Legal & compliance

Privacy policy

Read how Scedue collects, uses, shares, protects, retains, and transfers personal data, and how to exercise privacy rights.

Effective August 2, 2026Last updated August 2, 2026

In short: Scedue uses account, workspace, connected-platform, usage, and billing information to provide and secure the service. Optional product analytics runs only after consent. Scedue does not sell personal data. Privacy requests can be sent to support@scedue.com.

1. Scope and who is responsible

This Privacy Policy applies to scedue.com, app.scedue.com, related web applications, and support interactions that link to this policy (together, the “Services”). Scedue, trading as Scedue, is responsible for personal data collected for its own purposes through the Services.

A business customer may upload or connect personal data that it controls. For that data, the customer determines what is submitted and why, and Scedue acts as its service provider or processor to the extent required by applicable law. The customer must provide all notices and obtain all permissions needed for that data.

2. Personal data we collect

Account and identity information

Name, email address, authentication identifiers, profile details, workspace membership, role, and support preferences. We do not ask users to provide a social-network password to Scedue.

Workspace and content information

Brand rules, goals, memories, prompts, conversations, drafts, captions, comments, approval state, calendar entries, uploaded media and knowledge files, filenames, and other content a user chooses to submit.

Connected-service information

Social account identifiers, account type, display name, authorised access tokens, connection state, selected permissions, scheduled and published content, delivery status, and available post or audience analytics. Connected networks decide what data their APIs return.

Billing and transaction information

If paid plans are enabled, we receive limited billing details such as plan, amount, currency, tax location, payment status, transaction or subscription identifier, and partial payment-method details from the selected payment processor. Stripe, Razorpay, or another disclosed processor collects payment credentials directly. Scedue does not store full card numbers, CVV values, UPI credentials, or online-banking passwords.

Device, log, and usage information

IP address, browser and device type, operating system, timestamps, pages or features used, referring page, approximate location derived from IP, request and error logs, security events, and cookie or local-storage choices. Optional analytics is described in the Cookie Policy.

Communications

Messages sent to support, privacy, sales, or grievance channels, together with attachments and the information needed to investigate and respond.

3. Where data comes from

  • directly from users when they register, configure, upload, write, pay, or contact us;
  • from a customer organisation that invites a user to its workspace;
  • from connected social networks and integration providers after authorisation;
  • automatically from browsers, devices, logs, cookies, and consented analytics; and
  • from payment, fraud-prevention, and identity-verification providers when relevant.

4. How and why we use data

  • create accounts, authenticate users, and administer customer workspaces;
  • store brand context and content, generate drafts, and operate the content calendar;
  • connect authorised social accounts, schedule content, publish approved posts, and retrieve delivery or performance information;
  • provide paid plans, invoices, transaction support, cancellations, and refunds;
  • send requested, transactional, security, and service communications;
  • protect accounts, prevent fraud or abuse, debug failures, and maintain service reliability;
  • measure and improve the Services where consent or another valid permission applies;
  • comply with law, enforce agreements, resolve disputes, and establish or defend legal claims; and
  • perform another purpose clearly explained at collection, with consent where required.

Where consent is the basis for processing, it can be withdrawn through the available product control or by contacting us. Withdrawal does not affect processing already carried out lawfully and may prevent a requested feature from operating.

5. AI processing and connected publishing

Scedue sends the minimum context selected or retrieved for a task—such as a prompt, brand rule, conversation excerpt, or relevant knowledge passage—to an AI service provider to generate or analyse content. Users should not submit unnecessary sensitive personal data. AI output may contain errors and must be reviewed before use or publication.

When a user connects a social account, Scedue and its integration provider process authorised account data and content to perform the requested actions. The connected network separately processes data under its own terms and privacy policy. Disconnecting an account stops new authorised API activity but does not remove content already published on that network.

6. When we disclose data

We disclose data only as reasonably needed to:

  • operate the Services with vetted hosting, database, storage, AI, integration, email, analytics, support, fraud-prevention, and payment providers;
  • follow a user’s instruction, including publishing content to a connected network or sharing within the user’s workspace;
  • protect people and the service, investigate abuse, comply with lawful requests, or enforce legal rights; or
  • complete a corporate transaction such as financing, merger, acquisition, or sale, subject to appropriate confidentiality and notice where required.

Providers used for relevant features may include Supabase for infrastructure, Vercel AI Gateway and OpenAI for AI processing, Zernio and connected social networks for social integrations, Resend for transactional email, PostHog and Ahrefs for analytics, and Stripe or Razorpay for payments when activated. This list may change as the service evolves. Scedue does not sell personal data or share it for third-party cross-context behavioural advertising.

7. International processing

Scedue and its providers may transfer, process, and store data in India and other countries where they operate, to the extent permitted by applicable law. Those countries may apply different data-protection rules. We use contractual, organisational, and technical safeguards and obtain consent when applicable law requires it. Data processed outside India may be disclosed if lawfully required in that jurisdiction.

8. Retention and deletion

We retain personal data only while reasonably necessary for the purposes in this policy. Account and workspace data is generally retained while the account is active. Retention may continue for backup cycles, security investigations, dispute resolution, fraud prevention, enforcement, and legal, tax, accounting, or payment-record obligations. Retention periods vary by data type and legal requirement.

A valid deletion request removes or de-identifies eligible data from active systems. Residual copies may remain temporarily in restricted backups until they expire. Data that must be retained by law or for a live dispute is isolated and used only for that purpose. Content already published to a third-party network must be deleted through that network or its available tools.

9. Security

We use administrative, technical, and organisational safeguards designed for the nature of the data, including encrypted transport, access controls, tenant-scoped data access, protected provider credentials, logging, and backup and recovery controls. No service is completely secure. Users must protect their credentials, use strong authentication, restrict workspace access, and promptly report suspected compromise.

10. Rights and choices

Subject to applicable law and relevant exceptions, a person may ask to:

  • access a summary of personal data and processing activities;
  • correct, complete, or update inaccurate or incomplete personal data;
  • erase personal data that is no longer required;
  • withdraw consent or change optional analytics and communication choices;
  • receive information about relevant recipients or processors where required;
  • raise a grievance and receive a response; and
  • nominate another person to exercise applicable rights in the event of death or incapacity.

Send a request from the account email to support@scedue.com. We may verify identity and authority before acting. If Scedue processes the data solely for a customer organisation, the requester should contact that organisation first; we will support its response as required.

11. Children

The Services are intended for business users aged 18 or older and are not directed to children. We do not knowingly create accounts for children. If a parent or guardian believes a child provided personal data, they should contact us so that we can investigate and delete it where appropriate.

12. Third-party services and links

This policy does not govern independent websites, social networks, payment pages, or services that have their own privacy policies. Review those policies before connecting an account, authorising payment, or following an external link.

13. Changes and privacy grievances

We may update this policy to reflect product, provider, or legal changes. The page will show the new effective date, and material changes will be communicated through an appropriate service channel where required.

Privacy questions or grievances may be sent to support@scedue.com. Include the account email, a concise description of the request, and the response or remedy requested.

Questions about this document?

Contact Scedue at support@scedue.com. We normally respond to customer-service requests within two business days.