Soshi 22

Privacy Policy

Operator: Soshi 22 (Israel)

This policy explains what information Soshi 22 collects when you use the app, the website and the related services, why we use it, who we share it with and how you can control it. The service is built for business owners, and the data we collect serves one purpose: creating and publishing content for your business on social networks.

1. What we collect

Account and identity. You sign up with a phone number, and login is verified with a one-time code sent to that number on WhatsApp. We store the phone number, a username, the business name and industry, and a password if you choose to set one (stored as a hash only). At signup we also record the IP address and browser type, for security.

Business profile and content you provide. Business description, services, audience, style, the phone number and website used in calls to action, your logo, photos and videos you upload, topics and instructions you write for the system, and any edits you make to content.

Social network connections. Publishing goes through an external publishing provider (Socialync). We store your profile identifier at the provider and, in some setups, an access key for the provider, both encrypted. The permissions for the networks themselves (Facebook, Instagram, TikTok, YouTube, LinkedIn and others) are managed at the provider and under each network's terms. We never have access to the passwords of your social accounts.

Generated content. The posts, carousels, images, videos, narration and captions the system creates for you, together with publishing status, schedule times and links to published posts.

Performance data. After publishing we receive, through the publishing provider, aggregate data from the networks about your posts and accounts: followers, views, likes, comments, shares and reach. This data describes your business accounts, not individual people.

Payment. Customers in Israel pay in ILS through Morning; customers elsewhere pay in USD through Lemon Squeezy. Card details are entered directly with the payment provider, never pass through us and are never stored by us. We keep the chosen plan, payment status, transaction and invoice identifiers, and the business name, phone and email you provide at checkout.

Activity and usage. An activity log (which action, when, for which business), technical errors and general usage data that let us run the service and fix problems.

2. How we use it

To run the service: creating content that fits your business, designing it, scheduling it and publishing it to the networks you connected.

For identity and security: verifying logins, preventing abuse and protecting your account and the system.

For billing: managing your plan, quotas, renewals and invoices.

For operational messages: login codes, a notice when new content is ready for approval, reminders and service updates, sent on WhatsApp only to the number you signed up with. Messages other than login codes can be turned off in Settings or by asking us.

To improve the service: understanding which kinds of content perform, fixing errors and building new capabilities, based on aggregate data.

We do not sell personal data and we do not use your content to advertise other businesses.

3. Sharing and processors

Data is shared only with providers needed to run the service, only to the extent required, and under their own terms:

Supabase (database and authentication), Vercel (hosting of the app and website), Cloudflare R2 (storage of generated images and videos), Socialync (network connections, publishing and performance data), AI model providers that receive your business details and content to generate text, images and video (through OpenRouter and Groq), text-to-speech services for narration, Morning and Lemon Squeezy (payments and invoices), and the WhatsApp messaging service.

The social networks you publish to receive the content you approved for publishing; their use of it is governed by each network's policy.

We disclose data to authorities when required by law, or to protect our rights, safety or property or those of others.

Some providers operate outside Israel. When data is transferred abroad it is done only to provide the service and to providers that commit to adequate protection of the data.

4. Cookies and analytics

In the app we use essential cookies only: a login cookie (soshi_session) and a UI language cookie (soshi_ui_lang). The marketing site remembers your language choice in the browser.

The marketing site (soshi22.com) and the app (app.soshi22.com) run the Meta Pixel, which lets us measure the effectiveness of our advertising on Facebook and Instagram. The pixel may set Meta cookies under Meta's privacy policy. You can block it in your browser settings or in the ad settings of your Meta account.

First-party funnel analytics on the marketing site: we record which parts of a page were viewed, scroll depth, button clicks and time on page. This is recorded with an anonymous session id created in your browser and discarded when the tab closes, together with device class (desktop or phone), country, language, campaign UTM parameters and page path. No name, phone, email or IP address is collected.

We also use Vercel Web Analytics, cookieless visit analytics that does not identify users.

5. Retention

Account details, the business profile and generated content are kept for as long as the account is active.

Media files (images and videos) of posts that were already published are removed from our storage about 14 days after publishing; the post itself stays on the network where it was published. Unpublished drafts are deleted after 14 days and run logs after 30 days.

Payment records and invoices are kept as required by tax and accounting law.

After an account is closed, its data is deleted or anonymised within 30 days, except what we are legally required to keep. Backups are removed in the regular backup cycle.

6. Your rights and deletion

You can access the data we hold about you, correct it, receive a copy, ask for its deletion and close your account. You can disconnect a social network at any time from inside the app, which removes our ability to publish to it.

To request deletion, write to the address in section 9 from the phone or email registered on the account. We verify the request and act on it within 30 days.

WhatsApp messages other than login codes can be turned off in Settings or by asking us.

Residents of the EU and the UK also have the rights under the GDPR, including the right to lodge a complaint with their local data protection authority. Our legal bases are performance of the contract with you, our legitimate interest in running and securing the service, and your consent where it is required.

7. Minimum age

The service is intended for business owners and users aged 18 and over. We do not knowingly collect information about minors. If we learn that an account was opened by a minor, we delete it.

8. Changes to this policy

We may update this policy from time to time. The current version and its date always appear on this page. We will announce material changes in the app or on WhatsApp before they take effect.

9. Contact

Questions, access or deletion requests: main.soshi22@gmail.com. Operator: Soshi 22, Israel.

Terms of Use