Privacy Policy
Last updated: February 2026
Kodah (“we,” “us,” or “our”) operates kodahbranding.com and provides an AI-powered social media content platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
1. Information We Collect
- Account Information: Name, email address, password (hashed), and billing details when you register.
- Social Media Tokens: OAuth access tokens and refresh tokens for connected social accounts (Facebook, Instagram, LinkedIn, Twitter/X). These are encrypted at rest and used solely to publish content on your behalf.
- Content You Create: Posts, captions, images, schedules, campaign briefs, and other content you generate or upload within Kodah.
- Usage Data: Log data including IP addresses, browser type, pages visited, features used, and session duration.
- Device Information: Hardware model, operating system, unique device identifiers, and mobile network information.
2. How We Use Your Information
- Operate the Service: Authenticate your account, process payments, schedule and publish social media content, and provide support.
- Generate Content: Pass your prompts and brand context to AI models to produce captions, copy, and creative assets on your behalf.
- Improve Our AI: Analyze aggregated, de-identified usage patterns to improve AI content quality. We do not use your personally identifiable content to train AI models without explicit consent.
- Communications: Send transactional emails (receipts, security alerts) and, with your consent, product updates.
- Security & Compliance: Detect and prevent fraud, abuse, and Terms of Service violations.
3. Third-Party Services
We work with carefully selected third parties to operate Kodah:
- Supabase: Database storage and authentication infrastructure. See supabase.com/privacy.
- Stripe: Payment processing. Kodah does not store full credit card numbers. See stripe.com/privacy.
- OpenAI: Content generation via API. We have opted out of OpenAI using API data for model training. See openai.com/policies/privacy-policy.
- Social Platforms: When you connect a social account, you authorize Kodah to interact with that platform’s API (Meta, LinkedIn, Twitter/X, etc.) on your behalf.
We do not sell your personal information to third parties.
4. Data Retention
We retain your data for as long as your account is active. If you cancel your subscription or delete your account, we will delete your personal data, content, and social media tokens within 30 days. We may retain billing records for longer periods where required by law.
5. Your Rights
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data or delete your account from settings.
- Export / Portability: Request an export of your data in a machine-readable format.
- Withdraw Consent: Where processing is based on consent, withdraw it at any time.
To exercise any of these rights, contact privacy@kodahbranding.com. We will respond within 30 days.
6. Security
We implement industry-standard security measures including TLS encryption in transit and at rest, access controls, and regular security reviews. Social media tokens are stored encrypted. No method of transmission over the Internet is 100% secure.
7. Children’s Privacy
Kodah is not directed to children under 13. We do not knowingly collect personal information from children. Contact us if you believe a child has provided us personal information and we will delete it promptly.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or by posting a notice on our platform.
9. Contact Us
Questions about this Privacy Policy? Contact us at privacy@kodahbranding.com.