Privacy Policy
Effective Date: 16 July 2026
1. Overview of Our Privacy Practices
Rheos is an AI-powered content creation and social media management service provided by Rheos App Ltd ("Rheos", "we", "our" or "us"). This policy explains what personal data we collect, why we use it, who receives it, how long we keep it, and the choices and rights available to you.
Controller Details & Processor Status (UK GDPR)
Rheos App Ltd, company number 17105158. Registered office: 60 Farm Road, Beeston, Nottingham, England, NG9 5DA. Privacy contact: archie@rheos.app.
- Controller: Rheos acts as controller for account, billing, product-usage, support, sales and security data.
- Processor: Where a customer determines why and how workspace or social-media content is processed and asks Rheos to process it on the customer's behalf, Rheos may act as that customer's processor. The applicable role depends on the processing activity, not merely the type of data. Customers who require a data processing agreement can contact us.
The Service is intended for people aged 18 or over and is not directed to children. If you believe a child has provided personal data to Rheos, contact us so that we can investigate and take appropriate action.
2. Personal Data We Collect
We collect data you provide, data created through your use of Rheos, data obtained from services you choose to connect, and technical data generated when the Service operates.
A. Account, Organisation and Billing Data
- Name, email address, profile picture and authentication identifiers used with Firebase Authentication.
- Organisation, workspace, membership, role and administrator information.
- Subscription, invoice, transaction and customer references handled with Stripe. Rheos does not store raw credit-card information.
- Account-deletion requests and an audit snapshot of the deletion process.
B. Content, Sources and AI Data
- Post drafts, captions, schedules, publishing instructions and generated content.
- Images, videos, logos, brand guidelines, identity documents, source documents and other business assets you upload or import.
- Website pages you ask Rheos to retrieve (via our provider Firecrawl), including versioned markdown created from those pages.
- Prompts, source material, settings, and generated text or media submitted to or returned by Rheos's AI features.
- AI usage telemetry, which can include up to the first 500 characters of serialised input and up to the first 500 characters of serialised output per AI request, retained in usage records for billing, metering and abuse prevention.
C. Connected-Platform and Connector Data
When you authorise a connection, Rheos may receive account identifiers, usernames, profile images, administered pages or organisations, connection status, OAuth access or refresh credentials, publishing permissions, posts, comments, engagement and platform metrics needed for the feature you request. Optional asset-import connections include Google Drive, Microsoft OneDrive and Canva; these are used only when you choose to connect the relevant service and request an import. Platform-specific details are in the subsections below.
D. Product, Support and Technical Data
- IP address, browser and device information, pages and features used, timestamps, performance information, errors and diagnostic context.
- Product analytics linked to account or organisation identifiers through Amplitude.
- Session replay and interaction data through LogRocket and Sentry. Sentry error reporting on our servers includes default personal information (such as IP address); Sentry session replay in the browser masks anything you type into form fields but may capture visible on-screen text and media for a sample of sessions and for sessions where an error occurs.
- Support and sales communications through Intercom, and customer-lifecycle or CRM records through Attio.
- Email delivery and engagement information for messages sent through Resend.
3. Connected Social Platforms
When you connect a social account, we access data strictly in accordance with that platform's developer terms, and only to provide the publishing and engagement features you request.
A. LinkedIn (Community Management API)
- Permissions: w_member_social, w_organization_social (Company Page posting), r_organization_social (Company Page feeds), r_organization_admin.
- Data Accessed: User identity (name, ID), Organization Pages you administer, and "Member Data" (comments and likes on your posts from other LinkedIn members).
- Purpose: To enable you to draft, schedule, and publish content to your Personal Profile and Company Pages, and to view and reply to comments on your posts.
- Member Data: Names, photos and content of other LinkedIn members are fetched to display engagement on your posts and are not retained beyond the limits permitted by LinkedIn's API Terms.
B. Meta Platforms (Facebook, Instagram & Threads)
We use Meta's Graph API and Instagram APIs in compliance with Meta's Platform Terms and Developer Policies.
