Privacy Policy
Last updated: August 21, 2026
This policy covers Eagle I ("we," "our," "the platform"), a marketing dashboard product. It is provided as a plain-language description of our actual data practices, written for both users and platform reviewers (e.g. Meta's App Review). If you operate Eagle I commercially, replace the placeholder contact details below with your registered business's own before relying on this page for a live app review submission.
What we collect
- Account information: the email address and password (stored as a salted bcrypt hash, never in plain text) you use to sign in.
- Business profile: the company details you provide during onboarding — company name, industry, contact info, service area, services offered, differentiators, brand voice, and an optional logo image.
- Connected social accounts: if you choose to connect a Facebook Page or Instagram Business account, we store the Page/account identifiers and an encrypted access token issued to us by Meta, so we can publish posts on your behalf when you ask us to. We request only the permissions needed to read your Page list and publish posts:
pages_show_list, pages_read_engagement, pages_manage_posts, business_management, instagram_basic, instagram_content_publish.
- Usage data: a per-account monthly count of AI content generations, used only to enforce your plan's usage limit.
- Billing information: payment details are collected and processed entirely by Stripe; we store only your Stripe customer/subscription IDs, never your card details.
How we use it
- To generate marketing content (strategy suggestions, keyword ideas, competitor analysis, opportunity ideas) tailored to your business profile, using the Anthropic API. Generated content is cached in our database so we don't need to resend your business data to the AI provider every time you view a page.
- To publish content to Facebook/Instagram only when you explicitly click a "Publish" action inside the product — we never post automatically or without an action you took.
- To enforce plan usage limits and process subscription billing.
- To operate, secure, and improve the product itself.
What we don't do
- We do not sell your data.
- We do not share your business data or connected-account tokens with anyone other than the service providers strictly needed to run the product (Anthropic for AI generation, Meta for publishing you request, Stripe for billing, and our hosting/database provider).
- We do not post to your connected accounts except in direct response to an action you took in the product.
Data storage and security
Data is stored in a managed PostgreSQL database with encrypted connections. Social platform access tokens are encrypted at rest (AES-256-GCM) with a key that never leaves our server. Passwords are hashed with bcrypt and never stored or logged in plain text.
Your controls
- You can disconnect a Facebook/Instagram connection at any time from the product's Social HQ settings — this immediately deletes the stored access token.
- You can request full account and data deletion by contacting us (see below); we will delete your business profile, generated content, and any connected-account tokens.
Contact
Questions about this policy or a data request: miloyuval18@gmail.com