Sheevook

Privacy Policy

Last updated July 15, 2026

This policy explains what Sheevook does with your information. It is written to match how the product actually works, not to cover every hypothetical. If a section seems to promise more than the app does, the app wins and we will fix the wording.

Who this is for, and who is responsible

Sheevook is a single-account marketing workspace that you run yourself. One account, created on first run, owns the whole workspace. There are no other users to share your data with inside the product.

Because Sheevook is self-hosted, the person or organization running a deployment is the data controller for the workspace data in it: your marketing content, the platform connection tokens, and any attribution or conversion signals collected from visitors to your own product site. Sheevook is the software provider. It does not run a central service that collects your workspace data, so the app vendor does not receive your content, your tokens, or your analytics. This policy describes how the shipped software handles data. If you deploy Sheevookand collect other people's personal data through it, you are responsible for your own lawful basis, your own privacy notice to those people, and your own handling of their requests.

What we store

  • Your account. A username and a password. Passwords are hashed (scrypt) and never stored in plain text.
  • Your content and campaigns. The brands, posts, schedules, campaigns, and analytics you create in the workspace.
  • Platform connections. When you connect a social or ad platform, the OAuth access tokens that platform issues are stored so the app can publish and read analytics on your behalf. They are kept server-side and are never sent to your browser. Data those platforms return to the app (for example post metrics) is received from the platform, not collected directly from you.
  • Attribution and conversion signals.If you install the optional capture snippets on your own product site, the anonymous "how did you hear about us?" answers and post-signup conversion events they send are stored to close the content-to-outcome loop. They carry no login session and no personal profile. These signals come from visitors to your site, so you must disclose them in your own site's privacy notice.

Why we use it, and our legal basis

For users in the EU, UK, and other regions with equivalent laws, the legal bases we rely on are:

  • Performance of a contract - to run the workspace you set up: authenticating your account, storing your content, and publishing on your behalf through the platforms you connect.
  • Legitimate interests - to keep the app and your account secure, and to provide the analytics and attribution features that let the workspace function as intended. You can object to processing based on legitimate interests (see your rights below).
  • Consent - where you choose to enable an optional integration (a platform connection, or an AI provider), the content required to fulfill that action is processed on the basis of that choice, which you can withdraw at any time by disabling the integration.
  • Legal obligation - where we must retain or disclose data to comply with the law.

Where your data lives, and transfers

Run locally, your data lives in a SQLite database and media folder on your own machine. Deployed, it lives in the Postgres database and blob storage you configure. Sheevook does not run a central service that collects your workspace data. Because you choose where to host your deployment, you also choose where your data is stored and processed, and you are responsible for any cross-border transfer that choice implies (for example using an appropriate safeguard such as Standard Contractual Clauses where required).

Third parties you choose to enable

The app only talks to outside services you deliberately turn on:

  • Social and ad platformsyou connect (for publishing and analytics). Your use of each is governed by that platform's own terms and privacy policy.
  • AI providers, if configured. The app can run with no AI provider at all and falls back to deterministic output. When you enable the Anthropic API or the local Claude CLI, the content being generated is sent to that provider to fulfill the request. Prompts are sent only when a generation actually needs one.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. The app contains no third-party advertising or tracking pixels.

Cookies

Sheevook uses only the cookies it needs to work: a session cookie that keeps you signed in (a stateless, HMAC-signed token), and a small cookie that remembers which project is active. There are no advertising, analytics, or third-party tracking cookies.

AI-generated media

Media the app generates with AI is flagged as AI-generated and that flag is carried through to publishing so it can be disclosed where a platform supports it. We never generate a synthetic person, testimonial, or review. The app does not make any decision about you by solely automated means that would produce a legal or similarly significant effect.

How long we keep it

Because you control the deployment, your data is kept for as long as you keep it. Your content and analytics remain until you delete them. A platform's tokens are removed when you disconnect it. Deleting the workspace database removes everything. There is no separate copy held by the app vendor.

Your rights

Depending on where you live, you have some or all of the following rights over your personal data:

  • Access and know - what data is held and how it is used.
  • Rectification and correction - fix inaccurate or incomplete data.
  • Erasure and deletion - have your data removed.
  • Restriction and objection - limit or object to certain processing, including processing based on legitimate interests.
  • Portability - receive your data in a portable format.
  • Withdraw consent - at any time, without affecting processing that already happened lawfully.
  • Opt out of sale or sharing - not applicable here because we do neither, but the right is yours.
  • Non-discrimination - we will not treat you differently for exercising any of these rights.

Because you control the deployment, you can exercise most of these yourself: export or delete any content, disconnect any platform (which removes its stored tokens), or delete the workspace database entirely at any time. Disconnecting a platform in the app does not by itself revoke access on the platform side, so you may also want to remove the app from that platform's connected-apps settings. For anything you cannot do in the app, contact us using the details below.

If you are in the EU or UK and believe your data has been handled improperly, you also have the right to lodge a complaint with your local data protection supervisory authority.

Children

Sheevookis a business marketing tool and is not directed to children. It is not intended for anyone under 16 (or the minimum age set by your country, and under 13 in the United States), and it does not knowingly collect their personal data. If you believe a child's data has ended up in a workspace, delete it or contact us and it will be removed.

Security

The app hashes passwords with scrypt, keeps platform tokens server-side (never exposed to the browser), and signs session cookies with a server-only secret. No system is perfectly secure, and because you run the deployment, keeping your server, database, and credentials secure is part of your responsibility too.

Contact

For privacy questions or to exercise a right you cannot complete in the app, contact us at privacy@sheevook.com. If you run a deployment for others, you are the controller for that workspace and are the first point of contact for its users.

Changes

If this policy changes materially, the "last updated" date above changes with it. We review it at least once a year.