πŸš€
ScaleUp
← Back to sign up

Privacy Policy

Effective 18 August 2026Version 1.0Free beta
In short: we collect what we need to draft and publish your marketing β€” your sign-in details, your business profile, the sources you upload, and the tokens for the channels you connect. Your data is stored in India, encrypted, isolated per workspace, and never used to train AI models. We do not sell it. You can get a copy or have it deleted at any time.

1. Scope and who is responsible

This policy explains what personal data ScaleUp collects when you use scaleup.app and the ScaleUp application, why we collect it, who else processes it, how long we keep it, and what you can ask us to do with it.

ScaleUp, Business Bay, Dubai, United Arab Emirates, decides how and why your personal data is processed. That makes us the data controller under the EU and UK GDPR, the data fiduciary under India’s Digital Personal Data Protection Act, 2023 (DPDP Act), and the controller under UAE Federal Decree-Law No. 45 of 2021 (PDPL).

Separately, the material you upload about your own customers β€” for example a document containing customer names β€” is data you control. We process it only on your instructions, as your processor, under the licence in our Terms of Service.

2. What we collect

CategoryWhat it includes
Account and sign-in dataYour phone number or email address, your Google account identifier and verified email if you sign in with Google, one-time passcode attempt counts, session and refresh tokens, and the date, time and IP address at which you accepted our Terms.
Business profileBusiness name, owner name, category and sub-categories, team size, location, website, language and description.
Brand voice and goalsThe tone, style rules and marketing goals you select or write during onboarding.
Knowledge sourcesDocuments, links and FAQs you upload, the text extracted from them, and the numeric embeddings we derive so the agent can retrieve the right passage. These files are whatever you choose to upload β€” if they contain personal data about your customers or staff, we process that too.
MediaImages and other files you upload or generate, plus technical details such as dimensions, format, size and a content hash used to avoid storing duplicates.
ContentPost drafts, variants, edits, revision history, schedules, approval and rejection decisions, and publishing results.
Channel connectionsFor each Instagram or Facebook Page you connect: the account and Page identifiers, display name, the access token Meta issues (stored encrypted), token expiry, and connection health events.
Notification preferencesHow you want to be told about pending approvals, and your approval-mode setting.
Audit recordsAn append-only log of significant actions β€” who connected a channel, edited a post, approved, rejected, scheduled or published it β€” with actor, timestamp and request identifier.
Technical and usage dataIP address, browser and device type, pages and features used, timestamps, error reports and performance traces. We use this to keep the Service secure and working.

We do not ask for, and ask you not to upload, sensitive categories of data such as health, biometric, financial-account or government-identifier data. We do not collect payment card details, because the beta is free.

3. Why we use it, and our legal basis

PurposeLegal basis
Create and secure your account, verify your phone or email with a passcodePerformance of a contract with you (GDPR Art. 6(1)(b)); necessary to provide a service you requested (DPDP s. 7 / consent); contractual necessity (PDPL Art. 4).
Run the Service: store your profile, generate drafts, schedule and publish approved postsPerformance of a contract (GDPR Art. 6(1)(b)); your consent given at sign-up (DPDP s. 6); contractual necessity (PDPL Art. 4).
Publish to Instagram or FacebookPerformance of a contract, on your explicit per-post approval.
Keep an audit record of approvals and publishingLegitimate interests in accountability and dispute resolution (GDPR Art. 6(1)(f)); legal obligation where applicable.
Prevent abuse, fraud and unauthorised access; rate-limit and scan uploads for malwareLegitimate interests in security (GDPR Art. 6(1)(f)); permitted processing for security (DPDP / PDPL).
Diagnose faults and improve reliability using error reports and metricsLegitimate interests in maintaining a working service.
Send service messages, such as approval reminders and security noticesPerformance of a contract.
Send product news or marketing emailYour consent, which you can withdraw at any time.
Comply with law and respond to lawful requestsLegal obligation.

Where we rely on consent, you can withdraw it at any time β€” see your rights. Withdrawing consent does not affect processing already carried out, and may mean we can no longer provide part of the Service.

4. How AI processing works

To draft a caption or generate an image, we send our AI providers a prompt built from your business profile, brand voice, the relevant passages retrieved from your knowledge base, and your instructions. The provider returns a draft to us, and we show it to you.

