Skip to content

Legal

Privacy Policy

Last updated 3 October 2026.

This Privacy Policy explains what personal data Fibonacci Impact LLC (“we”, “us”) collects when you use Fibonacci Socials (the “Service”) and the website at socials.fib.im, what we do with it, how long we keep it, and how you can have it deleted. Fibonacci Socials lets you upload a video and publish it to social media accounts you connect.

1. Who is responsible

  • Account data. Fibonacci Impact LLC is the controller of the data about you as a user of the Service: your account, your sign-in, your organisation membership, billing records, support messages and call requests.
  • Customer content. For the videos, captions and settings you upload, and the social accounts you connect on behalf of your organisation, we act as a processor. We handle that content only to provide the Service, on your instructions. Your organisation decides what is published, where, and why.

Contact for privacy questions and requests: [email protected].

2. Data we collect about you

  • Account and sign-in data: your name, email address, the organisation you belong to and your role in it. Sign-in is handled through our single sign-on service.
  • Booking and sales data: what you send us through the setup call form or by email: your name, work email, company, website, team size, the platforms and plan you are interested in, preferred call times and your message.
  • Billing data: for a plan set up with us, the details we need to invoice you, such as your company name, billing contact and invoice history. For a plan bought online, the payment is taken on saas.fib.im by Creem, its merchant of record; we receive only which plan your account is entitled to, its status and until when. We never receive or store card numbers.
  • Technical data: IP address, browser type, timestamps and the requests you make, recorded in server logs to run and secure the Service.
  • Support correspondence: messages you send us and our replies.

3. Data we receive from connected platforms

When you connect a social account, you sign in on that platform's own page and approve the access Fibonacci Socials asks for through the platform's official OAuth process. We never see or store your password for any platform. In return the platform gives us:

  • OAuth tokens: an access token and, where the platform issues one, a refresh token and its expiry time. Tokens are encrypted at rest and used only to publish, check or delete content you have asked us to handle.
  • Basic profile data to identify the connected account, as below.
PlatformWhat we receiveWhat we use it for
TikTok Your TikTok open ID, display name and avatar. Creator info: the privacy options available to you, the maximum video length you can post, and whether comments, Duet or Stitch are turned off for your account. The publish ID and status TikTok returns for each video. To show which account is connected, to offer only the posting options your account has, to check limits before posting, and to report delivery status.
Instagram Your Instagram professional account ID, username and profile picture, and the IDs Instagram returns for the Reels and Stories we publish. To show which account is connected, to publish what you choose, and to report delivery status and links.
Facebook The list of Pages you manage (so you can choose which to connect), and for each Page you connect its ID, name, picture and Page access token. The IDs Facebook returns for the videos and Stories we publish. To let you pick a Page, publish to it, and report delivery status and links.
YouTube Your channel ID, channel title and thumbnail, and the video IDs YouTube returns for the uploads we make. To show which channel is connected, upload the videos you choose with the title you set, and report status and links.
X Your X user ID, name, username and profile image, and the IDs X returns for the media and posts we publish. To show which account is connected, publish what you choose, and report status and links.
LinkedIn Your LinkedIn member ID, name and profile picture (through LinkedIn's sign-in), and the IDs LinkedIn returns for the posts we publish. To show which account is connected, publish what you choose, and report status and links.
Pinterest Your Pinterest user ID, username and profile image, the list of your boards (so you can choose where to publish), and the IDs of the Pins we create. To let you choose a board, publish video Pins, and report status and links.
Threads Your Threads user ID, username and profile picture, and the IDs Threads returns for the posts we publish. To show which account is connected, publish what you choose, and report status and links.
Google Business Profile The Business Profile accounts and locations you manage (IDs and names, so you can choose one), and the IDs of the posts we create. To let you choose a location, publish video to it, and report status.

We do not ask for access to your direct messages, followers, contacts or analytics, and we do not read the other content in your accounts.

4. Content you upload

To publish for you, we store the videos you upload (and a cover image generated from each one), the captions and titles you write, the per-platform options you choose (for example TikTok privacy and disclosure settings), and for each delivery the post ID and link the platform returns, its status and any error message. We send your video and caption only to the platforms and accounts you select for that post.

5. How we use data, and our legal bases

  • To provide the Service: publishing, retries, status, deletion from platforms and team access. This is necessary to perform our contract with you.
  • To set up and bill paid plans: arranging your call, configuring your plan and invoicing. This is necessary for the contract, or to take steps at your request before entering into one.
  • To keep the Service secure and reliable: preventing abuse, investigating incidents and fixing faults. This is based on our legitimate interest in running a safe service.
  • To meet legal obligations, such as tax and accounting records.
  • To contact you about the Service: service and account emails, and replies to your requests.

We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not use data from connected platforms for advertising, profiling, or to train machine-learning or AI models.

6. Platform-specific commitments

TikTok

Fibonacci Socials uses TikTok's Content Posting API only to publish content you choose, to the TikTok account you connected, with the settings you select (privacy level, comment, Duet and Stitch settings, and commercial-content disclosure). If you choose “Send to drafts”, the video is delivered to your TikTok inbox and you finish and post it yourself in the TikTok app. We read your creator info only to show your account's posting options (such as the privacy levels available to you and your maximum video length) before you post. We do not use TikTok data for any other purpose.

