This Privacy Policy explains how PINTECH DOO Skopje (“PintechLabs”, “SendGecko”, “we”, “us”) handles personal data when you visit sendgecko.io, join the waitlist, or use the SendGecko app at app.sendgecko.io (together, the “Service”). We wrote it to be read by people, so we keep the words plain.
Who we are
SendGecko is operated by PINTECH DOO Skopje, Skopje, North Macedonia, the company behind PintechLabs. For personal data we collect about you ourselves (your account, billing, the waitlist, how you use the Service) we are the controller.
When you use SendGecko for your own brand or for clients, the content and contact details you put in (for example the people in your workspace, or names in a post) are yours. For that data we act as your processor, under our Data Processing Agreement.
Privacy questions and requests: contact@sendgecko.io.
What we collect
We collect only what we need to run SendGecko. Here is everything, grouped.
| Group | What it includes | Where it comes from |
|---|---|---|
| Account | Email address, name (if you add one), profile picture (if you sign in with Google), time zone, sign-in method, and the public key of any passkey you register. We never receive your fingerprint or face data; your device keeps that. | You, and Google if you choose Continue with Google |
| Workspace and team | Workspace and brand names, members, roles, and the email addresses of people you invite. | You |
| Connected channels | For each channel: the network, account or Page ID, display name, username, profile picture, connection status and the permissions you granted. Credentials (access and refresh tokens, app passwords, webhook URLs, channel tokens) are stored encrypted. | The network, and you |
| Your content | Posts, drafts, captions, hashtags, first comments, alt text, ideas, brand voice notes, snippets and Gecko Page content. Photos and videos you upload, plus resized copies we make for each network (we remove location data from images). Resources: the text of notes, web pages and documents you add for Gecko AI to read; we keep the extracted text, not the original file. | You |
| Performance data | Totals such as impressions, reach, views, likes, comments, shares, saves and clicks for the posts you published, and follower or member counts for your channels. These are counts, not the identities of the people behind them. | The networks |
| AI use | Your requests and the answers, which model was used, tokens and credits spent, and any AI provider keys you add (encrypted). | You |
| Billing | Plan, status, billing period, country (for tax) and the IDs Whop gives us. Card details go to Whop only; we never see them. | You, and Whop |
| Technical and security | IP address, browser and device type, time stamps, sessions, and a log of important actions (sign-ins, connecting a channel, billing changes). Error reports from the app, with tokens and keys removed. | Your device and our servers |
| Waitlist | Email address, the role you pick (optional), your referral code, who referred you, and when you confirmed. | You |
| Telegram link (optional) | If you link your own Telegram account for alerts and ideas: your Telegram ID, username and chat ID. | You, through Telegram |
| Gecko Page visitors | If you publish a Gecko Page, we count visits and link clicks with the visitor's country and the site they came from, in aggregate and without cookies. We don't build profiles of visitors. | Visitors' browsers |
| Messages to us | What you write to support, and our replies. | You |
We do not ask for the passwords of your social accounts (the one exception is a Bluesky app password, which you create just for SendGecko and can delete any time). We don't read private messages, we don't collect your followers' or contacts' personal data, and we don't knowingly collect special-category data. If you put such information in your own posts, it is still your content and you decide what to publish.
Google and YouTube data
This section covers two ways SendGecko can receive information from Google:
- Continue with Google (sign-in). We receive your name, email address and profile picture, so we can create and recognise your account.
- Connecting a YouTube channel. With your approval we can upload videos and Shorts you choose, read your channel's name and picture, and read analytics for your channel and videos. Permissions:
youtube.upload,youtube.readonlyandyt-analytics.readonly.
What we do with Google user data:
- We use it only to provide and improve the features you can see in SendGecko: signing you in, uploading and scheduling your videos, and showing your analytics.
- We don't transfer it to anyone else, except to provide those features with your consent, for security or abuse investigations, to follow the law, or as part of a merger or sale after you have been told and given your consent.
- We never sell it, use it for advertising (including retargeting or interest-based ads), or share it with data brokers.
- People at SendGecko don't read it unless you ask us to (for support), it is needed for security or to follow the law, or it is aggregated and used for internal operations.
