Privacy Policy

Last updated: September 11, 2026

This founder-draft notice describes how Avexio processes information in the product as it exists today. It is written for customers and for later founder and counsel review. It does not create extra contractual promises such as fixed retention periods, certifications, or deletion SLAs that the product does not implement.

1. Who we are

Avexio is an AI marketing platform that helps businesses create posts, images, and short videos, and optionally connect supported third-party social media platforms—including Facebook, Instagram, X, Threads, Pinterest, and YouTube—and, where supported in the product, publish or schedule content to destinations you authorize. Questions about this notice can be sent to support@avexio.ai.

2. Information we process

Depending on how you use Avexio, we may process:

  • Account and profile information, including name, email address, and authentication credentials managed by Supabase Auth.
  • Organization and business information, such as workspace name, brand details, and uploaded logos.
  • Content you submit or generate, including prompts, captions, images, videos, and related metadata.
  • Subscription and billing records needed to operate checkout, invoices, and plan changes.
  • Social connection data for supported platforms you authorize (including Facebook, Instagram, X, Threads, Pinterest, and YouTube). That may include account or channel identifiers, usernames or display names, pages, boards, channels, or other destinations available to the authorized account, granted permissions or scopes, OAuth access credentials or tokens needed to maintain the connection, and related token expiry or refresh information.
  • Publishing and scheduling records for content you ask Avexio to publish on supported platforms, such as status or results, provider post or content identifiers where applicable, and Meta-derived engagement information for Facebook Page posts when available through the permissions you granted.
  • Operational logs and hosting telemetry created while providing the service.

3. Why we use this information

We use this information to:

  • Create and authenticate accounts and keep you signed in.
  • Provide workspaces, brand profiles, and content libraries.
  • Generate marketing content with AI providers you invoke in the product.
  • Connect and maintain authorized social accounts and show available publishing destinations.
  • Publish or schedule content to destinations you authorize on supported platforms, when that capability is available in the product and you request it.
  • Retrieve information needed to operate the authorized integration, maintain connection authorization, diagnose integration failures, and record publishing or scheduling results.
  • Meter plan allowances, credits, and subscription status.
  • Send transactional messages such as invites and authentication email.
  • Maintain security, debug failures, and operate the hosted service.

4. Processors and third parties

Avexio uses infrastructure and AI providers to run the product. The following are evidenced by the current application:

  • Supabase — authentication, application database, and related backend services.
  • Cloudflare R2 — object storage for uploaded and generated files such as logos, images, video assets, and audio.
  • OpenAI — text, image, vision, speech/audio generation, and related AI processing for prompts and generated content.
  • Fal / Flux — image generation used in the AI video first-frame path.
  • Pika — image-to-video generation for photographic video motion.
  • Stripe — subscription checkout, customer portal, invoices, and payment processing.
  • Meta (Facebook, Instagram, and Threads) — OAuth and account connection; destination discovery and selection; publishing and scheduling where supported in the product; and Facebook Page-post engagement information when you connect a Facebook Page and grant the related permissions.
  • X — OAuth and account connection; text and image publishing and scheduling where supported in the product.
  • Pinterest — OAuth and account connection; reading the authorized account identity and available boards so you can select a board. Creating, publishing, or scheduling Pins through Avexio is not currently available in the product.
  • Google / YouTube — Google OAuth and YouTube API Services so you can authorize a Google/YouTube account, select a YouTube channel, and—when you explicitly publish or schedule a video in Avexio—upload that video to the selected channel. See section 6A.
  • Resend — transactional email such as agency invitations. Authentication email is sent through Supabase Auth.
  • Vercel — application hosting, deployments, and scheduled jobs.

Those providers process information according to their own terms and privacy notices. Avexio does not control those providers’ privacy practices. Avexio does not sell personal information.

5. Cookies and session storage

We use cookies required to keep you signed in (Supabase session cookies) and to remember the organization you currently have selected. We do not currently operate a separate product-analytics or advertising pixel in the application.

6. Social platform connections

When you connect a supported social platform from Social Connections in the dashboard, you authorize Avexio to access only the information and permissions needed for that integration for accounts you authorize. Avexio does not use those connections to access arbitrary other users’ private social data, run advertising or ad-campaign management, or provide social-platform analytics products beyond what is described in this notice.

If you connect Facebook, you authorize Avexio through Meta. Avexio stores Facebook user and Page access tokens in encrypted form using secure credential storage so the authorized connection can continue without requiring Facebook sign-in for every action. Avexio can list Facebook Pages you are permitted to manage. For Pages managed through a Meta Business Portfolio, Avexio requests the business_management permission only so those Pages can be discovered and listed. Avexio does not use business_management to manage ad accounts, business people or roles, Business Manager administration, or unrelated business assets.

If you connect Instagram or Threads through Meta, or connect X or Pinterest, Avexio stores the authorization credentials needed to maintain that connection and may list destinations available to the authorized account (such as an Instagram professional account, Threads profile, X account, or Pinterest boards) so you can select where content should go when publishing is available.

You can disconnect supported social accounts from Social Connections in the dashboard. Disconnecting removes or disables stored authorization credentials and tokens for that provider connection in Avexio according to the product implementation for that provider, disables related destination selection for that connection, and stops Avexio from using that connection to access or publish through Avexio. For Facebook, Avexio also makes a best-effort request to revoke corresponding Meta permissions; that request can fail, and disconnect still completes on Avexio. Avexio does not guarantee that permissions are removed on a provider’s systems. If you remove Avexio from Facebook, that deauthorization also stops Avexio from accessing or publishing through that Facebook identity. It does not by itself delete historical Facebook-related records in Avexio. A Facebook data-deletion request is a separate, stronger process. Appropriate historical Avexio operational and publication records may remain unless separately removed through product or support processes.

