Legal

Privacy Policy

Last updated: September 15, 2026

This Privacy Policy explains what personal data Contrics collects, why we collect it, how we use and share it, how long we keep it, where it is processed, and the rights you have. It applies to the Contrics web application and related services. Contrics is operated by the company identified on our Legal & Company Information page (“Contrics”, “we”, “us”, “our”).

1. Data controller

The company operating Contrics is the data controller responsible for your personal data. Our full legal identity — registered name, address and enterprise number — is published on our Legal & Company Information page. You can reach us about privacy at support@contrics.com.

If you are in the EU/EEA you may lodge a complaint with your local supervisory authority. In Belgium this is the Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), dataprotectionauthority.be. See also “Your rights” below.

2. Information we collect

We collect the following categories of personal data:

  • Account data. Your email address and authentication identifiers. If you sign in with Google, we receive your basic Google profile (name, email address, and profile image) to create and secure your account.
  • Workspace data. Your workspace settings and business profile (such as audience, offer, and positioning) that you enter to tailor generated content, plus other members you invite to a workspace.
  • Connected-platform data. Data we retrieve from social platforms you connect (Instagram, Threads, YouTube), see “Connected platforms and OAuth”.
  • Content and knowledge you provide. Documents, notes, and reference material you upload (“knowledge”); the content you generate, edit, and store; and its version history.
  • Billing data. Your subscription plan, credit balance and credit transactions, and the billing identifiers created by our payment processor. Card and payment-instrument details are handled by our payment processor and are not stored by Contrics.
  • Communications data. Messages you send us (for example support requests) and, where you request it (for example an enterprise demo), the contact details you submit.
  • Technical data. Session and authentication tokens stored in your browser, and server logs (such as IP address, timestamps, and error diagnostics) generated when you use the service.

3. How we use your data

We use personal data to:

  • Create, authenticate, and secure your account and workspaces.
  • Retrieve, store, and display analytics for the social accounts you connect.
  • Generate, improve, analyze, and store content and content recommendations you request.
  • Operate billing, subscriptions, and the credit system.
  • Send you service, security, and transactional messages.
  • Maintain the security, integrity, and reliability of the service and prevent abuse.
  • Comply with our legal obligations and enforce our Terms of Service.

4. Legal bases (GDPR)

Where the GDPR applies, we rely on the following legal bases:

  • Performance of a contract, to provide the account, workspace, analytics, content, and billing features you sign up for.
  • Consent, to connect a social platform on your instruction and to send optional communications. You may withdraw consent at any time (for example by disconnecting a platform).
  • Legitimate interests, to secure the service, prevent abuse, and improve reliability, balanced against your rights.
  • Legal obligation, to keep records required by tax, accounting, and other laws.

5. Connected platforms and OAuth (Instagram, Threads, YouTube)

When you connect a social account, you are redirected to that provider to authorize access. We receive and securely store an access token and, where the provider issues one, a refresh token, which we use to retrieve the data you authorize. We request read-only access only. Contrics never publishes, deletes, sends messages, replies to, or otherwise modifies content on your connected accounts.

The specific permissions we request are:

  • Instagram (Instagram API with Instagram Login): instagram_business_basic and instagram_business_manage_insights, to read your profile, your published media (such as caption, media type, permalink, thumbnail, likes, and comments), and your media and account insights and audience demographics.
  • Threads: threads_basic and threads_manage_insights, to read your profile, your threads, and their insights and audience demographics.
  • YouTube: https://www.googleapis.com/auth/youtube.readonly and https://www.googleapis.com/auth/yt-analytics.readonly, to read your channel and videos and their analytics (such as views, watch time, retention, traffic sources, and audience demographics).

Depending on the platform and permissions you grant, the data we retrieve may include your account identifier, username, display name and profile image, follower or subscriber counts, per-post and per-video metrics (such as reach, views, watch time, retention, click-through rate, likes, comments, saves, shares, replies, and reposts), aggregate audience demographics (such as age ranges, gender split, and top locations), and content metadata (such as captions, thumbnails, and permalinks). We use this data only to provide analytics and content features within your workspace. We do not sell it and do not use it for advertising.

6. Google API Services disclosure

Contrics uses YouTube API Services. By connecting YouTube, you also agree to the YouTube Terms of Service. Google’s handling of your data is described in the Google Privacy Policy. We access YouTube data through the YouTube Data API and the YouTube Analytics API on a read-only basis, store it as analytics snapshots within your workspace, and use it solely to display your analytics and to power the content features you request. We do not share YouTube data with third parties except the processors listed in this Policy that are strictly necessary to provide the service.

