Privacy Policy
Turtles Egg Marketing (marketing-app.turtlesegg.com) · Effective September 3, 2026
Turtles Egg Marketing ("the Service", "we") is a social-media planning and publishing application operated by Turtles Egg. This policy describes what the Service collects, how it is used, and the choices you have. It applies to this application only; shopping on turtlesegg.com is covered by the store's own privacy policy.
1. Information we collect
Account information
- Username, display name, and a password (stored only as a salted hash -- we cannot read it).
- Your role and brand memberships inside a workspace.
Content you create
- Posts, captions, briefs, comments, and media files you upload for publishing.
- CRM records you add or import (for example creator outreach contacts).
Connected social account data
- OAuth access and refresh tokens for accounts you choose to connect (YouTube/Google, TikTok, Instagram, Facebook, Pinterest, LinkedIn, Reddit). Tokens are encrypted at rest with AES-256-GCM and are never shown to any user, including administrators.
- Basic profile identifiers for the connected account (for example your YouTube channel name and ID, or TikTok display name) so the workspace can see which account is connected.
- Engagement metrics for content the Service published on your behalf (for example likes, comments, shares, views, and watch time), used to show performance dashboards.
Technical information
- Strictly necessary cookies: a session authentication cookie and a CSRF protection token. We do not use advertising or cross-site tracking cookies.
- Standard server logs (timestamps, request paths, IP addresses) and a security audit trail of sensitive actions, kept for security and troubleshooting.
2. Google user data (YouTube)
When you connect a YouTube channel, the Service requests the minimum scopes needed to do what you ask of it:
- Upload videos (youtube.upload) -- to publish the videos you schedule, to your own channel, at the time you choose. Uploads only ever happen as a result of a post a person created and approved.
- Manage your YouTube account (youtube.force-ssl) -- used only to add your published video to the playlist you selected, to list your playlists so you can select one, to confirm which channel is connected, and to read statistics for your own videos.
- YouTube Analytics (read-only) -- to show your own videos' watch time, average view duration, and subscriber changes in your dashboard.
- Basic profile and email -- displayed in your workspace settings so you can confirm the correct Google account is connected.
We do not sell Google user data, do not use it for advertising, and do not allow humans to read it except with your consent, for security purposes, or where required by law. You can revoke the Service's access at any time from your Google Account permissions page, or by disconnecting YouTube inside the app -- disconnecting deletes the stored tokens immediately.
The Service uses YouTube API Services. By connecting a YouTube account you also agree to the YouTube Terms of Service. Google's privacy practices are described in the Google Privacy Policy.
3. TikTok and other connected platforms
For TikTok, Instagram, Facebook, Pinterest, LinkedIn, and Reddit the Service follows the same pattern: it accesses your account only to (a) show which account is connected, (b) publish the specific content a person in your workspace created and approved, and (c) read back engagement metrics for that published content. Access can be revoked at any time in the app's Platform Connections page or from the platform's own security settings; disconnecting deletes the stored tokens.
4. How we use information
- To operate the Service: drafting, scheduling, publishing, and reporting on your content.
- To secure the Service: authentication, permission checks, and the audit trail.
- To support you when you contact us.
We do not sell personal information, do not share it with data brokers or advertising networks, and do not use connected-account data to train machine-learning models. AI caption drafting runs on infrastructure we operate; your briefs and captions are not sent to third-party AI providers.
5. When information is shared
- The platforms you direct us to publish to. When a post you approved is published, its content necessarily goes to that platform under your connected account.
- Infrastructure providers. The Service runs on servers we manage with hosting providers, which process data only to host the Service.
- Legal requirements. If required by law, or to protect the Service and its users from fraud or abuse.
6. Retention and deletion
- Connected-account tokens are deleted immediately when you disconnect a platform.
- Posts, media, and CRM records are kept while your workspace uses them and can be deleted in-app by users with the right permission.
- To delete an account or a workspace entirely, contact us at [email protected]; we honor verified requests within 30 days.
7. Security
Platform tokens and secrets are encrypted at rest (AES-256-GCM). All traffic is served over HTTPS. Access inside a workspace is role-based, fails closed, and security-relevant actions are written to an append-only audit log. No method of storage is 100% secure, but we build to current good practice and patch promptly.
8. Children
The Service is a business tool and is not directed to children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect data from children.
9. Changes
If this policy changes materially we will update this page and its effective date, and signed-in users will be notified in the app.
10. Contact
Questions or requests: [email protected] · Turtles Egg, Naples, Florida, USA.