Skip to main content

ProfileScribe legal

Privacy Policy

How ProfileScribe collects, uses, stores, shares, retains, and deletes professional profile data, approved source material, connected-account data, OAuth credentials, and publishing records.

Last updated: August 24, 2026

Data ProfileScribe Processes

Account and authentication data: name, email address, stable user and workspace identifiers, sign-in and verification records, account settings, and subscription or entitlement status.

Professional profile and approved-source data: work history, skills, projects, portfolio material, writing, public professional links, approved source URLs, source observations, and facts or corrections a user provides.

Generated and publishing data: drafts, media references, review decisions, publishing mode and destination selections, published-post identifiers and permalinks, delivery attempts, receipts, agent activity, and feedback used to improve later drafts.

Connected-platform data: provider account identifiers and display information needed to identify a selectable destination, such as a Facebook Page ID and name or an Instagram professional-account ID and username; granted permissions; encrypted access credentials; token expiry; connection health; and API results needed to complete and verify an authorized action.

Operational data: job status, timestamps, error and retry information, security and audit events, support correspondence, and limited technical records needed to protect the service, diagnose failures, enforce permissions, and prevent duplicate delivery.

Why ProfileScribe Processes Data

ProfileScribe uses account and professional data to authenticate users, maintain their profile, crawl only approved sources, identify source-backed changes, generate professional drafts, and show the user what the agent found or changed.

ProfileScribe uses connected-platform data to complete OAuth, list destinations the user is authorized to manage, let the user select a destination and publishing mode, publish only within the granted scope, check connection health, and record a receipt that explains what happened.

ProfileScribe uses operational and billing data to provide paid features, secure the service, enforce user permissions, schedule and retry authorized work safely, prevent duplicate posts, respond to support requests, investigate abuse or failures, and comply with applicable law and platform rules.

ProfileScribe does not sell connected-account or Meta Platform Data, use it for advertising, or use it to build unrelated profiles. Data received from Meta is used only to provide and secure the Facebook Page or Instagram professional-account features the user chose.

Connected Accounts, OAuth, and Publishing Control

When a user connects an external service, ProfileScribe uses OAuth or provider-issued credentials and requests only the permissions shown in the provider consent flow. Access credentials are encrypted at rest and are not displayed back to the user.

Users choose whether a connected destination is draft-only, review-first, or autopublish. ProfileScribe agents may publish only meaningful, source-backed professional updates within that configured scope. Users can change publishing mode, disconnect an account, remove an assisted account, and delete its stored credentials from the Distribution page.

Disconnecting stops ProfileScribe from making new requests with the stored connection and removes the credentials where the product indicates. A user can also revoke ProfileScribe directly in Facebook or Instagram settings. Disconnecting or revoking a provider connection does not by itself delete the user's entire ProfileScribe account or all historical ProfileScribe records; use the deletion process below for that request.

Sharing and Service Providers

ProfileScribe sends data to a connected platform only as needed to perform the action the user authorized. For example, it sends approved post content to the selected Facebook Page or Instagram professional account and stores the provider response needed for the delivery receipt.

ProfileScribe also uses contracted infrastructure, authentication, email, source-retrieval, and model providers to operate the service. Those providers process data only for the service functions assigned to them and are not authorized by ProfileScribe to sell it or use it for their own advertising.

Public profiles and timeline posts are visible to visitors and may be indexed by search engines. Private app pages, settings, encrypted credentials, internal agent controls, and non-public source records are not public profile content.

Retention

ProfileScribe keeps account, profile, approved-source, connection, draft, and publishing records while the account is active or while they are needed to provide the service. A user can remove source links and connected accounts earlier. Encrypted provider credentials are deleted when the corresponding connection is removed through the supported disconnect flow.

After a verified deletion request, ProfileScribe deletes or de-identifies the requested account data unless limited records must be retained for security, fraud prevention, legal compliance, dispute resolution, or accounting. Any retained exception is restricted to that purpose and kept only as long as required. Backup copies age out under the applicable backup-retention cycle.

How to Request Data Deletion

To request deletion of ProfileScribe data, email notifications@profilescribe.com from the email address associated with the ProfileScribe account. Use the subject “Data deletion request” and identify the ProfileScribe account plus any connected Facebook Page or Instagram professional account whose records should be included. Do not send passwords, access tokens, or other credentials.

ProfileScribe will verify that the requester controls the account before acting. After verification, ProfileScribe will delete or de-identify the requested ProfileScribe profile, approved-source records, drafts, internal posts, connected-account metadata, encrypted Meta credentials, and related service records, subject only to the limited retention exceptions above. ProfileScribe will confirm completion or explain any narrow record that must temporarily be retained.

Deleting ProfileScribe records does not automatically remove content that was already published to Facebook, Instagram, or another external service. The user can delete that content on the external service or identify it in the request so ProfileScribe can explain or use any deletion capability available to the connection. Revoking ProfileScribe in Facebook or Instagram settings is an additional way to stop future Meta data access.

Questions and Requests

For privacy questions, access or correction requests, connected-account questions, or a data-deletion request, contact ProfileScribe at notifications@profilescribe.com.