Privacy Policy

Last updated July 11, 2026

1. Scope

This policy describes what personal data Crosspine collects when you use the service, why we collect it, who processes it, and the rights you have over it.

2. Data we store

We store only what the service needs to operate:

  • Account data: your name, email address, and a salted password hash (never the password itself), plus workspace membership and role.
  • Connected-account credentials: OAuth tokens for the social accounts you connect, encrypted at rest with AES-256-GCM. Disconnecting a channel deletes its tokens.
  • Content: your drafts, scheduled posts, and uploaded media, retained until you delete them or your account.
  • Billing: subscription plan and status. Payments are processed by Stripe; card numbers never touch our servers.
  • Operational logs: request metadata (timestamps, request ids, status codes) for reliability and abuse prevention. Secrets are redacted from logs.

3. How we use it

To operate Crosspine: authenticate you, publish the posts you schedule to the networks you selected, process your media into the formats each platform requires, send transactional email (verification, password resets, invitations), and bill your subscription. We do not sell personal data and we do not use your content for advertising.

4. Who processes it

  • Social platforms: the content you schedule is transmitted to each network you selected, under that network's own terms and privacy policy.
  • Stripe: payment processing.
  • Our email provider: transactional mail delivery.
  • Anthropic: only when you use the optional AI assistant, your prompt and the draft text you asked it to work on are sent to Anthropic to generate the response.
  • Hosting: the infrastructure this deployment runs on.

5. Retention

Account data is kept until you delete your account. Posts and media are kept until you delete them. Channel tokens are kept until you disconnect the channel. Operational logs are kept for a limited period and then discarded.

6. Security

Channel credentials are encrypted at rest with a dedicated key, all traffic is encrypted in transit with TLS, and passwords are stored only as salted hashes. Access to production systems is restricted to the operator of this deployment.

7. Your rights

You can access and update your account data in Settings, and delete posts, media, and channels at any time from the app. Under the GDPR and similar laws you may also request access to, correction of, export of, or erasure of your personal data: contact support@crosspine.io and we will respond within 30 days.

8. Cookies

Crosspine uses only the session cookies required to keep you signed in. There are no advertising or cross-site tracking cookies.

9. Children

Crosspine is not directed at children and requires users to be 16 or older.

10. Changes

We may update this policy; material changes will be announced in the app or by email before they take effect. The date above always reflects the current version.

11. Contact

Privacy questions and data requests: support@crosspine.io. See also our Terms of Service.