Privacy Policy
Effective 9 October 2026. Last updated 9 October 2026.
This policy explains what personal data Contark collects, why, how long we keep it, who we share it with and how you can control or delete it. It also explains exactly what we do with data from the social media accounts you connect to Contark.
1. Who we are
Contark (contark.com) is a content planning, scripting, publishing and analytics service for creators, brands and agencies. It is operated by Coldabry LLC, a limited liability company registered in the United States, 1209 Mountain Road Pl NE #4337, Albuquerque, NM 87110, USA (EIN 38-4259144).
Coldabry LLC is the data controller for account data and the data processor for content and social media data that your organization brings into Contark. For any privacy question or request, write to rk@coldabry.com.
2. Data we collect
- Account data: your name, email address, password (stored only as a salted hash), the organizations and projects you belong to and your role in them.
- Content you create or import: strategies, ideas, scripts, plans, notes, uploaded files, inspirations you save, transcripts and analytics you import.
- Data from connected platforms: described in section 3, only after you connect an account and only within the permissions you grant.
- Usage and technical data: sign-in times, actions you take in the app (for example, which script was approved), credit usage, IP address and browser type in server logs, kept for security and abuse prevention.
- Billing data for prepaid balances (for example, the X API balance): amounts, dates and references. We do not store payment card numbers.
3. Data from connected social media accounts
You can connect accounts on social platforms to a Contark project so that Contark can publish, schedule, read analytics and manage comments for you. Connecting is always your choice, made by signing in on the platform's own page and approving the permissions shown there. We request only the permissions needed for the features you use. Contark does not read or send private or direct messages on any platform.
| Platform | What we read and store | What we do on your behalf |
|---|---|---|
| Instagram (professional accounts) | Account id, username, name, profile picture, follower count; your published media and captions; media and account insights (reach, views, likes, comments, saves, shares); comments on your media. | Publish and schedule posts, reels and stories; reply to, hide or delete comments on your media. |
| Facebook Pages | Ids, names and pictures of the Pages you choose; Page posts; Page and post insights; comments on Page posts. | Publish and schedule Page posts; reply to, hide or delete comments on Page posts. |
| Threads | Profile id, username, picture; your threads and replies; thread insights. | Publish and schedule threads; reply to and manage replies to your threads. |
| X | User id, username, name, picture; your posts; post metrics; replies and mentions of your account. | Publish and schedule posts; reply to posts. X charges for API use, paid from your organization's prepaid balance. |
| LinkedIn (profile and Pages) | Member id, name, profile picture and email from Sign In with LinkedIn; for Pages you administer: Page id, name, logo, posts, post and follower statistics, comments. | Publish and schedule posts on your profile or Pages; reply to comments on Page posts. |
| Bluesky | DID, handle, display name, avatar; your posts; likes, reposts and replies to your posts. | Publish and schedule posts; reply to posts. |
| YouTube | Channel id, title and thumbnail; your videos and their metadata; YouTube Analytics reports for your channel; comments on your videos. | Upload and schedule videos and update their metadata; reply to comments on your videos. |
| Google Business Profile | Account and location names and ids; posts; reviews; performance metrics. | Publish posts; reply to reviews. |
| TikTok | Open id, display name, avatar; your public videos and their statistics. | Upload and publish videos you approve in Contark. |
| Account id, username, boards, your pins and pin analytics. | Create pins on boards you choose. | |
| Medium and WordPress | Account or site id, name and URL; posts published through Contark. | Publish posts as drafts or live, as you choose. |
Platforms are added to Contark over time. A platform appears in Settings, Integrations only when its integration is available, and this table lists the maximum we will ever request from it.
4. Google and YouTube
Contark's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- we use Google user data (YouTube and Google Business Profile) only to provide and improve the user-facing features you see in Contark;
- we do not sell it, do not use it for advertising, and do not transfer it to others except as needed to provide those features, to comply with law, or as part of a merger or acquisition with notice to you;
- no person reads it unless you ask us to (for support), it is needed for security, or the law requires it;
- we do not use it to develop, improve or train generalized artificial intelligence or machine learning models.
Contark uses YouTube API Services. By connecting a YouTube channel you agree to the YouTube Terms of Service, and Google's Privacy Policy applies to data Google processes. You can revoke Contark's access at any time in your Google account security settings, in addition to disconnecting in Contark.
