Strike.os
Português

Privacy Policy

Last updated: 27 July 2026

This policy explains what data Strike.os (app.strike-os.com) collects, why, whom we share it with, how long we keep it, and how you can delete it. The data controller is Hugo Aires Fangueiro Marques, a sole trader established in Portugal. For any privacy question, contact hello@strike-os.com.

1. Who we are and who this applies to

Strike.os is an operations platform for marketing agencies: it brings together client management, content planning and publishing, a team calendar and billing. This policy applies to app users (agencies and their teams), client-users invited to the portal, and data from third-party accounts you voluntarily connect.

2. Data we process

• Account data: name, email, password (encrypted), role and preferences.

• Content you create: posts, captions, media files, comments, clients, invoices and notes.

• Usage and technical data: access and event logs needed to run and secure the service.

• Data from integrations you authorize: Meta (Facebook/Instagram), Google (Calendar), Stripe (payments) and, in the future, TikTok — detailed below.

3. Purposes and legal basis (GDPR)

We process your data to provide the service you signed up for (performance of a contract), to comply with legal obligations (e.g. invoicing), on the basis of legitimate interests (security, abuse prevention) and, where applicable, with your consent (connecting optional integrations). We do not sell your data or use it for advertising.

4. Meta (Facebook and Instagram) data

If you connect a client's Facebook and Instagram accounts, we collect and process: access tokens, Page IDs and names, the linked Instagram professional account id and username, and content/Page insights (reach, impressions, engagement). We use this data only to publish content and produce performance reports on those accounts, on behalf of the agency that authorized the connection. We do not sell this data or use it for advertising. Our use of Meta information complies with the Meta Platform Terms and Developer Policies. You can delete this data at any time (see section 12) or by removing the app in your Facebook settings.

5. Google (Google Calendar) data

If you connect your Google Calendar, we ask for your consent to: view and edit events (calendar.events) — to show availability in the Team Calendar and create scheduling events on your behalf; availability (calendar.freebusy) — to compute free/busy windows; and the account email (userinfo.email) — to identify the connected account. We only access the primary calendar of the account you connected (never another user's), do not delete unrelated events, and never sell this data or use it for advertising. You can disconnect at any time in Integrations — we revoke the token with Google and delete the synced events.

Artificial intelligence: data obtained from Google APIs (calendar events, availability and account email) is NEVER transferred to any AI model provider — neither raw, nor aggregated, nor in derived form — and is never used to develop, train or improve AI/ML models, whether our own or third-party. Strike.os AI features operate exclusively on the agency's own marketing content (topics, captions and social media metrics) and have no access to Google Calendar data.

Strike.os's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

6. Payment data (Stripe)

Payments are processed by Stripe. When you subscribe to Strike.os, or when an agency connects its Stripe account to bill its own clients, we process customer and subscription identifiers and payment status. Card data is collected and stored directly by Stripe (Strike.os never accesses it). Strike.os is not the merchant of record for payments an agency collects from its clients.

7. TikTok (future)

When TikTok integration is enabled, this policy will be updated to describe the data processed (account authorization and content publishing) before any collection.

8. How we store and protect data

Application data is stored in Supabase (PostgreSQL database and authentication) and on a dedicated server (Hostinger). All traffic uses HTTPS/TLS. Third-party access tokens (Meta, Google) are encrypted at rest with AES-256-GCM and only decrypted in memory when calling the respective APIs. Access is restricted by role and by Row-Level Security (per-account isolation); the service key is used only server-side and never exposed to the browser. Media files you upload are stored on the server and served over a secure connection.

9. Subprocessors

We rely on providers that process data on our behalf, solely to provide the service:

• Supabase — database and authentication.

• Hostinger — server hosting and media file storage.

• Meta — Facebook and Instagram APIs (only if you connect those accounts).

• Google — Google Calendar API (only if you connect).

• Stripe — payment processing.

• Resend — transactional email (invites, notifications).

• PostHog — app usage analytics (which features you use and where you run into friction), to improve the product. Hosted in the European Union; it does not receive data from the Meta or Google APIs. Session recordings have sensitive fields masked.

• Anthropic (Claude API, paid commercial plan) — generation of captions, content plans and report summaries. It receives only the marketing content you submit (topics, captions, aggregated social media metrics). It does NOT receive data from Google APIs (calendar, availability or account email) nor payment data. Under Anthropic's commercial terms, content submitted through the API is not used to train models.

10. International transfers

Where data is processed outside the European Economic Area by a subprocessor, such transfers are covered by appropriate safeguards (e.g. the European Commission Standard Contractual Clauses).

11. Retention

We keep your data while your account is active and for as long as necessary for the purposes described. Integration data (tokens and associated metrics) is retained while the connection is active. After you delete your account or a connection, the associated data is deleted within 30 days, unless a legal obligation requires retention (e.g. billing records).

12. Data deletion

You can request deletion at any time by emailing hello@strike-os.com. In addition: removing the app in your Facebook settings deletes the associated Meta tokens and metrics (deletion/deauthorize callback); disconnecting Google Calendar in Strike.os removes the Google tokens; and deleting your account deletes the associated data. The timeframe is up to 30 days.

13. Cookies

We use strictly necessary cookies (session and authentication) and functional preference cookies (language and theme). Since 24/07/2026 we also use PostHog for product analytics and session recording, which sets its own cookies: it helps us understand which features are used and where users run into friction, recordings have sensitive fields masked, it is hosted in the European Union, and it receives no data from the Google or Meta APIs. We do not use advertising or retargeting cookies.

14. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict, port and object to the processing of your data. To exercise any of these, contact hello@strike-os.com. You also have the right to lodge a complaint with the Portuguese Data Protection Authority (CNPD).

15. Changes to this policy

We may update this policy. Material changes will be communicated in the app or by email. The date at the top shows the latest revision.

16. Contact

Data controller: Hugo Aires Fangueiro Marques, a sole trader established in Portugal. VAT/Tax ID: 263 395 081. Registered address: Av. D. António Bento Martins Júnior, n.º 319, 3.º Esq., 4480-664 Vila do Conde, Portugal. Questions about this policy or your data: hello@strike-os.com.

Política de Privacidade — Strike.os