How we handle your data.
ARKKHE Corp ("we", "Octerio") respects your privacy. This policy describes what data we collect, how we use it, who we share it with, and how you can control this information.
1. Who we are
Octerio is a product of ARKKHE Corp — an AI social-media agent for automating posts, customer service, and paid ads on social networks.
- Email: arkkhecorp@gmail.com
- WhatsApp: +55 11 98057-6722
- Site: octerio.arkkhe.com
2. What data we collect
2.1 Data you provide
- Email (for authentication)
- Password (encrypted via bcrypt — never stored in plain text)
- Images uploaded for publishing
- Caption text and scheduling settings
2.2 Data from connected social networks
When you connect a social network account (Instagram, Facebook, Bluesky, Telegram, etc.), we receive:
- OAuth access token (encrypted via AES-256-GCM)
- Public username and profile picture
- Granular permissions you authorized (e.g., publish posts, read messages)
We never access your social network password. Only the OAuth token, with scope limited to the permissions you granted.
2.3 Usage data
- Posts published via Octerio
- Cross-post and scheduling history
- Usage counts for free trial and paid plans
2.4 Technical data
- IP address (for language detection and fraud prevention)
- Essential cookies (session and language preference)
- Technical error logs (no personal data)
3. How we use your data
- Operate the service (publish posts on your behalf to networks you authorized)
- Authenticate and protect your account
- Process payments via Stripe
- Send transactional emails (welcome, cancellation confirmation, etc.)
- Detect fraud, spam, and service abuse
We don't use your data for ads. We don't sell your data.
4. Who we share with
Only with service providers necessary to operate Octerio:
- Stripe — payments and Customer Portal
- Clerk — authentication
- Supabase — database
- Cloudinary — image hosting
- Make.com — transactional email automation
- Vercel — site and app hosting
- Social network APIs (Meta/Instagram/Facebook/Threads, Bluesky, Telegram, X, LinkedIn, TikTok, Reddit, Pinterest, Discord, YouTube, Google Business) — only to publish content you asked us to publish
We never share with third parties for marketing or ads.
5. Retention period
- Account data: while your subscription is active
- After cancellation: 30 days to allow reactivation, then deleted
- OAuth tokens: until you revoke access (on the social network or in /redes inside Octerio)
- Technical logs: 90 days
- Tax/payment records: 5 years per legal requirement
6. Your rights
You can at any time:
- Access your data at /configuracoes
- Correct inaccurate data
- Delete your account — instructions at /en/data-deletion
- Revoke access to a specific social network at /redes
- Export your data (request via email)
7. Cookies
We only use essential cookies:
octerio_lang— language preference (1 year)- Session cookies (Clerk) — authentication
We don't use tracking or profiling cookies. Vercel Analytics is aggregated and anonymous.
8. Security
- OAuth tokens encrypted (AES-256-GCM) at rest
- Passwords with bcrypt
- TLS 1.3 in transit
- Database access restricted by IP and role
- Audit logs for sensitive operations
In case of a security incident, we notify affected users within 72 hours, in line with applicable data protection laws.
9. Children
Octerio is not intended for users under 18. We don't knowingly collect data from minors.
10. Changes to this policy
Material changes will be notified via email 30 days in advance. Minor changes (typos, broken links) take effect without notice.
11. Contact
For any privacy questions:
- Email: arkkhecorp@gmail.com
- WhatsApp: +55 11 98057-6722
