Privacy
Privacy Policy
A global privacy notice for Promeo’s website, creation studio, generated library, business accounts, connected publishing channels, scheduling workflow, support, and security activity.
Effective date: 17 September 2026
This Privacy Policy explains how Alcaeus Development AB collects and uses personal data when a business representative visits or uses Promeo, a hosted service for generating marketing content and scheduling and submitting approved content to TikTok, Instagram, Threads, YouTube, managed Facebook Pages, Bluesky, LinkedIn, Discord, Mastodon, Telegram, X, and Pinterest.
1. Who is responsible
For account administration, service operation, security, support, and our own legal obligations, the data controller is:
Alcaeus Development AB
Registration number: 559461-9727
Fjällbrudens väg 11
132 45 Saltsjö-Boo, Sweden
Privacy contact: noel@alcaeus.app
When a business uploads content containing personal data and instructs Promeo to process it for a scheduled post, that business is normally the controller and Alcaeus acts as its processor or service provider. People appearing in a customer's post should contact that business first about the content. We will assist the business where required.
TikTok, Meta, Google, Bluesky, LinkedIn, Discord, Telegram, X, Pinterest, and the operator of each selected Mastodon server independently determine how they process data after a user connects an account or channel or content is submitted. Each platform provider or Mastodon server operator is an independent controller for that processing.
2. Scope
This policy applies to Promeo's website, business accounts, AI-assisted creation studio, generated-content library, social-platform connections, scheduling workflow, support, and related security and operational activity.
The public workspace supports uploaded or AI-generated persona portraits, persona scene variations and generic marketing images, manual post preparation, approved publishing and scheduling, API/MCP access, and available post analytics. Standalone four-slide generation and automated publishing campaigns are not part of the current public workspace.
It does not govern TikTok, Meta, Google/Firebase, Bluesky, LinkedIn, Discord, Telegram, X, Pinterest, a Mastodon server operator, Bunny, Replicate, a model provider, or another third party acting for its own purposes. Their own privacy notices apply to their independent processing.
Promeo is intended only for businesses represented by adults. It is not directed to children or to personal or household users.
3. Personal data we process
Account and business data
We may process:
- workspace name and account status;
- the representative's name and email address;
- Firebase user identifier, authentication provider, email-verification state, and sign-in timestamps;
- IP address, user-agent and browser information, device and session information, and security events; and
- communications, support requests, and privacy requests.
Firebase Authentication manages authentication credentials. Depending on the sign-in method, Firebase may process passwords, email addresses, phone numbers, provider identifiers, IP addresses, and user-agent information. Alcaeus does not receive a readable copy of a Firebase-managed password.
Social-platform connection data
When the representative connects TikTok, Instagram, Threads, YouTube, a managed Facebook Page, Bluesky, LinkedIn, Discord, Mastodon, Telegram, X, or Pinterest, we may process:
- platform account identifier, username, display name, and profile image;
- the Promeo Project to which each platform connection belongs;
- granted scopes and permission state;
- access and refresh tokens and their expiry;
- Discord installer, server and channel identifiers, granted permissions and bot appearance; legacy webhook identifiers and encrypted webhook tokens where applicable; a Pinterest board identifier; a Mastodon server domain and encrypted OAuth application credentials, or a Telegram channel identifier and the bot's posting-permission state, where applicable;
- creator settings and available privacy and interaction options;
- post, comment and reply identifiers, processing status, and failure information;
- available post-performance figures, such as views, likes, comments, and shares; and
- connection, disconnection, and token-refresh events.
We request only the permissions needed to connect the authorised account or channel, present applicable posting controls, submit approved content, and report status and performance. These include TikTok video.publish, Instagram business basic, content publishing and instagram_business_manage_comments for the account’s own approved comments, Threads threads_basic, threads_content_publish, and threads_manage_insights for post performance analytics, YouTube upload and read-only permissions, Facebook pages_show_list, pages_read_engagement and pages_manage_posts for managed Pages, pages_manage_engagement for Page-authored comments, pages_read_user_content as Meta’s review dependency for that comment permission, and read_insights for available Page post views, plus business_management to discover owned and client-managed Pages in approved Business portfolios, AT Protocol permissions used to maintain the authorised Bluesky session and create posts, LinkedIn openid, profile, and w_member_social for the connected member profile, Discord authorization to identify the installer and install the Promeo bot with required server/channel publishing permissions, Mastodon read:accounts, write:media, and write:statuses, Telegram channel-administrator permission for the Promeo bot to post messages, X profile/posting/media-upload and offline refresh access, and Pinterest account/board reading and Pin publishing access. Promeo does not retrieve visitor-authored Facebook posts, comments or ratings and does not request Threads reply-moderation access. Its Threads publishing permission also supports approved replies to the connected account’s own posts. Promeo does not request LinkedIn organisation-Page publishing permissions at launch.
