AjinsyBack home

Ajinsy Privacy Policy

Effective date: 31 July 2026

Last updated: 31 July 2026

Ajinsy ("Ajinsy", "we", "us") is an operating system for social media agencies, available at ajinsy.com. This policy explains what personal data we collect, why, and what rights you have.

Ajinsy is an independent service run as a sole proprietorship. For anything privacy related, write to support@ajinsy.com and we will handle it directly.

1. The two hats we wear

Ajinsy is a tool agencies use to manage their own clients, so we handle data in two distinct roles:

  • As a controller for data about you and your account: your name, email, password, workspace settings, billing status, and how you use Ajinsy. This policy covers that data.
  • As a processor for data your agency puts into Ajinsy about its own clients: intake answers, brand assets, strategies, content, feedback, and stored logins. Your agency decides what goes in and who sees it; we store and process it only to provide the service, on the agency's instructions. If you are an end client of an agency that uses Ajinsy, contact that agency about your data; they are the controller.

2. What we collect

Account data. Name, email address, and a password (stored only as a bcrypt hash; we cannot read it). Optionally a profile photo. If you join by invite, the inviting agency provided your email.

Workspace data. Agency name, branding (logo, colors), timezone, plan tier, team members and their roles, and settings.

Content your agency creates or uploads. Client profiles, intake form answers, strategies, content calendars, posts, review feedback, reports, and uploaded media. This can include personal data about your agency's clients; for that data we act as processor (see section 1).

Stored client logins. If an agency's client shares social media credentials through intake, or a team member adds them manually, the password is encrypted at rest with AES-256-GCM. Revealing a stored password is restricted to workspace owners and managers, and every reveal is logged and visible to the workspace.

Billing data. Payments are handled by Dodo Payments as merchant of record. We never receive or store card numbers. We store your plan tier, billing interval, subscription status, and payment-provider references.

Product analytics. To understand how the product is used, we record page views and a small number of named in-page actions. Each record holds the route pattern (for example "/clients/[id]/strategy", never the record id itself), a randomly generated visitor id kept in your browser's local storage, a per-tab session id, and, on the first event of a session, the referring URL and any utm_source, utm_medium, and utm_campaign values on the landing URL. This data is first party, is not sold or shared, is never used for advertising, and is not linked to your account. We do not store IP addresses in this analytics data.

Usage and technical data. Server logs (including IP address, request time, and user agent) kept for security and debugging, and error reports (see Sentry below).

Support communications. Messages you send through the in-app support chat, the contact form, or by email. The support chat starts with an AI assistant and can be escalated to a human; when it is escalated, the conversation is relayed to us over Telegram so we can reply (see section 6).

3. What we use it for, and on what legal basis

Where the EU or UK GDPR applies to you, these are the legal bases we rely on. Where other data protection laws apply, we rely on the equivalent lawful bases.

  • Providing the service (accounts, workspaces, content, calendar, review flows), using account, workspace, and content data. Basis: contract.
  • Payments and subscription management, using billing data. Basis: contract.
  • Transactional email (invites, password resets, review notifications), using your email address. Basis: contract.
  • AI features (strategy drafts, content plans, ideas, trends, pre-review), using the content you ask the AI to work on. Basis: contract.
  • Support (in-app chat, contact form, email), using your support communications. Basis: contract and legitimate interest.
  • Understanding product usage, using product analytics. Basis: legitimate interest.
  • Improving our AI features (see section 5), using filtered interaction examples. Basis: legitimate interest, with a workspace-level opt-out.
  • Security, abuse prevention, and debugging, using logs and error reports. Basis: legitimate interest.
  • Legal obligations (accounting, tax), using billing records. Basis: legal obligation.

We do not sell personal data. We do not run advertising or share data with ad networks.

4. AI processing

When you use an AI feature (drafting a strategy, generating a content plan, asking for ideas or trends, AI pre-review, caption rewrites, or the support assistant), the relevant content is sent to an AI provider to generate the response. Depending on the task and our configuration, that provider is one of:

  • OpenAI (USA), including live trend search.
  • Anthropic (USA).
  • DeepSeek (China).

We send only what the feature needs (for example, the client's brief, stored brand rules, and the text being worked on). We do not send your account password, stored client logins, or billing data to AI providers. AI requests are made server side under our API agreements with these providers; we do not use consumer chat products for your data.

