Skip to content
sendgecko

Privacy Policy

What SendGecko collects, why, how long we keep it, who we share it with, and the choices you have. Includes how we use data from Instagram, Facebook, Threads, TikTok, YouTube, LinkedIn and Pinterest.

Last updated

This Privacy Policy explains how PINTECH DOO Skopje (“PintechLabs”, “SendGecko”, “we”, “us”) handles personal data when you visit sendgecko.io, join the waitlist, or use the SendGecko app at app.sendgecko.io (together, the “Service”). We wrote it to be read by people, so we keep the words plain.

Who we are

SendGecko is operated by PINTECH DOO Skopje, Skopje, North Macedonia, the company behind PintechLabs. For personal data we collect about you ourselves (your account, billing, the waitlist, how you use the Service) we are the controller.

When you use SendGecko for your own brand or for clients, the content and contact details you put in (for example the people in your workspace, or names in a post) are yours. For that data we act as your processor, under our Data Processing Agreement.

Privacy questions and requests: contact@sendgecko.io.

What we collect

We collect only what we need to run SendGecko. Here is everything, grouped.

Personal data we collect
GroupWhat it includesWhere it comes from
AccountEmail address, name (if you add one), profile picture (if you sign in with Google), time zone, sign-in method, and the public key of any passkey you register. We never receive your fingerprint or face data; your device keeps that.You, and Google if you choose Continue with Google
Workspace and teamWorkspace and brand names, members, roles, and the email addresses of people you invite.You
Connected channelsFor each channel: the network, account or Page ID, display name, username, profile picture, connection status and the permissions you granted. Credentials (access and refresh tokens, app passwords, webhook URLs, channel tokens) are stored encrypted.The network, and you
Your contentPosts, drafts, captions, hashtags, first comments, alt text, ideas, brand voice notes, snippets and Gecko Page content. Photos and videos you upload, plus resized copies we make for each network (we remove location data from images). Resources: the text of notes, web pages and documents you add for Gecko AI to read; we keep the extracted text, not the original file.You
Performance dataTotals such as impressions, reach, views, likes, comments, shares, saves and clicks for the posts you published, and follower or member counts for your channels. These are counts, not the identities of the people behind them.The networks
AI useYour requests and the answers, which model was used, tokens and credits spent, and any AI provider keys you add (encrypted).You
BillingPlan, status, billing period, country (for tax) and the IDs Whop gives us. Card details go to Whop only; we never see them.You, and Whop
Technical and securityIP address, browser and device type, time stamps, sessions, and a log of important actions (sign-ins, connecting a channel, billing changes). Error reports from the app, with tokens and keys removed.Your device and our servers
WaitlistEmail address, the role you pick (optional), your referral code, who referred you, and when you confirmed.You
Telegram link (optional)If you link your own Telegram account for alerts and ideas: your Telegram ID, username and chat ID.You, through Telegram
Gecko Page visitorsIf you publish a Gecko Page, we count visits and link clicks with the visitor's country and the site they came from, in aggregate and without cookies. We don't build profiles of visitors.Visitors' browsers
Messages to usWhat you write to support, and our replies.You

We do not ask for the passwords of your social accounts (the one exception is a Bluesky app password, which you create just for SendGecko and can delete any time). We don't read private messages, we don't collect your followers' or contacts' personal data, and we don't knowingly collect special-category data. If you put such information in your own posts, it is still your content and you decide what to publish.

Data from the networks you connect

You connect a network by signing in on that network's own screen and approving the permissions listed there. We use the network's official API, never your password, and never anything you didn't approve. These promises apply to every network:

  • We publish only what you create and schedule, and only to the accounts, Pages and channels you connect and manage.
  • We read only your own account details and the performance numbers of your own posts. We don't read other people's content or private messages.
  • We don't sell, rent or share this data with advertisers, data brokers or ad networks. We don't use it for advertising, profiling, surveillance, or to train AI models, and we don't combine it with other data to build a profile of any person.
  • We don't send data from the networks to AI providers. Gecko AI only sees what you write and the Resources you choose.
  • We keep credentials encrypted, and delete them as soon as you disconnect a channel or the network tells us access was revoked. We delete the rest of that channel's data within 30 days (see Data Deletion).
  • SendGecko is independent. It isn't affiliated with or endorsed by any of these networks. Names and logos belong to their owners.

Here is exactly what we ask each network for and why. The permission names are the ones the network itself shows.

