Privacy Policy

Last updated September 29, 2026

eddivo ("we", "the app") helps small businesses and event organizers draft and publish social media posts about their events. This page describes what data we collect, why, and how you can have it removed. It is written to be accurate, not to be exhaustive legal boilerplate — if anything here is unclear, email privacy@dokport.dk and we'll clarify or fix it.

Who this is

eddivo is operated by Dokport (CVR 39875942), based in Denmark, which is the data controller for everything described here. Questions about this policy, or about the data held on your account, go to privacy@dokport.dk. Our database, file storage and hosting all run inside the European Union, on Supabase and Vercel infrastructure.

What we collect

  • Your account email and password (handled by Supabase Auth; we never see the password itself).
  • Your brand profile: name, tone, hashtags and posting style.
  • Events you create or import: title, date, venue, ticket links.
  • Media you upload: images, audio and video used to build posts.
  • Generated post drafts and captions, and their approval/publish status.
  • Access tokens for accounts you explicitly connect — a Facebook Page, an Instagram Business account, a TikTok account, a Google Calendar, a Google Business Profile, a YouTube channel — stored server-side only. The app's interface never receives these tokens back; it only ever sees whether a connection is working.
  • For a connected TikTok account: its account ID (open_id) and display name, so we can show which account is connected, and — each time you post — the account's current posting options (who may view a post, whether comments, duets and stitches are allowed), which we read from TikTok and do not keep.
  • For a connected Google Business Profile: the name and ID of the business location you chose to post for, so we can show it and publish to it. We read the list of locations your Google account manages only to let you choose, and do not keep it.
  • For a connected YouTube account: the name and ID of the channel you chose to upload to. We read the list of your channels only to let you choose, and do not keep it.
  • A push notification subscription endpoint, if you enable notifications on a device.
  • Basic operational logs (errors, request timestamps) used to keep the service running.

What we don't do

We don't sell data, and we don't use it for advertising — there is no advertising in this app. We don't read anything on a connected Google Calendar, Google Business Profile, Facebook Page or TikTok account beyond what's needed to sync events and publish the posts you approve — we never read your TikTok videos, followers, messages or analytics, your business profile's reviews, questions or insights, or your YouTube videos, comments, subscribers or analytics.

Where data goes

Data is only ever sent to a third party when it's necessary to do what you asked:

  • Meta (Facebook/Instagram) — when you connect an account and approve a post for publishing.
  • TikTok — when you connect a TikTok account and approve a post for TikTok: the finished video, its caption, the audience you chose, the promotional / branded-content settings you ticked, and whether its picture or clip is realistic AI-generated content (so TikTok can label it).
  • Google — when you connect Google Calendar, to sync events two ways.
  • Google Business Profile — when you connect it and approve an event's announcement or recap for Google: the picture (for a reel, the still it is made from) and its caption, published on the location you chose — the announcement as an event post with the event's title, start and end time and ticket link, the recap as an update.
  • YouTube — when you connect a channel and approve a reel for YouTube: the finished video, a title made from the event's name and date, its caption, the visibility and made-for-kids choice you made, and whether its picture or clip is realistic AI-generated content (so YouTube can label it).
  • An AI provider, to generate post drafts and choose music from your brand and event details. Depending on which provider we use, this step may process those details outside the EU, under the standard contractual clauses approved by the European Commission.
  • Supabase and Vercel, as our database, file storage and hosting.

How long we keep it

Data is kept for as long as your account is active. Disconnecting an integration (see below) deletes the stored token immediately. Full account deletion is described on the data deletion page.

Your choices

  • Disconnect Facebook, Instagram, TikTok, YouTube, Google Business Profile or Google Calendar at any time under Settings → Social Media (Google Calendar under Calendar settings) — this deletes the stored token immediately. For TikTok we also revoke the token with TikTok, and for Google we revoke it with Google unless another Google connection in the same workspace still uses it. You can revoke eddivo's access from TikTok's or Google's own account settings as well.
  • Request a copy of your data, or ask us to correct it, by emailing privacy@dokport.dk.
  • Request full account deletion — see Data Deletion.

Changes

If this policy changes in a way that matters, we'll update the date at the top of this page.