Privacy Policy
Last updated: 17 July 2026 Data controller: Envestis SA, Via Pretorio 13A, 6900 Lugano, Switzerland Business Identification Number (UID): CHE-339.253.743 Privacy contact: privacy@ciaopost.com
1. Who we are and the scope of this Policy
1.1. This Privacy Policy explains how Envestis SA (“ciaopost”, “we”, “us”) collects, uses, discloses, and protects personal data in connection with the ciaopost application, website, and services (the “Service”).
1.2. The Service is operated from Switzerland. We process personal data in accordance with the Swiss Federal Act on Data Protection (nLPD/FADP) and, where applicable, the EU General Data Protection Regulation (GDPR).
1.3. This Policy covers three groups of people: (a) Business users — merchants, companies, and their invited Team Members who hold an account; (b) End Customers — customers of a Business who record or provide a testimonial through the Service; (c) Website visitors — anyone who visits our public website.
1.4. Cookies and tracking technologies used on our website are described in a separate Cookie Policy.
2. Our two roles: controller and processor
This is the most important distinction in this Policy.
2.1. We are the data CONTROLLER for:
- the personal data of Business users (account, billing, and usage data);
- the personal data of website visitors.
2.2. We are a data PROCESSOR for:
- the personal data of End Customers contained in testimonials and consent records. In this case the Business is the controller and decides why and how this data is used; we process it only on the Business’s instructions to provide the Service.
2.3. As a consequence, an End Customer who wants to exercise rights over their testimonial (access, correction, deletion, withdrawal of consent) should contact the Business that collected it. We will assist the Business as processor.
2.4. Where we act as processor for End Customer data, that relationship is governed by a separate Data Processing Agreement (GDPR Art. 28), available to business customers.
3. Personal data we collect
3.1. Business users (we are controller)
| Data | Examples | Source |
|---|---|---|
| Identity & contact | name, business name, email | you, at sign-up |
| Account & profile | segment (b2c/b2b), business category, city, preferences | you |
| Team members | names and emails of invited team members | you |
| Authentication | login credentials, session data | you / generated |
| Billing | subscription tier, payment status, invoices (card data handled by our payment processor, not stored by us) | you / Stripe |
| Connected accounts | access tokens for the social accounts you connect (stored encrypted) | you, via OAuth |
| Usage | posts created, publish outcomes, quota usage, logs | generated |
| Support | messages you send us | you |
3.2. End Customers (we are processor, on the Business’s behalf)
| Data | Examples | Source |
|---|---|---|
| Identity | first name (and any name the customer provides) | the End Customer, via the Business |
| Testimonial content | video, voice recording, photo, and/or text | the End Customer |
| Biometric-adjacent content | the customer’s image and voice within the testimonial | the End Customer |
| Consent record | the authorisation, relevant identifiers, and finger-drawn signature | the End Customer |
| Transcription | text transcription of the spoken testimonial | generated by AI |
3.3. Website visitors (we are controller)
| Data | Examples | Source |
|---|---|---|
| Technical | IP address, device, browser, pages viewed | automatic |
| Cookies & pixels | analytics and advertising identifiers | see Cookie Policy, subject to consent |
3.4. Fraud-prevention data
To prevent repeated abuse of the free trial, we retain a minimal record derived from a connected social account: a hashed identifier, a flag indicating a trial was used, and a date. This record survives account deletion, because deleting it would defeat its purpose. It is not used for any purpose other than fraud prevention.
3.5. Approximate location (only if you allow it, only at onboarding)
What. Your device’s approximate location, read through your browser’s standard Geolocation API, and only after you allow it when the browser asks.
Why. To suggest your business’s city during onboarding, so you do not have to type it.
How. Turning the location into a city name happens on our own servers — a self-hosted geocoder (Nominatim), not an outside service. We do not store the coordinates, we do not share them with anyone, and we do not keep the full address. All we retain is the city name, which you confirm.
If you decline. You type your city yourself. Nothing is blocked.
No third party is involved in this: the location-to-city conversion is entirely internal, so there is no sub-processor for it (§6).
