Privacy Policy
Effective date: May 24, 2026
This Privacy Policy describes how FOZATO SEO PRIVATE LIMITED, operating under the brand name "Fozato" ("we", "us", or "our"), collects, uses, and discloses your personal information when you use our website, application, and associated services. By accessing or using our services, you agree to the collection and use of information in accordance with this Privacy Policy. Throughout this document, any reference to "Fozato" refers to FOZATO SEO PRIVATE LIMITED.
1. Data we collect
We collect only what is needed to operate the Service:
- Account information: Name, email address, profile picture, and Google account identifier when you sign in with Google OIDC.
- Workspace / tenant data: Workspace name, slug, optional custom domain, billing plan, member roles.
- Business profile: Business name, description, website URL, category, target language, and brand voice you enter during onboarding or funnel creation.
- Funnel content: Topics, keywords, scripts, generated voice tracks, generated videos, captions, and the metadata of every reel produced for you.
- OAuth tokens for connected social platforms: When you connect YouTube, Facebook, Instagram, Threads, LinkedIn, Pinterest, or Tumblr we receive access tokens (and refresh tokens, where the provider issues them). Tokens are encrypted at rest and used to publish content you explicitly request. If you connect Meta specifically for ad tracking ("Connect Meta" on the Integrations page), the same token is also used to read the list of Meta Businesses, Ad Accounts, and Pixels you have access to, so you can pick which one to connect — see "Meta Ads data" below.
- Published-post metadata: Remote post IDs, permalinks, and basic engagement metrics (views, likes, comments) fetched from the platform after a successful publish.
- Payment information: Billing is handled by Razorpay. We do not store full card numbers — we receive only a tokenized identifier and the order/subscription status from Razorpay.
- Operational logs: Request timestamps, IP address, user agent, and error traces used for security and debugging. Retained for up to 90 days.
2. How we use your data
- Provide and operate the Service (account, workspace, billing).
- Generate short-form video content using your business context, language preference, and topic keywords.
- Publish content to social platforms you have explicitly connected, only when you schedule or manually trigger a publish.
- Fetch public post metrics (impressions, views, likes) from connected platforms so we can show you reel performance.
- When you connect Meta for ad tracking, read your Meta Business, Ad Account, and Pixel list so you can select one, then automatically configure that Pixel and a Conversions API access token for your workspace's funnels — replacing the need to find and paste a Pixel ID or generate a token by hand.
- Send transactional emails (login confirmations, billing receipts, security alerts).
- Detect abuse, prevent fraud, and enforce our Terms.
We do not sell your data, use it to train third-party AI models outside the scope of generating your own content, or use it for advertising profiles.
3. Third-party services we rely on
The Service integrates with the following processors. Each provider has its own privacy policy.
- Google (Sign-In, Gemini, YouTube Data API): Authentication, AI script/voice generation, and YouTube Shorts publishing.(policies.google.com/privacy)
- Meta Platforms (Facebook, Instagram, Threads): Connecting Facebook Pages, Instagram Business accounts, and Threads for content publishing; and, if you use Connect Meta, reading your Meta Business, Ad Account, and Pixel list to set up ad conversion tracking. (www.facebook.com/privacy/policy)
- LinkedIn: Member video sharing via the "Share on LinkedIn" API.(www.linkedin.com/legal/privacy-policy)
- Pinterest: Video Pins via Pinterest's v5 API.(policy.pinterest.com/en/privacy-policy)
- Tumblr: Video posts via Tumblr's v2 API.(www.tumblr.com/privacy)
- Razorpay: Payment processing for paid plans. (razorpay.com/privacy)
- Hostkey B.V. (server hosting): Provides the server our application and self-hosted PostgreSQL database run on. Your account, workspace, and funnel data is stored in that database with row-level security between tenants; Hostkey has infrastructure-level access to the server but does not otherwise process your data.