You can revoke Contrics’s access to your Google data at any time by disconnecting YouTube in Contrics (Settings → Connections) or through your Google account at https://myaccount.google.com/permissions.

7. Google API Services User Data Policy. Limited Use

Contrics’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we use Google user data only to provide and improve the user-facing analytics and content features described in this Policy; we do not transfer or sell it for advertising, and we do not allow humans to read it except with your consent for support or security, where required by law, or in aggregated and anonymized form.

8. Meta Platform disclosure (Instagram and Threads)

Contrics uses the Instagram API with Instagram Login and the Threads API. It does not use Facebook Login and does not require a Facebook Page. Our access is read-only, and our use of Instagram and Threads data complies with the Meta Platform Terms and Developer Policies. We do not sell this data or use it for advertising. You can revoke access at any time by disconnecting the platform in Contrics, or from the “Apps and websites” settings of your Instagram or Threads account.

9. AI processing and AI providers

Contrics uses artificial intelligence to generate and improve content, to analyze content, and to produce written insights and recommendations from your analytics. To do this, we send the relevant inputs, such as your prompts, business profile, selected knowledge uploads, content, and the analytics being summarized, to AI providers that process them on our behalf to return your result.

We currently use AI providers such as Anthropic. Our AI providers process this data only to generate your output and, under our agreements with them, do not use it to train their models. AI-generated output can be inaccurate or incomplete and should be reviewed before you rely on or publish it. Contrics does not make decisions producing legal or similarly significant effects about you solely by automated means.

10. Third-party processors

We share personal data with a limited set of service providers (processors) that help us run Contrics, under contracts that require them to protect it and use it only on our instructions. We currently use providers such as:

  • Supabase, database, authentication, and serverless backend hosting (our primary data store).
  • Anthropic, AI processing for content generation, analysis, and insights.
  • Stripe, payment and subscription processing.
  • Email delivery providers such as Resend, sending transactional and notification emails.
  • Vercel, hosting and serving the application.
  • Media-processing providers, where you use image or video features that rely on them (for example background removal or speech-to-text), processing the files you submit for that feature.
  • Google Fonts, only inside the app when you choose a Google font for your brand kit: a preview of that typeface is loaded from Google's servers, which receive your IP address and browser details. The website's own typefaces are served by us.

The full, current list, with what each provider does and where it is located, is on our Subprocessors page. We also exchange data with the platforms you choose to connect (Google/YouTube and Meta/Instagram and Threads) as described above. We do not sell your personal data, and we do not share it for third-party advertising.

11. Payment processing

Paid plans and credit purchases are processed by our payment processor, Stripe. When you subscribe or buy credits, Stripe collects and processes your payment details directly under its own privacy policy; Contrics does not receive or store your full card details. We store the billing identifiers, plan, and transaction records needed to operate your subscription, credits, and invoices.

12. Email and notifications

We send account, security, and transactional emails (such as sign-in, billing, and service notices) through an email delivery provider. Where you submit a request such as an enterprise demo, we use the contact details you provide to respond. We do not send marketing email without a lawful basis, and you can opt out of non-essential messages.

13. Cookies and local storage

Today, Contrics loads no analytics or advertising script and sets no third-party advertising or cross-site tracking cookie. An advertising integration has been built but is not switched on; see section 14a. Full detail, including the consent categories and how to change your choice, is in our Cookie Policy. The site stores the following in your browser:

  • Your sign-in session (kept in local storage), so you stay signed in between visits.
  • Your cookie choice, so we do not ask again on every visit.
  • A referral code, only if you arrived through a referral link, kept until it is attached to your new workspace.
  • Interface settings you choose yourself inside the app, such as your theme and whether the sidebar is collapsed (a local storage entry or first-party cookie), saved when you change them.

The first three are required to provide the service you asked for. Interface settings are saved only when you change them yourself and are used for nothing else. Optional analytics and advertising stay off unless you switch them on, and you can review or change your choice at any time via “Cookie preferences” in the site footer.

14. Analytics processing

“Analytics” in Contrics refers to the metrics we retrieve from your connected social accounts and store as snapshots so you can view trends over time. This analytics data is scoped to your workspace, protected by tenant isolation, and is not sold or shared for advertising. We may also keep limited internal logs about how the service performs in order to operate and secure it.

