• How it works
  • Platforms
  • Pricing
  • FAQ
Sign inGet started
  • How it works
  • Platforms
  • Pricing
  • FAQ
Sign in
Legal

Privacy

Last updated 15 August 2026

Cyprian publishes on your behalf, which means we hold your media and the keys to your social accounts. This page says exactly what that involves: what we keep, where it lives, and how to get it back or get rid of it.

What we collect

Four things, and nothing beyond what the product needs to work.

  • Account details. Your email address and authentication records, so you can sign in and so we know whose workspace is whose.
  • Media you upload. The videos and images you attach, plus technical details we derive from them such as duration, dimensions, format and a checksum.
  • Connected accounts. When you connect a destination, we store access and refresh tokens for it, along with the account handle and identifier that destination reports back. We never receive or store your password for any platform.
  • Publishing records. What you scheduled, what you approved, when each attempt ran, whether it succeeded, and what the destination said if it failed.

We do not sell any of it, and we do not buy data about you from anyone else.

Where it is stored

Account details and publishing records are held in a Postgres database hosted in Ireland. Media files are held in Cloudflare R2 object storage with a Western Europe location hint. Uploads pass through our own servers rather than going directly from your device to storage, so the storage bucket is not publicly reachable.

Your original file is never modified. When a destination needs a smaller or differently encoded version, we create a separate derivative and leave the original untouched.

How we protect connected accounts

Access and refresh tokens are the most sensitive thing we hold, because they can post as you. Every one of them is encrypted with AES-256-GCM before it is written to the database, using a key that is never stored alongside the data it protects. Each token is additionally bound to the specific connection it belongs to, so a token row is useless if it is moved somewhere else in the database.

You can disconnect any destination at any time, which revokes our access and deletes the stored tokens for it.

Who else sees your data

We share data with a small set of processors, each for a specific job:

  • The destinations you connect.Instagram, TikTok, YouTube, X, LinkedIn, Facebook, Bluesky and others receive the media and text you approve for them. Once published, that content is governed by that platform’s own terms and privacy policy.
  • Supabase. Database and authentication hosting.
  • Cloudflare. Media storage.
  • Fly.io. Application hosting.
  • Google.When you describe what you want in your own words, that text is sent to Google’s Gemini API to draft a plan for you to review. The assistant only ever proposes; it cannot publish, schedule, delete or approve anything by itself.
  • Composio. Handles the connection to some destinations on our behalf.

We will also disclose data where the law requires it. If Cyprian is ever acquired, your data would transfer with it, and we would tell you before that happened.

How long we keep it, and how to delete it

Media and publishing records are kept while your account is open, because the record of what went out is the point of the product. Delete an item and we remove it and its derivatives. Close your account and we delete your media, tokens and account details within 30 days, keeping only what we are legally required to retain.

Your rights

Wherever you live, you can ask us to show you the data we hold about you, correct it, export it, or delete it. If you are in the UK, EU, or another region with equivalent law, you also have the right to object to or restrict how we process it, and the right to complain to your data protection authority.

We process your data to provide a service you asked for, and where we rely on your consent, such as connecting a destination, you can withdraw it at any time by disconnecting that destination.

To exercise any of this, email us. We answer within 30 days.

Children

Cyprian is not intended for anyone under 16, and we do not knowingly collect their data. If you believe a child has an account, tell us and we will remove it.

Changes

If we change this policy in a way that materially affects you, we will tell you in the app or by email before the change takes effect. The date at the top always reflects the current version.

Cyprian is operated by Cubeshell LLC.

Registered address: [TO BE COMPLETED BEFORE LAUNCH]

Questions, requests or complaints: hello@cyprian.ai

A mate who does the boring bit of posting.

hello@cyprian.ai

Product

  • How it works
  • Destinations
  • Web workspace
  • Get the app

Company

  • About
  • Stories
  • Questions
  • Status

Legal

  • Privacy
  • Terms
  • Security

© 2026 Cyprian. All rights reserved.