Legal

Privacy Policy

Effective: August 1, 2026 · Last updated: August 1, 2026

1. Who We Are

MasonBee ("MasonBee", "we", "us") provides a unified social API that lets developers publish and manage content across multiple platforms through a single integration. For the purposes of data-protection law, MasonBee is the data controller for account data, and a data processor for the end-user content you send through the API.

Questions about this policy go to privacy@masonbee.dev.

2. What We Collect

We group the data we hold into three buckets:

CategoryExamplesWhy
Account dataName, email, company, API keysTo create and secure your account
Connection dataOAuth tokens for linked social accountsTo publish and read on your behalf
Usage dataAPI request logs, delivery status, error tracesTo operate, debug, and bill the service

We do not sell personal data, and we do not add tracking to the posts you publish through us.

3. How We Use It

  • To deliver the core service — publishing, scheduling, the unified inbox, and analytics.
  • To secure accounts, detect abuse, and enforce platform rate limits.
  • To communicate about the service: transactional notices, and — only if you opt in — product updates.
  • To meet legal and tax obligations.

4. Who We Share It With

We share data only where it is necessary to run the service:

  1. 01Social platforms you connect — to carry out the actions you request through the API.
  2. 02Infrastructure sub-processors — hosting, error monitoring, and email delivery, each bound by a data-processing agreement.
  3. 03Authorities — only where legally required, and after review.

A current list of sub-processors is available on request.

5. How Long We Keep It

Account data is retained while your account is active and for a limited period after closure to meet legal obligations. Request logs are kept for a rolling operational window and then deleted. You can request earlier deletion at any time, subject to what the law requires us to keep.

6. Your Rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. To exercise any of these, email privacy@masonbee.dev — we respond within the timeframe your local law sets.

7. Security

OAuth tokens and API keys are encrypted at rest. Access is scoped and logged. No system is perfectly secure, but we design for least privilege and we tell affected users promptly if something goes wrong.

8. Changes To This Policy

If we make a material change, we will update the version and effective date above and, where appropriate, notify you by email. Continued use after a change means you accept the updated policy.

9. Contact

MasonBee · privacy@masonbee.dev. For general support, see the contact page.

10. Data Deletion

You can request deletion of your data at any time, either through the account deletion option in your MasonBee dashboard, or by emailing privacy@masonbee.dev from the address associated with your account with the subject "Data Deletion Request".

When you request deletion, we remove:

  • your account data (name, email, company, API keys);
  • your connection data (OAuth tokens for any linked social accounts, which are also revoked);
  • your usage data (API request logs, delivery records, and error traces) tied to your account.

We complete deletion within 30 days of a verified request and confirm by email once it is done. We may retain a minimal set of records only where the law requires it (for example, tax or accounting records), and we tell you what is retained and why.

Deleting your data with us removes the stored tokens and revokes our access to any social accounts you connected. It does not delete content you already published on those platforms, which you manage directly on each platform.