5. Meta: Facebook, Instagram and Threads
Data from Meta platforms is used only to provide the features in section 3 and in line with the Meta Platform Terms. We do not use it for advertising, do not sell it and do not combine it with data from other sources to profile you. If you remove Contark from your Facebook, Instagram or Threads settings, Meta notifies us and we delete the related connections and tokens automatically. You can follow the status of such a request on our data deletion page.
6. How we use data
- To run the service you asked for: plans, scripts, publishing, analytics and comment management (legal basis: performance of a contract).
- To keep the service secure, prevent abuse and fix errors (legitimate interest).
- To send service emails such as invitations and password resets. We do not send marketing email without consent.
- For AI features: when you use a feature that writes or analyses with an AI model, the text or metrics needed for that request are sent to the model provider your organization connected (for example OpenRouter), solely to return the result to you. Data from connected platforms is never used to train AI models, by us or by the model provider at our request.
7. How we store access tokens
When you connect an account, the platform gives Contark access and refresh tokens. We store them encrypted at rest (AES with HMAC authentication, Fernet), with the encryption key kept outside the database. Tokens are decrypted only in the server process that calls the platform. They are never shown in the app, never included in exports and never available through Contark's API or MCP tools. Our database enforces row-level security, so one organization's tokens and data cannot be read in the context of another organization.
8. Who we share data with
We do not sell personal data. We share it only with service providers that help us run Contark, under contracts that limit their use of it:
- Contabo GmbH: application servers and database, located in the European Union (France).
- Hetzner Online GmbH: encrypted off-site backups, located in Germany.
- Brevo (Sendinblue SAS): delivery of service emails.
- Cloudflare, Inc.: DNS and email forwarding for contark.com.
- Google: web fonts loaded by our pages (your IP address reaches Google when they load).
- AI model providers your organization configures, only for the AI requests described in section 6.
- The social platforms you connect, to perform the actions you request (for example, publishing a post).
We may disclose data if the law requires it, or to protect the rights, property or safety of our users or others.
9. How long we keep data
- Access tokens: while the account stays connected. Deleted immediately when you disconnect, when the platform tells us you removed Contark, or when your organization is deleted.
- Data fetched from platforms (posts, metrics, comments): while your organization uses Contark, refreshed regularly, and deleted within 30 days after the related account is disconnected or your organization is deleted. Platform data is not kept longer than each platform's terms allow.
- Account and content data: while your account is active, and deleted within 30 days after you ask us to delete it.
- Backups: rotated automatically and fully overwritten within 90 days.
- Server logs: up to 90 days.
10. Disconnecting and deleting data
- Disconnect an account at any time in Contark (Settings, Integrations). We revoke access at the platform where it supports that and delete the tokens immediately.
- You can also revoke access on the platform itself; see our data deletion instructions for each platform.
- To delete your Contark account and all its data, email rk@coldabry.com from the address you sign in with. We confirm and complete deletion within 30 days.
11. Your rights
Depending on where you live (for example under the EU and UK GDPR or US state privacy laws), you can ask us to access, correct, delete or export your personal data, to restrict or object to processing, and to withdraw consent. Write to rk@coldabry.com; we answer within 30 days. You may also complain to your local data protection authority. If your organization added you to Contark, some requests are handled together with that organization, which decides what content it keeps.
12. Security
Data is encrypted in transit (HTTPS with HSTS) and access tokens are encrypted at rest. Passwords are hashed. Each organization's data is isolated at database level, application access uses a role that cannot bypass that isolation, and we keep daily backups with tested restores. No system is perfectly secure; if a breach affects your data, we will notify you and the authorities as the law requires.
13. International transfers
Coldabry LLC is based in the United States and our servers are in the European Union. Where personal data moves between the EU and the US, we rely on the European Commission's Standard Contractual Clauses or another lawful transfer mechanism.
14. Cookies
Contark uses only cookies needed to run the service: a session cookie that keeps you signed in, and cookies that remember your selected organization, project and theme. We do not use advertising or analytics cookies.
15. Children
Contark is a business tool and is not directed to anyone under 16. We do not knowingly collect data from children.
16. Changes and contact
We will post any change to this policy on this page and update the date at the top. For material changes we will also notify account owners by email before they take effect.
Coldabry LLC, 1209 Mountain Road Pl NE #4337, Albuquerque, NM 87110, USA. Email: rk@coldabry.com.