100 free credits. No credit card required.Start building
Logo
Legal

Privacy Policy

This Privacy Policy explains how SocialCrawl collects, uses, stores, and protects your personal information when you use our platform and services.

Effective Date: 9 April 2026 | Last Updated: 22 September 2026

1. Introduction

Welcome to SocialCrawl, a unified social media data API operated by Ridio Company Ltd ("we," "us," or "our"), a company registered in England and Wales at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.

This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you visit our website, use our API services, or interact with our platform (collectively, the "Service"). It also describes your rights regarding your personal data and how to exercise them.

By accessing or using our Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our Service.

For questions about this Privacy Policy, contact us at hello@ridiocompany.com.

2. Information We Collect

We collect information in three ways. You give it to us, for example when you create an account, buy credits, or write to us. The site and the API record it as you use them, for example the page, the call, and the IP address. If you sign in with another company's account, that company sends us the basic profile in section 2.3.

2.1 Information You Provide Directly

When you create an account or use our Service, you may provide:

  • Account information: Name and email address
  • Password: Stored as a hash. If you turn on two-factor authentication, we store the authenticator secret and backup codes in encrypted form. If you register a passkey, we store what that sign-in method needs
  • API keys: A hash of each key, and an encrypted copy so we can show the key to you. We do not store the key in plaintext
  • Payment information: Credit purchases are processed by Stripe. We store your Stripe customer id and the transaction. We do not store your full card number. If you turn on automatic top-up, we also store the card brand, the last four digits, and the expiry
  • Communications: What you send when you contact us
  • Dashboard chat: If you use the chat in the dashboard, the messages in that conversation
  • Files: If a feature stores a file for your account, that file is stored on Cloudflare R2. We do not use Amazon S3

2.2 Information Collected Automatically

When you access our Service, we automatically collect:

  • IP address and user agent, on the session and on API request logs
  • Pages and product events while you use the site
  • API request logs: the endpoint, query parameters, status, timing, credits used, and whether the response was served from cache

2.3 Information from Third-Party Authentication Providers

If you sign in with a third-party account, we receive the name, email address, and profile picture that provider sends, and we keep the sign-in token from that provider so the session can continue. We ask only for that basic profile. The provider's own privacy policy covers what they do with your account there.

3. How We Use Your Information

3.1 Providing and Operating the Service

  • Creating and managing your account
  • Authenticating your identity and securing your sessions
  • Processing your API requests and routing them to appropriate data sources
  • Tracking your credit balance and processing credit purchases
  • Delivering API responses with normalised social media data

3.2 Improving the Service

  • Analysing usage patterns to identify features that need improvement
  • Monitoring API performance, response times, and cache efficiency
  • Understanding which platforms and endpoints are most used to prioritise development

3.3 Communication

  • Sending essential service emails: welcome messages, API key notifications, credit balance alerts, payment confirmations, and security notices
  • Sending optional emails: product updates and weekly usage reports (you can unsubscribe from non-essential emails at any time via the unsubscribe link in any email or through your account settings)
  • Responding to your support enquiries

3.4 Security and Fraud Prevention

  • Detecting and preventing unauthorised access, abuse, or fraud
  • Monitoring for suspicious API usage patterns
  • Maintaining platform integrity and security

3.5 Legal Compliance

  • Complying with applicable laws, regulations, and legal processes
  • Enforcing our Terms and Conditions
  • Protecting our rights, privacy, safety, or property

4. Legal Basis for Processing

Under the UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (EU GDPR), we process your personal data on the following legal bases:

Legal BasisWhen We Rely on It
Performance of a ContractAccount registration, processing API requests, credit transactions, and delivering the Service you signed up for
ConsentOptional product emails, which you can turn off at any time
Legitimate InterestsRunning the Service, product analytics, error diagnosis, preventing fraud, and keeping the platform secure, balanced against your rights
Legal ObligationRetaining transaction records for tax and accounting purposes, responding to lawful requests from authorities

You may withdraw your consent at any time where we rely on it as our legal basis. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

5. Data Sharing and Third Parties

We do not sell your personal data. We share it with service providers who process it for us, under contract:

