Legal
Privacy Policy
Last updated: September 18, 2026
1. Who we are
Rowe AI (“Rowe,” “we,” “us”) provides a multi-channel social scheduling and assistant product. This Privacy Policy explains what information we collect when you use the Rowe website, dashboard, APIs, and related services (the “Service”), how we use it, and the choices you have.
Contact: support@rowe.ai. Also see our Contact page.
2. Information we collect
Account data. Email address, display name, authentication identifiers from Supabase Auth (including Google sign-in if you choose it), and profile settings.
Social channel data. When you connect Instagram, Facebook, LinkedIn, X (Twitter), Gmail, or Outlook, we receive OAuth tokens and basic account identifiers (such as handle, page ID, or email address) required to publish, schedule, read insights, or manage inbox/comments as you authorize.
Content you create. Captions, media URLs, drafts, schedules, assistant chat threads, agent memory notes, webhooks, and personal access tokens you generate.
Usage & diagnostics. Approximate logs needed to operate the Service (API errors, publish job status, rate-limit events). We do not sell personal data.
3. Social platforms & API data
Rowe uses official provider APIs (including Meta Graph API for Instagram and Facebook Pages). We only request scopes needed for features you use. Platform data is used to:
- Publish, schedule, and cancel posts on your behalf
- Display calendars, analytics, inbox, and comments in the dashboard
- Power the in-app assistant and optional MCP / Agent API tools
Meta permissions (Facebook Login path). When you connect Instagram / Facebook, Rowe may request:
instagram_basic,pages_show_list,pages_read_engagement,business_management— discover and link your Professional Instagram account and Facebook Pageinstagram_content_publish,pages_manage_posts— create Feed, Reels, Stories, and Page posts you approve in Roweinstagram_manage_insights— show post and account analytics in the dashboardinstagram_manage_messages,pages_messaging,pages_manage_metadata— receive and reply to Instagram Direct messages in Inboxinstagram_manage_comments— list, reply to, and moderate comments on your media
We do not sell platform data. Tokens are used only to perform the actions you initiate (or schedule) in Rowe.
Token storage. Social access tokens are stored on the Rowe AI API vault (hosted on Railway), not in the browser localStorage and not in the Cursor MCP desktop client. The website authenticates you and calls the vaulted API to perform channel actions.
You can disconnect a channel at any time in the dashboard under Channels. Disconnecting revokes Rowe’s stored connection for that platform; you should also revoke access in the provider’s security settings if desired.
4. How we use information
- Provide, secure, and improve the Service
- Authenticate users and enforce rate limits
- Generate assistant drafts and analytics-derived playbooks you control
- Respond to support and compliance requests
- Comply with law and platform developer terms
Optional AI providers (for example Anthropic for in-app chat, or media helpers such as stock image / video generation services you enable) process prompts and outputs needed to fulfill your requests. Do not submit secrets or data you are not allowed to process with those providers.
5. Processors & subprocessors
We use trusted processors to run the Service, including:
- Supabase — authentication and application database / storage
- Railway — Rowe AI API and token vault hosting
- Vercel (or your chosen host) — website hosting
- Meta, LinkedIn, X, Google, Microsoft — connected social / email APIs
- Anthropic and similar AI vendors — when the assistant or compose tools are used
6. Retention
We retain account and content data while your account is active. Publish jobs, metrics, and logs may be kept for a reasonable period for reliability and abuse prevention. You may request deletion as described below.
7. Your rights & deletion
Depending on your location, you may have rights to access, correct, or delete personal data. To delete your Rowe account data and connected social tokens, follow the steps on our Data Deletion page or email support@rowe.ai with the subject “Data deletion request.”
8. Children
The Service is not directed to children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect data from children.
9. International transfers
We may process data in the United States and other countries where our processors operate. By using the Service you understand that your information may be transferred to those locations.
10. Changes
We may update this Policy from time to time. The “Last updated” date at the top will change when we do. Continued use of the Service after changes means you accept the updated Policy.