NotSoSocial Privacy Policy
Last updated: 16 September 2026. Nederlandse versie
NotSoSocial is a service of Winst.nl BV, Keizersgracht 520H, 1017 EK Amsterdam, the Netherlands, Chamber of Commerce no. 68717067. We help you see and answer the numbers, comments and messages of your own social media accounts in one place. Winst.nl BV is responsible for the processing described here.
This policy explains which data we process, why, on what legal basis, who helps us with it, and what your rights are.
What data we process, and why
- Account data: your email address, your name (if you enter one) and your password. We store your password only in hashed form (argon2id), so we cannot read it. Every account also gets a random account ID. We use this data to create your account, let you sign in, and email you codes to verify your address or set a new password. Legal basis: performance of the contract.
- Using the app without an email address: the app then creates a random device ID the first time you open it, and keeps it in your phone's secure storage. That ID is your account to us. It says nothing about you or your phone; it is only a number we recognise your data by. Legal basis: performance of the contract.
- Connected social media accounts: before you connect your first account, the app explains what we collect. You then give permission on the platform's own login page (for example Instagram or TikTok). We collect your posts with their statistics, the comments on them, your follower counts and, for Instagram and Facebook, your direct messages. When you connect an account, we fetch the last 90 days. The access keys (tokens) for these connections are managed by Zernio and never reach our own servers. We never see or store the password of your social media accounts. Legal basis: performance of the contract, at your request.
- What you create in the app: the posts you write or schedule, the photos and videos you add to them, your replies to comments, and the direct messages and voice messages you send. The app only uses your camera, photo library or microphone when you choose to. Whatever you publish or send goes through Zernio to the platform you picked, where that platform's own terms apply. We keep what the app needs to show it to you: the text, and a link to the photo, video or audio file. Legal basis: performance of the contract.
- Subscription data: whether you are on a trial or a subscription, which plan you have, and when it renews or ends. RevenueCat, which manages subscriptions for us, notifies us of every change, and we keep those notifications as a record. We never see your payment details: the app store you subscribed through, such as the App Store, handles the payment. Legal basis: performance of the contract.
- Notifications: if you allow notifications, we store your device's push token and your notification settings. We use them to tell you about new comments and messages, about a connection that is about to expire and, if you want, to send you a weekly summary of your numbers. A notification about a comment or message contains its text, so you can see on your lock screen what it is about. It reaches your phone through your device's push service. In the app you choose which notifications you get, and in your phone's settings you can turn them all off. Legal basis: performance of the contract, and only with your permission on your device.
- Technical data: when someone signs in (successfully or not) or deletes an account, our server logs the time, the IP address, the account ID and the domain of the email address (the part after the @, not the whole address). Errors are logged together with the account ID they occurred for, so we can fix them. To block too many attempts in a row, the server briefly keeps your IP address in its working memory; it is not written to our database. Our hosting provider also keeps its own logs of requests to our server, including the IP address and the type of device or browser. Legal basis: our legitimate interest in keeping the service secure and working. We don't track you for advertising, we don't sell data and we don't build profiles.
- On your phone: the app keeps your sign-in in your phone's secure storage, and settings such as language and theme on the phone itself. If you lock the app with Face ID, the app asks your phone to unlock it. The app only gets a yes or a no back; no biometric data ever reaches the app or us.
Messages from other people
Comments and messages that other people leave on your channels contain their personal data: their name, username, profile picture and text, and sometimes a link to a photo, video or voice message. We process this only to show it to you and let you reply. We keep it as long as your account exists, or until you disconnect that channel. Legal basis: the legitimate interest of you and us in being able to read and answer messages addressed to you.
Who we share data with
- Our hosting provider (servers in the EU). This is Railway, which runs our server and database and keeps the server logs.
- Resend sends the emails with your verification and password reset codes.
- Zernio connects the app to the social media platforms through their official interfaces. Zernio receives what it needs for that: your account ID, your connected accounts, your posts, statistics, comments and messages, and the photos, videos and voice messages you send through the app.
- RevenueCat manages your subscription status for us. RevenueCat receives your account ID, your purchases, and a device identifier that its software sends along (on iPhone, the identifierForVendor that Apple provides for this).
- Cloudflare (R2) stores backups of our database, if backups are set up.
- Apple or Google, depending on your phone. The app store you subscribed through, such as the App Store, handles the payment, and your device's push service delivers notifications. They do this under their own terms and privacy policies.
The parties in points 1 to 5 process data on our behalf, under a data processing agreement. We never sell data to third parties.
Data outside the European Economic Area
Some of these parties may process data in the United States. Where that happens, the transfer is based on the EU Standard Contractual Clauses or the EU-U.S. Data Privacy Framework, where applicable.
How long we keep data
We keep your data for as long as your account exists, with these details and exceptions:
- If you disconnect a channel, we immediately erase everything we collected for it.
- If you delete your account (always possible in the app, under Channels, Delete account), we immediately erase your account, your connections, all collected data, your subscription records, your notification settings and the registration of your devices. We also disconnect your social media accounts at Zernio and remove your profile there; if that fails, we automatically try again.
- Verification codes and sign-in sessions are erased 30 days after they expire.
- We keep at most the 500 most recent error reports, for all users together. Reports linked to your account are erased when you delete it.
- Subscription notifications from RevenueCat are kept for up to one year, as a record in case of a payment dispute. Notifications that arrive after you deleted your account are no longer linked to it, and are also erased after one year.
- Railway deletes server logs automatically after a fixed period, which depends on the hosting plan and is no longer than 30 days on ours.
- Backups, if set up, expire automatically within 30 days.
- We don't issue or keep invoices: the app store you paid through does that. The app store and RevenueCat keep their own records of your purchases; deleting your NotSoSocial account does not remove those.
Your rights
You can access your data and take it with you (in the app: Channels, Export my data), and you can ask us to correct, restrict or delete it. You can also object to processing that is based on our legitimate interest. Send questions and requests to support@notsosocial.app; we respond within one month. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Security
All connections are encrypted (HTTPS). Passwords are stored hashed (argon2id), so nobody can read them, not even us. The platforms' access keys are held by Zernio, not by us. Access to our systems is restricted, and sign-ins to our admin area are logged.
Changes
We will tell you in the app about important changes to this policy.
More help: Support. The rules for using the service: Terms of Service.