Privacy Policy

Last updated: July 2026

1. What we collect

Wahya collects only the information needed to run the platform:

Account and contact information — your name, email address, and workspace settings when you create and use a Wahya account.

Connected social accounts — when you connect a platform (such as TikTok, Facebook, or Instagram) through its official OAuth login, we store basic account details (name, handle, profile image) and the access tokens that platform issues. Tokens are stored securely server-side, are never exposed in the browser, and are never written to logs.

Uploaded media and content — videos, images, captions, and other content you upload or create for scheduling and publishing.

Lead and form submissions — information visitors submit through public intake forms hosted by Wahya (such as name, email, phone, and business details), which is stored for the workspace that owns the form.

2. How we use it

We use this information to operate Wahya: authenticating you, storing and scheduling your content, publishing to platforms you have connected and authorized, delivering notifications you configure (email/SMS to your own team), and keeping records like publishing and communication logs inside your workspace.

We do not sell your data. We do not share your data with advertisers.

3. Third-party services

Wahya runs on trusted infrastructure and integrates with services needed to provide its features. Depending on how you use Wahya, these may include: Supabase (database and file storage), Vercel (hosting), Resend (email delivery), Twilio (SMS delivery), Meta (Facebook/Instagram publishing), TikTok (publishing), and Cloudflare (form spam protection). Each processes only the data required for its function, under its own privacy terms.

4. Data retention and deletion

Your data stays in your workspace for as long as your account is active. You can disconnect social accounts at any time (which stops Wahya's access), delete uploaded media from your library, and request full deletion of your account and associated data by contacting us — we will process deletion requests promptly.

5. Security

Access to workspace data is protected by authentication and row-level security, so each workspace can only access its own records. OAuth tokens and provider credentials are handled exclusively server-side. Uploaded files live in private storage accessed through expiring, signed links.

6. Changes to this policy

We may update this policy from time to time. Material changes will be reflected on this page with an updated date.

7. Contact

Privacy questions or deletion requests: support@usewahya.com.