- We don't use it to develop, improve or train generalized AI or machine-learning models, and we don't send it to AI providers.
- We store it encrypted where it is sensitive (tokens), protect it as described in our Security page, and delete it as described below.
YouTube. By connecting a YouTube channel to SendGecko you agree to be bound by the YouTube Terms of Service. Google's handling of your data is described in the Google Privacy Policy.
Revoking access. You can revoke SendGecko's access to your Google account at any time in your Google security settings, or by removing the channel in SendGecko (Settings → Channels). When access is revoked we delete the credentials immediately, and delete any other data we received from the YouTube API within 30 days. We also refresh or delete stored YouTube API data at least every 30 days; analytics history is kept only while we can re-confirm your authorization.
How and why we use data
| Why | What we do | Legal basis (GDPR) |
|---|---|---|
| Provide the Service | Store your drafts and media, publish at the time you pick, show your calendar and analytics, enforce plan limits. | Contract (Art. 6(1)(b)) |
| Sign-in and security | Email codes, passkeys, sessions, rate limits, bot protection, spotting abuse and fraud, keeping audit logs. | Contract, and our legitimate interest in a safe service (Art. 6(1)(f)) |
| AI features | Send your requests to the model you choose and show you the result. | Contract |
| Billing | Manage your plan, limits and invoices; keep records tax law requires. | Contract; legal obligation (Art. 6(1)(c)) |
| Service emails | Sign-in codes, invitations, 'post failed' and 'reconnect needed' alerts, billing notices. You control the optional ones in Settings → Notifications. | Contract |
| Improving SendGecko | Cookieless usage statistics and error reports, so we can fix bugs and see which features help. | Legitimate interest (Art. 6(1)(f)) |
| Waitlist and launch news | Confirm your spot, tell you when SendGecko opens, and send occasional product news. | Consent (Art. 6(1)(a)); withdraw any time |
| Support | Answer your questions and fix problems. | Contract; legitimate interest |
| Legal claims | Establish, exercise or defend legal claims, and answer lawful requests. | Legal obligation; legitimate interest |
We don't make decisions about you by automated means that have legal or similarly significant effects, and we don't profile you for advertising.
Gecko AI and your data
Gecko AI is optional. When you use it, the text of your request goes to the AI provider of the model you pick, together with the context you allow: your draft, your brand voice, the Resources you selected or pinned, and (for matching your style) some of your recent posts. If you ask for alt text, the image is sent to a model that can see it.
- AI never publishes by itself. It makes suggestions. You review them, and nothing is posted unless you schedule it or you turned on an automation yourself.
- Our keys. We use the paid API plans of the providers listed on Subprocessors and, where the provider offers it, settings that keep your prompts out of model training. The page notes any exceptions.
- Your own key (BYOK). If you add your own provider key, we use it only for your requests, store it encrypted and show only its last few characters. Your data then goes to that provider under your agreement with them. We never silently fall back to our keys: that happens only if you switch on “use SendGecko credits as backup”.
- We don't train AI models on your content. We keep the text of AI requests and answers for 30 days to help fix problems, then only usage counts remain.
- Please don't put other people's personal data into prompts or Resources unless you have the right to.
Some networks ask you to label AI-generated content. The composer has a “Contains AI” switch for that. You are responsible for using it where a network requires it.
International transfers
Our servers are in Germany, and our team works from North Macedonia. Some of the companies on the Subprocessors page are in other countries, including the United States. When personal data leaves the European Economic Area or the UK, we make sure it is protected, using the EU Standard Contractual Clauses (and the UK addendum) and, for US providers that are certified, the EU–US Data Privacy Framework. Ask us at contact@sendgecko.io for a copy of the safeguards.