4. Why we use personal data and our legal basis
4.1. As controller (Business users and visitors)
| Purpose | Legal basis (GDPR) |
|---|---|
| Provide and operate the Service, manage your account | Performance of a contract (Art. 6(1)(b)) |
| Process payments and manage subscriptions | Performance of a contract (Art. 6(1)(b)) |
| Publish your content to your connected accounts | Performance of a contract (Art. 6(1)(b)) |
| Send service/transactional emails | Performance of a contract (Art. 6(1)(b)) |
| Secure the Service, prevent fraud and abuse | Legitimate interests (Art. 6(1)(f)) |
| Fraud-prevention record (§3.4) | Legitimate interests (Art. 6(1)(f)) |
| Comply with legal obligations (accounting, tax) | Legal obligation (Art. 6(1)(c)) |
| Improve the Service, aggregate analytics | Legitimate interests (Art. 6(1)(f)) |
| Suggest your city at onboarding from device location (§3.5) | Consent (Art. 6(1)(a)) |
| Marketing communications (where applicable) | Consent or legitimate interests |
| Website analytics and advertising cookies/pixels | Consent (Art. 6(1)(a)) — see Cookie Policy |
4.2. As processor (End Customer data)
We process End Customer testimonial and consent data only on the Business’s instructions, to provide the Service (produce, subtitle, caption, and publish the testimonial to the Business’s channels). The lawful basis for collecting and publishing End Customer data is the responsibility of the Business (the controller), whose basis is the consent the End Customer gives through the Service.
5. AI processing
5.1. To provide the Service we use AI to (a) transcribe spoken testimonials into text and (b) generate captions and hashtags for posts.
5.2. Transcription is performed via a Whisper-family model provided by our sub-processor OpenRouter. The audio/text is processed to produce the transcription and is not used to train third-party models.
5.3. The subtitle text reproduces the End Customer’s own words verbatim. AI-generated captions and hashtags are separate content authored on the Business’s behalf and reviewed by the Business before publication.
6. Who we share personal data with
6.1. We do not sell personal data. We do not use it for advertising, we do not build profiles from it, and we do not enrich our own or anyone else’s datasets with it. This holds for all personal data we hold — yours, your End Customers’, and anything received from a connected platform.
6.2. We share personal data with the following categories of recipients:
Sub-processors (acting on our instructions):
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting and storage | Germany (EU) |
| Stripe | Payment processing | EU and US |
| Brevo | Transactional email | EU |
| OpenRouter (Whisper-family model) | Transcription and AI captions | US |
| Sentry | Error monitoring | EU and US |
| Firebase Cloud Messaging | Push notifications | US |
A current list of sub-processors is maintained and available on request. Social media platforms (when you publish): when you publish content, it is sent to the platforms you connected (Facebook, Instagram, TikTok, X, Pinterest, YouTube, LinkedIn). Your and your End Customers’ content becomes subject to those platforms’ own privacy policies once published.
Advertising and analytics partners (website only, subject to consent): where you consent, our website loads tracking pixels from advertising and analytics partners (e.g. Meta/Facebook, TikTok, LinkedIn, Google/YouTube). These partners act as independent controllers or joint controllers for the data collected through their pixels. See the Cookie Policy for the full list and their policies.
Legal and corporate: we may disclose data where required by law, to enforce our terms, to protect rights and safety, or in connection with a merger, acquisition, or sale of assets.
7. Connecting social accounts — sign-in, publishing, and results
For every piece of data we take from a social platform, this section says three things: what it is, why we need it, and where you see it in ciaopost. If a permission does not map to something you do or see in the app, we do not request it.
One thing comes before all of it: every testimonial ciaopost publishes carries the signed consent of the person who appears in it, captured in the app before anything is published (§3.2). No signature, no post.
There are two separate connections and they never mix. Signing in with a social account tells us who you are. Connecting an account for publishing lets us post the content you approve to that account, and read how those posts perform. One never implies the other: you can sign in without ever connecting a publishing account, and neither gives us access to the other’s data.