  • Redaction is on by default. Our systems strip personal identifiers β€” email addresses, phone numbers, tokens, passcodes β€” from prompts and from logs before they leave our systems, unless there is a lawful reason to include them.
  • No training on your data. Our AI providers are engaged under terms that permit them to process your content only to return a result to us, and that prohibit using it to train their models. We do not use your content to train models either.
  • Retention at our providers is short. Prompts and outputs are not retained by them beyond what is needed to serve the request and meet their own abuse-monitoring obligations.
  • You decide what is published. A draft only becomes a post when you approve it.
No automated decisions about you
ScaleUp does not make decisions producing legal or similarly significant effects about you by automated means. The one consequential decision in the product β€” publishing content in your business’s name β€” is always made by a human: you.

5. Cookies and local storage

We use only what the Service needs to work. We do not use advertising cookies, and we do not track you across other websites.

What we storeWhy
su_access (cookie)Holds your signed-in session so the app knows it is you on each request. Expires when the session ends.
su_signup_contact, su_signup_method (browser session storage)Carries the phone or email you entered from the sign-up screen to the passcode screen. Cleared when you close the tab.

Third parties we embed for sign-in β€” currently Google Identity Services β€” may set their own cookies on their domain when you use them. Their handling is governed by their own privacy policies.

6. Who we share it with

We do not sell your personal data, and we do not share it for anyone else’s advertising. We share it only in these situations:

  • Service providers (sub-processors) who process data on our behalf under written terms, listed below.
  • Instagram and Facebook, when you approve a post β€” the post content, media and schedule go to Meta for publishing on your account.
  • Legal and safety β€” where we must comply with a law, regulation or valid legal request, or to establish or defend legal claims, or to protect the rights and safety of our users and the public.
  • Corporate transactions β€” if ScaleUp is involved in a merger, acquisition or asset sale, your data may transfer, subject to this policy and with notice to you.
Sub-processorWhat it does for us
Amazon Web Services (AWS)Hosting, database, object storage, CDN, encryption keys, transactional email (SES), sign-in directory (Cognito), image moderation (Rekognition), text extraction from documents (Textract).
Processed in India (ap-south-1), with global CDN edge delivery.
Anthropic (Claude, via Amazon Bedrock)Generating captions, hashtags and post drafts from your business profile, brand voice and knowledge base.
Processed in India (Bedrock, ap-south-1); United States on the direct-API fallback path.
Voyage AIConverting your knowledge documents into embeddings so the agent can retrieve them.
Processed in United States.
ReplicateAI image generation for post visuals, when you request it.
Processed in United States.
TwilioDelivering one-time passcodes to your phone number at sign-in.
Processed in United States and regional carriers.
Meta Platforms (Instagram, Facebook)Receiving the posts you approve, and returning the account and publishing status we show you.
Processed in United States and global.
GoogleVerifying your identity if you choose "Continue with Google".
Processed in United States and global.
SentryError and crash reporting so we can fix faults.
Processed in United States / European Union.
DatadogInfrastructure monitoring, metrics and operational logs.
Processed in United States / European Union.

We update this list when we add or replace a provider. Material changes are announced under changes to this policy.

7. Where your data lives, and international transfers

Your workspace data β€” profile, documents, media, posts and channel tokens β€” is stored in AWS Asia Pacific (Mumbai) β€” ap-south-1, India. Media is delivered through a global content delivery network using signed, expiring URLs.

Some of our providers process data outside that region, as noted in the table above. Depending on where you are, that may be a cross-border transfer:

  • From the EEA or UK: we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum or IDTA where applicable) with each recipient, together with encryption in transit and at rest and access controls. You can request a copy of the safeguards from privacy@scaleup.app.
  • From India: transfers are made to countries not restricted by the Central Government under s. 16 of the DPDP Act, and we will stop transfers to any country later restricted.
  • From the UAE: transfers are made either to jurisdictions recognised as providing adequate protection, or under contractual safeguards permitted by Articles 22 and 23 of the PDPL.

8. How long we keep it

We keep personal data only as long as we need it for the purpose it was collected, then delete it on the schedule below.

DataRetention
Account and sign-in records (email, phone, linked Google identity)For as long as your account is open, then deleted within 30 days of closure
Business profile, brand voice, goalsLife of the workspace, then deleted within 30 days of closure
Knowledge documents and their extracted chunks and embeddingsUntil you delete the document; chunks and embeddings are removed immediately and the stored file is purged within 30 days
Posts, drafts, revisions and media assetsLife of the workspace; deleted posts are purged within 30 days
Channel connections and access tokensUntil you disconnect the channel or the token is revoked, then deleted immediately
One-time passcode attempt counters7 days
Raw AI request/response logs (redacted copies are kept in the run record)30 days
Audit events (who approved, edited or published what)7 years β€” this is our record of your approvals and cannot be edited or deleted
Operational and error logsUp to 90 days
Encrypted database backupsUp to 35 days, after which deleted data disappears from backups too

Deleted records also persist for a short period in encrypted backups. Backups roll off on a 35-day cycle, after which the data is gone from them too.