- Permissions: pages_manage_posts, pages_show_list, business_management, instagram_business_basic, instagram_business_content_publish.
- Data Accessed: Facebook name, Instagram username, profile pictures, and list of managed pages.
- Purpose: To list your Facebook Pages and linked Instagram Business accounts, and to publish content (photos, videos, reels, stories) directly from the Rheos dashboard.
C. X (Twitter)
- Permissions: tweet.read, tweet.write, users.read, offline.access.
- Data Accessed: Your X username, display name, profile picture, and user ID.
- Purpose: To publish posts (text, images, and videos) to your X profile on your behalf. OAuth 2.0 access and refresh tokens are stored securely; access tokens are refreshed automatically and previous tokens are overwritten.
D. TikTok
- Permissions: user.info.basic, video.publish, video.upload.
- Data Accessed: Your TikTok display name, avatar, and open ID.
- Purpose: To publish video content to your TikTok profile on your behalf. OAuth 2.0 access and refresh tokens are stored securely.
E. Pinterest
- Permissions: boards:read, pins:read, pins:write, user_accounts:read.
- Data Accessed: Your Pinterest username, profile picture, and list of boards.
- Purpose: To create Pins (images and videos) on your Pinterest boards on your behalf.
F. YouTube
When you connect your YouTube account, we access data via the YouTube Data API v3 in accordance with Google's API Services User Data Policy and YouTube's Terms of Service.
- Permissions: youtube.upload, youtube.readonly.
- Data Accessed: Your YouTube channel name, channel ID, and channel thumbnail.
- Purpose: To identify your authorised channel and upload video content (including Shorts) to your YouTube channel on your behalf.
G. Bluesky
- Data Accessed: Your Bluesky handle and DID (decentralised identifier).
- Purpose: To publish posts (text and images) to your Bluesky profile on your behalf.
- Authentication: The connection flow asks for a Bluesky app password (not your main password), exchanges it once for session tokens, and discards it — the app password itself is never stored. You can revoke access at any time from your Bluesky settings.
H. Mastodon
- Permissions: read, write:statuses, write:media (via an OAuth application registered on your chosen instance).
- Data Accessed: Your Mastodon username, display name, avatar, and instance URL.
- Purpose: To publish posts (text, images, and videos) to your Mastodon profile on your behalf. Your data is processed via your chosen instance; we do not access other instances or federated content.
4. How and Why We Use Personal Data
We use personal data to:
- create and authenticate accounts, manage organisations and provide customer support;
- provide subscriptions, process payments and maintain financial records;
- import, store, organise and retrieve brand content and sources;
- generate text and media in response to customer instructions;
- draft, schedule, publish and measure content on customer-authorised platforms;
- operate optional connectors and MCP access authorised by the customer;
- monitor usage and plan allowances, prevent abuse and protect the Service;
- diagnose errors, analyse product use and improve performance and user experience;
- send service communications and, where permitted, marketing communications;
- manage customer and prospective-customer relationships; and
- meet legal, regulatory, tax, accounting and data-protection obligations.
Lawful Bases (UK GDPR)
We rely on contract for account administration, requested generation, imports, publishing and subscriptions; legal obligation for required tax, accounting and rights records; legitimate interests for proportionate security, diagnostics, service improvement and customer administration; and consent for non-essential cookies, pixels and marketing where consent is required. An OAuth permission you grant is an authorisation to access a platform and is not itself treated as UK GDPR consent.
We do not sell or purchase social-platform data, use it for surveillance, or use it to decide eligibility for employment, credit, housing or insurance. We do not use customer social content to train public AI models.
5. AI Processing
Rheos sends prompts, customer-provided source material, settings and generated media to one or more of these AI processors, depending on the feature used:
- Google AI Studio / Google Gemini for text generation and supported generation workflows;
- Fal.ai for image generation and fallback processing; and
- Microsoft Azure OpenAI (GPT-Image-2) for selected image-generation paths.
