OwlKonnectPrivacy Policy
Last updated: June 10, 2026
1. Introduction
OwlKonnect ("we", "our", or "us") is a social media management and scheduling platform that helps small businesses create, schedule, and publish content across multiple social media platforms, including Facebook, Instagram, Google Business Profile (GBP), YouTube, LinkedIn, Pinterest, Threads, Telegram, and X (Twitter).
This Privacy Policy explains what data we collect, how we use it, how we protect it, and your rights regarding your data. By using OwlKonnect, you agree to the practices described in this policy.
2. Information We Collect
When you use OwlKonnect, we collect only the minimum data necessary to provide the service.
Account Information
- Your name and email address (used to create and manage your OwlKonnect account)
- Password (stored as a hashed value — we never store plaintext passwords)
Connected Social Account Data
When you connect a social media account, we collect:
- Account identifier (user ID, page ID, channel ID, etc.)
- Account display name and profile picture URL
- OAuth access tokens and refresh tokens required to act on your behalf
- Platform-specific metadata needed to display your account within OwlKonnect
Content You Create
- Posts, captions, images, and videos you create or upload through OwlKonnect
- Scheduling details (date, time, target accounts)
- Publishing history
3. How We Use Your Information
We use the data we collect solely to provide and improve the OwlKonnect service:
- Authenticate your identity and maintain your session
- Display your connected social accounts within OwlKonnect
- Publish or schedule content to your connected accounts only when you explicitly request it
- Maintain a history of content published through OwlKonnect
- Send transactional notifications (post status, errors)
We do not sell, rent, share, or use your data for advertising or marketing purposes. We do not use your data to train machine learning models.
4. Google API Services — User Data Policy
Google Business Profile (GBP)
When you connect your Google Business Profile, we request the https://www.googleapis.com/auth/business.manage scope. This allows OwlKonnect to:
- Retrieve the list of business locations you manage, so you can select which location to post to
- Publish posts (updates, offers, events) to your Google Business Profile listing on your behalf
We do not read, store, or use any GBP data beyond what is required to display your locations and publish the content you create. GBP access tokens are stored securely and used only when you initiate a publishing action.
YouTube
When you connect your YouTube channel, we request the following scopes:
https://www.googleapis.com/auth/youtube.upload — to upload videos to your YouTube channel on your behalf when you publish or schedule a video through OwlKonnect.https://www.googleapis.com/auth/youtube.readonly — to read your YouTube channel's name and ID at connect time, so we can identify and display the connected channel within OwlKonnect.
We do not access your YouTube watch history, subscriptions, playlists, comments, likes, or any data unrelated to the videos you publish through OwlKonnect.
OwlKonnect's use of YouTube API Services is also subject to the YouTube Terms of Service and the Google Privacy Policy.
Google Sign-In Scopes
We also request openid, userinfo.email, and userinfo.profile to identify the Google account being connected and display your name and profile picture within OwlKonnect.
Cross-Account Protection (RISC)
OwlKonnect implements Google's Cross-Account Protection (Risk and Incident Sharing and Coordination) service. This means Google may notify us when a security event occurs on your Google account (such as a password change or account compromise). When we receive such a notification, we will suspend access to your connected Google accounts and prompt you to reconnect to ensure your account remains secure.
Google Data — Limited Use
We confirm that data received from Google APIs is:
- Used only to provide the scheduling and publishing features of OwlKonnect
- Not transferred to third parties except as necessary to provide the service (e.g., our hosting infrastructure)
- Not used for serving advertisements
- Not used for any purpose that is not disclosed in this privacy policy
- Not sold or used to determine creditworthiness
5. Meta (Facebook & Instagram) Permissions
When you connect a Facebook Page or Instagram Business account, we request the following permissions. Each is used only to power the feature described next to it:
- pages_show_list — To list the Facebook Pages you manage so you can choose which page to post to
- pages_manage_posts — To publish and schedule posts to your Facebook Pages on your behalf
- pages_read_engagement — To read basic page info and the comments on your posts so you can moderate them
- pages_read_user_content — To read the comments people leave on your Page’s posts inside the Engagement inbox
- pages_manage_engagement — To reply to, hide, and delete comments on your Page’s posts
- read_insights — To show your Page and post analytics (reach, impressions, engagement) in the Analytics dashboard
- pages_messaging / pages_manage_metadata — To receive and reply to messages in the unified Inbox (only when you enable it)
- business_management — To verify the Pages and accounts belong to your business during connection
- instagram_basic / instagram_business_basic — To access the Instagram Business account you connect
- instagram_content_publish / instagram_business_content_publish — To publish photos, videos, reels, and stories to your Instagram Business account
- instagram_business_manage_comments — To read, reply to, hide, and delete comments on your Instagram posts
- instagram_business_manage_insights — To show your Instagram account and post analytics in the Analytics dashboard
We do not post to your personal profile, and we never access data beyond what is listed above. Messages are accessed only if you turn on the Inbox feature.
5a. Threads Permissions
When you connect a Threads account, we request the following permissions:
- threads_basic — To identify the Threads account you connect
- threads_content_publish — To publish and schedule threads (text, image, video, and carousel posts) and to post your replies
- threads_delete — To delete a thread you published from inside OwlKonnect
- threads_read_replies — To read the replies on your threads inside the Engagement inbox
- threads_manage_replies — To hide and unhide replies on your threads
- threads_manage_insights — To show your Threads account and post analytics in the Analytics dashboard
6. LinkedIn
When you connect your LinkedIn account, we request permissions to publish posts to your LinkedIn profile or company page on your behalf. We access only your LinkedIn account identifier, display name, and the ability to create posts. We do not access your LinkedIn messages, connections, or any other personal data.
7. Other Platforms (Pinterest, Telegram, X, Bluesky, Mastodon)
For other platforms you choose to connect, we collect only the minimum data required: an account identifier, display name, and the access credentials needed to publish content on your behalf. We do not access data beyond what is necessary for scheduling and publishing.
8. Data Storage & Security
All data is stored on secured servers. We implement industry-standard security measures including:
- Encrypted database storage for access tokens and sensitive data
- HTTPS-only access to all OwlKonnect pages and APIs
- Access controls limiting data access to authorized personnel only
Access tokens are used exclusively to perform actions you explicitly initiate within OwlKonnect and are never exposed to other users.
9. Data Retention & Deletion
We retain your data for as long as your OwlKonnect account is active. You can:
- Disconnect any social account at any time from the Social Channels page — this immediately deletes the stored access tokens for that account
- Delete your OwlKonnect account by contacting us at [email protected] — all your data will be permanently deleted within 30 days
- Revoke Google access at any time via Google Account Permissions
- Revoke Facebook or Threads access at any time via Facebook App Settings or your Threads account’s connected-apps settings
- Automatic deletion on app removal — When you remove OwlKonnect from your Facebook, Instagram, or Threads settings, Meta notifies us through our deauthorize and data-deletion callbacks and we automatically disconnect and delete the stored data for that account. You can also submit a deletion request directly to [email protected].
10. Your Rights
You have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data
- Disconnect any or all connected social accounts at any time
- Withdraw consent for data processing at any time
To exercise any of these rights, contact us at [email protected].
11. Third-Party Services
OwlKonnect integrates with the following third-party platforms. Your use of these integrations is also subject to their respective privacy policies:
12. Children's Privacy
OwlKonnect is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page and notify you of significant changes by posting a notice within the OwlKonnect application.