Privacy policy
Last updated August 4, 2026
What we collect
We store account information provided by your login provider, content you create, connected social-account details, publishing activity, and payment and credit records. Payment funding details are handled by PayPal and are not stored by PageRain.
Sensitive data and how we protect it
We treat authentication credentials and the access and refresh tokens issued by connected platforms — X, Instagram, TikTok, YouTube, and 4i — as sensitive data, and protect them with the following mechanisms:
- Encryption in transit. All traffic to PageRain and to every provider we call runs over HTTPS/TLS. We never accept or transmit credentials over an unencrypted connection.
- Encryption at rest. Every OAuth access and refresh token is encrypted with AES-256-GCM before it is written to our database, using a key held in the application's secret configuration and never stored alongside the data. Our database and media storage are additionally encrypted at rest by the hosting platform.
- No credential handling. We never see or store your password for any connected platform, or your PayPal funding details. Authorization happens on the provider's own site and returns only a token.
- Least privilege. We request the narrowest scopes each feature needs, and tokens are decrypted only in memory, at the moment a publish or account lookup you asked for is carried out.
- Access control. Every private endpoint requires a valid session, and artist data is reachable only by the workspace owner and the members they have granted access. Administrative access to production systems is restricted to authorized personnel and used only to operate and support the service.
- Deletion. Disconnecting a platform deletes that connection record, including its stored tokens, from our database. Deleting your account deletes your connections, posts, and uploaded media.
Google user data
When you connect a YouTube channel, PageRain requests the youtube.upload and youtube.readonly scopes so it can identify the channel you connected and upload the videos you schedule. We do not read your viewing history, subscriptions, comments, or analytics. PageRain's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is never sold, never used for advertising, and never used to train AI models. You can revoke PageRain's access at any time from the artist's social connections page or at myaccount.google.com/permissions. Use of YouTube features is also subject to the YouTube Terms of Service and the Google Privacy Policy.
How we use it
We use this information to provide the service, authenticate you, generate requested AI content, publish content you approve, process credit purchases, prevent abuse, and maintain PageRain.
Service providers
We use providers for hosting, authentication, AI generation, payments, and social publishing. We share information only as needed to provide those functions. Content sent to X is also subject to X’s policies.
Retention and deletion
We retain account data while your account is active and as needed for legal, security, and accounting obligations. You can permanently delete your account and owned content from Account Settings, or at any time from pagerain.com/data-deletion. After deletion we keep one irreversible hash of your email address, with no other personal data attached, solely to record that the one-time signup credits have already been issued.
Your choices
You may request access, correction, or deletion of your personal information. You can disconnect social accounts or delete your PageRain account at any time.
Contact
For privacy questions or requests, email support@pagerain.com.