6A. Google / YouTube

Avexio uses Google OAuth and YouTube API Services when you choose to connect YouTube from Social Connections. Connecting is optional and user-directed: you must explicitly start the Google authorization flow for a business workspace.

When you connect Google/YouTube, Avexio may access:

  • Basic Google identity information needed to associate the OAuth connection with your Avexio business (such as a stable Google account subject identifier used for the connection record).
  • YouTube channel information available to the authorized Google account (such as channel identifiers, titles, and handles) so you can discover and select which channel Avexio should use for that business.

Avexio uses YouTube upload permission to upload videos only when you explicitly publish or schedule a video through Avexio for a completed video in your library. Current YouTube uploads through Avexio are Private. Avexio does not currently offer Public or Unlisted YouTube uploads in the product.

Avexio stores OAuth access and refresh credentials in encrypted form using secure credential storage so the authorized connection can continue without requiring Google sign-in for every action. Avexio also stores channel identifiers and selection state, and publication or scheduling metadata (such as titles you provide, Made for Kids declarations, provider video identifiers, permalinks, and job status) needed to operate publishing/scheduling and to maintain publication history.

Google/YouTube-derived connection credentials and channel identifiers are stored with Avexio’s infrastructure providers (including our application database host) so the product can run. Video files you generate or store in Avexio may reside in Avexio object storage and are sent to YouTube only when you publish or schedule. Avexio does not sell Google user data and does not use Google user data for advertising. Separately, content you create in Avexio (prompts, captions, images, videos) may be processed by Avexio’s AI and hosting providers as described in section 4; that is distinct from Google OAuth credentials.

Avexio’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Avexio’s use of YouTube API Services is also subject to the YouTube API Services Terms of Service and the YouTube API Services Developer Policies.

You can disconnect YouTube from Social Connections in the Avexio dashboard. Disconnecting disables the local YouTube connection for that business, clears channel selection for that connection, and removes or burns the locally stored OAuth credentials for that connection in Avexio. Avexio also attempts to revoke the Google authorization associated with that connection. If the Google revocation request fails because of a provider or network issue, Avexio still completes the local disconnect and does not leave those Avexio credentials active. Provider-side revocation may take some time to take full effect. Existing publication history, scheduling records, and related operational metadata in Avexio may be retained for product, operational, security, or legal purposes.

Separately from disconnecting in Avexio, you can revoke Avexio’s access to your Google Account from Google’s account settings (for example, Google Account → Security → Third-party access / Your connections to third-party apps). Revoking access on Google stops future authorized API use under those credentials; it does not by itself delete Avexio account content or historical Avexio records.

7. Publishing and engagement

Avexio publishes or schedules content only when you request it and only to destinations you authorize on supported platforms where that capability is available in the product. Current publishing and scheduling support includes Facebook Page posts (text and, when present in the product flow, a single image), Instagram image publishing and scheduling, text and image publishing and scheduling to X and Threads, and—where enabled for your workspace—private YouTube video publishing and scheduling. Pinterest connections are available for authorization and board selection; creating, publishing, or scheduling Pins through Avexio is not currently available. Avexio does not currently publish to LinkedIn or TikTok.

When available, Avexio may read engagement information for posts Avexio published to a connected Facebook Page, such as reactions, comments, and shares, using the pages_read_engagement permission. Avexio does not currently request Facebook Insights permissions (for example pages_read_insights) and does not obtain impressions or reach from Insights. Avexio does not provide Pinterest advertising, ecommerce, or Pinterest analytics functionality.

8. Retention and data deletion

We keep account, content, billing, and connection records while they are needed to provide the service. The product does not currently expose an automated account-deletion control or publish a fixed retention schedule. If you want a copy of your information or want your Avexio account or data deleted, email support@avexio.ai. We will review requests manually. Disconnecting a social provider is not the same as deleting your Avexio account or workspace data.

For Facebook-specific disconnect, deauthorization, and Meta data-deletion requests, see our Data deletion page. Avexio implements Meta deauthorization and User Data Deletion callbacks. When those callbacks are configured on the Meta app dashboard and running in a production deployment, Meta can notify Avexio. Deauthorization stops Facebook access and publishing for matching connections while retaining historical Facebook-related records. Data deletion removes or anonymizes Facebook-sourced connection data associated with the request. Until that production configuration is in place, Facebook data-deletion requests can also be sent to support. Avexio does not currently implement an automated Google/YouTube data-deletion callback; Google/YouTube-related deletion requests are handled through the support process above and through Google Account revocation described in section 6A.

9. Your choices

You can update profile and business information in the dashboard, manage billing through Avexio billing and the Stripe customer portal, disconnect social accounts, revoke third-party authorizations with the provider (including Google), and stop using the service by cancelling a subscription at period end. Privacy requests that the product cannot complete in-app should be sent to the support address above.

10. Children

Avexio is intended for business users. It is not directed to children.

11. Changes

We may update this notice as the product changes. The “Last updated” date at the top of this page will change when we do. Continued use of Avexio after an update means you are aware of the revised notice.

12. Contact

Privacy questions: support@avexio.ai. See our Data deletion page. You can also use our Contact page.