This Privacy Policy explains what SocioRolla Limited, a company which is owned and operated by REMOTEWORKPADI LTD. ("SocioRolla", "we", "us"), collects when you use our social media management product, why we collect it, and the choices you have. It works alongside our Terms of Use and Terms of Service.
1. Overview
SocioRolla is a social media management tool that lets solo social managers, small in-house teams, and agencies run multiple brands and their social feeds from one workspace. To do that, we hold a few categories of information: your account and workspace details, the Content you create and upload, the connected social accounts you authorize us to publish to, and basic usage data that keeps the service secure and working.
A few principles guide everything below:
- We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising as those terms are defined under California law.
- We do not use your Content to build advertising profiles, and we do not use it to train our own models.
- You own your Content. We process it only to operate the service for you — to draft, schedule, publish, and report on your posts.
- You stay in control of connected accounts. You can disconnect any social account at any time, which revokes our ongoing access to it.
This policy applies to our marketing site at sociorolla.com and the application at app.sociorolla.com. If you are an end customer of an agency that uses SocioRolla, your relationship is primarily with that agency, who acts as the controller of the data they put into the workspace.
2. What we collect
We collect the following, and nothing we don't need:
- Account details. Your name, email address, a password hash (never your plaintext password), and your workspace settings (organization name, brands, team members, roles, and preferences).
- Billing information. Your plan, billing contact, and billing history. Payments are handled by our third-party payment processor — we do not store full card numbers or full payment credentials on our systems.
- Your Content. The posts, captions, drafts, images and media, brand materials, brand-voice profiles, do's and don'ts, key facts, and any other material you create in or upload to SocioRolla.
- Connected-account data. When you connect a social account, we store an encrypted OAuth access token and refresh token, plus the minimum profile information and the analytics/performance metrics needed to publish on your behalf and report results back to you. See Connected accounts for detail.
- Usage, device, and log data. IP address, browser and device type, pages and features used, timestamps, and diagnostic logs. We use this for security, troubleshooting, and improving the product.
- Support communications. Messages you send us and information you provide when you contact support.
We collect this information directly from you, automatically as you use the service, and — for connected-account data — from the social platforms you authorize through their official APIs.
3. How we use it
We use the information above to:
- Operate the service — run your workspace, brands, calendar, and team permissions.
- Publish on your behalf — send your scheduled, queued, and recycled posts to the social accounts you connected, when you've scheduled or approved them.
- Provide AI-assisted suggestions — tailor a post idea per platform and generate drafts in your brand voice (see AI-assisted features).
- Generate analytics — report performance metrics for your posts and accounts.
- Process payments and manage subscriptions — including trials, renewals, and cancellations.
- Keep things secure — detect, prevent, and respond to fraud, abuse, and security incidents.
- Provide support — respond to your questions and fix problems.
- Comply with law — meet our legal and regulatory obligations and enforce our agreements.
Under the GDPR and UK GDPR, our legal bases are: performance of our contract with you (operating the service, publishing, billing); our legitimate interests (security, fraud prevention, improving the product, and analytics, balanced against your rights); your consent (for non-essential cookies and certain optional features, which you can withdraw at any time); and compliance with legal obligations.
4. Connected accounts & integrations
Connecting an Instagram, Facebook, LinkedIn, X (Twitter), or TikTok account is what lets SocioRolla publish for you. Here is exactly how that works:
- Authorization via OAuth. You connect each account through the platform's own official OAuth flow. We never see or store your social platform passwords.
- What we store. We store the OAuth access and refresh tokens issued to us, encrypted at rest using AES-256-GCM, along with the minimum profile data and the analytics/performance data needed to publish and report.
- What we do with it. We act on your behalf, through each platform's official API, only to do what you've asked — publish, schedule, recycle, and retrieve metrics.
- Disconnecting. You can disconnect any account at any time from your workspace. Doing so revokes our ongoing access; we stop publishing to that account and delete or de-activate the associated tokens.
Each connected platform has its own terms and developer/platform policies — including the Meta Platform Terms, the X Developer Agreement, and TikTok's and LinkedIn's developer terms. Your use of SocioRolla to act on those accounts must comply with them, and the platforms' own privacy practices for the data you publish are governed by their policies, not ours.
Google Drive and Google Calendar. You can optionally connect Google Drive and Google Calendar. Our access to your Google data uses the narrowest scopes that make each feature work, and is governed by this section and by the Google API Services User Data Policy:
- Google Drive. You choose specific files through Google's own Picker, and we access only the files you select — never the rest of your Drive. When you import a file, we copy it into SocioRolla's storage so it can be attached to and published with your post; that copy is retained as part of the post's media. We do not browse, search, index, or store any other part of your Drive.
- Google Calendar. We create and manage a single dedicated "SocioRolla" calendar and write your scheduled posts into it as events; we never modify your other calendars. We also read your existing events only to display them, read-only, alongside your content calendar in the app — they are fetched when you view the calendar and are not stored on our servers.
- Tokens and storage. Google OAuth access and refresh tokens are stored encrypted at rest using AES-256-GCM. We do not keep a mirror or ongoing copy of your Drive or Calendar.
