LAST UPDATED
June 22, 2026
Privacy Policy
Privacy Policy
This Privacy Policy explains how Soontra ("Soontra," "we," "us," and "our") collects, uses, discloses, stores, and protects information when you access or use our websites, applications, products, dashboards, collaboration tools, analytics tools, publishing tools, AI features, storage features, and related services (collectively, the "Service").
If you use the Service on behalf of a company, agency, team, brand, or other organization, this Privacy Policy applies to information processed through that organization's workspace.
Table of Contents
Information we collect
Account and profile information
We collect information you provide when you create or manage an account, including name, email address, password-related authentication data, profile picture, invite-code status, account settings, terms acceptance timestamps, workspace memberships, and authentication-provider information.
If you sign in with Google OAuth, we may receive profile information such as your name, email address, profile picture, provider identifier, and authentication status. (Google sign-in is used only to authenticate your Soontra account; it is separate from connecting a YouTube channel for analytics or publishing, which is its own optional authorization.)
Workspace and collaboration information
We collect workspace information such as workspace names, roles, permissions, projects, tasks, statuses, tags, folders, files, comments, documents, notifications, team members, invitations, workflow settings, share links, and activity within the workspace.
Uploaded media and files
We collect and process files and media you upload or import, including videos, audio, images, PDFs, documents, metadata, filenames, file sizes, MIME types, duration, thumbnails, storage keys, upload status, processing status, and related workspace context.
Depending on the feature, we may generate or store derived information such as transcripts, speech timing, OCR text, visual descriptions, scene summaries, embeddings, searchable indexes, moderation signals, thumbnails, previews, extracted text, captions, AI summaries, recommendations, and other analysis outputs.
Prompts, AI interactions, and generated outputs
We collect prompts, instructions, AI-agent interactions, tool or page-action context, generated responses, execution traces, confirmations, feedback, and related usage information so we can provide AI-assisted features, improve reliability, debug issues, maintain safety controls, and enforce usage limits.
Connected-platform information
If you connect YouTube, TikTok, Instagram, or another third-party platform, we collect the information authorized by you and made available by that platform, including account identifiers, profile details, OAuth scopes, OAuth token metadata, connection status, analytics data, and related sync records. OAuth access and refresh tokens are encrypted at rest.
If you use the Service to publish, upload, or schedule content to a connected platform, we also process the content and settings you provide or direct us to send, such as videos, images, captions, titles, descriptions, hashtags, thumbnails, cover frames, scheduled publish times, audience or privacy settings, interaction settings (for example, comment, duet, or stitch preferences), commercial-content and synthetic-media disclosures, publishing status, platform responses, and related publishing records.
More detail for YouTube, TikTok, and Instagram appears below.
Billing information
If you purchase a paid plan or add-on, our payment processor (Stripe) collects and processes billing information such as payment method details, billing address, tax information, invoices, subscription status, transaction history, and fraud-prevention signals. Soontra does not store full credit or debit card numbers.
Support and communications
We collect information you send to us through support, email, feedback, demos, sales communications, surveys, bug reports, or other communications.
Usage, device, log, and security information
We collect technical and usage information such as IP address, device and browser information, session data, pages viewed, feature usage, timestamps, referrers, error logs, performance data, rate-limit data, authentication events, integration events, security events, and approximate location inferred from IP address.
Cookies and similar technologies
We may use cookies, local storage, session storage, and similar technologies to keep you signed in, remember settings, secure the Service, measure usage, improve performance, and prevent abuse.
YouTube and Google user data
Soontra uses YouTube API Services. Google's own privacy practices are described in the Google Privacy Policy. You can manage or revoke Soontra's access to your Google account at any time through the Google security settings page.
If you connect YouTube, Soontra requests the following Google OAuth scopes, depending on the features you enable:
https://www.googleapis.com/auth/yt-analytics.readonly(read YouTube analytics)https://www.googleapis.com/auth/youtube.readonly(read channel and video metadata)https://www.googleapis.com/auth/youtube.upload(upload and publish videos you direct us to publish) — requested only when you enable YouTube publishing
We do not currently request caption-management or playlist-management permissions. If we introduce caption or playlist features in the future, we will request the additional YouTube scope they require https://www.googleapis.com/auth/youtube.force-ssl and update this policy; those features are not enabled today.