Google: YouTube and Google Business Profile

Fibonacci Socials's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide the publishing features you see in Fibonacci Socials. We do not transfer it to others except as needed to provide those features, to comply with law, or as part of a merger or acquisition with notice to you. We do not use it for advertising, and we do not allow humans to read it unless you ask us to (for example for support), it is needed for security or legal reasons, or it has been aggregated and anonymised.

Fibonacci Socials uses YouTube API Services. By connecting a YouTube channel you also agree to the YouTube Terms of Service, and Google's handling of your data is described in the Google Privacy Policy. You can revoke Fibonacci Socials's access to your Google account at any time at myaccount.google.com/permissions.

Meta: Facebook, Instagram and Threads

Data received through Meta's APIs is used only to identify the Pages and accounts you connect, publish the content you choose to them, and report delivery status. You can ask us to delete it at any time. See our Data Deletion instructions.

X, LinkedIn and Pinterest

Data received through these platforms' APIs is used only to identify the connected account, publish the content you choose, and report delivery status, under each platform's developer terms.

7. How long we keep data

  • OAuth tokens are kept while the account is connected. Disconnecting an account in Fibonacci Socials deletes its tokens straight away.
  • Uploaded video files and their cover images are deleted from our storage automatically 7 days after the last delivery of that post has finished (published, failed, removed from the platform or sent to TikTok drafts). By then each platform holds its own copy. After that, a failed delivery of the post can no longer be retried; the post's record stays. Deleting a post in Fibonacci Socials deletes its video straight away, unless another of your posts uses the same upload. Uploads never attached to a post are deleted 24 hours after they were uploaded. Deletion runs once an hour, so it can happen up to an hour after these times.
  • Post records (caption, options, platform post IDs, links and status) are kept while your account is active so you can see your history and delete posts from platforms, until you delete them or your account.
  • Account data is kept while your account is active and deleted within 30 days of the account being closed, apart from records we must keep by law, such as invoices, which are kept for as long as the law requires.
  • Call requests from people who do not become customers are deleted within 12 months.
  • Server logs are kept for up to 90 days.

8. Who we share data with

  • The platforms you choose. When you publish, your video, caption and options are sent to the platforms and accounts you selected. What happens to content on those platforms is governed by their own terms and privacy policies.
  • Sub-processors that help us run the Service, under contracts that require them to protect the data and use it only on our instructions: cloud hosting and storage, content delivery for this website, email delivery, and bot protection on our booking form (Cloudflare Turnstile, which checks the browser submitting it). A current list is available on request from [email protected].
  • Authorities, where the law requires it, or to protect the rights, safety or property of our users, the public or us.
  • A successor, if the business is merged or sold. The same commitments would continue to apply, and we would tell you first.

9. Where data is processed

Fibonacci Impact LLC is a company registered in Sharjah, United Arab Emirates, and our providers may process data in the United States, the European Union and other countries. Where the law requires it, for example for data from the EU, UK or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

10. Security

Connections use each platform's official OAuth, so we never handle your platform passwords. Tokens are encrypted at rest, traffic is encrypted in transit, access to production systems is restricted to staff who need it, and each organisation's data is kept separate from every other organisation's. No system is perfectly secure. If a breach affects your personal data, we will tell you and the relevant authorities as the law requires.

11. Your rights

Depending on where you live, you may have the right to access your personal data, correct it, delete it, receive a copy in a portable format, restrict or object to certain processing, and withdraw any consent you have given. California residents have the right to know, delete and correct personal information and not to be discriminated against for using these rights. We do not sell or share personal information as those laws define it.

To use any of these rights, email [email protected] from the address linked to your account. We may need to confirm your identity, and we reply within 30 days. If your request concerns content that an organisation uploaded, we will pass it to that organisation, because it controls that content. You can also complain to your local data protection authority.

12. Disconnecting accounts and deleting data

  • Disconnect in Fibonacci Socials: sign in at socials.fib.im/portal, open your connected accounts and choose Disconnect. The tokens for that account are deleted immediately and nothing more can be published to it.
  • Revoke at the platform: you can also remove Fibonacci Socials from each platform's own settings (its list of connected or permitted apps). This makes the tokens we hold stop working. Where to find this on each platform is listed on the Data Deletion page.
  • Delete posts: you can delete a post in Fibonacci Socials, and delete it from the platform where the platform's API allows it.
  • Delete everything: email [email protected] from your account's email address and ask us to delete your account. The full steps are on the Data Deletion page.

13. Cookies and similar technology

This website uses no advertising or analytics cookies. It loads fonts from Google Fonts, so your browser requests them from Google's servers, which see your IP address. The Fibonacci Socials app uses only the cookies and browser storage needed to sign you in and keep you signed in.

14. Children

The Service is for businesses and professionals and is not directed at children. You must be at least 18 to create an account. If you believe a child has given us personal data, contact us and we will delete it.

15. Changes to this policy

If we make material changes, we will update the date at the top and tell account holders by email or in the app before the changes take effect.

16. Contact

Fibonacci Impact LLC · [email protected] for privacy and data requests · [email protected] for everything else.