Legal
Privacy Policy
Last updated: May 2025
1. What We Collect
When you use Resonate, we collect and process the following data:
- Account data: your name, email address, and profile picture provided during sign-up.
- LinkedIn data: your LinkedIn profile information, posts, and engagement metrics - only when you explicitly connect your LinkedIn account.
- Integration data: content from third-party services you connect (e.g. Notion, Slack, Google Drive) - only when you authorize each connection.
- Generated content: AI-generated post ideas, drafts, and conversation history created within the app.
- Usage data: pages visited, features used, and interaction patterns within the application.
2. Where Your Data Is Stored
Your data is stored securely on Base44's managed cloud infrastructure (hosted on AWS). Third-party API credentials (LinkedIn via Unipile, Stripe for payments) are stored as encrypted server-side environment variables and are never exposed to the browser or frontend code.
3. How We Use Your Data
We do not sell your data to third parties. We do not use your data to train AI models.
- To generate personalized content ideas and LinkedIn post drafts using AI.
- To analyze your writing tone and match it in generated content.
- To manage your post scheduling and publishing workflow.
- To process payments and manage your subscription.
4. Third-Party Services
We use the following third-party services to operate Resonate:
- Unipile - to connect to and interact with your LinkedIn account.
- Stripe - to process subscription payments securely.
- AI providers - to generate content ideas and drafts. Your data is sent as prompts to models that do not retain or train on user inputs.
5. Your Rights (GDPR)
If you are in the EU/EEA, you have the right to:
- Access - download a complete export of your data at any time from Settings > Data & Privacy.
- Rectification - update your profile and content directly in the app.
- Erasure - permanently delete all your data from Settings > Data & Privacy.
- Portability - export your data in a machine-readable JSON format.
- Objection - disconnect any integration or stop AI processing at any time.
To exercise these rights, use the self-service tools in the app or contact us at tom@getresonate.ai.
6. Data Retention
We retain your data for as long as your account is active. If you delete your data or account, all personal data is permanently removed within 30 days. Anonymized, aggregated analytics may be retained for product improvement.
7. Security
- All API keys and secrets are stored server-side only - never in frontend code or browser storage.
- All communication is encrypted via HTTPS/TLS.
- Authentication is managed with secure token-based sessions.
- Backend functions validate user identity before processing any request.
- Stripe webhook signatures are cryptographically verified.
- Row-level security (RLS) ensures users can only access their own data.
- Error responses are sanitized - no internal stack traces or system details are exposed.
8. Cookies
We use essential cookies only for authentication and session management. We do not use advertising or tracking cookies.
9. Children's Privacy
Resonate is not intended for use by anyone under 18 years of age. We do not knowingly collect data from minors.
10. International Transfers
Your data may be processed in servers located outside your country of residence. We ensure appropriate safeguards are in place in accordance with applicable data protection laws.
11. Changes to This Policy
We may update this privacy policy from time to time. Material changes will be communicated via email or in-app notification. The "Last updated" date will always reflect the most recent revision.
12. Contact
For privacy-related questions or data requests, contact us at tom@getresonate.ai.