Coconut

Privacy Policy

This Policy explains how Coconut handles personal data across its websites, applications, workspaces, connected social channels, creator intelligence, AI-assisted features, and related services.

Effective July 24, 2026

Last updated July 24, 2026

Who Coconut is and scope

Coconut is the trading name of Coconut App Ltd, a company registered in England and Wales under company number 17124503. Its registered office is 3rd Floor, 86-90 Paul Street, London, England, United Kingdom, EC2A 4NE. Coconut App Ltd is the controller for the processing described below where it decides why and how personal data is used.

This Policy applies to personal data handled through coconutapp.xyz and Coconut websites, applications, APIs, agents, workspaces, connected-channel features, support, and related services (together, the “Services”). It covers Coconut users, customer contacts, workspace members, website visitors, people who contact us, and external creators whose public or licensed information appears in the Services.

You can contact Coconut about this Policy or a privacy request at [email protected].

Customer notices may also apply

A business customer may provide its own privacy notice for personal data that it controls and directs Coconut to process. This Policy describes Coconut’s own controller activities and explains how requests are routed when Coconut acts for a customer.

Coconut acts as controller for accounts, billing, security, support, product telemetry, communications, legal compliance, business operations, and Coconut-determined creator intelligence. For those purposes, Coconut determines the purposes and essential means of processing.

Coconut acts as processor where a qualifying business customer is the controller, determines the purpose of processing, and gives Coconut documented instructions for workspace content or connected-channel data. The customer remains responsible for its instructions, legal basis, notices, and handling of requests as controller. The Business Data Processing Terms in Coconut’s Terms of Service apply only if an order or written agreement expressly incorporates them and their role conditions are met.

A provider’s role follows the relevant purpose. Post for Me and other providers may act as Coconut’s processor or service provider when Coconut is controller, or as a subprocessor when Coconut processes personal data on a business customer’s documented instructions. White-label presentation does not mean that Coconut alone handles the processing or remove Post for Me from this processing chain.

How role allocation affects requests

Where Coconut is controller, it evaluates and responds to the request. Where Coconut acts only as a customer’s processor, Coconut may refer the requester to the workspace customer and assist that customer as required by the applicable data-processing terms and law.

Information we collect

The information Coconut handles depends on how a person, customer, or creator interacts with the Services. It may include the categories below.

Account, workspace, team, brand, and identity information

Names, email addresses, profile images, authentication identifiers, preferences, workspace and brand membership, team roles, invitations, permissions, administrative actions, and account or workspace status.

Billing and transaction information

Plan, subscription, billing contact, transaction, invoice, tax, payment status, and payment-provider identifiers. Payment-card information entered into a payment-provider form is handled by that provider rather than being intentionally stored as full card details by Coconut.

Customer Content, assets, and communications

Sources, brand information, prompts, uploads, media, assets, drafts, generated outputs, comments, messages, approvals, publication instructions, support requests, feedback, and associated metadata submitted to or created through the Services.

Connected-account information

Platform and account identifiers; names, usernames, handles, profiles, images, biographies, and URLs; access and refresh tokens; approved scopes and other permissions; token expiry, connection, and revocation status; posts, media, captions, comments and publication status; followers, reach, impressions, views, reactions, clicks, shares, watch data, and other performance metrics; and provider callbacks, webhook events, errors, rate limits, job state, and reconciliation metadata.

The precise fields depend on the native platform, the scopes approved by the account holder, and the capabilities made available to Coconut and Post for Me.

External creator, public, and derived information

Coconut may handle public data or licensed information about external creators who are not Coconut users, including names, handles, profiles, public posts, media, follower counts, engagement metrics, content categories, and source URLs. Coconut may create derived insights such as classifications, summaries, estimates, comparisons, recommendations, or other inferences from that information.

IP address, browser and device details, session and feature activity, referring information, cookies and similar technologies, API calls, logs, errors, performance diagnostics, operational job state, security events, and support or troubleshooting records.

Where information comes from

Coconut receives information directly from you when you register, configure a workspace, upload material, connect a channel, approve or publish content, communicate with us, or otherwise use the Services.

Information may also come from your organisation and other authorised workspace users; connected platforms; Post for Me; payment, identity, analytics, observability, storage, queueing, and communications providers; public web sources; licensed source-ingestion providers; official or permitted APIs; and customers who supply creator or content references.

Coconut also creates information from other data, including workspace activity, publication and reconciliation state, analytics observations, classifications, summaries, recommendations, and derived creator insights.

Third-party sources

A connected platform, data source, or provider may process information under its own terms and privacy notice. Public availability does not by itself remove privacy, accuracy, intellectual-property, publicity, or platform obligations.

How and why we use information

Where UK or EU data-protection law applies, Coconut uses the lawful bases below. A different or additional basis may apply under another jurisdiction. Where Coconut acts as processor, the customer determines the lawful basis for its processing.

