50-51, Danish Hills View, Kolar Road, Bhopal, Madhya Pradesh 462042, India. LabTech is responsible for the personal data described in this policy.
For any privacy question or request, write to connect@sociorep.com. For a grievance about how we handle your personal data, our Grievance Officer is Sajel Saxena, reachable at grievance@sociorep.com or at the address above.
SocioRep is currently in alpha and is intended for business use. Anyone can use the part of SocioRep that reads a business and writes a post, without an account. Creating a SocioRep account still requires an invite.
Information we collect
We collect the following categories of information.
Account information. When you create an account we store your email address, a securely hashed version of your password (we never store your password in readable form), your name, and — if you provide it — your date of birth, together with email-verification and account-status information.
Business and brand information. To do its job, SocioRep stores the business and brand details you provide or that are drawn from your website: your business name, description, tagline, audience, keywords, brand colours and fonts, website address and social handles, logo, and your goals and focus notes. This can include your business locations (street address, city, PIN code, phone number and opening hours) and your products (name and price).
Information about other people you add. If you add team members or staff to your brand profile, we store the details you enter about them (such as name, role and birthday). If you add testimonials, these may contain a customer's name or words. You are responsible for having the right to provide this — see "Information about other people".
The content SocioRep creates. We store the posts, drafts, designs, images, videos and blog posts produced for your brand. Blog posts you choose to publish are public.
Connected channels. If you connect a social media channel, we store that channel's access tokens in encrypted form, along with the connected account's identifier and display name. During the current alpha, channel connections use placeholder credentials only.
Billing information. Payments are handled by our payment processor, Razorpay. In connection with billing we store information such as your billing email, GSTIN, billing address, plan and subscription details, payment identifiers and invoices.
Sign-in and session information. When you sign in we store a hashed session identifier, and we record the IP address and browser/device information (user-agent) associated with your active sessions, for security.
Security and anti-abuse information. To detect and prevent fraud and abuse, we keep a limited security log. This is the only place we hold a raw IP address, and we automatically remove the raw IP after 30 days, keeping only a one-way hashed form for fraud prevention.
AI request records. Each time SocioRep generates something for you we keep a record of the request — which brand it was for, what it was for, the model used, and what it cost us. This record is how your credit usage and our costs are accounted for.
Product-usage information. We record basic navigation events — which screens were reached and whether an action completed — to keep the product working well. These records deliberately do not include your IP address or your browser/device information.
At signup we keep only a coarsened form of your network address (a network prefix and a device class), not your full IP address.
Using SocioRep without an account
You can use SocioRep without creating an account: tell us your website or describe your business, say what you would like to post about, and we will write and design a post for you. This section explains what happens to what you give us when you do that. Everything here is in addition to the rest of this policy, which continues to apply.
How we recognise you. We place a cookie in your browser. Our database holds only a one-way hashed form of that cookie's value — the value itself never reaches it. That cookie is the only way the work you make can be found again.
What we store with it. The website address you gave us; the business name and logo we read from that website; the material we extracted from the page; what you typed; the directions we offered you; and the posts made. If you upload a photograph, we store the photograph.
Photographs you upload. We re-encode every uploaded photograph and remove the camera information embedded in it, including any location the camera recorded. A photograph taken on a phone often carries where it was taken, and these posts are made to be published.
Where the text goes. To write your post we send the text — your website's words and what you typed — to OpenAI through our own internal gateway, exactly as we do for an account holder. We send text only, never your images. The section "Service providers we share data with" describes those providers and what they receive.
How long it lasts. Thirty days. The period is set when the record is created and cannot be extended, and the cookie's own lifetime is set from the same value, so the two cannot come apart. On the thirtieth day the record stops being reachable, whether or not it has yet been removed. A nightly job then deletes the record together with any photographs uploaded with it. If a photograph's deletion cannot be confirmed, we keep the record and try again rather than remove the record while the file is still there.
