Epoyo
Privacy Policy
Effective 17 August 2026. This policy explains how Epoyo processes personal data across its website, account service, applications, connected services, support, email updates, and release infrastructure.
1. Scope
This policy applies to epoyo.com, account.epoyo.com, the Epoyo application and connected Epoyo services, waitlists and email updates, support correspondence, and transactional email. Individual applications may display additional notices when a feature needs more specific processing.
2. Data we process
Website and security: IP address, request URL, browser and device information, timestamps, and network or security signals needed to deliver the site, prevent abuse, and diagnose reliability. We do not currently use advertising cookies, tracking pixels, or behavioral advertising.
Waitlists and email updates: email address, selected product or newsletter topics, consent version and timestamps, confirmation state, source page, and delivery, unsubscribe, bounce, complaint, or suppression status. Joining a product waitlist does not create an Epoyo Account.
Epoyo Account: email address, immutable authentication identifier, optional display name, profile details, email-verification state, signed-in session metadata, security events, plan and entitlement status, and authorization grants for connected services. Supabase handles password credentials; the Epoyo application does not receive your password.
Workspaces and collaboration: cloud workspaces and boards you choose to synchronize, content and media you add, sharing and publishing choices, collaborator roles, comments, direct and group messages, attachments, friend and block relationships, reports, and moderation records. Demo work remains in your browser unless you choose to create an account and import it.
Application and release operations: application identifier, platform, architecture, version, release and download requests, short-lived session information, and explicit authorization decisions. Optional product-improvement analytics are off by default. If enabled, Epoyo keeps content-free daily counts such as app opens for 30 days; these counters exclude content, titles, messages, files, people, IP addresses, and a raw activity timeline, and turning the setting off erases retained counters.
Support and email: destination address, message template and delivery status for transactional or consented update mail; support ticket details and files you deliberately provide; and the information you include when contacting support, legal, or security. Never send us passwords, recovery codes, or private tokens.
3. Why we process data
We process data to provide requested services and account access, secure and operate the platform, deliver transactional messages and updates you requested, respond to support and legal requests, improve reliability, enforce the terms, and meet legal obligations. Waitlist and optional newsletter messages are based on consent, which you may withdraw at any time. Where the GDPR applies, other bases are performance of a contract or steps you request, legitimate interests in secure and reliable services, and compliance with law.
4. Cookies and local storage
Account authentication and security use strictly necessary browser storage or cookies. Applications may use local browser storage to keep local work. We do not currently use advertising or cross-site behavioral tracking cookies.
5. Connected services you authorize
The Epoyo application can read statistics from services you connect: Stripe, Shopify, RevenueCat, Google Analytics, YouTube, TikTok, Instagram, Pinterest, X, LinkedIn, and Bluesky. Connections are read-only. Epoyo requests only read permissions and never posts, edits, or deletes anything on a connected service on your behalf.
What we store: the access credential for each connection, encrypted at rest; the connected account's display name and identifier so you can recognize it; daily aggregate figures such as follower counts, engagement totals, sessions, and revenue; and, for each post a connected account publishes, the platform's own identifier for it, when it was published, its format (video, image, carousel or text), its length where the platform reports one, and its view, like, comment, share and save counts. Those per-post figures are what lets Epoyo tell you which of your formats and lengths are working, and they are kept for as long as the rest of your history under your plan. We do not store the content of your posts (no caption, title, hashtags, thumbnail or media), and we do not store your videos, messages, subscriber lists, or customer records from connected services. Figures refresh when you open the dashboard and, where the operator has enabled it, on a background schedule. Disconnecting a service deletes its credential immediately, and where the provider supports remote revocation Epoyo also ends the authorization on the provider's side. Deleting your account removes every connection and all figures derived from it.
Google user data: Epoyo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through Google APIs is used only to display your own analytics back to you. It is not used for advertising, is not sold, and is not read by humans except with your permission, where required for security, or to comply with law.