Service providerPurposeWhat they receive
StripePaymentsEmail address, amounts, and a customer id. Your full card number stays with Stripe. If you turn on automatic top-up, we store the card brand, last four digits, and expiry
ResendEmailYour email address and the message
PostHogProduct analyticsWhen you are signed in: your account id, name, and email, plus the pages and features you use. PostHog does not record your screen
VercelHostingIP address and request logs for the site and the API
NeonDatabaseThe account data described in this policy. The database is in the United Kingdom
Upstash (QStash)Background jobsYour user id and the details the job needs, such as an email we are sending
Cloudflare R2File storageA file the product stores for your account, when a feature does that. We do not use Amazon S3
Cloudflare TurnstileBot check on signupThe signup check in your browser, including the IP address
DataFastProduct analyticsA visitor id, and the name of an event such as an account being created
Google AdsAdvertising measurementA conversion when you create an account or buy credits, including the amount and a transaction id

Upstream data providers

To answer an API call we send the query parameters, such as a public username, a post URL, or a search term, to outside data providers and, where the platform has one, that platform's own public API. They do not receive your account email or your API key. Where a call includes an AI step, that step also receives the query and short excerpts of public results.

Publicly available platform data

Separately from your account, the Service retrieves publicly available social media data (public profiles, posts, comments, and engagement metrics) for our customers. For that processing we act as a controller under the UK GDPR, relying on legitimate interests (Article 6(1)(f)).

  • We handle only data that is publicly accessible without logging in. We do not retrieve private accounts, private posts, direct messages, or other login-gated content.
  • Most responses are cached for between 2 and 30 minutes, then expire. A transcript can be cached for up to 30 days. A label on a public post, comment, or review can be kept for up to 30 days. A request that sends an idempotency key can reuse the stored response for up to 24 hours.
  • We do not keep a general archive of every response. A monitor's results stay until you delete the monitor. A cohort stays until you delete it or until the retention period you set ends (7 to 90 days). Cohort contents are encrypted.
  • Our Public Data Notice explains, for anyone whose public information may appear in API responses, what categories of data are involved, the sources, the legal basis, and how to object or request suppression.
  • Our Terms and Conditions prohibit customers from using this data for facial recognition, biometric identification, surveillance or behavioural monitoring of individuals, or re-identification.
  • We do not ask you for information about your health, religion, politics, or similar matters. A public post the API returns can contain whatever that person wrote, which may include that kind of information. We do not use it to profile you.

Legal Disclosures

We may disclose your information if required by law, or in good faith belief that disclosure is necessary to:

  • Comply with a legal obligation or lawful request from authorities
  • Protect and defend our rights or property
  • Prevent or investigate wrongdoing related to the Service
  • Protect the safety of our users or the public

6. International Data Transfers

Ridio Company is based in the United Kingdom. The account database is hosted by Neon in the United Kingdom. The Service runs on Vercel, and some of the providers named in this policy operate in the United States or elsewhere, so your personal data may be processed outside the UK or the European Economic Area (EEA).

A transfer out of the UK has to rest on a safeguard the UK GDPR recognises. That safeguard sits in the contract with the provider. It may be standard contractual clauses, or an adequacy decision where one applies. This policy names the provider. It does not set out each contract. If you need a provider's contract, write to hello@ridiocompany.com.

7. Data Retention

We keep personal data only for as long as we need it for the purposes in this policy.

DataHow long we keep it
Account, API keys, credit ledger, email log, saved searches, monitorsWhile the account is open. Deleted when you confirm account deletion. There is no further holding period
SessionsA session lasts up to 7 days and renews while you use the site. The session row is removed when the account is deleted
API request logs90 days, then deleted. Deleted sooner if you delete the account first. The log includes the call, the query parameters, the IP address, and the user agent. We do not aggregate or anonymise it
CohortsUntil you delete the cohort, or until the retention period you set (7 to 90 days), and when the account is deleted
Dashboard chatUntil you delete the conversation, or when the account is deleted
Files stored for the accountThe database record is removed with the account. Account deletion does not by itself delete the file from Cloudflare R2
API response cache2 to 30 minutes for most calls. Up to 30 days for content that does not change, such as a transcript. Labels on a public post, comment, or review can be kept for up to 30 days
Idempotent responsesUp to 24 hours, when a request uses an idempotency key
Payment recordsStripe's record of the payment, and the order record in our database, are kept for tax and accounting. They are not deleted with the account. The in-product credit ledger is deleted with the account
PostHog, DataFast, and Google AdsKept by those providers. We do not run a separate deletion job for them
Site search logA scrubbed query can remain after the account is deleted. The user id on that row is removed

Confirming the deletion link in the email deletes the account then. We do not keep it for another 30 days.