If you create an account. Everything you made without an account moves into your new account, and the record we kept against the cookie is deleted in the same step. It is all or nothing: if any part of the move fails, none of it is applied.
Fair-use limits. There are limits on how many posts can be made from one browser, and from one network, in a day and in a week. They exist to keep the service available and to prevent abuse.
Removing it. There is no button that deletes one of these records on request, and we would rather say so than imply one exists. Two things are true instead. The record removes itself on the thirtieth day. And you can end your own access to it at any time by clearing this site's cookies in your browser — though the record itself stays with us until that thirtieth day. If you would like to write to us about it, connect@sociorep.com.
How we use your information
We use your information to:
- provide the SocioRep service — understanding your brand, planning and creating content, and keeping your calendar moving;
- create and secure your account, and keep you signed in;
- process payments and issue invoices, through Razorpay;
- send you service communications, such as verification, security, billing and account emails;
- detect, prevent and investigate fraud, abuse and security incidents;
- maintain, troubleshoot and improve the reliability of the product;
- meet our legal and tax obligations.
We do not sell your personal information. We do not run third-party advertising, and we do not track you across other websites or apps.
Cookies
SocioRep uses a small number of first-party cookies and no third-party tracking cookies. We do not use analytics, advertising or social-media tracking pixels of any kind. Because none of our cookies are used for advertising or for tracking you across other sites, we do not show a tracking-consent banner; the cookies we use are either strictly necessary for the service to work or remember a preference you have set.
The cookies we use are:
- sr_session — keeps you signed in (strictly necessary).
- sr_csrf — protects forms against cross-site request forgery (strictly necessary).
- sr_org — remembers which organisation you are working in (functional).
- sr_brand — remembers which brand you are working in (functional).
- sr_mode — remembers your light/dark display preference (preference).
- sr_skin — remembers your chosen theme (preference).
Our public marketing pages set only the strictly-necessary security cookie, and our public blog sets no cookies at all. The functional and preference cookies are set only after you sign in. The only third-party script we load is our payment provider's secure checkout, which loads only on the billing page after you are signed in.
Service providers we share data with (sub-processors)
To run SocioRep we rely on a small set of service providers. Each receives only the data it needs for its role.
- OpenAI — generates text. We send text prompts that include business-identifying details (such as your brand name, description, tagline and audience) to OpenAI through our own internal gateway. We send text only — never your images. We use a standard OpenAI developer API account. Under OpenAI's standard API terms, data sent through the API is not used to train their models by default, and may be retained by OpenAI for a limited period for abuse monitoring before deletion, except where they are required to keep it longer by law. We do not have any custom or negotiated arrangement beyond those standard terms.
- Anthropic — a configured fallback for text generation. Anthropic is used only if OpenAI is temporarily unavailable; in normal operation no data reaches it. When the fallback engages, the same text prompts (business-identifying details; text only — never your images) go to Anthropic through our own internal gateway instead, so the Service keeps working. We use a standard Anthropic developer API account, under the same kind of standard terms described above, with no custom arrangement.
- Razorpay — processes payments. Razorpay receives billing information including your name, email, phone number, GSTIN and payment details. It is our payment processor and the main third party that receives your contact details.
- Brevo — delivers our email. Our service emails (such as verification, security and account messages) are sent through Brevo, which processes the recipient email address and message content in order to deliver them.
- Cloudflare — protects and delivers our website. Cloudflare processes visitor traffic, including IP addresses, at its edge network.
- DigitalOcean — hosts our application, database and stored media (see "Where your data is stored").
- Pexels — provides stock imagery. We send only search topics; no personal data is sent to Pexels.
Publishing channels (for example Meta / Facebook / Instagram and LinkedIn) are listed here for transparency: if and when you connect one of these channels, we will share the content and account information needed to publish on your behalf. During the current alpha, publishing to social platforms is not active and these providers do not currently receive your data.
