Legal
Privacy Policy
Last updated pending incorporation
This policy explains how Robin ("Robin", "we", "us") collects and uses personal data when you use our website and service. We are the data controller for the purposes of UK data protection law (UK GDPR and the Data Protection Act 2018). Our ICO registration will be confirmed before launch.
1.Who this applies to
This policy covers our customers (UK business owners who sign up to Robin) and visitors to our website. Where Robin posts on your behalf to your own social accounts, you remain the controller of your audience's data on those platforms; we act as your processor for that activity.
2.What we collect
- Account details, your name, business name, email, mobile number, town, and website.
- Connected channel data, when you connect Instagram, Facebook or Google Business Profile, we store the access token the platform gives us and the page, account and location details that come with it, so Robin can publish on your behalf. We do not read the posts already on your accounts, and we never ask for or store your platform passwords.
- Photos and content, images you upload or send to us by WhatsApp, and the captions and posts Robin drafts for you.
- WhatsApp messages, photos and short messages you send to our WhatsApp number, processed to add images to your photo pool.
- Payment data, handled by Stripe. We receive your Stripe customer and subscription ids, whether the subscription is active, and which plan you are on. We never see or store any part of your card number.
- Usage data, page views and a small number of product events through Vercel Analytics, and error reports and request timings through Sentry, so we can keep the product working and improve it.
3.Why we use it, and our lawful basis
- To provide the service (drafting, scheduling and publishing your posts), performance of our contract with you.
- To learn and refine your brand voice, performance of our contract, and our legitimate interest in improving output quality.
- To take payment and prevent fraud, performance of our contract and our legitimate interests.
- To send service messages (your Monday approval link, billing notices), performance of our contract.
- To send marketing, where you have opted in, your consent, which you can withdraw at any time.
4.Who we share it with
We use a small number of trusted processors, each under a data processing agreement:
- Meta Platforms, to list the pages you manage and to publish to your connected Instagram and Facebook accounts via the Graph API.
- Google, to publish to your Google Business Profile.
- Stripe, payment processing.
- Twilio, WhatsApp messaging.
- Anthropic, the AI model that drafts your captions. Content sent for drafting is not used to train their models.
- Sentry, error reporting and performance monitoring for the app itself.
- Supabase, to store your data, and Vercel, to host and serve the app and to provide the usage analytics above, within the UK/EU where possible.
We do not sell your personal data, and we never share it outside the relationship you have with us.
5.How long we keep it
We keep your account and content data for as long as you are a customer, and for a short period afterwards so you can reactivate. When you close your account we delete or anonymise your personal data within 30 days, except where we must keep limited records (for example billing records for tax purposes) for as long as the law requires.
6.Your rights
Under UK GDPR you have the right to access, correct, delete, restrict or object to our use of your data, and to data portability. You can exercise any of these at any time:
- by emailing our contact address (to be confirmed before launch), or
- via our data deletion request page.
You also have the right to complain to the Information Commissioner's Office (ico.org.uk) if you are unhappy with how we have handled your data.
7.Security and international transfers
We protect your data with encryption in transit and at rest, access controls, and the privacy-by-design measures built into the product. Where data is transferred outside the UK (for example to a US-based processor), we rely on appropriate safeguards such as the UK International Data Transfer Agreement or adequacy regulations.
8.Changes
We will update this policy as the product develops and will tell you about material changes before they take effect.
Questions about this document? Email our contact address (to be confirmed before launch) or write to Robin, to be confirmed before launch, United Kingdom.