Legal
Privacy
What FeedMosaic processes
FeedMosaic processes account details, secure authentication records, billing identifiers, feed settings, and content metadata returned by social platforms you choose to connect. Passwords are stored as one-way hashes. Provider access tokens are encrypted at rest.
Connected social accounts
When you authorize YouTube, Instagram, or TikTok, FeedMosaic requests read-only access needed to identify your account and import the eligible posts you choose to display. FeedMosaic stores encrypted provider tokens plus account and post metadata so it can refresh your feed. A published feed makes the selected post metadata and official provider embeds available to visitors of the website where you install it. FeedMosaic does not request permission to publish, edit, or delete posts on your behalf.
Google and YouTube user data
For YouTube, FeedMosaic requests the youtube.readonly scope only. It uses this access to identify the channel selected by the user and retrieve that channel’s uploads for the user-facing feed builder and embeds. FeedMosaic does not use Google user data for advertising, credit decisions, or training generalized artificial-intelligence models, and does not sell it. FeedMosaic shares it only with infrastructure processors needed to operate the service and with visitors when the user deliberately publishes a feed.
You can disconnect YouTube from the Connections screen, which removes the stored tokens, or delete the FeedMosaic account to remove feeds and imported content. You can also revoke FeedMosaic from your Google Account permissions at any time. FeedMosaic’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Billing
Payments are processed by Stripe. FeedMosaic stores Stripe customer and subscription identifiers, but does not store full card numbers or card security codes.
Service and security data
Technical logs may include request timestamps, error information, network addresses, and browser details. A limited set of conversion events is retained for up to 90 days without storing free-form page content.
Retention and deletion
Account data is retained while the service is active and as needed for security, billing, legal, and fraud-prevention obligations. You can delete the account from Billing or follow the data deletion instructions.
Processors and transfers
FeedMosaic relies on hosting, database, transactional email, social-platform, and payment providers to operate the service. Those providers process only the data required for their role and apply their own privacy terms.
Your choices
You may request access, correction, export, or deletion of personal information, subject to applicable legal exceptions. Contact privacy@feedmosaic.com.