Contract — service delivery and administration

Coconut uses account, workspace, Customer Content, connected-account, billing, and communications information as needed to authenticate users; provide collaboration, source ingestion, creator analysis, drafting, assets, scheduling, publishing, feeds, metrics, AI-assisted features, support, subscriptions, and requested account administration; and take steps requested before entering a contract.

Legitimate interests — service, security, and improvement

Coconut uses relevant account, usage, diagnostic, support, publication, and provider information to secure the Services, prevent fraud and abuse, troubleshoot, monitor reliability, understand feature use, maintain audit and reconciliation records, improve workflows, and protect Coconut, customers, providers, and other people. The interests are reliable service operation, network and information security, product administration, and proportionate business improvement, balanced against individual rights.

Legitimate interests — creator intelligence

Where appropriate after balancing the interests involved, Coconut uses external creator public data, provenance, content, metrics, and derived insights to let customers discover, understand, compare, and monitor relevant creators and content. Coconut considers the nature and source of the information, reasonable expectations, potential effects, accuracy, objection, and suppression when applying this basis.

Coconut uses information where necessary to meet tax, accounting, regulatory, court, law-enforcement, and other legal obligations, and where necessary to establish, exercise, or defend legal claims.

Coconut relies on Consent where the law requires it, such as for certain optional cookies, electronic marketing, or a specifically presented optional use. Consent can be withdrawn without affecting processing already carried out lawfully before withdrawal.

AI, inferences, and automated processing

Coconut uses AI and automated systems to help produce drafts, summaries, classifications, rankings, recommendations, performance analyses, workflow suggestions, embeddings, and other inferences. Depending on the feature, these systems may process prompts, Customer Content, connected-account data, external creator information, outputs, and relevant usage context.

Coconut may send the information needed to provide a feature to AI model and processing providers. Provider retention, use, and training treatment depends on the provider, contract, configuration, and feature. This Policy does not promise that every provider follows one universal retention or training rule.

Acknowledging this Policy is not consent to use Customer Content or connected-account data to train or fine-tune a general-purpose model. If Coconut proposes a separate general-model training purpose, it must provide an accurate disclosure and any notice, choice, opt-in, or agreement required for that processing.

Human review and significant decisions

Automated results can be inaccurate, incomplete, or non-unique. Users should apply human review before publishing or materially relying on them. Coconut does not describe the current content and creator-assistance features as making a solely automated decision that has a legal or similarly significant effect on a person. If such a feature is introduced, Coconut will assess and disclose the applicable safeguards and rights.

Sharing and disclosures

Coconut shares personal data only as appropriate for the relevant purpose, role, and instructions. Recipients may include the categories below.

Service providers and subprocessors

Providers supporting authentication, hosting, databases, storage, delivery, social integration, publishing, source ingestion, AI processing, billing, analytics, observability, security, queueing, communications, and support may receive the information required to perform their services.

Workspace users and connected platforms

Information is available to authorised members according to workspace roles and settings. At a user’s or customer’s direction, Coconut and Post for Me send content, account information, and instructions to connected social platforms and receive supported account, post, status, and metric information from them. Post for Me remains a recipient and service provider even where the connection flow is presented under Coconut branding.

Coconut may disclose information to professional advisers, auditors, insurers, courts, regulators, law-enforcement bodies, or other parties where required by law or reasonably necessary to protect rights, security, or safety. Information may also be disclosed in connection with a financing, reorganisation, merger, acquisition, asset transfer, or similar transaction, subject to appropriate safeguards.

Aggregated and de-identified information

Coconut may use and disclose information that has been aggregated or de-identified so that it is not reasonably linked to a person, where permitted by law. Coconut does not treat information as de-identified merely because direct identifiers have been removed if it remains reasonably linkable.

Subprocessor and provider register

The providers below describe the current service categories evidenced in Coconut’s product. The role, data involved, and processing geography depend on the purpose, customer relationship, actual service configuration, provider terms, and data flow. Coconut does not state that every provider processes in one fixed country.

Social integration and publishing

Post for Me supports connected-account authorisation and token handling, publishing, feeds, analytics, callbacks, webhooks, retries, and related integration operations. It may handle connected profiles, identifiers, tokens, scopes, posts, media, metrics, and operational events as a service provider, processor, or subprocessor according to Coconut’s role. A Coconut-branded authorisation or workflow does not remove Post for Me from that data flow.

Identity and billing

Clerk supports authentication and identity administration and may handle identity, contact, session, device, and security information. Stripe supports subscription billing and payments and may handle billing contacts, payment details, transaction, invoice, tax, fraud, and payment-status information.

Analytics and observability

PostHog supports product analytics and may handle device, browser, session, feature-event, and related identifiers according to the enabled configuration. Sentry supports error monitoring and observability and may handle diagnostic, error, request, device, user-reference, and performance information included in an event.

