Privacy Policy
Last updated: April 29, 2026
This Privacy Policy explains how Content Factory ("we", "us", "our", "the Service")
operated by AUTMZR collects, uses, stores, and protects information when you use our social media
management platform available at cf.autmzr.ru and
cf.autmzr.com (together, "the Sites").
The Service helps content creators, marketers, and small businesses schedule and publish posts
across multiple social media networks from a single interface.
1. Information We Collect
1.1 Information you provide
- Account information: name, email address, password (hashed), and organization name when you register.
- Content you create: text, images, videos, scheduled posts, drafts, brand voice profiles, and posting preferences.
- Communications: messages you send to our support team.
1.2 Information from connected social media accounts
When you connect a social media account (Facebook Page, Instagram Business, Threads, TikTok,
LinkedIn, YouTube, Telegram, VK, MAX, Dzen), the Service receives, with your explicit authorization, only the
data necessary to publish your content and read related metadata:
- Profile basics: account name, ID, profile picture, username, account type (e.g. Business / Creator).
- Pages and channels you administer: list of Pages or communities you manage, their IDs and names.
- Authentication tokens: OAuth access tokens and refresh tokens issued by the platform, stored encrypted (AES-256-GCM at rest) and used solely to perform actions you initiate.
- Engagement metadata: aggregate account statistics (follower count, following count, total likes, number of posts) and view / like / comment / share counts for your public posts, retrieved on demand to build the analytics screen. We read counts only — never the identities of the people behind them.
We do not request or store private messages, friends/followers lists, audience personal data,
location data, or contact lists.
1.3 Automatic information
- Operational logs: timestamps of API calls, IP address (for security), browser user-agent, and post IDs.
- Cookies: a session cookie to keep you signed in. We do not place advertising or analytics tracking cookies.
2. How We Use Information
- To authenticate you and operate your account.
- To publish content you author to the platforms you have connected, on your explicit instruction.
- To display analytics (post performance, engagement counts) for posts you published through the Service.
- To provide customer support and respond to inquiries.
- To detect and prevent abuse, fraud, and platform-policy violations.
- To improve the Service (anonymized, aggregated metrics only).
We do not use your data for advertising, profiling, or sale to third parties.
3. How We Share Information
We share information only in the following limited cases:
- With the social platforms you connect (Meta, TikTok, LinkedIn, Google, Telegram, VK, MAX) — we relay your post content and use authorization tokens to act on your behalf via their official APIs.
- With infrastructure providers who process data on our behalf under written data-processing agreements:
- Cloudflare, Inc. — content delivery and DDoS protection.
- Anthropic PBC — generative AI for optional draft assistance (only on your explicit request).
- OpenRouter / image-generation providers — only when you choose AI image generation.
- Cloud storage providers — to host media you upload.
- For legal compliance — when required by valid legal process (subpoena, court order) under applicable law.
- In a business transfer — if we are acquired or merged, with continuity of this Privacy Policy.
We do not sell, rent, or trade your personal information.
4. Data Retention
- Account information: retained while your account is active.
- Authentication tokens: retained until you disconnect the channel or revoke access on the platform.
- Posts and drafts: retained until you delete them.
- Operational logs: retained for 90 days, then automatically deleted.
- Backup snapshots: retained for up to 30 days, then rotated out.
- After account deletion: all primary data is purged within 30 days; backups within 60 days.
5. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: request a copy of personal data we hold about you.
- Rectification: correct inaccurate or incomplete data.
- Erasure ("right to be forgotten"): delete your data — see Support and Data Deletion.
- Restriction: limit how we process your data.
- Portability: receive your data in a machine-readable format.
- Objection: object to specific processing activities.
- Withdraw consent: revoke previously granted permissions at any time, without affecting prior lawful processing.
For California residents (CCPA): you have the right to know what personal information
we collect, to request deletion, and to opt out of any sale of personal information (we do not sell).
We do not discriminate against users who exercise these rights.
For EEA / UK residents (GDPR): the lawful bases on which we process your data are
(a) performance of contract (Article 6(1)(b)), (b) consent for optional features (Article 6(1)(a)),
and (c) legitimate interest in operating and securing the Service (Article 6(1)(f)).
To exercise any right, contact us at fdrvaa84@gmail.com.
We respond within 30 days.
6. Children's Privacy
The Service is not directed at children under 13 (or 16 in the EEA). We do not knowingly collect
information from children. If you believe a minor has provided us information, contact us — we will
delete it.
7. International Data Transfers
The Service is operated from servers located in Kazakhstan, with content delivery through
Cloudflare's global network. By using the Service, you consent to your data being transferred,
stored, and processed in jurisdictions outside your country of residence. Where such transfers
occur from the EEA, we rely on appropriate safeguards (Standard Contractual Clauses).
8. Security
- All connections are encrypted with TLS 1.2 or higher (Let's Encrypt certificates).
- Authentication tokens and sensitive fields are encrypted at rest using AES-256-GCM.
- Servers are firewalled; access is restricted by SSH keys and multi-factor authentication.
- We follow the principle of least privilege for internal staff access.
- Security incidents are reviewed and, where required, reported within 72 hours.
9. Third-Party Services
The Service connects to third-party APIs as you direct. Each platform has its own privacy policy:
10. Changes to this Policy
We may update this Policy. Material changes will be notified by email to active account holders
and posted on this page with an updated "Last updated" date. Continued use after changes
constitutes acceptance.
11. Contact
For privacy questions, data deletion requests, or concerns:
Back to home · Terms of Service · Support and Data Deletion