The data sent depends on your request and may include prompt text, brand documents, website-source content, images or generation settings. Images and videos you import (for example from Google Drive) are also processed by our AI providers to generate tags and short descriptions that power search inside your own asset library. Each provider is bound by its commercial API terms and does not train on customer inputs.
6. Cookies, Pixels and Similar Technologies
- Necessary and security technologies: used for core service delivery, authentication, security, error diagnostics (Sentry) and remembering consent choices. These operate without consent as they are required to run and protect the Service.
- Support messaging: Intercom provides support and sales messaging. We treat it as a functional support tool, so it loads without a consent gate.
- Analytics and experience technologies: Google Analytics, Microsoft Clarity, Factors.ai, Amplitude and LogRocket are used for measurement, product analytics and/or session replay. On the marketing site these are gated behind consent.
- Marketing technologies: Meta, LinkedIn and OpenAI Ads pixels are used for advertising measurement or campaign attribution, gated behind consent on the marketing site.
Where consent is the basis for a non-essential technology, you can refuse or withdraw it through the consent controls on the site. Withdrawing consent does not affect processing that occurred before withdrawal. Browser controls may also block or delete cookies, but doing so can affect features that depend on them.
7. Google API Services User Data & Limited Use
Rheos only requests Google access needed for a feature you choose to use.
Google Drive (read-only import)
Used to let you select and import your authorised Drive content into Rheos. On connection we store OAuth tokens; on import we store the file you selected (plus its name, type, size and thumbnail) in your workspace. Google Docs, Sheets and Slides are exported to standard document formats. Imported images and videos are processed as described in Section 5 to make them searchable in your library.
YouTube (publishing)
As described in Section 3F: youtube.upload and youtube.readonly, used to identify your authorised channel and upload your approved video content.
Google Search Console, Google Analytics & Site Verification (rolling out)
Rheos is introducing an optional connection that lets you link your own Google Search Console and Google Analytics 4 properties to your Rheos analytics dashboard. If you connect:
- Search Console (webmasters): we read your site's search performance data (queries, pages, clicks, impressions, position) to display it in your dashboard and to generate content and website-improvement recommendations for you. Only when you explicitly request it — during guided setup or after publishing content — we also add your verified site as a Search Console property and submit or resubmit your sitemap.
- Analytics (analytics.readonly): we read your GA4 reporting data to correlate search and AI-search visibility with on-site outcomes, for your dashboard only.
- Site Verification (siteverification): used, at your request, to help verify your site so Search Console can be set up for you.
Apart from the customer-requested setup actions above (site verification, adding your property, sitemap submission), all access is read-only. Access is scoped to your own properties, is never used for advertising, is never sold or shared beyond the service providers needed to operate the feature, and is not used to train AI models. Google-derived data is stored in your workspace only where the feature requires it, and is deleted when you disconnect the integration or delete your account (subject to Section 9). You can disconnect at any time from your Rheos analytics settings, and you can also revoke Rheos's access at myaccount.google.com/permissions.
Google Limited Use disclosure: Rheos's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8. Who Receives Personal Data
We disclose data only where needed to operate the Service, complete a customer-authorised action, manage our relationship with you, or meet legal obligations. Our service providers and subprocessors are:
- Hosting & core infrastructure: Vercel; Google Cloud / Firebase (Authentication, Firestore, Storage, Functions).
- AI generation: Google AI Studio / Gemini; Fal.ai; Microsoft Azure OpenAI (GPT-Image-2) on selected image-generation paths.
- Payments: Stripe (subscriptions and related tax/accounting records). We do not store raw credit-card information.
- Email: Resend (transactional and marketing email delivery).
- Website retrieval: Firecrawl (customer-requested website retrieval and scraping).
- Analytics, replay & error monitoring: Amplitude; LogRocket; Sentry.
- Support & customer lifecycle: Intercom; Attio.