Post and scheduling data
We may process:
- uploaded photos, captions, hashtags, and cover or ordering choices;
- proposed posting date, time, time zone, and status;
- privacy, interaction, music, commercial-content, own-brand, and branded-content choices;
- optional user-authored comments or replies, their destination-specific settings and delivery delays;
- preview and express-approval records;
- submission attempts, platform responses, errors, and cancellation information; and
- technical metadata associated with uploaded files.
Uploaded media may contain images, voices, names, likenesses, or other personal data about employees, creators, customers, or other people. The business that uploads the media is responsible for having a valid legal basis, giving required notices, and obtaining necessary rights and consent.
Creation-studio and library data
When the representative uses the creation studio, we may process:
- Project records containing names, descriptions, audiences, allowed features, and voice direction;
- persona names, descriptions, scene instructions, topics, parent-persona relationships, source-Project relationships, and other prompts;
- customer-uploaded persona portraits, persona variations, generic images, filenames, file types, file sizes, and image dimensions;
- optional generated reference images selected from the Customer's library;
- generated persona portraits, generic images, slideshow copy, captions, and rendered slides;
- generation type, model and provider identifiers, source-asset relationships, status, errors, timestamps, and expiry; and
- the Customer's decisions to open, delete, or copy generated results into a posting draft.
Creation-studio inputs, customer uploads, and generated outputs may contain personal data, confidential information, trademarks, or likenesses. The Customer decides what to submit and is responsible for having a valid basis and all necessary rights and notices. These disclosures and Promeo's Terms explain that requested generation inputs and selected references are sent to Replicate; images uploaded directly into the library are stored by Promeo and are not sent to Replicate unless the Customer later selects one as a generation reference.
Essential website data
Promeo uses only storage and similar technologies needed for authentication, security, session continuity, load balancing, and user preferences at launch. We do not currently use advertising cookies or optional analytics cookies.
If we later introduce non-essential analytics or advertising technology, we will update this policy and provide consent or opt-out controls where required before using it.
4. Where the data comes from
We receive personal data:
- directly from the business representative during registration, upload, scheduling, approval, support, or privacy requests;
- directly from the representative through Project information, library uploads, generation prompts, and reference selections;
- from Replicate and the selected model when they return generation status and output;
- from TikTok, Meta, Google, Bluesky, LinkedIn, Discord, Telegram, X, Pinterest, or the selected Mastodon server when the representative authorises or verifies a platform connection or Promeo checks posting capabilities, status, and available post-performance figures;
- from Firebase when it authenticates and secures the account;
- automatically from the representative's browser, device, and use of Promeo; and
- from the business that uploads media concerning other people.
We do not obtain data from data brokers.