Information about other people
SocioRep lets you add information about other people to your brand — for example team members, or customers whose testimonials you want to feature. When you provide this information, you confirm that you have the rights and consent needed to share it with us and to have it used to create content for your brand. We process this information on your behalf and under your instructions. If someone asks you to remove their information, please remove it from your brand, or write to connect@sociorep.com and we will help.
Where your data is stored
Our primary systems are in India. The SocioRep application, its database, and the media and brand assets you upload or that we create for you are hosted with DigitalOcean in its Bangalore (India) region.
Some of the providers named above process specific data outside India in order to perform their role: Cloudflare handles website traffic on its global edge network; OpenAI, and Anthropic when the fallback engages, receive the text prompts described above; and Brevo processes the recipient address and content of our service emails. Razorpay processes payment data. Apart from those specific transfers, your data stays on our India infrastructure.
How we protect your data
We take reasonable technical and organisational measures to protect your information. Passwords are stored using strong one-way hashing and are never readable by us; session and verification tokens are stored hashed; and the access tokens for any connected channel are encrypted. Traffic between you and SocioRep is protected with HTTPS/TLS. Each customer's data is kept logically separate, and that separation is enforced by the database itself rather than only by application code. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
How long we keep your data
We keep your personal information for as long as your account is active and for a limited period afterwards, so that we can operate the service, meet our legal and tax obligations, and prevent abuse.
Work made without an account is on a fixed cycle of its own: thirty days from when the record is created, not extendable, after which the record and any photographs uploaded with it are removed. See "Using SocioRep without an account".
Some data is kept on shorter, fixed cycles: sign-in sessions expire automatically, and the raw IP address in our security log is automatically removed after 30 days, leaving only a one-way hashed form.
Records we are legally required to retain — such as invoices and payment records — are kept for the period the law requires, even after your account is closed. Limited security and audit records are also retained to protect the service.
To request deletion of your data, see our Data Deletion page, which sets out exactly what is removed and what is kept.
Your rights and grievance redressal
Subject to applicable law, you may ask to access the personal information we hold about you, to correct it if it is inaccurate, or to request its deletion. Much of your account and brand information can also be viewed and edited directly in the product. To make a request, or if you have any concern about how we handle your personal data, write to connect@sociorep.com.
Our Grievance Officer is Sajel Saxena. You can raise a grievance about your personal data at grievance@sociorep.com, or by post to LabTech, DHV 3/50-51, Danish Hills View, Kolar Road, Bhopal, Madhya Pradesh 462042, India. We aim to acknowledge and respond within a reasonable time.
Deleting your data
You can ask us to delete your account and associated data by writing to us from your account's email address. Self-service deletion inside the product is not available yet, so a member of our team carries it out. If you used SocioRep without an account, see "Using SocioRep without an account" — that work is on its own thirty-day cycle and is not tied to an account we could delete.
Some information is retained where we are legally required to keep it — for example invoices and payment records — or where a limited, pseudonymous record is needed for security and fraud prevention. Our Data Deletion page sets out precisely what is removed, what is kept, and why.
Children
SocioRep is a business tool intended for use by adults aged 18 and over. It is not directed at children, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, write to connect@sociorep.com and we will take appropriate steps.
Changes to this policy
We may update this Privacy Policy from time to time. Every version carries the version number and effective date shown at the top of this page. When we make material changes we update those, and where appropriate we notify you or ask you to accept the new version. Your continued use of SocioRep after an update means you accept the updated policy.
Questions about this policy? Write to connect@sociorep.com. For privacy or grievance matters, contact our Grievance Officer, Sajel Saxena, at grievance@sociorep.com. SocioRep is operated by Sajel Saxena under LabTech, GSTIN 23BBFPS9664D1ZF, at DHV 3/50-51, Danish Hills View, Kolar Road, Bhopal, Madhya Pradesh 462042, India.
See also: Terms of Service · Data Deletion · Refunds & Billing