Facebook

What you connect
Facebook Pages you manage.
Permissions we ask for
pages_show_listpages_read_engagementpages_manage_postsread_insights
What we use them for
List the Pages you choose to connect, publish the posts, photos, videos and Reels you schedule, and show how those posts performed.
What we don’t do
We never post to your personal profile or to groups, and we don't read private messages.

Instagram

What you connect
Instagram professional (Business or Creator) accounts.
Permissions we ask for
instagram_business_basicinstagram_business_content_publishinstagram_business_manage_insightsinstagram_business_manage_comments
What we use them for
Read your profile name and picture, publish the photos, carousels, Reels and Stories you schedule, post the first comment you wrote, and show post and account insights.
What we don’t do
We don't read your messages, follow or like for you, or reply to comments on your behalf.

Threads

What you connect
Threads profiles.
Permissions we ask for
threads_basicthreads_content_publishthreads_manage_insights
What we use them for
Read your profile name and picture, publish the posts and threads you schedule, and show how they performed.
What we don’t do
We don't follow, like or reply for you, and we don't read other people's posts.

TikTok

What you connect
TikTok accounts.
Permissions we ask for
user.info.basicuser.info.statsvideo.uploadvideo.publishvideo.list
What we use them for
Read your nickname and avatar, show the privacy and interaction options TikTok allows for you, send the videos and photos you schedule to TikTok (either as a draft in your TikTok inbox or as a direct post, whichever you choose), and show how your videos performed (views, likes, comments and shares) and how many followers you have.
What we don’t do
We never add watermarks or promotional text to your content, never post without your confirmation of each post's settings, and never read your TikTok messages.

YouTube

What you connect
YouTube channels.
Permissions we ask for
https://www.googleapis.com/auth/youtube.uploadhttps://www.googleapis.com/auth/youtube.readonlyhttps://www.googleapis.com/auth/yt-analytics.readonly
What we use them for
Upload and schedule the videos and Shorts you choose, set their title, description, privacy and made-for-kids settings, read your channel name and picture, and show how your videos performed.
What we don’t do
We don't delete or edit your existing videos, and we don't use YouTube data for ads or send it to AI providers.

LinkedIn

What you connect
LinkedIn profiles, and company Pages you administer.
Permissions we ask for
openidprofileemailw_member_socialw_organization_socialr_organization_socialrw_organization_admin
What we use them for
Read your name and picture, publish the posts, images, videos and PDF carousels you schedule to your profile or to a Page you administer, and show how they performed.
What we don’t do
We don't send connection requests or messages, and we don't read your feed or your contacts.

Pinterest

What you connect
Pinterest accounts.
Permissions we ask for
boards:readpins:readpins:writeuser_accounts:read
What we use them for
Read your account name and boards, publish the Pins you schedule to the board you pick, and show how they performed.
What we don’t do
We don't follow people or save other people's Pins for you.

Telegram

What you connect
Telegram channels where you add our bot as an administrator.
Permissions we ask for
post_messagesedit_messagesdelete_messages
What we use them for
Publish and edit the messages you schedule in your channel. If you link your own Telegram account for alerts, we also store your Telegram ID and username to message you.
What we don’t do
The bot doesn't read or store your channel's other content or your chats. Telegram doesn't share post views with bots, so we don't show them.

Viber

What you connect
Viber channels.
Permissions we ask for
Channel token (given by you)
What we use them for
Publish the messages you schedule to the channel the token belongs to.
What we don’t do
We only use the token to post to that one channel.

Bluesky

What you connect
Bluesky accounts.
Permissions we ask for
App password (given by you)
What we use them for
Publish the posts and threads you schedule from the account the app password belongs to.
What we don’t do
We never ask for your main password. You can delete the app password in Bluesky at any time.

Mastodon

What you connect
Mastodon accounts on any server.
Permissions we ask for
read:accountswrite:statuseswrite:media
What we use them for
Read your account name and picture and publish the posts and media you schedule.
What we don’t do
We don't read your timeline, follow, boost or favourite for you.

Discord

What you connect
Discord channels, through a webhook you create.
Permissions we ask for
Webhook URL (given by you)
What we use them for
Post the messages you schedule to the channel the webhook belongs to.
What we don’t do
A webhook can only post. We can't read the channel or its members.