Depending on your channel and YouTube API availability, Soontra may collect and process YouTube information such as channel ID, channel title, channel thumbnail, subscriber counts, view counts, watch time, upload counts, video performance metrics, likes, comment counts, shares, traffic sources, audience demographics, geography, device types, operating systems, playback locations, playlists, retention data, search terms, content types, reporting periods, deltas, and related analytics.
When you use Soontra's publishing features for YouTube, Soontra also processes the videos, titles, descriptions, tags, custom thumbnails, scheduling, visibility settings, and the "made for kids" and altered-or-synthetic-content declarations that you provide or direct us to send to your channel. You make those declarations as part of composing the post; Soontra transmits them to YouTube as you specify.
Soontra uses YouTube and Google user data only to provide, maintain, secure, and improve user-facing Soontra features that you enable, such as analytics dashboards, workspace reports, AI-assisted summaries you request, trend detection, and the publishing, uploading, scheduling, and metadata features you initiate, along with related support, security, and troubleshooting.
All actions that create, upload, modify, or schedule content on your YouTube channel are initiated by you or by your authorized workspace members and are carried out at your direction. Soontra does not upload, publish, modify, or delete content on your channel except as you direct through the Service.
Soontra does not use YouTube or Google user data to serve ads, retarget ads, personalize third-party ads, sell data, broker data, conduct surveillance, determine creditworthiness, or make lending decisions.
Soontra's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
TikTok user data
If you connect TikTok, Soontra requests TikTok OAuth scopes, depending on the features you enable:
user.info.basic(basic profile information; also required to prepare a post)user.info.stats(account statistics)video.list(public video metadata)video.publish(publish content directly to your TikTok account at your direction) — requested only when you enable TikTok publishing
Soontra publishes to TikTok using TikTok's Direct Post method. Soontra does not use TikTok's upload-to-inbox flow. If a TikTok authorization grant includes the video.upload permission because it is enabled on the TikTok application, Soontra does not use that permission.
Depending on your account and TikTok API availability, Soontra may collect and process TikTok information such as open ID, display name, avatar URL, follower counts, like counts, video counts, public-video metadata (including title, description, duration, cover image, share URL, and creation time), public-video performance counters (views, likes, comments, shares), music metadata, reporting periods, deltas, sync status, and related analytics. When you compose a post, Soontra also retrieves your current TikTok creator information (such as your username, available privacy options, and content-interaction settings) so the options presented match your account.
When you use Soontra's publishing features for TikTok, Soontra also processes the videos, titles, captions, cover frames, privacy and audience settings, interaction settings (comment, duet, and stitch preferences), commercial-content disclosures (branded content, your own promotional content, and AI-generated-content labeling where applicable), scheduling, and related metadata that you provide or direct us to send to TikTok.
Before any content is sent to TikTok, you select and confirm the relevant post settings — including the privacy or audience level, interaction settings, and any commercial-content disclosure — and provide explicit consent to publish that specific post. Soontra does not pre-select a privacy level on your behalf and does not publish without your per-post confirmation.
To publish, TikTok retrieves your media from a temporary, signed, time-limited link generated by Soontra (TikTok's required "pull from URL" delivery). These links are short-lived and are used only to deliver the specific content you have chosen to publish.
Soontra uses TikTok data only to provide, maintain, secure, and improve user-facing Soontra features that you enable, such as TikTok dashboards, workspace analytics, AI-assisted summaries you request, trend reporting, and the publishing and scheduling features you initiate, along with related support, security, and troubleshooting.
All actions that publish content to your TikTok account are initiated by you or your authorized workspace members and carried out at your direction. Soontra does not modify your profile data, send messages, or run ads.
Instagram User Data
Soontra uses the Instagram API with Instagram Login (it does not use Facebook Login or Facebook Pages). If you connect Instagram, Soontra requests the following scopes, depending on the features you enable:
instagram_business_basic(read profile and media)instagram_business_manage_insights(read account and media insights)instagram_business_content_publish(publish content to your Instagram professional account at your direction) — requested only when you enable Instagram publishing
Instagram publishing is available only for Instagram Business or Creator (professional) accounts, as required by Meta.
Depending on your account and Meta API availability, Soontra may collect and process Instagram information such as Instagram account ID, username, account name, profile picture, media IDs, media type, timestamps, captions, permalinks, account insights, media insights, views, reach, follower counts, accounts engaged, total interactions, profile-link taps, follower demographics and online-followers information where available, reporting periods, deltas, sync status, and related analytics.