7.1. Signing in with Google, Facebook or LinkedIn. If you sign in this way instead of the email code, the platform sends us your email address and your name — nothing more.
| Sign-in with | What we receive | Why | Where you see it |
|---|---|---|---|
email, name (via openid, email, profile) | create and recognise your account | your ciaopost profile | |
email, name (via email, public_profile) | create and recognise your account | your ciaopost profile | |
email, name (via openid, profile, email) | create and recognise your account | your ciaopost profile |
Signing in gives us no access to your posts, your friends or connections, your Pages or channels, or anything you publish. Connecting an account to publish is a separate step (§7.3).
7.2. What we hold for a connected publishing account. The access and refresh tokens, the account or Page identifier, its display name, the result the platform returns for each post, and — for the posts ciaopost published for you — the engagement metrics the platform reports on them (likes, comments, shares, reach and views), which we show you in your ciaopost dashboard (§7.3). We read those metrics only for the posts we published for you — never your timeline, your followers, your audience, or anyone else’s content. Tokens are encrypted at rest. We publish through each platform’s official API — we never automate a browser, and we never use or see your password.
7.3. What each publishing permission is for. Three kinds of thing, and nothing else: publish the content you approve; connect the right account; prefill your profile from the account’s own name, category and location so you do not retype them. On some platforms we also read how your posts perform — reach, likes, comments and the like — but only for the posts we published for you, and only to show you the results in your ciaopost dashboard, so you can see how your testimonials are doing without opening every app one by one. We never read your timeline, your audience, or anyone else’s content.
| Platform | Permissions, and what each does | Where you see it | What we never take |
|---|---|---|---|
pages_manage_posts — publish your approved post, and read the Page’s name, category and location to prefill your profile. pages_read_engagement — read the likes, comments, shares and link clicks on the posts we published for you. read_insights — read the impressions and views on those same posts. | The post on your Page; your results in the ciaopost dashboard; your business name, category and location prefilled into your profile at setup | Your followers or their contacts, your messages, your feed, anyone else’s posts, any audience or demographic data | |
instagram_basic — identify the Instagram business account on your Page, so we know where to publish. instagram_content_publish — publish your approved post. instagram_manage_insights — read the impressions, saves and views on the posts we published for you. | The post on your account; your results in the dashboard | Your follower list, your direct messages, your existing posts, anyone else’s content | |
| TikTok | video.upload + video.publish — publish your approved video. video.list — read the likes, comments, shares and views on the videos we published for you. | The video on your account; your results in the dashboard | Your followers, your existing content, anyone else’s content, any audience data |
| X | tweet.write — publish your approved post. users.read — identify the connected account (its handle), so you can confirm which one you linked. tweet.read — read the likes, retweets, replies, views and impressions on the posts we published for you (not your timeline). | The post on your account; the account name at connect; your results in the dashboard | Your timeline or feed, your followers, your direct messages, anyone else’s posts |
pins:write — publish your approved pin. boards:read — list your boards so you can choose where to pin. pins:read — read the saves, impressions, views and outbound clicks on the pins we published for you. | The pin on your board; your board list while composing; your results in the dashboard | Your followers, your existing pins, anyone else’s content | |
| YouTube | youtube.upload — upload your approved video (a Short) to the channel you connect. | The Short on your channel | Your channel analytics, comments, subscribers, watch history, or your existing videos |
w_organization_social — publish your approved post to the Company Page. A read permission over the organisations you administer — list your Company Pages and read the connected one’s name and location, to identify where to publish and prefill your profile. | The post on your Company Page; your business name and location prefilled into your profile at setup | We post to the Company Page only, never as you personally (we do not request w_member_social); no connections, no member feed, no analytics |
Across every platform: ciaopost does not use any platform’s data for advertising, to build audiences, or to train models. Where a permission reads engagement, it reads only the aggregate metrics of the posts we published for you — never your followers, their contacts, your messages, or anyone else’s content. Where a permission lists something — your Pages, your boards, the organisations you administer — that is only so you can pick the destination.
