Privacy Policy
Last updated: September 18, 2026
This policy describes how RichFeed (https://richfeed.social), a social-media scheduling and publishing service operated by Kashif Nehal, handles personal data. It matches the product as it actually runs today — not a generic template. Questions or requests: adorablekashif786@gmail.com.
What RichFeed is
RichFeed lets you connect your own social accounts, compose a post, pick which connected accounts should receive it, and schedule a publish time. At that time RichFeed calls each platform's API on your behalf and records whether the publish succeeded. We only post to an account you connected, with content you supplied, at a time you set. We do not run ads, boost posts, scrape feeds, read DMs, or sell data.
What we collect
When you use RichFeed we store:
- Account. Email address and a hashed password, held by our auth provider (Supabase Auth). We do not store plaintext passwords. Optional profile fields you enter in Settings (display name, avatar) and a workspace name.
- Notification preferences. In-app toggles for failed posts and accounts that need reconnect. These preferences are stored only; RichFeed does not currently send email or push notifications.
- Connected social accounts. Platform, platform account id, username/handle where the platform returns one, display name, avatar URL, and the OAuth scopes you granted. Today that means LinkedIn (personal), Instagram, Facebook Pages, Threads, YouTube, and X (Twitter). X publishing is paused on our side for billing reasons; if you connected X we still hold that row until you disconnect or delete it.
- OAuth tokens. Access tokens and, where the platform issues one, refresh tokens. These are encrypted at rest with AES-256-GCM before they are written to the database. We decrypt a token only in the publish worker, at the moment we call the platform API for a post you scheduled.
- Scheduled posts. Captions, hashtags, media files you upload, per-target caption overrides, and the date/time you chose for each account. Media is stored in a public object bucket so the destination platform can fetch the file at publish time.
- Publish results. Per-target status (scheduled, published, failed, needs reconnect), the platform's post id and permalink when the platform returns them, and a plain-language log of publish attempts (including error categories, not stack traces).
- Short-lived connect tickets. A one-use ticket (about 60 seconds) that bridges our app to a platform's OAuth screen. It is deleted when used or when it expires.
- Operational logs. Our hosting providers (web, API, and worker) may record request metadata such as IP address, user agent, and timestamps as part of running the service. We do not run advertising pixels, analytics SDKs, or cross-site trackers.
Why we collect it
We use this data only to:
- Create and authenticate your RichFeed account.
- Connect the social accounts you choose, and keep those connections working (including refreshing a token when the platform requires it).
- Publish the content you composed to the accounts you selected, at the times you directed, and show you whether each publish succeeded.
- Respond to privacy, deletion, and support requests you send to the contact address above.
We do not use your captions, media, or social-account data to train AI models, to advertise, or to build profiles for anyone else.
How tokens are stored
OAuth access and refresh tokens are encrypted at rest with AES-256-GCM using a server-side key. Ciphertext is stored in our database; plaintext tokens are not written to logs. Tokens are decrypted in the worker process only to call the platform API for a post you scheduled.
Who we share data with
We share data with a connected platform only at your direction: when you complete that platform's OAuth consent, and when a scheduled post is published to an account you selected (caption, hashtags, and media URLs). We do not share data with ad networks. We do not sell or rent personal data.
The platforms that may receive data, if you connect them, are:
- Meta — Instagram, Facebook Pages, and Threads
- LinkedIn — personal profile posting
- Google — YouTube
- X (Twitter) — when that connection is active
We also use infrastructure processors that host the product, under their own terms, solely to operate RichFeed: Supabase (authentication, database, media storage), Vercel (the website), Railway (API and publish worker), and Upstash (job queue and short-lived connect tickets). They process data to provide those services to us, not to market to you.
Cookies
We use essential session cookies so you can stay signed in (Supabase Auth). We do not set advertising or third-party tracking cookies.
Retention
We keep account, connection, and post data for as long as your RichFeed account exists, so you can see history and status. Disconnecting a social account (Accounts → Disconnect) marks it disconnected so it cannot be chosen for new posts; the row, encrypted tokens, and existing post history stay until you remove that account permanently or we delete your RichFeed account. Already-scheduled posts for that account may still publish unless you cancel them first.
"Remove permanently" on a disconnected account deletes that social-account row and its stored tokens immediately, but only if no scheduled or published posts still reference it.
A verified request to delete your entire RichFeed account is completed within 30 days. After that, the data listed above is removed from our production database and media bucket. Residual copies in encrypted backups are overwritten on the backup rotation cycle, typically within 30 days of the production deletion.
How to disconnect an account or delete your data
Step-by-step instructions, including how to request full account deletion, are at Data Deletion Instructions. In short: disconnect or remove a social account from Accounts, and email adorablekashif786@gmail.com from the address you use to sign in to delete the RichFeed account itself. You can also revoke RichFeed's access in the social platform's own settings (for example Meta Business Integrations or Google Account permissions).
Your rights (EEA, UK, California, and similar laws)
If those laws apply to you, you may request access to the personal data we hold, correction of inaccurate data, deletion, and a portable copy of account and post data (we will provide it in a common machine-readable format). California residents: we do not sell personal information and we do not share it for cross-context behavioral advertising. To exercise any of these rights, email adorablekashif786@gmail.com. We will verify the request against the signed-in account email before acting. You may also lodge a complaint with your local data-protection authority.
Children
RichFeed is not directed at children under 13 (or under 16 where that is the applicable age). We do not knowingly collect data from children.
Changes
If this policy changes in a material way we will update the date above and post the new version at this URL. Continued use of RichFeed after that date means you accept the updated policy.
Contact
Privacy and data-deletion requests: adorablekashif786@gmail.com. This inbox is monitored. Please use the same email address you use to sign in to RichFeed so we can verify the request.