6. Events your own applications send to Epoyo
Workspaces can receive product events (for example "signup started" or "paywall viewed") from your own website or application through a publishable ingest key. Each event carries an event name, a pseudonymous visitor identifier that you choose, an optional campaign code, an optional timestamp, and optional properties. For this data you are the controller of your end users' information and Epoyo processes it on your behalf, solely to show you your own dashboard: funnels, trends, and per-link attribution. Do not place names, email addresses, or other directly identifying information in visitor identifiers or event properties; Epoyo's setup instructions say the same. Epoyo does not use these events for advertising, does not sell them, does not combine them across customers, and sets no cookies on your end users. Ingestion volume is metered per plan, stored events are removed once they pass your plan's retention period (Section 8), and you can export everything you hold as CSV or NDJSON at any time.
Hosted link pages are public pages you create with one entry per post. They contain no scripts and set no cookies. When a visitor taps an entry, Epoyo adds one to that link's counter for that calendar day (there is no per-click log and no profile of the visitor) and forwards them to your destination without a referrer.
7. Service providers and international processing
Cloudflare provides content delivery, bot verification, DNS, and security and may process data in the United States, the EEA, and other network locations using its published transfer safeguards. Supabase provides authentication and database services; project data is primarily stored in the selected project region, while authorized subprocessors may process data elsewhere under contractual safeguards. Resend (Plus Five Five, Inc.) provides transactional and consented update email from the United States. Proton AG provides company email from Switzerland. Railway Corp. provides application hosting and database infrastructure for the Epoyo application (app.epoyo.com) and may process data in the United States or the deployment region configured for the service. Stripe processes subscription payments; Epoyo never receives or stores full card numbers. Purchases made through the Apple App Store or Google Play are processed by those stores, and Epoyo receives only the verification data needed to activate your plan. Anthropic PBC provides the model behind the AI brief and campaign suggestions in the Epoyo application, from the United States. It is enabled. It receives only short derived statements about your own figures, such as that posts over a stated length reached a stated multiple of your median. It never receives your post content, captions, thumbnails or media, a credential for any connected service, your customers’ records, or the visitor identifiers and event properties described in Section 6. Every figure the model writes is checked against the statements it was given before it is shown to you, and output containing a figure that was not among them is discarded rather than corrected. We share only what each provider needs for its role and may disclose data where law requires it.
8. Retention
Account and profile data is kept while the account is active. A scheduled account closure has a 14-day cancellation window; after it ends, private credentials, sessions, profile data, private attachment bytes, and other account-only records are removed or anonymized. Content and records that must remain meaningful to collaborators, prevent abuse, resolve disputes, or meet accounting or other legal duties may retain an anonymized account reference. Waitlist confirmation links expire after 24 hours. Confirmed subscription and consent records are kept while you remain subscribed; after unsubscribe, minimal consent and suppression records may be retained to honor the request and prevent unwanted mail. Backups expire through normal provider cycles. Security, authentication, delivery, and release logs are retained only for configured operational and abuse-prevention needs. Support correspondence may be kept for up to 24 months after the matter closes; records required by tax, accounting, dispute, or other law are kept for the applicable statutory period. Product events and link-click counts (Section 6) are retained for 30 days on the Free plan and one year on paid plans, then removed automatically; Epoyo emails the account holder about a week before the oldest data is removed, with a link to export it first. Daily aggregate figures from connected services (Section 5) are kept while the connection exists and removed with it.
9. Your choices and rights
Every marketing email provides an unsubscribe or preference link. Withdrawing consent does not affect processing that was lawful beforehand. You can export account metadata, an authorized workspace snapshot, and your analytics history (CSV or NDJSON), end other sessions, manage optional analytics, disconnect any connected service at any time from Integrations (which deletes its stored credential immediately) and schedule account closure in Epoyo's Privacy center. See Delete your Epoyo account for instructions and an email alternative. Subject to applicable law, you may also request access, correction, deletion, restriction, objection, or data portability. We may verify identity before acting. Requests normally receive a response within 30 days, although complex requests may take longer where law permits. Contact legal@epoyo.com. You may also complain to the Swiss Federal Data Protection and Information Commissioner or your competent data-protection authority.
10. Automated decisions, children, and security
Epoyo does not currently make decisions producing legal or similarly significant effects solely by automated processing. Account registration is intended for people aged 16 or older. We use access controls, encrypted transport, isolated application authorization, provider security controls, and release verification, but no system can be guaranteed completely secure. Report suspected vulnerabilities to security@epoyo.com.
11. Changes and contact
We will update the effective date and provide appropriate notice when material changes affect current users. Privacy questions and rights requests: legal@epoyo.com. General support: support@epoyo.com.