Social Scribe

Privacy policy

Last updated 27 August 2026

This policy

This page explains what Social Scribe stores, why, and how you can ask us to delete it. For questions, DM @jain_harshit on X.

What we store

Waitlist: first name, last name, and email. We send those to a Google Sheet we control so we can write when accounts open. We only use that list for launch mail.

Account: email and a hashed password, held by our auth provider (Supabase). We do not see the password in plain text.

Studio content: post body and notes, draft/ready stage, schedule, tags, themes, weekly slots, cooldown settings, and whether a piece is reusable.

Images: up to four per post, 4 MB each, jpeg/png/gif/webp, plus optional alt text. Files live in a private bucket. The app uses short-lived signed URLs to show them.

Send history: when a post was sent, success or failure, and the X post id when a send succeeded.

X connection, if you link one: X user id, handle, display name, avatar URL, and access and refresh tokens. Those tokens are encrypted at rest. We use them only to post as you and to refresh the connection.

Cookies and local storage

Session cookies from Supabase Auth keep you signed in. They are required for the app.

ss-theme remembers light or dark. We also keep that choice in localStorage. We do not follow your system preference.

While you connect X, we set short-lived httpOnly cookies (x_oauth_state and x_oauth_verifier, SameSite=Lax, about ten minutes) so the OAuth handshake can finish.

Recent emoji picks stay in localStorage on this device.

We do not set advertising cookies. We do not run a third-party analytics pixel.

Why we use this

To run the product: sign you in, store drafts, show the calendar, post to X when you ask, remember the theme, and email waitlist people when accounts open. We do not sell your data.

Who else sees it

Supabase hosts auth, the database, and image storage.

Vercel hosts the app.

X receives the posts and images you choose to send, under X’s terms.

The waitlist webhook writes name and email to a Google Sheet we control.

Those processors only get what they need for that job.

How long

Account data stays until you ask us to delete it, or we close the product. Waitlist rows stay until we no longer need the list, or you ask us to remove them.

Session cookies last for the auth session. The theme cookie lasts about a year. X OAuth handshake cookies expire in about ten minutes. Encrypted X tokens stay until you disconnect X or we delete the account.

Delete an account

Message @jain_harshit on X. Tell us the email on the account. We will delete the account, posts, images, and encrypted X tokens.

Disconnecting X in Connections only drops the X connection. You can also delete individual posts and images in the app, and sign out. There is no self-serve account delete button yet.

Children

Social Scribe is not meant for children. Do not create an account if you are under 18.

Changes

We will update this page when the product’s data practices change. The date at the top is the current version.