Privacy Policy
Last updated 2 September 2026
Who we are
ThoughtPost AI helps a team draft, schedule and publish content to social networks, and reports how that content performed. It is operated independently as Spore AI.
For the purposes of UK and EU data protection law, Spore AI is the data controller for the information described below. Questions about this policy, or a request to see, correct or delete your data, go to privacy@getspore.ai.
What we collect
Your account. Your email address, your name if you give one, your workspace and your role in it.
What you type in. Brand descriptions, audience definitions, post drafts, schedules, and any documents or links you attach as source material.
What connected accounts return. When you connect LinkedIn or Google, we store what those APIs give us for the permissions you granted — described in the next section.
Nothing else. We do not buy data about you, build advertising profiles, or track you across other websites.
Connected accounts, and exactly what each permission does
Google — sending email (gmail.send). Lets us send a message on your behalf. It does not permit reading your inbox, listing your contacts, or seeing any email that already exists, and we do not have those permissions.
Google — analytics (analytics.readonly). Lets us list the Google Analytics properties your account can see, so an administrator can choose which one belongs to which brand, and read aggregate traffic reports for it. It is read-only: we cannot change a property, a data stream, or anything else in your Google account. The reports we read contain visit and visitor totals, not individual people.
LinkedIn. Your basic profile, permission to post as you, and — for Company Pages where LinkedIn tells us you are an administrator — permission to post as the Page and read its aggregate analytics. LinkedIn’s Page analytics are anonymised before they reach us: we cannot see who viewed or followed a Page, and no API offers that.
You can disconnect either account at any time in the app, and revoke our access directly from your Google account permissions page. Disconnecting deletes the stored tokens.
Google user data: limited use
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically:
- We use Google data only to provide the features you have asked for — sending an email you composed, and reporting the traffic your posts sent.
- We do not sell it, and we do not use it for advertising.
- We do not use it to train, fine-tune or improve generalised AI models. No data obtained from a Google API is sent to any model provider.
- No human reads it, except with your explicit permission, to resolve a security problem, to comply with the law, or where the data has been aggregated and anonymised.
AI generation, and what is sent where
Draft copy is produced by large language models. To generate a draft we send the relevant prompt and context — your brand and audience descriptions, your instructions, and any source material you attached — to a model provider. We currently use Anthropic and OpenAI models, routed through our own service.
We do not send your Google or LinkedIn account data to a model provider, and we do not permit providers to train on content sent through our API access.
Who else processes your data
Each of these is used for one job and holds only what that needs:
- Supabase — database and sign-in.
- Vercel — hosting and request logs.
- Resend — sending transactional email such as invitations.
- Polar — subscriptions and payment. Card details go to Polar and its payment processor; we never see or store them.
- Anthropic and OpenAI — generating draft copy, as described above.
- LinkedIn and Google — the accounts you connect.
How connected-account credentials are stored
Access and refresh tokens are encrypted before they are written to the database, using AES-256-GCM with a key held only in the server environment. A token is never rendered into a page, returned by an API, or written to a log.
An Analytics connection is made once for a workspace by an administrator, and every member of that workspace can then see the reports it produces. If you are an administrator connecting an account, you are granting that access on your colleagues’ behalf.
Keeping and deleting data
We keep your content for as long as your workspace exists, because it is the working material of the product. Deleting a brand, a post or a connection deletes it. Closing a workspace deletes its data, including its content, connections and stored tokens.
Content already published to LinkedIn is not ours to delete — it lives on LinkedIn under its own terms, and you would remove it there.
To request access to your data, a copy of it, correction, or deletion, write to privacy@getspore.ai. If you are in the UK or EU, you also have the right to object to processing and to complain to your data protection authority.
Changes
If we change this policy in a way that affects how your data is used, we will say so in the app rather than quietly changing the date at the top.