If your workspace prefers that its content is not processed by a particular provider, contact us; Enterprise plans can arrange restricted AI routing.

5. Improving our AI (training data), and how to opt out

To make Ajinsy's AI better at agency work, we collect examples of AI interactions from workspaces: for example, a change request and the revision that satisfied it. Before storage, examples pass a quality filter, and this dataset is used only to improve Ajinsy's AI features. We do not sell it, license it, or share it with third parties.

Opt-out: workspace owners can turn this off at any time in Settings under Data collection. Opting out stops new collection immediately; on request we also delete previously collected examples from your workspace.

6. Who else touches your data (subprocessors)

  • Hetzner Online GmbH (Germany, EU): application and database hosting.
  • Dodo Payments (USA / India): payments, as merchant of record.
  • Resend (USA): transactional email delivery.
  • Sentry (EU data residency): error monitoring.
  • OpenAI (USA): AI processing.
  • Anthropic (USA): AI processing.
  • DeepSeek (China): AI processing.
  • Telegram (international): relaying escalated support conversations to us.
  • Google (USA / global): media storage through the Drive API, only if your agency connects Google Drive.

Where a provider is outside the EEA, transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision, per the provider's data processing agreement. Where we handle EU personal data outside the EEA ourselves, we rely on appropriate safeguards under the GDPR.

Support over Telegram. When a support conversation is escalated to a human, the conversation text and the workspace and sender it came from are relayed through Telegram so we can respond. Do not put passwords or other secrets into support chat.

Google Drive. If your agency connects Google Drive, uploaded media is stored in your agency's own Drive, not on our servers. We store an encrypted refresh token to access it on your behalf. Our use of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements: Drive access is used only to store and retrieve your agency's media, never for advertising, and never transferred to third parties except as needed to provide that feature.

7. Cookies and local storage

We use only what the product needs:

  • A session cookie to keep you signed in (essential).
  • A preference cookie remembering your last opened client (functional).
  • Local storage for your light/dark theme choice, and for the randomly generated analytics visitor id described in section 2.
  • Session storage for the per-tab analytics session id.

No advertising cookies, no cross-site trackers, no fingerprinting, and nothing shared with third-party ad networks. If you would rather not be counted in product analytics, clear your browser storage for ajinsy.com or tell us and we will exclude you.

8. Retention

  • Account and workspace data: kept while your account is active. If you delete your workspace, its content is deleted from the live database within 30 days; encrypted backups roll off within 30 further days.
  • Stored client logins: deleted immediately when removed in the vault, or with the client, or with the workspace.
  • Training examples: kept until you opt out and request deletion, or until we no longer need them.
  • Product analytics: kept up to 24 months, then deleted.
  • Server logs: up to 90 days.
  • Support conversations: kept up to 24 months so we have context on past issues.
  • Billing records: as long as applicable tax law requires (at least five years).

9. Security

  • Passwords are hashed with bcrypt; stored client logins and OAuth tokens are encrypted at rest with AES-256-GCM.
  • All traffic is encrypted in transit (TLS), including client-facing subdomain pages.
  • Role-based access inside workspaces; freelancers only see clients assigned to them.
  • Password reveals and platform-admin support actions are audit logged.
  • Database backups run nightly and are kept on a rolling schedule.
  • Access to production systems is restricted to one authorized person using key-based authentication.

No system is perfectly secure. If we learn of a breach affecting your personal data, we will notify you and the relevant authority as the law requires.

10. Your rights

You can ask us to:

  • Access the personal data we hold about you;
  • Correct inaccurate data;
  • Delete your data;
  • Export your data in a portable format;
  • Restrict or object to certain processing, including the legitimate-interest processing above;
  • Withdraw consent where processing is based on consent.

Write to support@ajinsy.com. We respond within one month.

You can also complain to your local data protection authority. In the EEA and the UK, that is the supervisory authority for the country you live in.

If your data was entered into Ajinsy by an agency (you are their client), direct requests to that agency; we will assist them as their processor.

11. Children

Ajinsy is a business tool, not directed at children, and we do not knowingly collect data from anyone under 16.

12. Changes

We will post changes here and update the date at the top. For material changes we will email workspace owners before they take effect.

13. Contact

Ajinsy

Email: support@ajinsy.com