Skip to content
KariSMMa, home

Privacy policy

What we collect when you use the KariSMMa website and portal, why, who helps us process it, and the choices you have.

Who we are

KariSMMa is a social media management platform operated by Intelligent Punks ("we", "us"). This policy covers the website at karismma.com and the portal at portal.karismma.com. If you have a question about it, or want to use any of your rights, email us at info@intelligentpunks.com.

The website

The website does not use cookies, analytics or advertising trackers. Like every website, it is served by a hosting provider (Vercel) that processes technical data such as your IP address, browser and the pages requested, to deliver the pages and keep the service secure.

What we collect in the portal

Your account. Your name, email address and sign-in details. Sign-in is handled by our authentication provider, Clerk. We also keep which workspaces you belong to and your role in each (Owner, Manager or Client approver).

Your brands and content. Brand kits (logo, colours, voice, audience, hashtags, banned words, language and website), posts and their media, comments between team members, approval decisions, reports, plans and automation rules.

Connected social accounts. When you connect Facebook, Instagram, Threads, YouTube or TikTok, the network gives us an access token and the data the permissions you approve allow: profile details, posts, their results, and for Facebook and Instagram, the comments and direct messages that arrive in the inbox. Access tokens are encrypted at rest.

Approval links. A person who approves posts through a share link enters a name and an email address. We store them with each decision; their browser also keeps them so they do not have to type them again.

AI features. When you use an AI feature, the text, images and instructions needed for it are sent to the AI provider that performs it (see below). If you connect your own AI key, we store it encrypted and use it only for your workspace.

Brand scans. When you ask KariSMMa to fill in a brand kit, it reads the public website address you give it, or the public profiles and recent captions of the brand's connected social accounts.

Billing. Payments are processed by Stripe. We receive the details needed to manage your subscription, such as the plan, the status of payments and invoices. We do not receive or store full card numbers.

Activity log. Actions in a workspace, such as approvals, publishing, deletions, connections and role changes, are recorded with who did what and when.

AI apps (MCP). If you connect an AI app such as Claude or ChatGPT to KariSMMa, the app sends us only the tool it calls and that tool's inputs (for example a brand name, a post's text or a date range), and we send back the workspace data the tool is for, within your role and the brands the connection may see. We never receive or read your conversations with the AI app, its memory or your files. We keep each change made through an AI app in the Activity log, a per-minute count of calls for rate limits, and each connection's name, when it was last used and from which app. Personal access tokens are stored only as a one-way hash and their last four characters. What the AI app does with the answers is governed by its provider's terms and your settings there. You can revoke a token or disconnect an app at any time in Settings, Connections, AI apps.

How we use data

We use data to provide the service you ask for: to publish and schedule posts, import their results, show analytics and reports, bring comments and messages into the inbox, run automations you set up, perform AI actions, manage billing, keep accounts secure and answer support requests. We do not sell personal data and we do not use it for advertising.

Who processes data for us

  • Vercel: hosting of the website and portal.
  • Supabase: database and file storage.
  • Clerk: sign-in and account management.
  • Stripe: payments and billing.
  • Meta (Facebook, Instagram, Threads), Google (YouTube) and TikTok: the networks you connect, through their official interfaces.
  • AI providers, when you use an AI feature: Anthropic (Claude), OpenAI, Google (Gemini), Runway, Higgsfield, ElevenLabs and Magnific.

Some of these providers process data outside your country, including in the United States.

YouTube

KariSMMa uses YouTube API Services to publish videos and read their results for channels you connect. By connecting YouTube you also agree to the YouTube Terms of Service, and Google's use of data is described in the Google Privacy Policy. You can remove KariSMMa's access at any time in your Google account's security settings, as well as by disconnecting the channel in KariSMMa.

Cookies and browser storage in the portal

The portal uses only cookies needed for it to work, none for analytics or advertising:

NamePurposeHow long
Clerk's session cookiesKeep you signed inAs set by Clerk
smm_brandThe last brand you opened1 year
smm_ui_langYour interface language1 year
smm_week_startThe first day of the week you chose1 year
Sign-in state cookies for each networkSecurity check while you connect an accountMinutes
fb_pick_sessionEncrypted, while you choose a Facebook PageMinutes
acct_takeoverProof of ownership when moving an account between workspacesMinutes

Your theme choice and, for approval links, the approver's name and email are kept in your browser's local storage, not in cookies.

How long we keep data

We keep workspace data while the workspace is active. Activity log entries are kept for two years. Approval links stop working after the number of days chosen, at most seven. When you disconnect a social account, its access token and the posts and images imported from it are deleted. An owner can delete a brand. To close an account or a workspace and delete its data, email us.

If you remove KariSMMa from your Facebook settings, Meta tells us and we delete the data that came from that connection.

Your rights

Depending on where you live, you may have the right to access, correct, delete or export your personal data, to object to or restrict how we use it, and to complain to a data protection authority. Email info@intelligentpunks.com and we will respond within the time the law requires.

Security

Access tokens and AI keys are encrypted at rest. Access inside a workspace follows roles, and Client approvers see only the brands they are given. No system is perfectly secure, so please tell us at once if you notice anything suspicious.

Children

KariSMMa is a business tool and is not directed at children.

Changes to this policy

We will update this page when the service or the law changes, and change the date at the top. For significant changes we will also tell workspace owners in the portal or by email.