Bright’s Social Media Manager

Privacy Policy

This policy explains what personal data Bright's Social Media Manager ("we", "us") collects, why, who we share it with and what rights you have. It follows the Kenya Data Protection Act, 2019. We are run by Bright Coders, Nairobi, Kenya. Questions: privacy@example.com.

1. Who is responsible for what

  • Your account and workspace data (your name, email, brand details, billing): we are the data controller.
  • Your customers' data that passes through your connected accounts (comments and messages people send your business): you are the controller and we process it for you, only to show it to you in the Inbox and help you reply.

2. What we collect

  • Account: name, email address, a hashed password (never the password itself), or your Google account ID if you sign in with Google, and the time and IP address of sign-ins.
  • Workspace: business name, brand profile, FAQ, posts, drafts, photos and videos you upload, settings, and your credit and plan history.
  • Connected social accounts: the names and IDs of the Facebook Pages and Instagram accounts you connect, and the access tokens that let us act on them. Tokens are encrypted and never shown. We never see or store your Facebook or Instagram password.
  • Activity from those accounts: your published posts, their likes, comments and reach, follower counts, and comments and messages your audience sends (name or username, text and time). Webhook copies of messages are deleted soon after they are processed.
  • Payments: plan, amount, date and method. Card details go straight to the card processor and never touch our servers. For M-Pesa we keep only the last three digits of the phone number.
  • Technical: session and security cookies, error logs and an audit log of important actions (sign-in, connect, publish, delete, plan changes).

3. Why we use it

  • To provide the service you asked for: scheduling and publishing posts, showing your inbox and analytics, generating drafts (contract).
  • To keep the service secure, prevent abuse and fix problems (legitimate interest).
  • To bill you and keep accounting records (contract and legal obligation).
  • To email you about your account, sign-in codes, receipts, failed posts and plan reminders (contract). We do not send marketing email without your consent, and we do not sell personal data.

4. AI processing

When you ask for a draft, reply suggestion, brand profile or insight, the text needed for that request (for example your brief, your brand profile, a customer's message and your FAQ, or summary numbers) is sent to an AI provider. Depending on how the service is configured this is Anthropic or DeepSeek. We send only what the request needs, a person always reviews before anything is published or sent, and our providers' terms are used to ensure your content is not used to train their general models. AI output can be wrong: check it before you approve it.

5. Who we share data with

Only service providers that help us run the service, under contract:

  • Meta (Facebook and Instagram): to publish, read comments and messages and fetch analytics for accounts you connect. Their own privacy policy applies to data on their platforms.
  • AI providers: Anthropic and/or DeepSeek, as described above.
  • Payment providers: Safaricom (M-Pesa), Flutterwave and Paystack, to process payments.
  • Google, if you choose "Continue with Google".
  • Hosting and email delivery providers, who store and send the data on our behalf.
  • Authorities, where the law requires it.

Some of these providers are outside Kenya. Where data is transferred abroad we rely on your consent through using the service, the contract needed to provide it, and appropriate safeguards required by the Kenya Data Protection Act.

6. How long we keep data

  • Your workspace data: until you delete the workspace or we end the account.
  • Raw webhook copies of customer messages: deleted once processed (and in any case within days).
  • Payment and invoice records: as long as tax and accounting law requires (currently at least five years), even after deletion.
  • Security and audit logs: kept for a limited period, then removed or anonymised.

7. Your rights

You can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or move it elsewhere, and you can withdraw consent at any time. You can change your name, workspace and password in Settings. Email privacy@example.com and we will respond promptly and within the time limits in the law. If you are unhappy with our answer you can complain to the Office of the Data Protection Commissioner of Kenya (odpc.go.ke).

8. Deleting your data

Sign in and use Settings → Delete workspace and data. We disconnect your social accounts, revoke our access and permanently delete your content. You can also remove our app in your Facebook settings (Business Integrations); Facebook then notifies us and we delete the data tied to that Facebook user. See how to delete your data.

9. Security

Access tokens and API keys are encrypted at rest, passwords are hashed, every sign-in needs an emailed code, staff access is separated from client access and logged, workspaces are isolated from each other, and connections use HTTPS. No system is perfectly secure; if there is a breach affecting you we will tell you and the regulator as the law requires.

10. Cookies

We use only the cookies needed to keep you signed in and to protect forms from forgery. We do not use advertising or cross-site tracking cookies.

11. Children

The service is for businesses and people aged 18 or over. We do not knowingly collect data from children.

12. Changes

If we change this policy in a way that matters we will tell you in the app or by email before it takes effect. The date at the bottom shows the latest version.

© 2026 Bright Coders. Last updated 1 October 2026.