8. Your Rights

Rights for All Users

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your personal data (subject to legal retention obligations)
  • Data Portability: Request your data in a structured, commonly used, machine-readable format
  • Opt-Out of Marketing: Unsubscribe from non-essential emails at any time via the unsubscribe link in any email or your account email preferences

Additional Rights Under UK GDPR and EU GDPR

  • Restrict Processing: Request that we limit how we use your data in certain circumstances
  • Object to Processing: Object to processing based on legitimate interests
  • Withdraw Consent: Withdraw consent at any time where processing is based on consent
  • Lodge a Complaint: File a complaint with a supervisory authority. In the UK, this is the Information Commissioner's Office (ICO) at ico.org.uk

Additional Rights Under CCPA/CPRA (California Residents)

  • Right to Know: Request details about the categories and specific pieces of personal information collected
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out of Sale: We do not sell your personal information
  • Non-Discrimination: We will not discriminate against you for exercising your privacy rights

Additional Rights Under Korea's Personal Information Protection Act (PIPA)

  • Access and Correction: Request access to and correction of your personal information
  • Suspension of Processing: Request suspension of processing
  • Deletion: Request deletion of your personal information
  • Right to Be Informed: Be notified about the collection, use, and sharing of your personal information
  • Consent Withdrawal: Withdraw consent for the collection and use of your personal information at any time
  • Right to Remedy: Seek remedies for damages caused by personal information infringement

How to Exercise Your Rights

Contact us at:

  • Email: hello@ridiocompany.com
  • Post: Oscar Lee (Chief Privacy Officer), Ridio Company Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom

We will respond within 30 days (or within the timeframe required by applicable law). We may verify your identity before processing your request.

9. Cookies and Tracking Technologies

We use cookies and similar technologies to operate and improve our Service.

Essential Cookies

Required for the Service to function. These cannot be disabled without breaking core functionality.

CookiePurpose
socialcrawl.session_tokenKeeps you signed in. A session lasts up to 7 days and renews while you use the site
socialcrawl.stateProtects the third-party sign-in flow. Single use
socialcrawl.two_factorHolds two-factor sign-in state for the session

Analytics and advertising

These are set when you use the site. A banner on the site stores a cookie preference. That preference does not switch these off. You can block them in your browser.

Cookie or tagPurposeProvider
ph_*_posthogPages and product events. When you are signed in, also your account id, name, and email. Screen recording is offPostHog
datafast_visitor_idA visitor id, used to record events such as an account being createdDataFast
Google tagA conversion when you create an account or buy credits, including the amount and a transaction idGoogle Ads

Managing cookies

You can control cookies through your browser settings. Most browsers let you view, delete, or block cookies. Blocking essential cookies may stop you signing in.

For detailed information about the cookies we use, please refer to our Cookie Policy.

10. Security

We implement appropriate technical and organisational measures to protect your personal data:

  • In transit: Connections use TLS
  • Passwords: Salted and hashed. We do not store the plaintext password
  • API keys: A hash and an encrypted copy. We do not store the key in plaintext
  • Two-factor secrets and backup codes: Encrypted, if you turn two-factor authentication on
  • Cohort contents: Encrypted
  • Access: Limited to people who need it for their work

No method of transmission over the Internet or electronic storage is 100% secure. While we cannot guarantee absolute security, we are committed to promptly addressing any security incidents in accordance with applicable law.

11. Children's Privacy

Our Service is not directed at children under the age of 14. We do not knowingly collect personal data from children under 14. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at hello@ridiocompany.com, and we will promptly delete such information.

12. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our practices, technologies, or legal requirements. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this policy
  • Notify you by email or through a prominent notice on our platform at least 30 days before changes take effect
  • Where required by law, obtain your consent to material changes

We encourage you to review this Privacy Policy periodically.

13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices:

Ridio Company Ltd Attn: Oscar Lee, Chief Privacy Officer 71-75 Shelton Street, Covent Garden London, WC2H 9JQ, United Kingdom

Email: hello@ridiocompany.com Phone: +44 20 4524 7944

For UK GDPR enquiries, you may also contact the Information Commissioner's Office (ICO) at ico.org.uk.

For enquiries under Korea's Personal Information Protection Act, you may contact the Personal Information Protection Commission (PIPC) at pipc.go.kr.