When you use Soontra's publishing features for Instagram, Soontra also processes the images, videos, reels, carousels, captions, an optional first comment, scheduling, and related metadata that you provide or direct us to send to your account.
To publish, Instagram retrieves your media from a temporary, signed, time-limited link generated by Soontra (Meta's required "pull from URL" delivery). These links are short-lived and are used only to deliver the specific content you have chosen to publish.
Soontra uses Instagram data only to provide, maintain, secure, and improve user-facing Soontra features that you enable, such as Instagram dashboards, workspace analytics, AI-assisted summaries you request, growth and performance reporting, and the publishing and scheduling features you initiate, along with related support, security, and troubleshooting.
All actions that publish or upload content to your Instagram account are initiated by you or your authorized workspace members and carried out at your direction. Soontra does not access direct messages, manage ads, or otherwise mutate your Instagram account beyond the publishing actions you initiate.
If you remove Soontra's access through Meta or Instagram controls, Meta may send Soontra a deauthorization callback. If you request deletion through Meta or Instagram controls, Meta may send Soontra a data deletion callback. When Soontra receives a valid signed callback, Soontra deletes or disconnects matching Instagram connection records and removes retained Instagram analytics and published-media records associated with the matching connection. For data deletion callbacks, Soontra returns a confirmation code and a status URL https://www.soontra.com/data-deletion-status where you can check the status of the request.
How we use information
We use information to:
Provide, operate, maintain, and secure the Service.
Create and manage accounts, sessions, workspaces, roles, and permissions.
Store, process, preview, stream, download, index, search, and organize uploaded files.
Generate transcripts, summaries, visual descriptions, search indexes, embeddings, AI outputs, analytics, notifications, recommendations, and workspace insights.
Provide YouTube, TikTok, Instagram, and other connected-platform dashboards and reports.
Publish, upload, and schedule content to connected platforms when you direct us to do so, including processing the media, captions, settings, disclosures, and scheduling you provide.
Operate AI-agent features, page actions, tool execution, semantic search, content repurposing, and analytics explanations.
Process billing, subscriptions, add-ons, quotas, storage limits, AI minutes or credits, invoices, taxes, and payment disputes.
Send service messages, security notices, product updates, billing notices, support responses, and other communications.
Monitor performance, debug errors, prevent abuse, enforce terms, rate-limit requests, detect suspicious activity, protect users, and maintain audit logs.
Comply with law, legal process, platform requirements, and enforceable requests from courts, regulators, law enforcement, and connected platforms.
Analyze and improve the Service using aggregated, de-identified, or otherwise privacy-protective information where appropriate.
AI processing
Soontra uses AI-related systems to provide features such as transcription, visual and video analysis, semantic search, summaries, recommendations, analytics explanations, agentic workspace actions, and content repurposing.
We use third-party AI, transcription, embedding, moderation, storage, and infrastructure providers to process User Content and connected-platform data only for user-facing features you enable. The specific provider, model, routing path, prompt strategy, or inference method may change over time and is not a commitment of the Service. When you use AI features on connected-platform data — for example, asking the assistant to summarize your YouTube, TikTok, or Instagram analytics — that data may be processed by our AI providers solely to generate the response you requested, and not to train their models.
For Google user data obtained through Google APIs, AI-related processing is limited to user-directed, user-facing Soontra features. We do not use Google user data, and do not permit our service providers to use Google user data, to create, train, improve, or fine-tune generalized, foundation, frontier, or cross-customer AI or machine-learning models. We also do not store Google user data in generalized, foundation, or frontier models.
We do not sell your uploaded content or connected-platform data. For non-Google workspace content, we use content to provide, secure, support, and improve Soontra features, and we may use aggregated or de-identified information for product analytics, reliability, safety, and quality.
You should not submit sensitive information to AI features unless you have authority to do so and are comfortable with that information being processed to provide the requested feature.
Google API Limited Use commitments
For information received from Google APIs, Soontra follows the Google API Services User Data Policy, including Limited Use requirements.
This means, among other things:
We limit use of Google user data to providing or improving user-facing features that are visible in Soontra.
We do not sell Google user data.
We do not transfer Google user data to advertising platforms, data brokers, or information resellers.
We do not use Google user data for serving ads, retargeting, personalized advertising, or interest-based advertising.
We do not use Google user data to determine creditworthiness or for lending purposes.