5. Why we use personal data
| Purpose | Data generally used | Legal basis where GDPR-style law applies | Is it required? |
|---|---|---|---|
| Create and authenticate the business account | Account identifiers, email, verification, session and security data | Performance of the agreement with the Customer and our legitimate interest in secure access | Yes. Promeo cannot provide an account without it. |
| Upload, generate, and store requested marketing content | Customer-uploaded library images, prompts, Project and audience information, selected reference media, provider status, and outputs | Performance of the agreement and the Customer's instructions; consent where separately required for a third person's sensitive data | The selected image is required for an upload; the requested prompt and reference are required for generation. Promeo cannot create or store the requested library item without the applicable input. |
| Connect and maintain authorised social-platform accounts for a Project | Project association, platform and Page identifiers, scopes, tokens, connection events | Performance of the agreement and the user's authorised request | At least one destination connection is required for scheduling. Without a selected connection, Promeo cannot submit a post. |
| Prepare, schedule, and submit approved posts | Media, captions, settings, schedules, approvals, publish status | Performance of the agreement; processing on the Customer's instructions where Alcaeus acts as processor | Yes for each scheduled post. Omitted settings or media may prevent submission. |
| Display posting controls and report results | Creator settings, privacy options, status and errors | Performance of the agreement and compliance with selected-platform requirements | Yes for publishing and status reporting. |
| Display post-performance and audience analytics | Post identifiers, available views, likes, comments, and shares, and current follower, subscriber, or channel-member totals returned by connected platforms | Performance of the agreement and the user's request to view the results of authorised publishing | Optional. The publishing workflow remains available without opening Analytics. |
| Secure and troubleshoot Promeo | IP address, user agent, logs, failures, account and session events | Our legitimate interests in preventing abuse, maintaining reliability, and protecting users and systems | Collected automatically. Blocking essential security data may prevent use. |
| Provide support and communicate about the Service | Contact details, messages, relevant account and post information | Performance of the agreement and our legitimate interests in customer support | Optional, but we may be unable to answer without relevant information. |
| Establish, exercise, or defend legal claims and comply with law | Relevant account, transaction, communication, security, and content records | Legal obligation and legitimate interests in protecting legal rights | Required where applicable. |
Where we rely on legitimate interests, we consider whether the processing is necessary and balance our interests against the individual's rights. Where local law requires consent for a particular activity, we will request it separately and it may be withdrawn prospectively.
We do not use personal data to make decisions producing legal or similarly significant effects about business representatives. Each selected platform may independently moderate or restrict content and accounts under its own rules.
6. How media is transferred for generation and publishing
Selected platform APIs retrieve approved media from a public URL. For this purpose, Promeo may temporarily upload approved media to Bunny storage and expose it through a hard-to-guess public URL.
Anyone who obtains that URL may technically be able to access the file while it remains active. Customers must not upload unnecessary sensitive or confidential material. Promeo removes the temporary copy according to the retention periods below after the selected platforms complete retrieval, the post reaches a final failure, or the schedule is cancelled.
Customer-uploaded library images and generated images are also stored through hard-to-guess Bunny URLs so that the Customer can preview and reuse them and, when the Customer selects an item as a generation reference, Replicate can retrieve it. These URLs remain active for the library retention period unless the Customer deletes the item or closes the account sooner.
When the Customer requests a generation, Promeo sends the applicable prompt, settings, and selected reference URL to Replicate. Replicate and the selected model process that information to produce the requested output. Replicate states that API prediction inputs, outputs, output files, and logs are removed after approximately one hour by default. Promeo copies completed output to Bunny before that provider copy expires so the Customer can review and use it.
Each selected platform receives the approved content, caption, applicable settings, and related submission information when Promeo submits the post. TikTok, Meta, Google, Bluesky, LinkedIn, Discord, Telegram, X, Pinterest, and the selected Mastodon server then process that information under their own privacy policies and platform or server terms.
YouTube API Services
Promeo uses YouTube API Services to identify the authorised YouTube channel, upload approved videos, and display available performance statistics for those uploads. Google's processing is governed by the Google Privacy Policy, and the Customer can review or remove Promeo's Google access in Google's security settings.
Disconnecting YouTube in Promeo removes the stored connection and asks Google to revoke the token. Promeo deletes YouTube authorised data as soon as practicable and no later than 7 calendar days after the Customer disconnects or revokes access, closes the Promeo account, requests deletion, or the token can no longer be refreshed. This YouTube-specific deletion period overrides any longer general retention period below. Deleting Promeo-held data does not delete videos or other data already stored by YouTube; the Customer must manage those items in YouTube.
Meta Platform services
Promeo uses Meta Platform services to identify Facebook Pages, Instagram professional accounts, and Threads profiles that the Customer is authorised to manage; publish Customer-approved content; report submission status; and display available performance statistics. Promeo uses Meta data only to provide these user-requested features and does not use it for advertising, surveillance, or unrelated profiling. Meta's independent processing is described in the Meta Privacy Policy.
The Customer may disconnect each Instagram, Threads, or Facebook Page connection in Promeo. The Customer may also remove Promeo through Facebook's Business Integrations settings or the applicable Instagram or Threads settings. On notice that access has been removed, or when the Customer requests account deletion, Promeo revokes the authorisation where supported and promptly deletes the associated Meta access tokens and Promeo-held profile, Page, permission, and connection data, subject only to the backup, security, and legal exceptions in Section 9. Disconnecting or deleting Promeo data does not delete posts or other data already stored by Meta; the Customer must manage that material on the relevant Meta service.