7.4. Disconnecting, and revoking at the platform. You can disconnect any account in ciaopost at any time; we delete the tokens for it. Deleting the token ends our access: from that moment ciaopost cannot and does not access that platform on your behalf. You can also revoke our access from the platform’s own settings, which works whether or not you use ciaopost again:
| Platform | Where to revoke our access |
|---|---|
| Google / YouTube | https://security.google.com/settings/security/permissions |
| Facebook / Instagram | https://www.facebook.com/settings?tab=business_tools |
| TikTok | TikTok app → Settings and privacy → Security → Manage app permissions |
| https://www.linkedin.com/psettings/permitted-services | |
| X | https://x.com/settings/connected_apps |
| Pinterest → Settings → Security → Apps |
7.5. YouTube. ciaopost uses YouTube API Services. By connecting a YouTube channel you also agree to the YouTube Terms of Service (https://www.youtube.com/t/terms). Google’s handling of your data is governed by the Google Privacy Policy (https://policies.google.com/privacy). You can revoke ciaopost’s access to your Google data at any time at the Google security settings page (https://security.google.com/settings/security/permissions), and you can disconnect the channel inside ciaopost. We store YouTube data only for as long as needed to publish and report on what you asked us to publish, and we do not use it for advertising or to build audiences.
ciaopost’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
7.6. Meta. Where you connect a Facebook Page or Instagram professional account, we handle Platform Data under the Meta Platform Terms and Developer Policies. We use it only to publish the content you ask us to publish and to report the outcome back to you. To have the data we hold from a Meta connection deleted, disconnect the account in ciaopost — which deletes its tokens — or write to privacy@ciaopost.com with the account concerned, and we will delete it and confirm in writing. See also Section 10.
7.7. The platform’s own terms still apply to you. Each connected platform has its own terms, community rules, and privacy policy, and they govern your account and your published content there. We do not override them, and our Terms of Service do not grant you any right on a platform that the platform does not give you.
8. International data transfers
8.1. We are based in Switzerland. Some sub-processors and advertising partners are located outside Switzerland/the EU, including in the United States.
8.2. Where we transfer personal data outside Switzerland/the EEA, we rely on appropriate safeguards: Standard Contractual Clauses, and the Swiss-US and EU-US Data Privacy Framework where the recipient is certified under it. For transfers out of the United Kingdom we rely on the UK International Data Transfer Agreement or the UK Addendum to the Standard Contractual Clauses. For personal information provided from Japan to a third party in a foreign country, see §10.9. For disclosure of Australian personal information to overseas recipients, see §10.8.
8.3. A copy of the safeguard we rely on for any given recipient is available on request at privacy@ciaopost.com.
9. How long we keep personal data
| Data | Retention |
|---|---|
| Business account data | For the life of the account + 30 days after closure |
| Billing/invoice data | As required by law (ten years, Swiss accounting rules) |
| End Customer testimonials & consent records | Per the Business’s instructions; consent records kept as evidence for ten years |
| Connected-account tokens | Until you disconnect or close the account |
| Logs and technical data | 12 months |
| Fraud-prevention record (§3.4) | Retained beyond account deletion, for as long as needed to prevent abuse |
| Website analytics | Per the Cookie Policy |
When data is no longer needed, we delete or anonymise it, subject to legal retention obligations and the fraud-prevention exception above.
10. Your rights
10.1. Depending on your location and applicable law (GDPR/nLPD), you have the right to:
- access your personal data;
- rectify inaccurate data;
- erase your data (“right to be forgotten”), subject to legal exceptions and the fraud-prevention record;
- restrict or object to processing, including processing based on legitimate interests and direct marketing;
- data portability;
- withdraw consent at any time, where processing is based on consent (this does not affect prior processing);
- lodge a complaint with a supervisory authority (in Switzerland, the FDPIC; in the EU, your local data protection authority).
10.2. Business users may exercise these rights by contacting us at
privacy@ciaopost.com.10.3. End Customers should exercise rights over their testimonial by contacting the Business that collected it, because the Business is the controller of that data (§2). We will support the Business’s response as processor.
10.4. We respond within the timeframe required by law (generally one month under GDPR). We may need to verify your identity before acting.
10.5. We do not make you ask twice. The rights below are the ones your own law gives you. Where a right exists in one country and not another, we do not use that as a reason to refuse: write to privacy@ciaopost.com and we will do it. It is simpler for us to treat everyone the same way than to run six rulebooks.
