Govoko Platform Privacy Policy

Last updated: 2026/09/10

Govoko (the "Platform") values your privacy. This policy explains how we collect, use, and protect your personal information.

1. Information We Collect

1.1 Registration Information

  • Email address, username, display name
  • Date of birth (for age verification)
  • Profile picture and bio
  • Social media links (optional)

1.2 Content Data

  • Creator-published content (photos, videos, text)
  • User comments, likes, and bookmarks
  • Subscription records and interaction history
  • Chat messages

1.3 Payment Information

  • Last four digits of credit cards (full numbers securely processed by Stripe)
  • Subscription plans and transaction records
  • Tips and content purchase records
  • Creator earnings and withdrawal records

1.4 Technical Data

  • IP address, browser type, operating system
  • Device identifiers
  • Website usage behavior (via Cookies)
  • System logs and error records

2. How We Use Your Information

2.1 Service Provision

  • Create and manage your account
  • Provide creator-fan interaction features
  • Process subscriptions, tips, and content purchases
  • Send important notifications and updates

2.2 Service Improvement

  • Analyze usage to optimize platform features
  • Personalized content recommendations
  • Improve user experience
  • Prevent fraud and abuse

2.3 Communication

  • Respond to customer inquiries
  • Send important notices (e.g., terms changes)
  • Provide marketing information (opt-out available)

3. Information Sharing

3.1 With Creators

When you subscribe or purchase content, creators can see:

  • Your display name and avatar
  • Subscription status and duration
  • Your comments and interactions

3.2 Third-Party Service Providers

  • Stripe: Secure payment processing
  • Cloudflare: Content delivery and security
  • Supabase: Database storage
  • AWS: Media file storage and processing

3.3 Legal Requirements

We may disclose your information when:

  • Complying with court orders or legal processes
  • Protecting platform, user, or public rights and safety
  • Preventing fraud or security threats
  • Cooperating with lawful law enforcement requests

4. Data Protection

  • SSL/TLS encryption for all sensitive data transmission
  • Encrypted database storage
  • Regular security vulnerability scanning and patching
  • Firewall and intrusion detection systems
  • Staff confidentiality agreements
  • Least privilege data access controls

5. Cookie Usage

5.1 Essential Cookies

  • Maintain login status
  • Remember language preferences
  • Security and protection mechanisms

5.2 Analytics Cookies

  • Understand platform usage
  • Content performance tracking
  • Platform performance monitoring

6. Your Rights

  • Access: Request to view collected personal data
  • Correction: Update or correct personal information
  • Deletion: Request account and data deletion
  • Portability: Request data export
  • Opt-out: Unsubscribe from marketing emails

7. Age Requirement

Users must be 18 years or older. We do not knowingly collect data from minors. If discovered, such data will be deleted immediately.

8. Data Retention

  • Account data: Active period + 30 days after deletion
  • Content data: Per creator settings
  • Payment records: 5-7 years as required by law
  • Technical logs: Auto-deleted after 90 days

9. International Data Transfers

Your data may be transferred to servers outside your country. We ensure recipients maintain equivalent data protection standards. Using our service indicates your consent to such transfers.

10. Policy Changes

We may update this Privacy Policy. Significant changes will be communicated via email or platform announcements.

11. Third-Party Social Platform Integration (Meta / Instagram / Threads)

When you use Govoko's "Social Publishing" feature to authorize a connection to your own Instagram Business or Threads account, the following terms apply:

11.1 Permissions Requested

  • instagram_business_basic: Read basic information about your Instagram Business account (account name, ID, profile picture, account type) so you can confirm the connected account in the Govoko dashboard.
  • instagram_business_content_publish: Publish reviewed images or short videos to your own Instagram Business account when you publish them manually, schedule them, or explicitly enable per-character synchronized publishing in Govoko.
  • instagram_business_manage_messages: Requested incrementally only when you separately enable Instagram messaging. It receives messages people initiate with your professional account and sends a reply only after you review, edit, and press send for that message. It never auto-replies or initiates contact with someone who has not messaged you.
  • threads_basic: Read basic information about your Threads account.
  • threads_content_publish: Publish text, image, or video content you have reviewed in Govoko to your own Threads account — either when you publish it yourself, or on a schedule you configure. Scheduling is off by default, and you can disable it or return to per-item approval at any time.
  • threads_read_replies / threads_manage_replies: Read replies on your own Threads posts and automatically create suggested drafts. A reply is sent only after you review, edit, and approve that item, and only from your own account.
  • threads_manage_insights: Read performance metrics for your own Threads content for creator dashboard analytics and suggestions.

11.2 Data We Store

  • Platform account ID (Instagram / Threads user_id)
  • Account username and display name
  • OAuth access token (encrypted at rest)
  • Token expiration and granted scopes
  • Connection and revocation timestamps for audit purposes
  • Instagram synchronized-publishing delivery records: source Threads post ID, caption, media type and URL, delivery status and attempt count, Instagram creation / media ID, permalink, error details, and related timestamps
  • Posts you publish through this platform and their results (post ID, permalink, timestamps)
  • Replies left on your posts by others: reply text, the replier's public account name and public avatar URL, reply ID and timestamps. Used solely to generate and send your reply, and deleted automatically after 90 days
  • Account-level performance metrics (aggregate reach, views, clicks) used to display results in your dashboard
  • Instagram direct messages people send to you: message text, the sender's platform-scoped ID, the sender's public account name, and timestamps. Used only to draft and send your reply, and only when you review each message and press send in your dashboard. We never auto-reply to direct messages and never message anyone who has not contacted you first. Deleted automatically after 90 days. Applies only if you have enabled messaging

11.3 Data We DO NOT Access, Store, or Share

  • Your follower or following lists
  • Any data about third parties who have not interacted with your posts
  • Any data unrelated to publishing, replying, or displaying your results
  • Any data unrelated to the publishing feature

11.4 Token Security and Retention

All access tokens are stored encrypted with AES-256-GCM; the encryption key is held separately from application data and is not distributed with the source code. Tokens are retained only while you maintain the connection. We immediately clear stored tokens when:

  • You manually click "Disconnect" in the Govoko dashboard
  • You remove the Govoko app authorization from your Instagram / Threads settings (triggered via Meta Deauthorize Callback)
  • You request deletion of your Govoko account (all tokens and related data are purged within 30 days)
  • The system detects the token has been revoked or invalidated by the platform

11.5 Data Deletion Requests

You can request deletion of Instagram / Threads-related data we hold via any of the following:

  • Click "Disconnect" on the Govoko "Social Connections" page
  • Remove the Govoko app in Instagram / Threads settings — Meta will automatically notify our platform to purge data
  • Email a written request to support@govoko.com

When we receive a Meta Data Deletion or Deauthorize callback, we clear the token and account connection data and also delete Instagram synchronized-publishing delivery records for the affected creators that own those connections.

The following callback endpoints are registered with Meta to handle these requests:

  • Data Deletion Callback: https://govoko.app/api/meta/data-deletion
  • Deauthorize Callback: https://govoko.app/api/meta/deauthorize

11.6 User Responsibilities

By using the social publishing feature, you represent and warrant that:

  • You are the legitimate owner of, or have explicit authorization for, the connected Instagram / Threads account
  • You will not use this platform for spam, impersonation, coordinated inauthentic behavior, or any violation of Meta Community Standards
  • All content is published only to accounts you have authorized, and is sent by your manual action, by a schedule you configured, or by automation you explicitly enabled. You can switch to per-item review or disable automation at any time

12. Contact Us

For privacy policy questions, contact: support@govoko.com