TikTok services
Promeo uses TikTok for Business Accounts API data only to identify the authorised creator, display TikTok-supplied posting choices, submit expressly approved content, and report its status and available performance statistics. TikTok's independent processing is described in the TikTok Privacy Policy.
The Customer may disconnect TikTok in Promeo or remove Promeo in the applicable TikTok account settings. Promeo then revokes access where supported and promptly deletes the associated TikTok tokens and Promeo-held connection data, subject only to the backup, security, and legal exceptions in Section 9. Content already submitted to TikTok must be managed on TikTok.
7. Service providers and other recipients
We disclose personal data only as needed for the purposes described in this policy.
| Recipient | Role and purpose | Data involved |
|---|---|---|
| Google/Firebase | Processor providing Firebase Authentication, Cloud Functions, App Hosting, Google Cloud SQL, and associated security and infrastructure | Account, authentication, schedule, post metadata, logs, and operational data as configured |
| Bunny | Processor providing storage and hard-to-guess public delivery of generated and approved post media | Uploaded and generated media, object paths, and technical request data |
| Replicate and selected model providers | Providers processing prompts, settings, and optional reference media to generate the requested images and slideshow copy | Generation prompts, Project and audience information, reference URLs and media, outputs, prediction identifiers, logs, and technical metadata |
| TikTok | Independent platform and controller receiving authorised content through the TikTok for Business Accounts API | TikTok connection data, approved media, captions, settings, schedules when submitted, publish status, and available post-performance figures |
| Meta (Instagram, Threads, and Facebook) | Independent platform provider and controller receiving authorised content through the Instagram, Threads, and Facebook Pages APIs | Instagram, Threads, and Facebook Page connection data, approved media, captions, schedules when submitted, publish identifiers or errors, and available post-performance figures |
| Google/YouTube | Independent platform provider and controller receiving authorised content through YouTube Data API v3 | YouTube channel and connection data, rendered approved videos, titles, captions, upload identifiers, status or errors, and available post-performance figures |
| Bluesky | Independent platform provider and controller receiving authorised content through AT Protocol APIs | Bluesky identifiers, profile data, encrypted OAuth session material, approved media, captions, repository record identifiers or errors, and available post-performance figures |
| Independent platform provider and controller receiving authorised content through LinkedIn member and publishing APIs | LinkedIn member identifier, profile data, encrypted OAuth credentials, approved text or media, and post identifiers or errors | |
| Discord | Independent platform provider and controller receiving authorised content through the Promeo bot or an existing webhook connection | Installer, server and channel identifiers, OAuth permissions and credentials, bot appearance, legacy webhook credentials where applicable, approved content, and message identifiers or errors |
| X | Independent platform provider and controller receiving authorised posts | Connected profile information, OAuth credentials, approved content/media, and post identifiers or errors |
| Independent platform provider and controller receiving authorised Pins | Connected account and board information, OAuth credentials, approved media/captions/links, and Pin identifiers or errors | |
| Selected Mastodon server operator | Independent server operator and controller receiving authorised content through Mastodon APIs | Server domain, Mastodon account and profile data, encrypted OAuth credentials, approved text or media, and status identifiers or errors |
| Telegram | Independent platform provider and controller receiving authorised content through the Telegram Bot API | Telegram channel identifiers and profile data, approved text or media, and message identifiers or errors |
| Professional advisers and technical contractors | Confidential support, security, legal, accounting, and incident response where necessary | Only the data reasonably needed for the task |
| Authorities, courts, and transaction parties | Legal compliance, protection of rights, or a corporate transaction subject to appropriate safeguards | Relevant data required by law or due diligence |
We require processors to protect personal data and process it only under appropriate instructions and contractual safeguards.
We do not sell personal data. We do not share personal data for cross-context behavioural advertising or targeted advertising, and we do not disclose it to data brokers.
Alcaeus does not train or fine-tune its own artificial-intelligence models using Customer Content and does not initiate training jobs with Customer Content. Replicate and selected model providers process generation inputs and outputs under their applicable terms and privacy commitments. We do not use personal data for unrelated profiling.
