Last updated: 8 October 2026
Privacy Policy
This Privacy Policy describes how Socialligator ("we", "us") collects, uses and protects information when you use the Socialligator application and related services (the "Service"). Socialligator is built for solo founders running their own products.
1. Who is responsible
The data controller for your account data is [COMPANY NAME], [REGISTERED ADDRESS], registered under [SIREN / REGISTRATION NUMBER]. Contact: support@socialligator.com. Full company details are on our legal notice.
For data about the visitors of the sites, funnels and feedback hubs you publish with Socialligator, you are the controller and we process that data on your behalf: see published sites and funnels and feedback hubs.
2. What we collect
- Account data: email address, name (optional), password hash, plan, credit balance and billing status.
- Content you create: projects, tasks, notes and voice notes, knowledge base documents, chat transcripts, funnels, sites and generated marketing assets.
- Your contacts: the people and deals in the built-in CRM, including leads captured by your forms and chatbot.
- Connected services: when you connect a payment provider, ad platform, social account, mailbox or email service (by OAuth or API key), we store the encrypted credentials and the data you authorise us to sync.
- Analytics of your sites: page views, sessions and events measured on the sites and funnels you publish (details on the processing page).
- Service logs: timestamps, requests and error traces used to run and secure the Service. We use no third-party analytics or advertising cookies on Socialligator itself.
3. Browser extension
The optional Socialligator browser extension connects one browser at a time to your workspace, each with its own access token that you can disconnect at any time (Settings → Browser extension, or API & agents).
- Captures: only when you click save, the page title, its address, the text you selected and, on LinkedIn, the visible name and headline are sent to your workspace to create the task, note, document, contact or company you chose.
- Focus Guard: your distraction list stays in your browser. Page addresses are compared with it inside the browser and are never sent to us.
- Notes on pages: your highlights, sticky notes, checklists and drawings are stored in your browser. When you turn on sync (you are asked first), they are copied to your workspace with the page title and address (tracking and token-like parameters removed), visible only to you, so they follow you to your other browsers and show in the app. Deleting a note deletes it everywhere; your synced notes are deleted when you leave a workspace.
- Page context: while the side panel shows the page you are on, the extension sends its host name (and, on a LinkedIn profile or company page, that page's address) so your workspace can show what it already knows about it. This is never stored or logged and can be turned off in the extension's settings.
- Site audit: runs inside your browser on the page you are on. Only when you ask for a PageSpeed test is the page address sent to Google PageSpeed Insights, from your browser.
- Mentor: the questions you type, and when you choose to share the page, its title, link, readable text and your highlights on it (each shown and switchable before sending), are sent to the AI Mentor.
- The access token is kept in the extension's own storage. The extension cannot delete your records or send, publish or enroll anything on your behalf.
4. How we use it
- To provide, maintain and secure the Service, and to enforce plan limits and credits.
- To send transactional emails (sign-in and password reset, billing, security and service notices). We do not send marketing emails unless you opt in.
- To generate the AI outputs you request: your prompt and the context needed for it are sent to the AI processors listed below for that request only.
5. What we do not do
- We do not sell your data.
- We do not use your content to train AI models, and we do not share it with advertisers.
- We only share data with the processors listed in section 6, to run the Service.
6. Processors
We use these providers to run the Service:
- Hosting: Hetzner Online GmbH (Germany). Our servers, the PostgreSQL database, the ClickHouse analytics database and Redis are self-hosted on Hetzner servers in the European Union. Daily backups are encrypted before they leave the server and are stored with Backblaze B2.
- Cloudflare: DNS, custom hostnames for short links on your domains, Turnstile bot checks on some forms, and Cloudflare Pages when you publish a generated site there.
- AI: most AI requests go through the TeamoRouter model gateway, with OpenRouter as the fallback for chat. Embeddings, voice-note transcription and some models go through OpenRouter, image generation and editing through Runware, and text-to-speech through OpenAI. When we configure a model provider directly (OpenAI, Anthropic or Google), it receives requests the same way: only what the request needs.
- Payments you connect: Stripe, Paddle, Lemon Squeezy, Creem and Whop, only when you connect your own account to sync your revenue. Your customers' card details never reach us.
- Our own billing: Stripe, or Creem acting as merchant of record, processes your subscription and top-up payments. We never see your card number.
- Email delivery: Resend, Brevo or our SMTP provider for platform emails; for the emails you send to your contacts, the email service you connect (SMTP, Resend or Brevo). If you connect an email marketing tool, the contacts you choose to sync are sent to it.
- Backblaze B2: encrypted off-site backups of our databases (retained up to 8 weeks).
- Gmail (optional): when you connect your mailbox through Google OAuth, to read and send email from Socialligator.
- Serper and DataForSEO: search results, keyword ideas and search volumes for the SEO features. Only your keywords and queries are sent.
- Treg (optional, your own account): when you save your own Treg token, the social, ad and Google accounts you connect through Treg, and the SEO data calls, go through your Treg account. Treg receives what each request needs (the post you publish, the keywords you research, the report you ask for) and bills you directly. We store your token encrypted and keep a record of each call (feature, cost, Treg's call id) for 180 days.
- Sentry (optional): error reports, when enabled, to fix bugs.
- Platforms you connect: ad and social platforms (for example Meta, TikTok, Google, LinkedIn) and scheduling tools (Cal.com) receive what you ask us to publish or send, such as posts or conversion events.
7. Retention
- Account data and content: for as long as your account exists.
- Analytics events of your sites are stored in ClickHouse and deleted automatically after your plan's retention period: Free 180 days, Starter 1 year, Pro 2 years, Scale 5 years.
- Encrypted backups are kept for up to 8 weeks, then deleted.
8. Your rights
You can export your data and delete your account from the Settings page. Deleting your account removes it, its personal data and every business it owns; copies in backups expire with the backup rotation above. You can also ask for access, correction, erasure, restriction or portability, or object to processing, by emailing support@socialligator.com. If you are in the EU, you can complain to your data protection authority (in France, the CNIL).
9. Cookies
Socialligator only sets cookies that are strictly necessary or remember your choices:
- Session and CSRF cookies (Auth.js): keep you signed in and protect forms.
- Onboarding and preference cookies: remember that you finished onboarding, your feature preferences and your onboarding profile, so the app does not ask again.
- Active business: remembers which business you are working in.
- Sidebar state: remembers whether the app sidebar is open (7 days).
No tracking or advertising cookies are set on Socialligator. Cookies on the sites you publish are described on the processing page.
10. Children
The Service is not intended for anyone under 16 and we do not knowingly collect data from them.
11. Changes
If we change this policy materially, we will notify users by email before the change takes effect.
12. Contact
Questions? Email support@socialligator.com.