Google and YouTube data

This section covers two ways SendGecko can receive information from Google:

  • Continue with Google (sign-in). We receive your name, email address and profile picture, so we can create and recognise your account.
  • Connecting a YouTube channel. With your approval we can upload videos and Shorts you choose, read your channel's name and picture, and read analytics for your channel and videos. Permissions: youtube.upload, youtube.readonly and yt-analytics.readonly.

What we do with Google user data:

  • We use it only to provide and improve the features you can see in SendGecko: signing you in, uploading and scheduling your videos, and showing your analytics.
  • We don't transfer it to anyone else, except to provide those features with your consent, for security or abuse investigations, to follow the law, or as part of a merger or sale after you have been told and given your consent.
  • We never sell it, use it for advertising (including retargeting or interest-based ads), or share it with data brokers.
  • People at SendGecko don't read it unless you ask us to (for support), it is needed for security or to follow the law, or it is aggregated and used for internal operations.
  • We don't use it to develop, improve or train generalized AI or machine-learning models, and we don't send it to AI providers.
  • We store it encrypted where it is sensitive (tokens), protect it as described in our Security page, and delete it as described below.

YouTube. By connecting a YouTube channel to SendGecko you agree to be bound by the YouTube Terms of Service. Google's handling of your data is described in the Google Privacy Policy.

Revoking access. You can revoke SendGecko's access to your Google account at any time in your Google security settings, or by removing the channel in SendGecko (Settings → Channels). When access is revoked we delete the credentials immediately, and delete any other data we received from the YouTube API within 30 days. We also refresh or delete stored YouTube API data at least every 30 days; analytics history is kept only while we can re-confirm your authorization.

How and why we use data

Purposes and legal bases
WhyWhat we doLegal basis (GDPR)
Provide the ServiceStore your drafts and media, publish at the time you pick, show your calendar and analytics, enforce plan limits.Contract (Art. 6(1)(b))
Sign-in and securityEmail codes, passkeys, sessions, rate limits, bot protection, spotting abuse and fraud, keeping audit logs.Contract, and our legitimate interest in a safe service (Art. 6(1)(f))
AI featuresSend your requests to the model you choose and show you the result.Contract
BillingManage your plan, limits and invoices; keep records tax law requires.Contract; legal obligation (Art. 6(1)(c))
Service emailsSign-in codes, invitations, 'post failed' and 'reconnect needed' alerts, billing notices. You control the optional ones in Settings → Notifications.Contract
Improving SendGeckoCookieless usage statistics and error reports, so we can fix bugs and see which features help.Legitimate interest (Art. 6(1)(f))
Waitlist and launch newsConfirm your spot, tell you when SendGecko opens, and send occasional product news.Consent (Art. 6(1)(a)); withdraw any time
SupportAnswer your questions and fix problems.Contract; legitimate interest
Legal claimsEstablish, exercise or defend legal claims, and answer lawful requests.Legal obligation; legitimate interest

We don't make decisions about you by automated means that have legal or similarly significant effects, and we don't profile you for advertising.

Gecko AI and your data

Gecko AI is optional. When you use it, the text of your request goes to the AI provider of the model you pick, together with the context you allow: your draft, your brand voice, the Resources you selected or pinned, and (for matching your style) some of your recent posts. If you ask for alt text, the image is sent to a model that can see it.

  • AI never publishes by itself. It makes suggestions. You review them, and nothing is posted unless you schedule it or you turned on an automation yourself.
  • Our keys. We use the paid API plans of the providers listed on Subprocessors and, where the provider offers it, settings that keep your prompts out of model training. The page notes any exceptions.
  • Your own key (BYOK). If you add your own provider key, we use it only for your requests, store it encrypted and show only its last few characters. Your data then goes to that provider under your agreement with them. We never silently fall back to our keys: that happens only if you switch on “use SendGecko credits as backup”.
  • We don't train AI models on your content. We keep the text of AI requests and answers for 30 days to help fix problems, then only usage counts remain.
  • Please don't put other people's personal data into prompts or Resources unless you have the right to.

Some networks ask you to label AI-generated content. The composer has a “Contains AI” switch for that. You are responsible for using it where a network requires it.