How long we keep data
| What | How long |
|---|---|
| Your account and workspace | Until you delete them. Then we remove them within 30 days, apart from encrypted backups (see below). |
| Access tokens, app passwords and webhook URLs for connected networks | Deleted immediately when you disconnect a channel, when the network tells us access was revoked, or when you delete your account. |
| Posts, drafts, ideas, Resources and Gecko Page content | Until you delete them or your workspace. Deleted items are kept for up to 30 days so you can undo a mistake, then removed. |
| Media you upload | Until you delete it or your workspace. Resized copies made for a network are removed after 14 days. Deleted files are purged within 30 days. |
| Analytics from your networks | For the history your plan includes (7 days to 2 years). Data from YouTube is refreshed or deleted at least every 30 days, as YouTube requires, and analytics are kept only while we can re-confirm your authorization. |
| AI requests and answers | The text is kept for 30 days to help us fix problems, then only the usage counts (model, tokens, credits) remain. |
| Your own AI provider keys (BYOK) | Encrypted, until you remove the key or delete your workspace. |
| Security and audit logs | Up to 12 months. |
| Server and error logs | Up to 30 days (error reports up to 90 days). |
| Billing records | For as long as tax and accounting law requires. They live with our payment provider. |
| Waitlist email and referral data | Until you ask us to remove you, or until 12 months after we open SendGecko to everyone. |
| Encrypted backups | Nightly backups are kept for 30 days. Deleted data can remain in a backup until that backup expires, and is never restored into the live service afterwards. |
How we protect data
Tokens, app passwords and AI keys are encrypted with AES-256-GCM before they are stored. There are no passwords to steal: you sign in with passkeys, email codes or Google. Every request is checked against your workspace and your role. Read the details on Security. No system is perfect: if there is a breach that affects your personal data, we will tell you and the authorities within the time the law sets (72 hours for the authority under GDPR).
Your rights and choices
Whoever you are, you can ask us to:
- tell you what we hold about you and give you a copy (and a portable export);
- correct anything that is wrong;
- delete your data (see Data Deletion);
- stop using your data for a purpose you object to, or limit how we use it;
- withdraw a consent you gave, for example for waitlist emails.
Email contact@sendgecko.io from the address on your account. We may ask a question to make sure it is you. We answer within 30 days (and tell you if a complex request needs longer). It is free, and we won't treat you worse for using your rights.
If you are in the EEA, UK or North Macedonia, the GDPR and the local data protection law give you these rights, and you can complain to your data protection authority. Ours is the Agency for Personal Data Protection (North Macedonia).
If you live in California or another US state with a privacy law, you can ask to know, correct and delete your personal information, and to opt out of its sale or sharing. We don't sell or share personal information for advertising, so there is nothing to opt out of, and we honour Global Privacy Control signals anyway. You can use an authorised agent; we will ask for proof.
Children
SendGecko is for people aged 18 and over. We don't knowingly collect data from anyone younger. If you think a child has given us data, write to contact@sendgecko.io and we will delete it.
Changes to this policy
We'll update this page when something changes and update the date at the top. If a change matters (a new purpose, a new kind of data), we'll email workspace owners and show a notice in the app at least 30 days before it applies, unless the law or a security need means it must apply sooner.
Contact
PINTECH DOO Skopje, Skopje, North Macedonia
Privacy: contact@sendgecko.io
General: contact@sendgecko.io
3.Data from the networks you connect
You connect a network by signing in on that network's own screen and approving the permissions listed there. We use the network's official API, never your password, and never anything you didn't approve. These promises apply to every network:
Here is exactly what we ask each network for and why. The permission names are the ones the network itself shows.
Facebook
pages_show_listpages_read_engagementpages_manage_postsread_insightsInstagram
instagram_business_basicinstagram_business_content_publishinstagram_business_manage_insightsinstagram_business_manage_commentsThreads
threads_basicthreads_content_publishthreads_manage_insightsTikTok
user.info.basicuser.info.statsvideo.uploadvideo.publishvideo.listYouTube
https://www.googleapis.com/auth/youtube.uploadhttps://www.googleapis.com/auth/youtube.readonlyhttps://www.googleapis.com/auth/yt-analytics.readonlyLinkedIn
openidprofileemailw_member_socialw_organization_socialr_organization_socialrw_organization_adminPinterest
boards:readpins:readpins:writeuser_accounts:readTelegram
post_messagesedit_messagesdelete_messagesViber
Channel token (given by you)Bluesky
App password (given by you)Mastodon
read:accountswrite:statuseswrite:mediaDiscord
Webhook URL (given by you)