9. How we protect it

  • Encryption in transit (TLS) and at rest for databases, object storage and backups.
  • Channel access tokens are encrypted with a dedicated managed key, separately from the rest of the database.
  • Every workspace is isolated at the database level, with row-level security enforcing the boundary on every read and write, and per-workspace prefixes in object storage.
  • Personal identifiers are stripped from application logs and AI prompts by default; secrets are never logged.
  • Uploaded files are scanned for malware, and generated images are screened for unsafe content.
  • Least-privilege access for our staff, secrets held in a managed secrets store, and an append-only audit trail of significant actions.

No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant regulator β€” the Data Protection Board of India, your EEA or UK supervisory authority, or the UAE Data Office β€” within the timeframes those laws require.

10. Your rights

Whichever law applies to you, you can ask us to do the following, free of charge, by emailing privacy@scaleup.app from your registered address:

  • Access β€” get a copy of the personal data we hold about you, and a summary of how it is processed and who it has been shared with.
  • Correct β€” have inaccurate or incomplete data corrected, completed or updated.
  • Delete β€” have your data erased where we no longer need it, or where you withdraw the consent it rests on.
  • Withdraw consent β€” as easily as you gave it, for anything based on consent.
  • Object or restrict β€” object to processing based on legitimate interests, or ask us to pause processing while a dispute is resolved (EEA/UK and UAE).
  • Portability β€” receive your data in a structured, commonly used, machine-readable format, or have it sent to another provider where technically feasible (EEA/UK and UAE).
  • Nominate β€” nominate another individual to exercise your rights if you die or become incapacitated (DPDP Act, s. 14).
  • Complain β€” see grievance redressal below.

We respond within 30 days. We may need to verify your identity first, and we may keep data we are legally required to retain β€” such as audit records of approvals β€” even after other data is deleted. Under the DPDP Act you are also expected to provide accurate information and not to file false or frivolous complaints.

11. Deleting your data and disconnecting Meta

Removing ScaleUp's access to Instagram or Facebook
Disconnect the channel in the app, or remove ScaleUp from Settings β†’ Apps and Websites in your Facebook or Instagram account. Either action revokes our access token immediately and stops all future publishing. We delete the stored token straight away. Posts already published stay on your account β€” you control those in the Meta apps.

To delete your ScaleUp workspace and everything in it:

  • Email privacy@scaleup.app from your registered email address, or from the address linked to your account, with the subject β€œDelete my account”.
  • We confirm your identity and the request, then queue the deletion.
  • Your workspace content is deleted within 30 days, and disappears from encrypted backups within a further 35 days.
  • We retain only audit records of approvals and publishing, and anything the law requires, as set out in the retention table above.

You can also delete individual items at any time in the app β€” knowledge documents, media and posts β€” without closing your account.

12. Children

ScaleUp is a business tool and is not directed at children. We do not knowingly collect personal data of anyone under 18. If you believe a child has provided us data, contact privacy@scaleup.app and we will delete it. Under the DPDP Act we do not undertake tracking, behavioural monitoring or targeted advertising directed at children.

13. Changes to this policy

We update this policy as the Service changes. The version and effective date at the top of this page tell you which version is current. For material changes β€” a new purpose, a new category of data, or a new class of recipient β€” we will notify you in the app or by email before the change takes effect, and where the law requires it we will ask for your consent again.

14. Contact and grievance redressal

For any privacy question or request, or to complain about how we handle your data, write to our Grievance Officer:

Grievance Officer
ScaleUp
Business Bay, Dubai, United Arab Emirates
grievance@scaleup.app

We acknowledge complaints within 7 days and aim to resolve them within 30 days, as required by the DPDP Act and the Information Technology (Intermediary Guidelines) Rules.

If you are not satisfied with our response, you can complain to the Data Protection Board of India, to your local supervisory authority in the EEA or UK, or to the UAE Data Office, depending on where you are.


ScaleUp Β· Business Bay, Dubai, United Arab Emirates
Also read our Terms of Service.