← Back to home

Privacy Policy

Effective date: June 25, 2026

1. Who We Are

Gai Engine ("Gai Engine", "we", "us", or "our") operates the platform available at https://gai-engine.vercel.app (the "Service"). The Service is an AI-powered social media management and business growth platform that allows users to connect their social media accounts, generate AI-assisted content, schedule and publish posts, manage leads, and analyze engagement across platforms including TikTok, Facebook, and Instagram.

This Privacy Policy explains what data we collect, why we collect it, how we use and protect it, and how you can request deletion of your data. By using the Service, you agree to this policy.

2. Data We Collect

2.1 Account Information

When you register, we collect your email address and a hashed password via our authentication provider (Supabase). We do not store plaintext passwords.

2.2 Business Information

You may provide your business name, website URL, industry, and other descriptive information to configure your workspace. This information is used to personalize AI-generated content and analytics.

2.3 Social Media Account Connections

When you connect a social media account (TikTok, Facebook, or Instagram), we receive an OAuth 2.0 access token issued by that platform. These tokens are encrypted at rest using AES-256-GCM encryption with a platform-specific key before being stored in our database. We never store tokens in plaintext.

The scopes we request from each platform are:

  • TikTok: user.info.basic, video.upload, video.publish — used solely to retrieve your display name, open ID, and to publish video content you have approved.
  • Facebook: pages_show_list, pages_read_engagement, pages_manage_metadata, business_management — used to identify and connect Pages you manage and to publish approved content to those Pages.
  • Instagram: instagram_basic, instagram_manage_comments, instagram_manage_messages — used to identify your connected Instagram Business Account and to publish approved image or video content.

We do not use these permissions to collect data about other users of those platforms. We do not build profiles or databases on any individuals beyond what is necessary to provide you with the Service.

2.4 Content You Create or Approve

We store content you create, generate with AI, or approve for publishing — including social media posts, captions, scripts, SEO pages, campaign assets, and lead notes. This content is stored in your workspace and may be committed to a private GitHub repository associated with your account for version history.

2.5 Lead and Prospect Data

If you enter leads, prospects, or referrals into the platform, we store the information you provide (such as names, contact details, source, and notes). You are responsible for ensuring you have the right to enter this data and that doing so complies with applicable law.

2.6 Analytics and Engagement Data

We retrieve and store post performance metrics and engagement data from connected social media platforms using the permissions you have granted. This data is used to generate analytics dashboards visible only to you.

2.7 AI Interactions

When you request AI-generated content (such as social posts, lead scores, or brand scans), your inputs and business context are sent to our AI provider (OpenAI). OpenAI's usage policies apply to data transmitted to their API. We do not use your data to train our own models. We store the AI-generated outputs in your workspace for review and approval before any publishing action is taken.

2.8 Usage and Log Data

Our hosting provider (Vercel) automatically collects standard server log data, including IP addresses, browser type, pages visited, and timestamps. This data is used for security, debugging, and service reliability purposes.

3. How We Use Your Data

  • To authenticate you and maintain your account and workspace.
  • To generate AI-assisted content based on your business information and instructions.
  • To publish content to your connected social media accounts when you explicitly approve and initiate a publish action.
  • To retrieve engagement analytics from your connected social accounts and display them to you.
  • To score and manage leads and prospects within your workspace.
  • To send scheduled jobs (content publishing, analytics refreshes, engagement monitoring) that you have configured.
  • To maintain an audit log of approval decisions for your records.
  • To communicate with you about your account, service updates, or security matters.

We do not sell your personal data. We do not use your data for advertising. We do not share your data with third parties except as described in Section 4.

4. Third-Party Services

We use the following third-party services to operate the platform:

  • Supabase — Database and authentication. Your data is stored in a Supabase PostgreSQL instance with row-level security policies. Supabase Privacy Policy.
  • Vercel — Hosting and edge infrastructure. Vercel Privacy Policy.
  • OpenAI — AI content generation. Inputs are sent to OpenAI's API to generate text and content. OpenAI Privacy Policy.
  • GitHub — Version control for approved content and operational workflows. Content you approve may be committed to a private repository. GitHub Privacy Statement.
  • TikTok — Social publishing. We use the TikTok Content Posting API to publish video content you have approved. TikTok's own privacy policy governs data on their platform. TikTok Privacy Policy.
  • Meta (Facebook / Instagram) — Social publishing. We use the Meta Graph API to publish content you have approved to your Pages and Instagram Business Account. Meta Privacy Policy.

5. TikTok Data Use Disclosure

In accordance with TikTok's Developer Terms of Service, we disclose the following regarding our use of TikTok API data:

  • We access TikTok data solely to provide the Service to you — specifically, to publish video content you have created and approved to your TikTok account.
  • We retrieve your TikTok display name and open ID for the purpose of identifying and displaying your connected account. This information is stored in your workspace only.
  • We do not collect, aggregate, or build profiles on any TikTok users other than the account owner who has explicitly authorized our application.
  • We do not share TikTok user data with third parties except as strictly necessary to operate the Service (e.g., storing your encrypted token in Supabase).
  • TikTok access tokens are encrypted at rest using AES-256-GCM and are never stored in plaintext.
  • You may revoke our access to your TikTok account at any time by disconnecting the integration in Settings or by revoking access in your TikTok account settings.

6. Meta Data Use Disclosure

In accordance with Meta's Platform Terms, we disclose the following regarding our use of Meta platform data:

  • We access Facebook Pages and Instagram Business Account data solely to publish content you have approved, and to display basic account information within your workspace.
  • We do not use Meta platform data for any purpose beyond the Service you have requested.
  • Meta access tokens are encrypted at rest using AES-256-GCM and are never stored in plaintext.
  • You may revoke access at any time through Settings or directly via your Facebook account settings.

7. Data Security

We implement technical, physical, and administrative safeguards to protect your data, including:

  • AES-256-GCM encryption for all OAuth access tokens stored at rest.
  • Row-level security (RLS) policies in our database ensuring users can only access their own workspace data.
  • HTTPS encryption for all data in transit.
  • HMAC-SHA256 webhook signature verification for all inbound webhook events.
  • Bearer token authentication on all automated worker endpoints.
  • Immutable approval audit logs to track all content approval decisions.

If we become aware of a security compromise, we will notify affected users promptly.

8. Data Retention

We retain your data for as long as your account is active. If you request deletion of your account, we will delete your personal data and workspace content within 30 days, except where we are required to retain it by law or for legitimate business purposes (such as fraud prevention or legal disputes). Encrypted access tokens are deleted immediately upon account deletion or integration disconnection.

9. Your Rights and Data Deletion

You have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data in your account settings.
  • Delete your account and all associated data.
  • Disconnect any social media integration at any time, which immediately invalidates our access to that account.
  • Export your workspace content by contacting us.

To request deletion of your data, email us at privacy@gai-engine.com with the subject line "Data Deletion Request" and your registered email address. We will process your request within 30 days.

10. Children's Privacy

The Service is intended for use by businesses and is not directed at children under 13. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected such data, we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy at this URL and updating the effective date. Continued use of the Service after changes constitutes acceptance of the updated policy.

12. Contact Us

For privacy-related questions, data access or deletion requests, or security concerns, contact us at:

HomeTerms of ServiceContact