Privacy Policy
Last updated: July 31, 2026
Tool Social ("we", "the service") helps website owners schedule and publish posts to their own social media accounts. This policy explains what we store, why, and how you can remove it.
Who we are
Tool Social is operated by the Tool Social team and is available at tool.bivon.dev. For any privacy question or data-deletion request, contact support@bivon.dev.
What we collect
- Account details — your name, email, and a hashed password, used to sign you in.
- Connected social accounts — when you connect a Facebook Page, Instagram Business account, Pinterest, or X, we store the access tokens and basic identifiers (page/account id and name). Tokens are encrypted at rest.
- Content you provide — website feed URLs, ingested articles, uploaded videos, captions, and the schedule for your posts.
- Publishing results and analytics — the status of each post and, where you grant permission, aggregate engagement metrics (reach, impressions, reactions, link clicks) for the posts we published on your behalf.
How we use it
- To publish the posts you schedule to the social accounts you connected.
- To add your blog link as the first comment on a post, when you enable that option.
- To show you the status of your posts and, if enabled, their engagement metrics.
- To operate, secure, and support your account.
Facebook / Instagram (Meta) data
When you connect a Meta account, we request only the permissions needed to publish on your behalf and to report on those posts: listing the Pages you manage, publishing posts and comments to the Page you choose, and (optionally) reading insights for posts we published. We do not access private messages, friends lists, or unrelated content, and we never post without an action you configured. Our use of information received from Meta APIs follows Meta's Platform Terms and Developer Policies.
What we do NOT do
- We do not sell your data or your audience's data.
- We do not share your data with third parties for advertising.
- We do not post to your accounts except the posts you schedule or approve.
Data sharing
We share data only with the infrastructure providers needed to run the service (our hosting/server and the social platforms you connect, in order to publish your posts) and where required by law. AI captions are generated via an AI provider (Anthropic or, through OpenRouter, a compatible model) using only the article title or the text you provide.
Retention and deletion
We keep your data while your account is active. You can remove data at any time:
- Disconnect a social account on the Connections page — this deletes the stored token and that account's data from the workspace.
- Delete posts, sources, or videos from within the app.
- Delete your account — email support@bivon.dev and we will remove your account and associated data.
Security
Access tokens and API secrets are encrypted at rest. The service is served over HTTPS. Access is restricted to your own workspaces; administrators who manage the service on your behalf may access workspaces they operate for you.
Changes
We may update this policy; the "Last updated" date above reflects the latest version. Continued use after a change means you accept the updated policy.