8. International transfers
Alcaeus is established in Sweden, but providers may process personal data in other countries.
Firebase Authentication processes data in the United States. Google states that Firebase Authentication uses data such as email addresses, passwords, phone numbers, user agents, and IP addresses for authentication, security, and abuse prevention. More information is available in Firebase's Privacy and Security documentation.
TikTok, Meta, Google, Bluesky, LinkedIn, Bunny, Firebase, Replicate, selected model providers, and their subprocessors may process data outside the country where the business representative is located. When transfer restrictions apply, we use or rely on appropriate mechanisms such as:
- an adequacy decision or recognised data-protection framework;
- approved standard contractual clauses or equivalent contractual safeguards; or
- another transfer mechanism permitted by applicable law.
Individuals may contact noel@alcaeus.app for information about the safeguards relevant to their data.
9. Retention
We keep personal data only for as long as needed for the stated purpose, including to provide the Service, meet legal obligations, resolve disputes, and protect the Service.
| Data | Normal retention |
|---|---|
| Project records, including Project name, description, audience, allowed features, and voice | For the account lifetime or until the Customer deletes the Project; Promeo-controlled active copies are then deleted promptly and backups expire as described below |
| Creation prompts, persona and Project relationships, library metadata, customer-uploaded library images, and generated images or slides | 30 days after upload or generation, or sooner when the Customer deletes the library item, deletes its parent Project, or closes the account |
| Replicate API prediction inputs, outputs, files, and logs | Replicate states that these are removed after approximately 1 hour by default for API predictions |
| Uploaded post media | Retained through the scheduled submission and deleted within 7 days after every selected platform reports completion or final failure, or after the schedule is cancelled |
| Captions, schedules, approval records, settings, publish identifiers, and status history | 12 months after the scheduled posting time, except provider-derived data removed earlier in response to a valid deletion or revocation request |
| Instagram and Threads data subject to a provider deletion or deauthorization request | Connections, profile data, credentials and associated provider identifiers in post/comment history are removed through background cleanup; the confirmation page reports completion only after cleanup and a final check for in-flight work finish |
| Meta deletion confirmation receipts and unused hashes that prevent old authorizations from restoring deleted data | 90 days after completion; receipts contain no account name, raw provider account identifier or access token |
| Post-performance and audience figures requested in Analytics | Retrieved from the relevant platform when Analytics is opened and not stored as a separate Promeo analytics history at launch |
| Social-platform access and refresh tokens, and associated platform profile, Page, permission, and connection data | Until the relevant connection is disconnected, access is revoked at the provider, deletion is requested, or the Promeo account is closed; then promptly revoked where supported and removed from Promeo-controlled systems, subject to the backup, security, and legal exceptions below |
| YouTube authorised data, including channel data, credentials, upload identifiers, and related API status | Until required for the authorised feature, then deleted as soon as practicable and within 7 calendar days after access is revoked or disconnected, the Promeo account is closed, the Customer requests deletion, or authorisation can no longer be refreshed |
| Active business account and representative data | For the account lifetime; Promeo-controlled active copies are deleted within 30 days after account closure |
| Security and operational logs | 90 days, unless needed longer to investigate an active security incident, abuse, or legal claim |
| Support correspondence | 2 years after the support matter closes |
| Promeo-controlled backups | Expire within 30 days after deletion from active systems |
| Data needed for legal claims or statutory obligations | For the applicable limitation or legally required period, then deleted or anonymised |
Google states that Firebase Authentication keeps logged IP addresses for a few weeks and retains other authentication information until the Firebase customer initiates deletion of the user. Google may take up to 180 days after that deletion request to remove Firebase Authentication information from its live and backup systems. This provider-controlled period may therefore extend beyond Promeo's 30-day active-system deletion target.
If a submission is still processing or its outcome is uncertain, temporary media may be retained beyond the normal period only as long as reasonably necessary to prevent a failed transfer, investigate the outcome, or permit safe cleanup.
We may retain anonymised or aggregated information that can no longer reasonably identify an individual.
10. Security
We use reasonable technical and organisational measures designed to protect personal data, including access controls, encrypted network connections, provider security features, logging, least-privilege practices, and procedures for handling incidents and deletion.
No online service can guarantee absolute security. Customers must protect their Firebase and connected-platform credentials, use secure devices, promptly remove access from former representatives, and notify us of suspected compromise.
If a personal-data breach occurs, we will investigate and notify affected customers, individuals, platform providers, or authorities when required by applicable law or our contractual obligations.
11. Privacy choices and rights
Depending on location and applicable law, an individual may have the right to:
- know whether and how we process personal data;
- access or receive a copy of personal data;
- correct inaccurate or incomplete data;
- delete personal data;
- restrict or object to processing;
- receive portable data in a commonly used format;
- withdraw consent without affecting earlier lawful processing;
- opt out of sale, sharing, targeted advertising, or certain profiling;
- appeal our refusal of a privacy request; and
- receive equal service without unlawful discrimination for exercising privacy rights.
Promeo does not currently sell personal data, share it for cross-context behavioural advertising, use it for targeted advertising, or conduct profiling that produces legal or similarly significant effects.
EEA, United Kingdom, and Switzerland
Individuals in these regions may exercise rights of access, correction, deletion, restriction, portability, and objection under applicable data-protection law. They may withdraw consent where consent is the basis and complain to their local supervisory authority.
United States
Residents of US states with applicable privacy laws may request access, correction, deletion, or a copy of covered personal information and may use an authorised agent where permitted. They may also appeal a denied request by replying to our decision. Because Promeo does not sell covered personal information or use it for targeted advertising, no sale or targeted-advertising opt-out is currently necessary.
Rights may be subject to legal exceptions. For example, we may retain data needed for security, legal obligations, disputes, or the rights of another person.
12. Exercising rights, deleting an account, and disconnecting channels
Privacy requests may be sent to noel@alcaeus.app. The request should identify the Promeo account and the right being exercised.
We may request information reasonably necessary to verify identity, authority to act for the business, or an authorised-agent request. We will respond within the period required by applicable law and explain any denial and available appeal or complaint route.
The business representative may:
- delete individual uploaded or generated library items from the creation studio;
- disconnect any individual platform account or Facebook Page attached to the selected Project through Promeo controls or the provider's permission settings;
- cancel pending schedules through Promeo;
- request export or deletion of account data; and
- close the Promeo account.
Disconnecting one channel stops future authorised submissions through that connection but does not affect other connections or delete content already sent to a platform. Account deletion does not delete posts from connected platforms. Those posts must be managed through the relevant platform.
When Instagram or Threads sends a valid deletion or deauthorization request, Promeo removes associated provider-derived data across affected Projects, including identifiers and account details copied into post and comment history. User-authored compositions and unrelated destinations may remain under their normal retention rules. A composition with no remaining destination becomes an unapproved draft. The deletion status remains in progress while background cleanup and checks for already-running work finish. Security, legal and backup exceptions in Section 9 still apply.
When an account closes, we will delete uploaded and generated library items, cancel pending schedules, revoke platform authorisation where supported, remove tokens, and delete or retain data according to Section 9.
13. Children
Promeo is a business service for representatives aged 18 or older. We do not knowingly create accounts for children or collect children's personal data for their own use of the Service.
Customer Content and generation references must not include children's personal data unless the Customer has a valid legal basis, all required parental or guardian permissions, and has confirmed that the generation, content, and planned publication are lawful and appropriate.
If you believe a child has created an account or personal data was submitted unlawfully, contact noel@alcaeus.app.
14. Changes to this policy
We may update this policy when Promeo, our providers, legal requirements, or privacy practices change. The effective date at the top identifies the current version.
For material changes, we will provide reasonable notice through the Service or by email before they take effect unless an earlier change is required for legal, security, or platform-compliance reasons.
15. Complaints and contact
Questions, requests, or complaints may be sent to:
Alcaeus Development AB
Registration number: 559461-9727
Fjällbrudens väg 11
132 45 Saltsjö-Boo, Sweden
Email: noel@alcaeus.app
Individuals in the EEA may complain to the Swedish Authority for Privacy Protection (IMY) or another competent supervisory authority. Individuals elsewhere may contact the privacy or data-protection regulator responsible for their location.
Swedish Authority for Privacy Protection (IMY)
Integritetsskyddsmyndigheten
Box 8114
104 20 Stockholm, Sweden
Email: imy@imy.se
Phone: +46 (0)8 657 61 00
IMY contact page