Privacy Policy
Last updated: February 25, 2026
1. Introduction
SaphesAI ("we", "us", or "our") operates the SaphesAI platform, including the IG Lead Engine service. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services. Please read this policy carefully. By using our services, you consent to the data practices described in this policy. If you do not agree with the terms of this privacy policy, please do not access or use our services.
2. Information We Collect
2.1 Account Information
When you create an account, we collect your name, email address, and password. This information is required to provide you with access to our services.
2.2 Business Information
When you use the IG Lead Engine service, we collect business information you provide during onboarding, including: your business name, industry, target audience description, brand colors, brand voice preferences, website URL, Instagram handle, testimonials, statistics, and common customer objections. This information is used to generate personalized content for your business.
2.3 Instagram Account Data
When you connect your Instagram Business Account to our service, we access your Instagram Business Account ID and page access token through the Meta/Facebook API. We use these credentials solely to publish content you have approved to your Instagram account. We do not access your personal Facebook profile, private messages, friend lists, or any data beyond what is required for content publishing.
2.4 Usage Data
We automatically collect certain information when you visit our website, including your IP address, browser type, operating system, referring URLs, and pages viewed. This information helps us analyze trends and improve our services.
2.5 Content and Performance Data
We collect data about the content generated through our service, including carousel text, images, approval decisions, and Instagram post performance metrics (views, profile clicks, engagement). This data is used to improve content quality and measure service effectiveness.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Generate personalized Instagram content based on your business information
- Publish approved content to your connected Instagram account
- Track content performance and generate analytics reports
- Process payments and manage subscriptions
- Communicate with you about your account and our services
- Monitor usage patterns to detect and prevent abuse
- Comply with legal obligations
4. How We Share Your Information
We do not sell your personal information. We may share your information in the following circumstances:
Service Providers:
We use third-party services to operate our platform, including Supabase (database hosting), Stripe (payment processing), Anthropic Claude API (AI content generation), Google Imagen API (image generation), and Meta/Instagram API (content publishing). These providers only receive the data necessary to perform their functions and are contractually obligated to protect your information.
Instagram Publishing:
When you approve content for publishing, we send the composed images and caption text to Instagram via the Meta Graph API. This content becomes public on your Instagram profile according to your Instagram privacy settings.
Legal Requirements:
We may disclose your information if required by law, regulation, legal process, or governmental request.
Business Transfers:
In connection with a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
5. Data Retention
We retain your account information and business data for as long as your account is active or as needed to provide you with our services. Content data (generated carousels, images, performance metrics) is retained for the duration of your subscription plus 90 days. If you delete your account, we will delete or anonymize your personal information within 30 days, except where we are required by law to retain it. Instagram access tokens are stored securely and deleted immediately upon account disconnection or deletion.
6. Data Security
We implement appropriate technical and organizational measures to protect your personal information, including encryption of data in transit (TLS/SSL), secure database hosting with row-level security, and encrypted storage of sensitive credentials such as API tokens. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
7. Your Rights and Choices
You have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate personal information.
- Deletion: Request deletion of your personal information and account. We will process deletion requests within 30 days.
- Data Portability: Request an export of your data in a machine-readable format.
- Disconnect Instagram: You can disconnect your Instagram account at any time through your account settings. This will immediately revoke our access to your Instagram account and delete stored access tokens.
- Withdraw Consent: You may withdraw your consent for data processing at any time by contacting us or deleting your account.
To exercise any of these rights, contact us at contact@saphesai.com.
8. Meta/Facebook Platform Data
Our service integrates with the Meta/Facebook Platform to publish content to Instagram. In connection with this integration:
- We only request the minimum permissions necessary: instagram_basic, instagram_content_publish, and pages_read_engagement.
- We do not use Facebook data for advertising, data brokering, or any purpose unrelated to providing our content publishing service.
- We do not transfer, sell, or share Facebook/Instagram data with third parties except as required to provide the service (e.g., storing media in our secure database for publishing).
- You can revoke our access at any time by removing our app from your Facebook App Settings (Settings > Business Integrations) or by contacting us.
- Upon revocation or account deletion, we will delete all stored Facebook and Instagram data within 30 days.
9. Cookies and Tracking
We use essential cookies to maintain your session and preferences. We do not use advertising cookies or third-party tracking cookies. Our analytics are limited to basic usage data as described in Section 2.4.
10. Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without parental consent, we will take steps to delete that information.
11. International Data Transfers
Your information may be transferred to and processed in countries other than your own. Our service providers, including database and API providers, may operate servers in various locations. We ensure that appropriate safeguards are in place to protect your information in accordance with this Privacy Policy.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by updating the "Last updated" date at the top of this page and, where appropriate, by sending you an email notification. Your continued use of our services after any changes indicates your acceptance of the updated policy.
13. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at:
Email: contact@saphesai.com
For data deletion requests, please include "Data Deletion Request" in the subject line and we will process your request within 30 days.