Privacy Policy
Last updated: April 23, 2026
1. Who we are
The Hive ("we", "us", "our") is a creator-services platform that helps brands plan, produce, and publish social content. This Privacy Policy explains what data we collect, why we collect it, and how we protect it.
2. Information we collect
Account data: name, email, and profile picture you provide at signup.
Workspace content: ideas, scripts, files, comments, and other material you upload.
Connected social accounts: when you link Instagram, Facebook, YouTube, TikTok, or LinkedIn, we receive an access token, your account ID, handle, display name, and avatar URL from that platform. We never receive your platform password.
Usage data: pages viewed, actions taken, and basic device/browser metadata for security and product improvement.
3. How we use your data
Operate the platform: store your content, sync your workspace, send notifications.
Publish on your behalf: when you explicitly schedule or send a post, we use your stored OAuth token to upload that single post to the platform you selected.
Generate AI suggestions for captions, hashtags, thumbnails, and posting times.
Provide customer support, prevent abuse, and comply with legal obligations.
We do not sell your personal data. We do not use your social-account data for advertising, profiling, or training third-party models.
4. How we store and protect your data
All data is stored in encrypted databases hosted on Supabase (AWS infrastructure).
OAuth refresh tokens are encrypted at rest using AES via pgcrypto with a key only our backend can read.
Row-level security ensures workspace data is isolated — only members of your workspace can read it.
HTTPS/TLS is enforced for all data in transit.
5. YouTube Data API specific disclosures
Our YouTube integration uses the YouTube Data API Services. By connecting your YouTube account you agree to be bound by the YouTube Terms of Service and the Google Privacy Policy.
You can revoke our access to your YouTube account at any time at Google Account → Security → Third-party apps or from inside The Hive at Settings → Connected Social Accounts → Disconnect.
We only request the scopes strictly necessary to upload, list, and update videos you explicitly publish through The Hive. We do not access viewers' personal data, comments, or analytics beyond what you publish.
6. Data sharing
We share data with:
Social platforms (Instagram, Facebook, YouTube, TikTok, LinkedIn) — only the specific posts and metadata you choose to publish.
Infrastructure providers (Supabase, AWS, Resend for email) under strict data-processing agreements.
AI providers (Google Gemini via the Lovable AI Gateway) — content you submit for generation. AI providers are contractually prohibited from training on your data.
7. Your rights
Access, export, or delete your account and workspace data at any time from Settings.
Disconnect any social account at any time from Settings → Connected Social Accounts.
Request deletion of all data by emailing us (see Section 9). We will respond within 30 days.
If you are in the EU/UK, you have rights under GDPR including data portability and the right to object.
If you are in California, you have rights under CCPA including the right to know and the right to delete.
8. Data retention
We retain your data while your account is active. When you delete your account, we delete all associated workspace content and revoke all OAuth tokens within 30 days, except where retention is required by law (e.g. transactional records).
9. Contact
Privacy questions, deletion requests, or platform-specific concerns: privacy@thehive.io
10. Changes
We may update this policy as the product evolves. Material changes will be announced by email and in-app notification at least 14 days before they take effect.