We do not use Google user data, or allow service providers to use Google user data, to create, train, improve, or fine-tune generalized, foundation, frontier, or cross-customer AI or machine-learning models.
We do not store Google user data in generalized, foundation, or frontier AI models.
We restrict human access to Google user data to situations such as user-directed support, security, abuse investigation, legal compliance, or aggregated/internal operations allowed by applicable policy.
We require personnel and service providers who handle Google user data to follow applicable confidentiality, security, and policy requirements.
How we disclose information
We may disclose information:
To workspace members according to workspace roles, permissions, sharing settings, comments, documents, projects, files, dashboards, and collaboration features.
To service providers and subprocessors that help us operate the Service, as described in the next section.
To connected platforms when needed to authenticate, refresh, revoke, sync, validate, publish to, or operate integrations you enable.
To payment processors for billing, tax, fraud-prevention, subscription, and dispute handling.
To comply with law, legal process, court orders, subpoenas, government requests, platform requirements, or enforceable legal obligations.
To enforce our Terms, protect rights, prevent harm, investigate abuse, secure the Service, or respond to emergencies.
In connection with a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar corporate transaction, subject to applicable legal and platform-policy requirements.
With your consent or at your direction.
When you direct Soontra to publish or upload content to a connected platform, that content and its associated metadata are transmitted to the relevant platform (YouTube, TikTok, or Instagram) and become subject to that platform's terms and privacy practices.
We do not sell your Google user data, YouTube data, TikTok data, Instagram data, uploaded media, or workspace content.
Service providers and subprocessors
We rely on a limited set of third-party providers to operate the Service. Each processes information only as needed to provide its function and under contractual confidentiality and security obligations. Our core infrastructure providers include:
Provider
Provider
Purpose
Purpose
Supabase
Supabase
Database, authentication, and real-time infrastructure (system of record)
Database, authentication, and real-time infrastructure (system of record)
Cloudflare
Cloudflare
Object storage (R2) for your files and media, and bot/abuse protection (CAPTCHA) on sign-in forms
Object storage (R2) for your files and media, and bot/abuse protection (CAPTCHA) on sign-in forms
Amazon Web Services (AWS)
Amazon Web Services (AWS)
Cloud compute used to process, transcode, and prepare media
Cloud compute used to process, transcode, and prepare media
Customer.io
Customer.io
Transactional email delivery (verification, password reset, receipts, invitations) and product/usage messaging
Sentry
Sentry
Error monitoring and application performance/observability
Vercel
Vercel
Application hosting and delivery
Upstash
Upstash
Rate limiting, security counters, and ephemeral caching
Inngest
Inngest
Background job and scheduled-task orchestration
Liveblocks
Liveblocks
Real-time collaborative document editing
YouTube and Google Drive APIs for the integrations you enable, and Google's Gemini AI models for media understanding, transcription support, and semantic search of content you upload
In addition to Google, we use third-party AI, transcription, embedding, and content-moderation providers (which may include both U.S.-based and international providers) to power user-facing AI features you enable. These providers process content only to deliver the feature you requested and are subject to the commitments in the "AI processing" and "Google API Limited Use commitments" sections, including that Google user data is never used to train their models. The specific AI providers and models may change over time as we improve the Service. If you would like the current list of AI subprocessors, contact info@soontra.com.
Security
We use technical and organizational safeguards designed to protect information, including authentication controls, encryption of OAuth tokens at rest (AES-256-GCM), encrypted connections in transit, workspace isolation, database-level access controls and row-level security, role-based workspace permissions, rate limits, login-lockout controls, CAPTCHA and abuse-prevention checks, signed-webhook verification for inbound platform callbacks, infrastructure monitoring, and operational logging with secret/PII redaction.
No security measure is perfect. You are responsible for protecting your credentials, devices, networks, workspace permissions, third-party accounts, and exported or downloaded content.
Retention
We retain information for as long as reasonably necessary to provide the Service, maintain workspaces, comply with legal and platform obligations, resolve disputes, enforce agreements, secure the Service, maintain backups, support billing, and operate legitimate business records.
Retention periods vary based on the type of information:
Account and workspace records are generally retained while the account or workspace is active.
Uploaded files and derived indexes are generally retained while the file, workspace, or account remains active, unless deleted or subject to a shorter retention setting.
Billing records may be retained as required for tax, accounting, dispute, fraud-prevention, and legal purposes.
Security logs, operational logs, telemetry, and backup copies may be retained for a limited period after deletion from active systems.