14a. Advertising and conversion measurement

Advertising is separate from analytics and has its own consent category. Accepting analytics does not enable advertising, and never has.

Status: built, not switched on. Contrics has implemented an integration with Google Ads and the Meta Pixel, but no advertising account is configured, so no advertising script loads and no advertising data is sent to either provider today. This section describes what happens once it is enabled, so the description is already accurate when that day comes.

  • Purpose. To measure whether our advertising leads to sign-ups and checkouts, and to show relevant ads on other sites.
  • Legal basis. Your consent, given through the advertising category of our cookie banner. You can withdraw it at any time from “Cookie preferences” in the footer, which stops further advertising events.
  • Data. Event data such as which page you were on and whether a sign-up or checkout was started, plus the identifiers Google and Meta set in your browser. We do not send your email address, name, phone number or account identifier to either provider, and Advanced Matching is deliberately not implemented.
  • Recipients. Google Ireland/LLC and Meta Platforms Ireland/Inc., acting as independent controllers for their own advertising purposes under their own policies.
  • Transfers. Both providers may process data outside the EU/EEA, including in the United States, under the safeguards described in “International transfers”.

We have also prepared, but not enabled, a server-side conversion interface for Meta (the Conversions API). It is inactive: no access token is configured and no server-side advertising event is sent. If it is ever enabled it will require the same advertising consent as the browser pixel — sending a measurement from our servers instead of your browser does not remove your right to refuse it.

Full detail of the cookies involved is in our Cookie Policy.

15. Security

We protect personal data with technical and organizational measures, including:

  • Encryption of data in transit (TLS) and encryption of data at rest.
  • Workspace-level tenant isolation enforced by row-level security in the database.
  • Secure storage of connected-platform access and refresh tokens.
  • Restricted, least-privilege access to production systems.

No system is perfectly secure, but we work to protect your data and to respond promptly to any incident that affects it.

16. International transfers

Contrics is operated from the European Union. Some of our processors (for example AI, payment, hosting, and platform providers) are located in or transfer data to countries outside the EU/EEA, including the United States. Where we transfer personal data outside the EU/EEA, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses or an applicable adequacy decision.

17. Data retention

We keep personal data for as long as your account is active and as needed to provide the service, then delete or anonymize it as follows:

  • Connected-platform tokens and analytics. When you disconnect a platform, we revoke and delete the stored access and refresh tokens for that platform and delete the analytics we synced from it.
  • Account data and workspace content. When you delete your account or request deletion, we remove your personal data within 30 days.
  • Backups. Residual copies in encrypted backups are purged on our ordinary backup-rotation schedule.
  • Legal retention. We may retain limited records (such as invoices) where required for tax, accounting, legal, or security purposes.

18. Your rights

Subject to applicable law, you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data or update your business profile.
  • Request erasure of your account and associated data.
  • Restrict or object to certain processing.
  • Export your generated content and workspace data (data portability).
  • Withdraw consent, including by disconnecting any connected platform.
  • Lodge a complaint with your local data protection authority.

To exercise any of these rights, email support@contrics.com. We respond within the periods required by law.

19. Account deletion and connected-account revocation

You can disconnect any platform at any time in Settings → Connections, which immediately revokes and deletes the stored token for that platform and removes the analytics synced from it. You can request full deletion of your account and data by emailing support@contrics.com. You can also revoke Contrics’s access directly from the provider, for Instagram and Threads via your account’s “Apps and websites” settings, and for Google/YouTube at https://myaccount.google.com/permissions. See our Data Deletion page for full details.

20. Children

Contrics is intended for use by businesses and creators and is not directed to children. It is not intended for anyone under the age of 16, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.

21. Future functionality

Where Contrics offers competitor research, it analyzes publicly available information about the accounts you choose to track; no personal data about you is sent to the service that fetches that information. We are developing further features that are not available today, such as publishing content to your connected accounts or AI agents that carry out tasks on your behalf. When we release such features, we will process only the data needed to provide them and will update this Policy before or when they become available.

22. Changes to this Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “last updated” date above and, where appropriate, notify you in the app or by email. Your continued use of Contrics after an update means you accept the revised Policy.

23. Contact

Questions about this Privacy Policy or your data? Email support@contrics.com and we will respond promptly.