- Optional MCP identity: Auth0, where the OAuth MCP route is used (see the MCP Privacy Notice).
- Consent-gated marketing & measurement: Google Analytics; Microsoft Clarity; Factors.ai; Meta; LinkedIn; OpenAI Ads.
- Customer-authorised social APIs: Meta (Facebook, Instagram, Threads); LinkedIn; X; TikTok; Pinterest; Google (YouTube); Bluesky; and the operator of your chosen Mastodon instance.
- Optional content connectors: Google Drive; Microsoft OneDrive; Canva.
A customer-selected MCP or AI-assistant provider may also receive data when you deliberately authorise that client to call Rheos tools; that provider acts under its own privacy terms (see the MCP Privacy Notice). We may also disclose information where required by law or in connection with a corporate transaction, subject to applicable data-protection requirements.
9. Retention, Disconnection & Deletion
We keep account and workspace data while the account is active and as needed to provide requested features. For categories without a fixed period — including analytics, replay, error logs, OAuth logs, website-source versions, AI usage snippets, CRM/support data, platform logging and backups — we use necessity, security, contractual and legal requirements as the retention criteria.
Account Deletion
When an eligible account-deletion request is confirmed:
- access is disabled immediately;
- the account is scheduled for hard deletion after a 30-day recovery period;
- connected integrations are disconnected; and
- Rheos records an audit snapshot of the deletion process.
After the 30-day period, Rheos deletes the account and associated active customer data. A de-identified Stripe customer archive (with personal contact details removed) is retained for up to 7 years in line with UK tax and accounting record-keeping requirements. Residual copies may persist for a limited period in backups before cycling out. A sole owner of a multi-user organisation may need to transfer ownership before the account can be deleted.
Disconnecting Social & Content Accounts
You may disconnect any linked account at any time via your Rheos settings. Disconnecting stops future access through Rheos and removes Rheos-held connection credentials. As part of account deletion we also make provider-side revocation requests for Meta and LinkedIn; for other providers we recommend additionally revoking Rheos from the provider's own settings (for example your Bluesky app passwords page or Google account permissions).
Facebook & Instagram Removal
To remove Rheos from your Facebook or Instagram account: go to Facebook Settings & Privacy → Settings → Apps and Websites, find Rheos, and click Remove. To have the data Rheos holds for that connection deleted, disconnect the platform in Rheos or contact archie@rheos.app — or delete your Rheos account as described above.
10. International Transfers
Some of our providers process personal data outside the United Kingdom, including in the United States. Where we transfer personal data internationally we rely on appropriate safeguards for the provider and destination concerned — such as the UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses, or UK adequacy regulations where they apply. You can contact us for a description of the safeguard applicable to a particular transfer.
11. Your UK GDPR Rights
Subject to the conditions and exemptions in data-protection law, you may:
- access your personal data and receive information about how it is used;
- rectify inaccurate or incomplete personal data;
- erase personal data in qualifying circumstances;
- restrict processing in qualifying circumstances;
- receive or transfer eligible data in a portable, machine-readable format;
- object to processing based on legitimate interests, and object at any time to direct marketing; and
- withdraw consent at any time where processing relies on consent, without affecting earlier lawful processing.
To exercise a right, email archie@rheos.app. We may need to verify your identity and clarify the scope of a request. You also have the right to complain to the UK Information Commissioner's Office (ICO) — see ico.org.uk. You may complain to the ICO without first raising the matter with us, although the ICO may ask whether you have.
12. Security
We use technical and organisational measures intended to protect personal data, including encryption in transit, access controls and scoped authorisation. No online service can promise absolute security.
13. Changes to This Policy
We will update the effective date when this policy changes. For a material change, we will provide notice through the Service or by email before the change takes effect where required.
14. Contact Us
For privacy questions, rights requests or complaints, contact:
Rheos App Ltd
Company number: 17105158
Registered office: 60 Farm Road, Beeston, Nottingham, England, NG9 5DA
Email: archie@rheos.app