Nashrkhana (“نشرخانة”, “we”, “the service”) lets you write a post once and publish it to several social media platforms, and read the replies to it in one place. Doing that requires access to the social accounts you choose to connect. This page explains exactly what we hold, why, for how long, and how to get rid of it.
1. Who we are
The service is operated from nashrkhana.com. For any privacy question, including access and deletion requests, contact privacy@nashrkhana.com. We aim to respond within 30 days.
2. What we collect
| Category | What it is | Why |
|---|---|---|
| Account details | Name, email address, hashed password, timezone, language. | To create your account and sign you in. Passwords are hashed and never stored or transmitted in readable form. |
| Connected channels | Platform access and refresh tokens, the connected profile's ID, display name, and avatar. | To publish on your behalf and read replies. Tokens are stored encrypted. |
| Content you create | Post text, images, and video you upload; schedules; drafts. | To publish it where and when you asked. |
| Engagement | Comments, mentions, and direct messages on your posts, including the commenter's public username and message text. | To show you a single inbox across platforms and let you reply. |
| Performance data | Likes, comments, shares, reach, and impressions returned by each platform. | To show you how a post performed and when your audience is active. |
| Technical logs | API request records and error traces. | To diagnose failures. Retained 30 days, then deleted. |
What we do not collect
- Payment card numbers. If you subscribe, payment is handled entirely by Stripe and card details never reach our servers.
- Your social media password. Connecting a channel uses OAuth, so you authenticate with the platform directly and we receive only a scoped token.
- Contacts, location, or anything from your device beyond what you deliberately upload.
3. Platform data and the permissions we request
When you connect a channel, the platform shows you exactly which permissions we are asking for, and you can decline. We request the narrowest set that makes the feature work — typically the ability to read your profile, publish content, and read and reply to comments. We do not request advertising or audience data unless you explicitly enable the ads features.
Data obtained from a platform is used only to provide the features you can see in the app. It is never sold, never shared with other users, and never combined into a profile of you for any purpose beyond running the service.
4. Artificial intelligence
The app offers optional AI assistance for writing captions, suggesting hashtags, and translating posts. This applies only when you actively use those features.
- By default these run on a model hosted on our own infrastructure, and the text does not leave our servers.
- If a task is configured to use an external provider, the text of that specific request is sent to them to generate a response. Providers are used under agreements that prohibit training on submitted data.
- We do not use your content to train any model, our own or anyone else's.
5. Where your data lives, and who can see it
Data is held on servers we control and is accessible only to the people operating the service, and only when necessary — investigating a fault you reported, or responding to a legal obligation. Access tokens are encrypted at rest. Traffic to and from the app is encrypted in transit with TLS.
We share data with third parties only in these cases:
- The social platforms you connect — to publish and read what you asked us to.
- Stripe — to take payment, if you subscribe.
- Push notification providers (Apple, Google) — to deliver notifications you enabled.
- Where the law requires it — in response to a valid legal request.
We do not sell personal data, and we do not share it for advertising.
6. How long we keep things
| Account and posts | Until you delete your account. |
| Channel tokens | Deleted immediately when you disconnect the channel. |
| Engagement and metrics | Detailed records for 90 days, then kept only as aggregate totals. |
| Technical logs | 30 days. |
| Deleted accounts | Fully removed within 30 days, including backups. |
7. Your rights
You can, at any time:
- Disconnect a channel — from the app. Its tokens are deleted immediately and we stop receiving anything from that platform.
- Delete your account — from the app, or by emailing privacy@nashrkhana.com. This removes your posts, media, engagement history, and tokens.
- Request a copy of the data we hold about you.
- Correct anything inaccurate.
- Object to a particular use, or withdraw a permission you previously granted.
You can also revoke our access from the platform's own settings, which works independently of anything you do here.
8. Children
The service is not intended for anyone under 16, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will remove it.
9. Changes
If we change this policy in a way that materially affects how your data is used, we will notify you in the app before the change takes effect. The date at the top always reflects the current version.
10. Contact
Privacy questions, access requests, and deletion requests: privacy@nashrkhana.com