Who we share data with

We do not sell personal data, and we do not share it for cross-context behavioural advertising. We share it only in these cases:

  • Companies that help us run SendGecko (hosting, email, payments, error monitoring, AI models). They act on our instructions under data processing terms. The full list, with what each one sees and where, is on Subprocessors. There are currently 13 entries, and the AI providers only receive data when you choose their model.
  • The networks you connect. We send them what you publish. What they do with it is governed by their own terms and privacy policies, linked above.
  • People in your workspace. Members see the content and channels their role allows. If you share an approval link, the guest sees the posts you chose.
  • Authorities and advisers when the law requires it, to protect rights, safety or the Service, or to our lawyers and accountants under confidentiality.
  • A buyer if SendGecko is ever merged or sold. We would tell you first, and this policy would keep applying.

International transfers

Our servers are in Germany, and our team works from North Macedonia. Some of the companies on the Subprocessors page are in other countries, including the United States. When personal data leaves the European Economic Area or the UK, we make sure it is protected, using the EU Standard Contractual Clauses (and the UK addendum) and, for US providers that are certified, the EU–US Data Privacy Framework. Ask us at contact@sendgecko.io for a copy of the safeguards.

How long we keep data

Retention periods
WhatHow long
Your account and workspaceUntil you delete them. Then we remove them within 30 days, apart from encrypted backups (see below).
Access tokens, app passwords and webhook URLs for connected networksDeleted immediately when you disconnect a channel, when the network tells us access was revoked, or when you delete your account.
Posts, drafts, ideas, Resources and Gecko Page contentUntil you delete them or your workspace. Deleted items are kept for up to 30 days so you can undo a mistake, then removed.
Media you uploadUntil you delete it or your workspace. Resized copies made for a network are removed after 14 days. Deleted files are purged within 30 days.
Analytics from your networksFor the history your plan includes (7 days to 2 years). Data from YouTube is refreshed or deleted at least every 30 days, as YouTube requires, and analytics are kept only while we can re-confirm your authorization.
AI requests and answersThe text is kept for 30 days to help us fix problems, then only the usage counts (model, tokens, credits) remain.
Your own AI provider keys (BYOK)Encrypted, until you remove the key or delete your workspace.
Security and audit logsUp to 12 months.
Server and error logsUp to 30 days (error reports up to 90 days).
Billing recordsFor as long as tax and accounting law requires. They live with our payment provider.
Waitlist email and referral dataUntil you ask us to remove you, or until 12 months after we open SendGecko to everyone.
Encrypted backupsNightly backups are kept for 30 days. Deleted data can remain in a backup until that backup expires, and is never restored into the live service afterwards.

How we protect data

Tokens, app passwords and AI keys are encrypted with AES-256-GCM before they are stored. There are no passwords to steal: you sign in with passkeys, email codes or Google. Every request is checked against your workspace and your role. Read the details on Security. No system is perfect: if there is a breach that affects your personal data, we will tell you and the authorities within the time the law sets (72 hours for the authority under GDPR).

Your rights and choices

Whoever you are, you can ask us to:

  • tell you what we hold about you and give you a copy (and a portable export);
  • correct anything that is wrong;
  • delete your data (see Data Deletion);
  • stop using your data for a purpose you object to, or limit how we use it;
  • withdraw a consent you gave, for example for waitlist emails.

Email contact@sendgecko.io from the address on your account. We may ask a question to make sure it is you. We answer within 30 days (and tell you if a complex request needs longer). It is free, and we won't treat you worse for using your rights.

If you are in the EEA, UK or North Macedonia, the GDPR and the local data protection law give you these rights, and you can complain to your data protection authority. Ours is the Agency for Personal Data Protection (North Macedonia).

If you live in California or another US state with a privacy law, you can ask to know, correct and delete your personal information, and to opt out of its sale or sharing. We don't sell or share personal information for advertising, so there is nothing to opt out of, and we honour Global Privacy Control signals anyway. You can use an authorised agent; we will ask for proof.

Cookies

We use only the cookies the Service needs to work, and cookieless statistics. No advertising cookies, no cross-site tracking. The list is on the Cookie Policy.

Children

SendGecko is for people aged 18 and over. We don't knowingly collect data from anyone younger. If you think a child has given us data, write to contact@sendgecko.io and we will delete it.

Changes to this policy

We'll update this page when something changes and update the date at the top. If a change matters (a new purpose, a new kind of data), we'll email workspace owners and show a notice in the app at least 30 days before it applies, unless the law or a security need means it must apply sooner.

Contact

PINTECH DOO Skopje, Skopje, North Macedonia
Privacy: contact@sendgecko.io
General: contact@sendgecko.io