- Revoking access. You can disconnect Google at any time from your SocioRolla workspace, and you can review or revoke SocioRolla's access directly in your Google Account under Third-party apps with account access.
SocioRolla's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. AI-assisted features
SocioRolla's Compose feature uses AI to tailor a post idea per platform and draft suggestions in your brand voice. AI features are powered by third-party AI model providers, accessed through the Vercel AI SDK. You should understand:
- What we send. To generate a suggestion, we send the relevant Content and context (for example, your post idea and the brand-voice profile) to the AI provider solely to produce the output you requested.
- Confidentiality and training. AI providers receive this data under contractual confidentiality terms, and we do not permit them to use your Content to train their own models where that use is contractually controllable.
- You remain in control. AI output is a suggestion only. You always edit and approve before anything is scheduled or published. We make no guarantee about the accuracy, appropriateness, or performance of AI suggestions — you are responsible for what you publish (see our Terms of Use).
7. Subprocessors
We rely on a focused set of subprocessors to deliver SocioRolla, including cloud infrastructure and hosting, our payment processor, AI model providers (via the Vercel AI SDK), and email and product-analytics tools. Each is bound by a written agreement requiring appropriate confidentiality and security. If you are a business customer subject to the GDPR or UK GDPR and need our Data Processing Agreement or a current list of subprocessors, contact us at privacy@sociorolla.com. Our DPA point of contact is privacy@sociorolla.com.
9. Data retention
We keep personal information only as long as we need it:
- Account and workspace data for as long as your account is active.
- Your Content, including scheduled posts, while your account is active; if you cancel a paid plan, scheduled posts are retained until the end of your billing period as described in our Terms of Service.
- Deleted brands for 30 days after you delete them, so the deletion can be undone — see below.
- Connected-account tokens until you disconnect the account or close your workspace.
- Billing records for as long as required for tax, accounting, and legal purposes.
- Logs and diagnostic data for a limited period appropriate to security and troubleshooting.
Deleting a brand. Deleting a brand does not erase it immediately. It is hidden from your workspace and stops all activity on it — scheduled posts are cancelled, analytics collection stops, and no further notifications are sent — but it is held for 30 days so you can restore it, along with its projects, posts, media, and connected-account records. During that window the data still exists on our systems, and any access tokens for its connected accounts remain stored (though unused). After 30 days it is removed permanently and cannot be recovered.
If you want a brand and its data gone straight away, use Delete permanently instead of the ordinary delete. That skips the 30-day window entirely: we tell each connected platform to revoke our authorization, and we erase the brand's data immediately and irreversibly. Disconnecting an individual social account also revokes that authorization at once, without waiting.
When you close your account, we delete or de-identify your personal information within a reasonable period, except where we must retain it to comply with law, resolve disputes, or enforce our agreements. You can export your data before you leave (see Cancellation & refunds).
10. Security
We protect your information with:
- Encryption in transit and at rest, including AES-256-GCM encryption of connected-account tokens.
- Access controls and role-based permissions, so data is scoped to your organization and brands and visible only to authorized teammates.
- Regular security reviews of our systems and practices.
No system is perfectly secure, but if a breach affecting your personal information occurs, we will notify you and the relevant authorities as required by law. You also play a part: keep your password confidential and manage your teammates' roles carefully.
11. Your rights & choices
Depending on where you live, you have rights over your personal information.
- GDPR / UK GDPR. You may request access, correction, deletion, restriction, or portability of your data; object to processing based on legitimate interests; and withdraw consent at any time. You may also lodge a complaint with your local data protection authority.
- California (CCPA/CPRA). You may request to know, delete, and correct your personal information, and to opt out of "sale" or "sharing" — though we do not sell or share personal information as defined by that law. We will not discriminate against you for exercising any of these rights.
- Everyone. You can update your account details in-app, manage cookies, disconnect social accounts, and export your data.
To make a request, email privacy@sociorolla.com. We will verify your identity before acting and respond within the timeframes the law requires. You may use an authorized agent where the law permits. If an agency manages your data in SocioRolla, please direct requests to that agency, who is the controller; we will assist them as a processor.
12. International transfers
SocioRolla operates from Nigeria and uses service providers that may process data in other countries, including the United States and the European Union. When we transfer personal information out of the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards — principally the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum) — together with supplementary measures where needed. Because SocioRolla is established in Nigeria and not in the EEA or the UK, we will appoint a representative under Article 27 of the EU GDPR, and a separate representative under the UK GDPR, if and when our processing brings us within their scope — for example, once we offer the Service to, or monitor the behaviour of, individuals in the EEA or the UK — and we will publish their names and contact details here. To request a copy of the relevant transfer safeguards, email privacy@sociorolla.com.
13. Children's privacy
SocioRolla is a business tool and is not directed to anyone under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact privacy@sociorolla.com and we will delete it.
14. Contact us
Questions about this Privacy Policy or your data? Email our privacy team at privacy@sociorolla.com. For legal matters, legal@sociorolla.com; for help with the product or billing, support@sociorolla.com.

