Legal

Privacy Policy

Last updated: 27 July 2026

1. Who we are and who this applies to

Strike.os is operated by Hugo Aires Fangueiro Marques, a sole trader established in Portugal, who is the data controller under the GDPR. Strike.os is an operations platform for marketing agencies: it brings together client management, content planning and publishing, a team calendar and billing. This policy applies to visitors of this website (strike-os.com), to users of the app (app.strike-os.com) and their teams, to client-users invited to the portal, and to data from third-party accounts you voluntarily connect. For any privacy question, contact hello@strike-os.com.

2. Data we process

Account data: name, email, password (encrypted), role and preferences. Content you create in the app: posts, captions, media files, comments, clients, invoices and notes. Usage and technical data: access and event logs needed to run and secure the service. Data from integrations you authorize: Meta (Facebook/Instagram), Google (Calendar), Stripe (payments) and, in the future, TikTok — detailed below. On this website, if you join the waitlist, we store your email and, when you provide them, your name and agency size.

3. Purposes and legal basis (GDPR)

We process your data to provide the service you signed up for (performance of a contract), to comply with legal obligations (for example, invoicing), on the basis of legitimate interests (security and abuse prevention) and, where applicable, with your consent (joining the waitlist and connecting optional integrations). We do not sell your data, we do not use it for advertising, and we do not train third-party AI models with your content.

4. Facebook & Instagram data (Meta Platform)

When an agency connects a client's Facebook Page and Instagram professional account — always with that client's authorization through Facebook Login — Strike.os receives the data needed to provide the service: access tokens (encrypted at rest), Page and Instagram account identifiers and names, the content scheduled and published, and performance insights (reach, impressions, views, likes, comments, saves). We use this data only to schedule and publish content to those accounts and to produce performance reports for the agency and its client. We never sell it, never use it for advertising, never share it with third parties other than the subprocessors that run our service, and never use it to train AI models. To delete this data, an end user can remove Strike.os from their Facebook/Instagram app settings — our deletion/deauthorization callback automatically and permanently deletes their access tokens and associated metrics from our systems — or email hello@strike-os.com. Strike.os complies with the Meta Platform Terms and Developer Policies.

5. Google (Google Calendar) data

If you connect your Google Calendar, we ask for your consent to: view and edit events (calendar.events) — to show availability in the Team Calendar and create scheduling events on your behalf; availability (calendar.freebusy) — to compute free/busy windows; and the account email (userinfo.email) — to identify the connected account. We do not access data beyond the connected calendar, do not delete unrelated events, and never sell this data or use it for advertising. Data obtained from Google APIs is never transferred to any AI model provider — neither raw, nor aggregated, nor in derived form — and is never used to develop, train or improve AI/ML models, whether our own or third-party. Strike.os AI features operate exclusively on the agency's own marketing content and have no access to Google Calendar data. Strike.os's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

6. Payment data (Stripe)

Payments are processed by Stripe. When you subscribe to Strike.os, or when an agency connects its Stripe account to bill its own clients, we process customer and subscription identifiers and payment status. Card data is collected and stored directly by Stripe — Strike.os never accesses it. Strike.os is not the merchant of record for the payments agencies collect from their own clients.

7. TikTok (future)

When TikTok integration is enabled, this policy will be updated to describe the data processed (account authorization and content publishing) before any collection takes place.

8. How we store and protect data

Application data is stored in Supabase (PostgreSQL database and authentication) and on a dedicated server (Hostinger). All traffic uses HTTPS/TLS. Third-party access tokens (Meta, Google) are encrypted at rest with AES-256-GCM and only decrypted in memory when calling the respective APIs. Access is restricted by role and by Row-Level Security (per-account isolation); the service key is used only server-side and is never exposed to the browser. Media files you upload are stored on the server and served over a secure connection.

9. Subprocessors

We rely on providers that process data on our behalf, solely to provide the service: Supabase (database and authentication); Hostinger (server hosting and media file storage); Meta (Facebook and Instagram APIs, only if you connect those accounts); Google (Google Calendar API, only if you connect); Stripe (payment processing); Resend (transactional email, such as invites and notifications); Plausible Analytics (aggregate, anonymous visit statistics for this website); PostHog (product analytics and session recording inside the app, hosted in the European Union, with sensitive fields masked); Anthropic (Claude API, paid commercial plan — generation of captions, content plans and report summaries). Anthropic receives only the agency's marketing content (topics, captions and aggregated social media metrics); it does not receive Google API data or payment data, and under its commercial terms content submitted through the API is not used to train models.

10. International transfers

Where data is processed outside the European Economic Area by a subprocessor, such transfers are covered by appropriate safeguards — for example, the European Commission Standard Contractual Clauses.

11. Retention

We keep your data while your account is active and for as long as necessary for the purposes described. Integration data (tokens and associated metrics) is retained while the connection is active. After you delete your account or a connection, the associated data is deleted within 30 days, unless a legal obligation requires retention (for example, billing records). Waitlist emails are kept until launch, or until you ask us to remove them.

12. Data deletion

You can request deletion at any time by emailing hello@strike-os.com with the subject "Account deletion". We confirm your identity and delete within 30 days. In addition: removing Strike.os from your Facebook app settings deletes the associated Meta tokens and metrics (deletion/deauthorization callback); disconnecting Google Calendar in Strike.os removes the Google tokens; and deleting your account deletes the associated data. Encrypted backups are purged in the following cycle (max. 90 days).

13. Cookies and analytics

This website (strike-os.com) only loads measurement tools after you accept them in the consent banner: Google Analytics 4 and Meta Pixel (campaign measurement) and Plausible Analytics (aggregate statistics). If you decline, none of them is loaded. Inside the app (app.strike-os.com) we use strictly necessary cookies (session and authentication) and functional ones (language and theme), plus PostHog for product analytics and session recording — recordings have sensitive fields masked and PostHog receives no data from the Google or Meta APIs. We do not use advertising or retargeting cookies inside the app. The details are in our Cookie Policy.

14. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict, port and object to the processing of your data. To exercise any of these, contact hello@strike-os.com — we respond within 30 days. You also have the right to lodge a complaint with the Portuguese Data Protection Authority (CNPD).

15. Changes to this policy

We may update this policy. Material changes will be communicated in the app or by email. The date at the top shows the latest revision.

16. Contact

Data controller: Hugo Aires Fangueiro Marques, a sole trader established in Portugal. Questions about this policy or your data: hello@strike-os.com.