Privacy Policy
Last updated: 25 September 2026
1. Who we are and who this applies to
Strike.os is operated by Hugo Aires Fangueiro Marques, a sole trader established in Portugal, who is the data controller under the GDPR. Strike.os is an operations platform for marketing agencies: it brings together client management, content planning and publishing, a team calendar and billing. This policy applies to visitors of this website (strike-os.com), to users of the app (app.strike-os.com) and their teams, to client-users invited to the portal, and to data from third-party accounts you voluntarily connect. For any privacy question, contact hello@strike-os.com.
Strike.os acts as the Data Controller with regard to the data of your agency account. However, for the data of your clients that you upload or connect to the platform, your agency is the Data Controller and Strike.os acts exclusively as a Data Processor, governed by our Data Processing Agreement (DPA).
2. Data we process
Account data: name, email, password (encrypted), role and preferences. Content you create in the app: posts, captions, media files, comments, clients, invoices and notes. Usage and technical data: access and event logs needed to run and secure the service. Data from integrations you authorize: Meta (Facebook/Instagram), Google (Calendar), Stripe (payments) and, in the future, TikTok — detailed below. On this website, if you ask for a twenty-minute call, we store your name, email, agency name, the client bracket and the team size you give us.
3. Purposes and legal basis (GDPR)
We process your data to provide the service you signed up for (performance of a contract), to comply with legal obligations (for example, invoicing), on the basis of legitimate interests (security and abuse prevention) and, where applicable, with your consent (connecting optional integrations) and for pre-contractual steps at your request (the call you ask for on this site). We do not sell your data, we do not use it for advertising, and we do not train third-party AI models with your content.
4. Facebook & Instagram data (Meta Platform)
When an agency connects a client's Facebook Page and Instagram professional account — always with that client's authorization, given on Meta's consent screen — Strike.os receives the data needed to provide the service: access tokens (encrypted at rest), Page and Instagram account identifiers and names, the content scheduled and published, and performance insights (reach, impressions, views, likes, comments, saves). The connection is made through one of two routes, depending on what the client has: Facebook Login, which connects the Facebook Page and the Instagram account linked to that Page; or Instagram Login (Business Login for Instagram), which connects an Instagram professional account without requiring a Facebook Page. We use this data only to schedule and publish content to those accounts and to produce performance reports for the agency and its client. We never sell it, never use it for advertising, never share it with third parties other than the subprocessors that run our service, and never use it to train AI models. To delete this data, an end user can remove Strike.os from their Facebook/Instagram app settings — our deletion/deauthorization callback automatically and permanently deletes their access tokens and associated metrics from our systems — or email hello@strike-os.com. Strike.os complies with the Meta Platform Terms and Developer Policies.
5. Google (Google Calendar) data
If you connect your Google Calendar, we ask for your consent to: view and edit events (calendar.events) — to show availability in the Team Calendar and create scheduling events on your behalf; availability (calendar.freebusy) — to compute free/busy windows; the account email (userinfo.email) — to identify the connected account; and the list of your calendars (calendar.calendarlist.readonly) — so you can choose which one to connect. We do not access data beyond the connected calendar, do not delete unrelated events, and never sell this data or use it for advertising. Data obtained from Google APIs is never transferred to any AI model provider — neither raw, nor aggregated, nor in derived form — and is never used to develop, train or improve AI/ML models, whether our own or third-party. Strike.os AI features have no access to Google Calendar data. Strike.os's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. Payment data (Stripe)
Payments are processed by Stripe. When you subscribe to Strike.os, we process customer and subscription identifiers and payment status. Card data is collected and stored directly by Stripe — Strike.os never accesses it.
7. TikTok (future)
When TikTok integration is enabled, this policy will be updated to describe the data processed (account authorization and content publishing) before any collection takes place.
8. How we store and protect data
Application data is stored in Supabase (PostgreSQL database and authentication, hosted in the European Union — Ireland) and on a dedicated server (Hostinger). All traffic uses HTTPS/TLS. Third-party access tokens (Meta, Google) are encrypted at rest with AES-256-GCM and only decrypted in memory when calling the respective APIs. Access is restricted by role and by Row-Level Security (per-account isolation); the service key is used only server-side and is never exposed to the browser. Media files you upload are stored on the server and served over a secure connection.
9. Subprocessors
We rely on providers that process data on our behalf, solely to provide the service: Supabase (database and authentication); Hostinger (server hosting and media file storage); Meta (Facebook and Instagram APIs, only if you connect those accounts); Google (Google Calendar API, only if you connect); Stripe (payment processing); InvoiceXpress (certified invoicing, Portugal: issuing Strike.os invoices to your agency; and, if you connect your InvoiceXpress account, issuing your documents to your clients, in your account); Resend (transactional email, such as invites and notifications); Plausible Analytics (aggregate, anonymous visit statistics for this website); PostHog (product analytics and session recording inside the app, hosted in the European Union, with sensitive fields masked); Anthropic (paid commercial plan — the Claude API, for generating captions, content plans and reports with AI analysis). For AI features, Anthropic receives the data each requested text needs — including the client's name and brand profile, the notes you write in the request, the captions and metrics of posts and, in reports with AI analysis, the financial data and team tasks the report covers. The AI features cannot access Google Calendar data (§5), and we do not give that data to Anthropic in any other way, including in support operations; and card data is never seen by Strike.os (§6). Anthropic therefore does not receive Google Calendar data or card data, and under its commercial terms the content it receives is not used to train models.
10. International transfers
Where data is processed outside the European Economic Area by a subprocessor, such transfers rely on an adequacy decision of the European Commission — the one for the United Kingdom, where the application server is located, or the one for the EU-U.S. Data Privacy Framework, for certified providers — or on the European Commission Standard Contractual Clauses. Where the contracted provider is in the EEA and its own subprocessors process the data outside the EEA, it is that provider that makes the transfer and that must frame it within one of the mechanisms provided for in the GDPR. Annex 3 of the DPA states the mechanism for each provider that processes your clients' data on behalf of your agency.
11. Retention
We keep your data while your account is active and for as long as necessary for the purposes described. Integration data (tokens and associated metrics) is retained while the connection is active. After you delete your account or a connection, the associated data is deleted within 30 days, unless a legal obligation requires retention (for example, billing records). Call requests made on this website are kept for up to 24 months, or until you ask us to remove them.
12. Data deletion
You can request deletion at any time by emailing hello@strike-os.com with the subject "Account deletion". We confirm your identity and delete within 30 days. In addition: removing Strike.os from your Facebook app settings deletes the associated Meta tokens and metrics (deletion/deauthorization callback); disconnecting Google Calendar in Strike.os removes the Google tokens; and deleting your account deletes the associated data.
14. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, port and object to the processing of your data. To exercise any of these, contact hello@strike-os.com — we respond within 30 days. You also have the right to lodge a complaint with the supervisory authority of your country of habitual residence; the supervisory authority for the data controller is the Comissão Nacional de Proteção de Dados (CNPD), in Portugal.
15. Changes to this policy
We may update this policy. Material changes will be communicated in the app or by email. The date at the top shows the latest revision.
16. Contact
Data controller: Hugo Aires Fangueiro Marques, a sole trader established in Portugal. Tax ID: 263 395 081. Address: Av. D. António Bento Martins Júnior, n.º 319, 3.º Esq., 4480-664 Vila do Conde, Portugal. Questions about this policy or your data: hello@strike-os.com.