Connected-platform tokens and connection records are retained as needed to operate, secure, troubleshoot, revoke, reconnect, audit, or comply with platform and legal requirements. When an integration is disconnected, some deactivated connection records or encrypted token records may remain for a limited period where needed for security, audit, revocation, troubleshooting, legal, or platform-compliance purposes.
For YouTube/Google authorized data, Soontra follows the YouTube API Services Developer Policies and Google API Services User Data Policy. Stored YouTube API data is refreshed or deleted on an ongoing basis and at least every 30 days, and in practice our analytics and published-video data are refreshed on a recurring sync (approximately every 6 hours) while a channel remains connected. Authorization tokens are revoked when you disconnect.
Content that you have already published or uploaded to a connected platform lives on that platform and is governed by that platform's own retention and deletion controls. Disconnecting Soontra or deleting data within Soontra does not remove content that has already been posted to YouTube, TikTok, or Instagram.
Deletion and revocation
You may delete uploaded files through the Service where available. When a file is deleted, Soontra removes the active file record and associated active searchable/indexed content that the Service maintains for that file; the underlying stored object is removed through our deletion and routine cleanup processes, subject to backup, security, legal, moderation, and technical limitations.
Workspace owners may delete workspaces where the Service provides that option, subject to ownership, last-workspace, billing, moderation, legal, and technical limits. Workspace deletion removes active workspace projects, files, members, settings, and associated data according to the product's deletion flow, subject to backup, security, legal, moderation, and technical limitations.
You may delete your account from your account/profile settings in the Service (this requires reauthentication), or by contacting info@soontra.com. Deleting your account cancels active workspace subscriptions, revokes any API keys and connected-integration grants, deletes your user profile and the workspaces you solely own (member and content records cascade-delete), and erases your associated marketing/CRM profile from our messaging provider, subject to backup, billing, legal, and technical limitations. Account deletion may be limited if you are the sole owner of a workspace with other members.
You may disconnect YouTube, TikTok, or Instagram integrations through Soontra settings where available. Disconnecting an integration stops future syncs and publishing and disables Soontra's active use of that connection. Depending on the platform and integration, Soontra may attempt token revocation, clear caches, delete or deactivate connection records, retain limited records for security or audit purposes, or require reconnection if access expires or is revoked.
For YouTube, you may also revoke Soontra's access through your Google account security settings. Soontra will use reasonable efforts to revoke YouTube authorization tokens promptly where technically available and will delete stored YouTube user data that you request us to delete as soon as possible and within 7 calendar days, subject to legal obligations. For YouTube API data that may be retained only while authorized or refreshed, Soontra will delete or refresh that data within the periods required by YouTube API Services policies.
You may also revoke connected-platform access through platform controls, such as TikTok app/account settings or Meta/Instagram app settings where those platforms provide the control. For valid Meta or Instagram deauthorization and data deletion callbacks, Soontra removes matching Instagram connection records and retained Instagram analytics and published-media records associated with the matching account, and for data deletion callbacks returns a confirmation code and a status URL where you can check the status.
Full step-by-step instructions are available in our Data Deletion & Management Policy.
Your choices and rights
Depending on your location and applicable law, you may have rights to access, correct, delete, export, restrict, or object to certain processing of personal information. You may also have the right to opt out of certain disclosures or uses.
To make a privacy request, contact info@soontra.com. We may need to verify your identity and authority before acting on a request. If your information is controlled by a workspace owner or organization, we may direct your request to that workspace owner or organization.
You can also control certain information directly in the Service, including account profile details, workspace settings, notification preferences, file deletion, workspace deletion, integration disconnects, account deletion, and billing settings, depending on your role and plan.
Communications
We may send transactional, security, billing, product, and support communications. You may opt out of certain non-transactional communications, but we may still send messages necessary to provide, secure, or administer the Service.
International processing
Soontra is headquartered in the United States. We and our service providers may process information in the United States and other jurisdictions. Those jurisdictions may have data protection laws different from where you live.
Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. The Service is intended for users who meet the eligibility requirements in our Terms of Service. If you believe a child provided personal information to us, contact info@soontra.com.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If changes are material, we will provide notice through the Service, email, or another reasonable method. The updated Privacy Policy will be effective when posted or as stated in the notice.
Contact
For questions or requests about this Privacy Policy or our data practices, contact:
Soontra Miami, Florida, United States
Email: info@soontra.com
