// Legal

Privacy Policy

Last updated: September 23, 2026

This policy explains how InvisibleAPI, a product built by EmbedSocial ("InvisibleAPI", "we", "us", and "our"), handles personal information when you visit invisibleapi.ai, use our website, or use our API, dashboard, MCP server, and related services (collectively, the "Service").

1. Information we collect

Information you provide

We collect information you provide when you register for an account, contact us, ask for support, join an organization, or otherwise use the Service. This can include your name, email address, company name, organization details, messages, and any information you choose to include in a support request.

Account, billing, and authentication information

To create and administer your account, we process account identifiers, login details, API-key metadata, organization membership, plan and subscription information, invoices, and transaction records. Payments are processed by Stripe or another payment provider acting on our behalf. We do not store full payment-card numbers.

Connected social accounts and API data

When you connect a social account, the relevant platform provides us with the data and permissions you approve through its authorization flow. Depending on the platform and permissions granted, this may include account or profile identifiers, account name, profile image, access and refresh tokens, scopes, account status, publishing metadata, and account insights.

We use these credentials to operate the connection, refresh authorization where the platform permits it, publish or schedule the content you request, report job status, and provide the Service. We do not receive your social-platform password through these authorization flows. You may disconnect an account or revoke our access through the Service or the applicable platform's account settings.

Content and activity in the Service

We process the content and instructions sent through the API, dashboard, or MCP server, including post text, media URLs, scheduling details, destination accounts, job status, logs, and error messages. We also collect usage information needed to run, secure, and improve the Service, such as API requests, timestamps, IP address, user agent, referring pages, rate-limit and quota events, and diagnostic logs.

Website analytics and cookies

Our website uses strictly necessary browser storage to remember your cookie preferences. We use PostHog for privacy-conscious, cookieless product analytics; it is configured to use memory-only persistence and does not write analytics cookies or persistent browser identifiers. Where we introduce optional analytics or marketing technologies, we will ask for consent where required and explain the available choices in our cookie controls.

We also use one first-party attribution cookie, ia_attr, set on invisibleapi.ai and its subdomains for up to 90 days. It holds a random identifier, the time and page of your first visit, the type of source that referred you (for example search or social), the referring website's domain name, and any campaign (UTM) parameters in the link you followed. It lets us tell which of our pages led to a sign-up, and we attach the same values to the PostHog analytics events described above.

We also use Amplitude for website analytics, with data stored in Amplitude's EU data center. Amplitude sets first-party cookies (named AMP_ followed by an identifier) that hold a random device identifier and session information, so it can recognise return visits. It records the pages you view and how you interact with our website, such as clicks and form submissions. We do not record your screen or use session replay on our website.

If you are in the European Economic Area, the United Kingdom, or Switzerland, or we cannot determine your country, we set the attribution cookie and start Amplitude only after you accept analytics cookies. Elsewhere both are on by default, and you can refuse them at any time with the Reject option in our Cookie Settings: we then delete the attribution cookie and Amplitude stops collecting data. We treat a Global Privacy Control signal from your browser as a refusal wherever you are. To choose which rule applies, your browser asks our hosting provider, Cloudflare, for your country; the answer is kept in your browser for the current session only.

2. How we use information

We use personal information to:

  • provide, operate, maintain, and improve the Service;
  • create and administer accounts, organizations, API keys, and connected social accounts;
  • process subscriptions, payments, invoices, and trial eligibility;
  • execute publishing, scheduling, authorization, and other requests you submit;
  • communicate with you about the Service, including support, security, administrative, and transactional messages;
  • understand aggregate service use, troubleshoot issues, prevent abuse, and protect our systems and users;
  • send product updates or marketing communications where permitted by law; and
  • comply with legal obligations and enforce our agreements.

You can opt out of non-essential marketing emails by using the unsubscribe link in the message or by contacting us at support@invisibleapi.ai. Transactional and service-related messages may still be sent when necessary to operate your account or comply with our obligations.

4. How we share information

We do not sell personal information. We share information only as needed to provide and protect the Service, including with:

  • Service providers that support hosting, infrastructure, email, customer support, payment processing, analytics, security, and backup. They may process information only under our instructions and for the services they provide to us.
  • Social platforms when you authorize a connection or request an action, such as publishing content or retrieving account information. Their use of information is governed by their own terms and privacy policies.
  • Members of your organization, who may see information made available through your shared account, including connected accounts, publish jobs, and relevant account details according to their role.
  • Authorities or other parties where required by law or where we reasonably believe disclosure is necessary to protect rights, safety, security, or to investigate fraud or abuse.
  • A successor organization in connection with a merger, acquisition, financing, reorganization, sale of assets, or similar transaction, subject to applicable law.

5. Retention and security

Retention

We keep personal information for as long as needed to provide the Service, meet the purposes described in this policy, resolve disputes, enforce agreements, and satisfy legal, accounting, or reporting requirements. When information is no longer needed, we delete or anonymize it where feasible. Backup copies may persist for a limited period before being overwritten under our backup practices.

Security

We use appropriate technical and organizational measures designed to protect personal information, including encrypted transmission, access controls, and practices intended to limit access to authorized personnel and service providers. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

6. Your privacy rights

Subject to applicable law, you may have the right to request access to, correction of, deletion of, or restriction of your personal information; object to certain processing; withdraw consent; or receive a portable copy of information you provided to us. You may also have the right to lodge a complaint with your local data protection authority.

To exercise these rights, email support@invisibleapi.ai. We may need to verify your identity and authority before fulfilling a request. If we process information on behalf of one of our customers, you should direct your request to that customer first; we will support them as required by applicable law.

7. Other important information

International transfers

Your information may be processed in countries other than the one where you live. Where required, we use appropriate safeguards for international transfers of personal information.

Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, please contact us so we can take appropriate action.

Third-party links and services

The Service may link to or integrate with third-party services. Their privacy practices are governed by their own policies, not this one. We encourage you to review those policies before providing information to them.

Changes to this policy

We may update this policy from time to time. We will post the revised version on this page and update the "Last updated" date. If a change is material, we will provide additional notice where required by law.

8. Contact us

For questions about this policy or our privacy practices, contact us at support@invisibleapi.ai.

InvisibleAPI is built by EmbedSocial. For correspondence related to this policy, you may also write to EmbedSocial PLTD, 28mi Oktomvri N.5 et.2, Petrich 2850, Bulgaria.