Fozato AI's use and transfer of information received from Google APIs to any other app will adhere to Google Data API Services User Data Policy, including the Limited Use requirements. (developers.google.com/terms/api-services-user-data-policy#limited-use)
4. How we handle social-platform tokens
Tokens issued by YouTube, Facebook, Instagram, Threads, LinkedIn, Pinterest, and Tumblr are used to publish content you explicitly request, fetch engagement metrics on posts we published for you, delete those posts when you remove them in the Service, and — for Meta specifically, when you use Connect Meta — set up ad conversion tracking as described below.
- Tokens are encrypted at rest using AES-256 with keys held in our backend secrets store.
- We do not browse your social account, read DMs, post without your trigger, or share tokens with any third party.
- You can revoke any connection at any time inside the Service (Settings → Connected accounts → Disconnect) or at the social provider (e.g. Facebook → Settings → Business Integrations → Remove).
- We honor data-deletion callbacks from Meta and other providers — when a user revokes our app at the provider, the corresponding tokens and connection rows are deactivated on our side automatically.
Meta Ads data (Connect Meta)
If you use Connect Meta on the Integrations page, we use your Meta access token to read the Businesses, Ad Accounts, and Pixels your Meta account can access, so you can choose which one to connect — we never see or store any other advertiser's data, only what your own token can see. Once you pick a Pixel, we store its ID, the ID and name of its Business and Ad Account, and (when Meta grants it) a Conversions API access token, all under your workspace and encrypted at rest the same way as other platform tokens. This is used to send your funnels' conversion events (page views, leads, purchases) to that Pixel, and — if you enable Auto-Hide Spam Comments — to read the active ads under that Ad Account, find which Facebook Page post or Instagram media each ad's creative is attached to, and hide spam or policy-violating comments there. Outside of that one moderation feature, we do not read, modify, or otherwise access your ad campaigns, spend, or creatives. Disconnecting removes this configuration but keeps your historical funnel and lead data intact.
5. Storage, security, and retention
- Multi-tenant isolation: data is partitioned per workspace using PostgreSQL row-level security so one tenant cannot access another tenant's rows even in the event of an application-layer bug.
- Encryption in transit: all traffic to the Service uses HTTPS (TLS 1.2+).
- Encryption at rest: the database is encrypted by our hosting provider; OAuth tokens and refresh tokens are additionally encrypted at the application layer.
- Retention: account, workspace, and funnel data are retained for as long as your account is active. Generated videos hosted on Cloudinary are kept while the associated reel record exists in the Service. Operational logs are kept up to 90 days.
- Deletion: deleting your account removes your profile, workspaces, funnels, social-account tokens, and generated videos within 30 days. Some records may be retained longer when required by law (e.g. tax invoices for paid plans).
6. Your rights
Depending on your jurisdiction (GDPR, CCPA, DPDP Act, etc.) you have the following rights over your personal data:
- Access — request a copy of the data we hold about you.
- Correction — fix inaccurate or incomplete data.
- Deletion — ask us to erase your account and associated data, subject to legal retention obligations.
- Restriction — limit how we process your data.
- Portability — receive your data in a machine-readable format.
- Withdraw consent — revoke any OAuth connection at any time.
- Lodge a complaint with your local data-protection authority if you believe we have violated your rights.
To exercise any of these rights, email support@fozato.com from the email address associated with your account. We respond within 30 days.
8. AI-generated content
Reel scripts, voice tracks, and assembled videos are generated using third-party AI models. The prompts we send include only the business context you have provided. We do not send your OAuth tokens, customer lists, or payment data to any AI provider.
You are responsible for reviewing AI-generated content before publishing and for ensuring it complies with the terms of the platforms you publish to.
9. Children's privacy
The Service is not directed to children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, email support@fozato.com and we will delete it promptly.
10. International data transfers
Our infrastructure runs on cloud providers located in multiple regions. By using the Service you consent to your data being processed in jurisdictions outside your own, including the European Union, India, and the United States. Where required by law we rely on Standard Contractual Clauses or equivalent transfer mechanisms.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be announced by email or in the Service at least 14 days before they take effect. The "Effective date" at the top of this page is always current.
12. Contact us
Questions, requests, or concerns about this policy or how we handle your data: