Privacy Policy
Last Updated: July 30, 2026
This Privacy Policy describes how ITI Symmetrics ApS, trading as MySoMeData ("we," "us," or "our"), collects, uses, discloses, and safeguards your information when you use our website, platform, and application programming interfaces (collectively, the "Service").
Our Service connects to your designated social media accounts via OAuth to aggregate performance metrics and expose them through a developer API. We are committed to protecting your privacy and handling your data in compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the developer policies of our platform partners (Meta, TikTok, and Pinterest).
Please read this policy carefully. If you do not agree with the terms of this Privacy Policy, please do not access or use the Service.
1. Introduction
We respect your privacy and are committed to protecting the personal data we hold about you. The purpose of our Service is to provide a unified analytics utility that aggregates your social media performance metrics into an accessible API.
ITI Symmetrics ApS (CVR-nr. 43254502), Sankt Peders Stræde 10, 1. tv, 1453 København K, Denmark, acts as the "Data Controller" for the account and billing information you provide directly to us. For the social media platform metrics retrieved via OAuth and exposed through our API, we process this data in accordance with this policy and the developer terms of the respective social media networks.
2. Information We Collect
We limit our collection of information to what is necessary to provide, maintain, and secure the Service. We collect the following categories of data:
A. Account Data
- Registration Information: To create an account, we collect your email address and profile credentials.
- Billing Information: Payment processing is handled securely by our third-party payment processor, Stripe. We do not store your raw credit card numbers or bank account details on our servers; we receive only limited transaction details and payment tokens from Stripe.
B. Social Media Platform Data (Read-Only)
When you explicitly authorize our Service to connect to your social media accounts (Instagram, TikTok, and Pinterest) using the official OAuth authorization flows, we collect read-only data. We do not request permissions to write, post, edit, or delete content, nor do we request direct messaging permissions. The data collected includes:
- Profile Metadata: Read-only profile details such as usernames, display names, profile image URLs, and account identifiers.
- Media Metrics: Aggregated engagement data associated with your posts, videos, or pins, including views, likes, comments, shares, saves, and historical performance statistics.
- Audience Metrics: Aggregated subscriber and follower counts.
We access this data solely through the official, public APIs provided by Meta, TikTok, and Pinterest.
C. API Keys
- To enable access to your aggregated data via our API, the Service generates unique API keys. We store only cryptographically hashed versions of these API keys in our database to prevent unauthorized access.
3. How We Use Your Information
We use the information we collect strictly to operate the Service. Specifically, we use your data to:
- Provide, maintain, and monitor the performance of our API and metrics-aggregation engine.
- Manage your account, process payments, and provide customer support.
- Comply with our legal obligations and enforce our terms of service.
No Sale or Renting of Data: We do not sell, rent, lease, or share your personal data, platform metadata, or social media metrics with third parties for marketing, advertising, profiling, or cross-context behavioral advertising purposes. Your data is used exclusively to deliver the functionality of the Service to you.
4. Data Retention & Caching
To provide analytics and historical trend reporting, we store historical metrics retrieved from your connected social media accounts. However, our storage and caching practices are strictly bound by the developer terms of our platform partners:
- Caching Compliance: We do not cache or store retrieved social media data longer than permitted by the respective platforms' developer policies (e.g., Meta's Platform Terms, TikTok Developer Terms, and Pinterest Developer Terms).
- Token Management: We store your OAuth access tokens and refresh tokens securely to maintain the connection. We respect platform token expirations and refresh cycles. If you revoke access or if a token expires, we cease data retrieval for that account immediately.
- Account Deactivation: If you close your account or disconnect a specific platform, the associated platform data is queued for deletion from our active systems as described in Section 6.
5. Data Security
We implement reasonable, industry-standard administrative, technical, and physical security measures designed to protect your information from unauthorized access, loss, alteration, or disclosure:
- Encryption in Transit: All data transmitted between our servers, the social media platform APIs, and your API integrations is encrypted using Transport Layer Security (TLS/HTTPS).
- Encryption at Rest: Sensitive authentication credentials, including OAuth access tokens, refresh tokens, and database backups, are encrypted at rest using industry-standard AES-256 encryption.
- Hashed Credentials: User passwords and generated API keys are stored only as secure cryptographic hashes.
While we take rigorous steps to secure your data, no method of transmission or electronic storage is completely secure, and we cannot guarantee absolute security.
6. User Control & Data Deletion
You maintain complete control over the connections between our Service and your social media accounts. You can revoke our access at any time using either the platform's native settings or by requesting a complete deletion of your data from our systems.
A. Revoking Access via Platform Settings
To disconnect our application and revoke our access to your social media accounts, you can manage your permissions directly within each platform's settings:
Instagram / Facebook (Meta):
- Log into your Facebook or Instagram account.
- Navigate to Settings & Privacy > Apps and Websites (or Website Permissions).
- Locate MySoMeData in the list.
- Click Remove or Revoke to terminate our access token.
TikTok:
- Open the TikTok app or log into TikTok via a browser.
- Go to your Profile > Settings and Privacy > Security > Manage app access.
- Select MySoMeData and click Remove Access.
Pinterest:
- Log into your Pinterest account.
- Go to Settings > Apps (or Connected Apps).
- Locate MySoMeData and click Revoke Access.
Once access is revoked, our Service will no longer be able to fetch updated metrics from that platform.
B. Complete Data Deletion Request
You may request the permanent deletion of your account and all associated historical data stored in our database at any time.
- To initiate a complete deletion, please email us at support@mysomedata.com with the subject line "Data Deletion Request."
- Upon receipt and verification of your request, we will permanently delete your account profile, billing metadata, stored OAuth tokens, and all cached social media historical metrics from our active databases within thirty (30) days, subject to any retention required for legal, tax, or accounting purposes.
7. Third-Party Processors
We utilize trusted third-party service providers to assist in delivering the Service. These processors are contractually bound to process your data only as necessary to perform services on our behalf and in compliance with this Privacy Policy and applicable data protection laws.
- Payment Processing: We use Stripe to process credit card payments and subscription billing. Stripe's use of your personal information is governed by their privacy policy, which can be viewed at https://stripe.com/privacy.
- Hosting and Infrastructure: Our servers and databases are hosted on secure cloud infrastructure providers compliant with standard security frameworks (such as SOC 2 and ISO 27001).
8. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, operational requirements, or modifications to social media platform developer policies.
When we make changes, we will update the "Last Updated" date at the top of this policy. If the changes are material, we will provide you with more prominent notice, such as sending an email notification or displaying a banner within the Service dashboard prior to the change becoming effective. We encourage you to review this policy periodically to stay informed about how we protect your information.
9. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy, your personal data, or our compliance practices, please contact us at:
ITI Symmetrics ApS
CVR-nr. 43254502
Sankt Peders Stræde 10, 1. tv, 1453 København K, Denmark
Email: support@mysomedata.com