10.6. United Kingdom
If you are in the UK, the UK GDPR and the Data Protection Act 2018 apply to you. Your rights are those in §10.1, and you may complain to the Information Commissioner’s Office (ICO), Wycliffe House, Water Lane, Wilmslow SK9 5AF — https://ico.org.uk/make-a-complaint/. Where we send personal data from the UK to a country without a UK adequacy decision, we rely on the UK International Data Transfer Agreement or the UK Addendum to the Standard Contractual Clauses.
10.7. United States
We do not sell personal information, and we never have.
Advertising and “sharing”. Under California law (CCPA/CPRA), letting an advertising platform set a pixel on our website counts as “sharing” for cross-context behavioural advertising, and you have the right to opt out of it. On this website that opt-out is already the default: no advertising or analytics pixel loads unless you allow it first, and until you do, nothing about your visit reaches Meta, TikTok, LinkedIn, Google, Pinterest, or X. You can change or withdraw that permission at any time with the cookie button in the bottom-left corner of every page. If your browser sends a Global Privacy Control signal, we treat it as a refusal and load nothing — you do not need to tell us twice.
Your rights. Depending on your state — California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon, Montana and others as they take effect — you have some or all of the rights to know what we collect and why, to access a copy, to correct it, to delete it, to opt out of sale, sharing, targeted advertising and profiling, to be free from discrimination for exercising any of them, and to appeal a refusal. Write to privacy@ciaopost.com. We do not process sensitive personal information for the purpose of inferring characteristics, and we do not knowingly collect or sell the data of anyone under 16.
Appeals. If we refuse a request, we will say why, and you may appeal by replying to that answer. We will respond to the appeal within the time your state’s law allows, and we will tell you how to complain to your Attorney General if you are still not satisfied.
10.8. Australia
If you are in Australia, the Privacy Act 1988 and the Australian Privacy Principles apply. You may ask for access to your personal information (APP 12) and for its correction (APP 13) at privacy@ciaopost.com. We disclose personal information to overseas recipients (APP 8) — our sub-processors in §6, principally in Switzerland, the EU and the United States — and we take reasonable steps to ensure they handle it consistently with the APPs. You may complain to us first at privacy@ciaopost.com; if you are not satisfied with our answer, you may complain to the Office of the Australian Information Commissioner (OAIC) — https://www.oaic.gov.au/privacy/privacy-complaints. We will notify you and the OAIC of an eligible data breach as required by the Notifiable Data Breaches scheme.
10.9. Japan
If you are in Japan, the Act on the Protection of Personal Information (APPI) applies. We use personal information for the purposes set out in §4 and for no other purpose without telling you. We provide personal information to third parties in a foreign country — our sub-processors in §6, in Switzerland, the EU and the United States — on the basis of your consent and having taken the measures the APPI requires of a provider of personal data to a foreign third party; the information in Article 28 about those countries and their recipients’ measures is available on request at
privacy@ciaopost.com. You may request disclosure, correction, suspension of use, or deletionof your retained personal data at privacy@ciaopost.com, and you may raise a complaint with the Personal Information Protection Commission (PPC) — https://www.ppc.go.jp/.
10.10. Representatives. Envestis SA is established in Switzerland and has no establishment in the EU or the UK. Where a representative is required for a market we serve, that appointment is made before we offer the Service there, and the current details are published in this Policy and available at privacy@ciaopost.com.
11. Security
11.1. We implement technical and organisational measures appropriate to the risk, including encryption of connected-account tokens at rest, access controls, and secure infrastructure.
11.2. No system is perfectly secure. We cannot guarantee absolute security, but we maintain measures designed to protect personal data and will notify you and the relevant authorities of a data breach where required by law.
12. Children
12.1. The Service is intended for businesses and adults. Business accounts require users to be at least 18.
12.2. The Business must not use the Service to capture testimonials from minors unless lawfully permitted with appropriate consent, and the Business is responsible for that compliance.
13. Changes to this Policy
We may update this Policy. We will post the updated version with a new date and, for material changes, provide notice by email and in-app notice.
14. Contact
Data controller: Envestis SA, Via Pretorio 13A, 6900 Lugano, Switzerland Business Identification Number (UID): CHE-339.253.743 Privacy contact: privacy@ciaopost.com Legal contact: legal@ciaopost.com