Hosting, database, object storage, and queueing

Cloud hosting, managed database, and object storage providers support the application, records, and media. QStash supports queueing and delivery of scheduled or background jobs and may handle job payloads, identifiers, timing, status, and delivery metadata. The precise providers, regions, and data classes follow the deployed service and actual service configuration.

Source ingestion

ScrapeCreators and Bright Data support collection of permitted public or licensed social and creator information and may handle source URLs, public profiles, public posts, media references, metrics, provider results, and ingestion diagnostics.

AI model and processing providers

AI model and processing providers support generation, classification, analysis, embeddings, and related features. They may receive feature inputs, prompts, selected Customer Content, creator information, outputs, and operational metadata required for the request. Their processing is governed by the provider and configuration used for that feature.

Changes to providers

Coconut may add, replace, or remove providers as the Services change. Where a business data-processing agreement requires advance notice or permits a reasonable objection to a subprocessor change, Coconut will follow that agreement.

International transfers

Coconut is established in the United Kingdom. Some providers or connected platforms may process personal data outside the country where the person is located. The existence and destination of an international transfer depend on the actual transfer, provider, deployment, support access, connected platform, and service configuration.

Where restricted-transfer rules apply, Coconut uses an available mechanism appropriate to the actual flow. Depending on the parties and destination, this may include UK or EU adequacy regulations or decisions, the EU Standard Contractual Clauses with the UK Addendum, the UK International Data Transfer Agreement, or a recipient’s valid participation in the Data Privacy Framework where applicable. Coconut may also assess transfer risks and use supplementary contractual, organisational, or technical measures where required.

Contact [email protected] for information about the safeguard relevant to a particular transfer, subject to confidentiality and security limitations.

Customer-instructed transfers

A customer may cause additional transfers by choosing workspace members, connected accounts, platforms, sources, or publication destinations in other countries. Where expressly incorporated, the Business Data Processing Terms and documented instructions govern Coconut’s processor obligations for those transfers.

Retention

Coconut retains personal data only for as long as reasonably needed for the purpose for which it is held, taking account of the active customer relationship, customer instructions where Coconut is processor, legal and billing obligations, security, dispute and claim needs, provider reconciliation, technical dependencies, and whether information can instead be deleted, restricted, aggregated, or de-identified. Retention differs by category rather than following one universal deadline.

Account and workspace data

Retained while an account or workspace is active and afterwards only as needed to administer closure, preserve authorised workspace continuity, respond to requests, meet legal obligations, resolve disputes, or protect security and audit integrity.

Connected-account tokens and data

Access and refresh tokens, scopes, account state, owned posts, metrics, callbacks, and reconciliation information are retained according to the active connection, provider operation, customer instructions, disconnect or revocation state, security needs, and lawful publication or audit requirements. Disconnect does not by itself determine retention of every related record.

Scheduled jobs and publication records

Scheduled jobs are retained while pending or processing and as needed afterwards for delivery status, failure handling, customer support, provider reconciliation, publication history, audit, security, and dispute resolution.

External creator intelligence

Public or licensed creator data, provenance, observations, and derived insights are retained according to source permissions, relevance, freshness, customer use, accuracy, objection or suppression status, legal obligations, and the need to prevent inappropriate re-ingestion.

Billing and transaction records

Invoices, payments, subscription events, tax information, and related audit records are retained as needed for accounting, tax, fraud prevention, charge disputes, legal obligations, and claims.

Logs and security records

Usage, diagnostic, job, audit, and security records are retained according to troubleshooting, reliability, fraud and abuse prevention, investigation, access review, incident handling, legal, and dispute needs, with access limited according to their purpose.

Objects, model artefacts, and backups

Uploaded objects, generated media, embeddings, evaluation or model artefacts, and backups follow the lifecycle of the related feature and system, customer instructions where applicable, recovery needs, provider behavior, legal holds, and deletion or de-identification capability. Backups may be isolated from ordinary use and removed through their normal lifecycle; this Policy does not promise a fixed removal deadline.

Security

Coconut uses technical and organisational safeguards intended to protect personal data, including access controls, measures supporting system confidentiality and integrity, security monitoring, and incident handling.

Safeguards are selected in light of the information, processing, and risks involved and may be supported by providers’ own controls. No method of storage or transmission is completely secure, and Coconut cannot guarantee absolute security.

Please report a suspected security issue to [email protected] without sending passwords, access tokens, or unnecessary sensitive data.

Scope of security statements

This Policy does not claim a security certification, universal encryption condition, fixed data residency, or incident-response time. Any additional contractual security commitment must be stated in the applicable written agreement and supported by current evidence.

Cookies and similar technologies

Coconut and its providers may use cookies, local storage, pixels, SDKs, and similar technologies. The technologies present depend on the page, product feature, device, and current configuration.

Strictly necessary

These technologies support sign-in, session continuity, security, fraud prevention, network delivery, and features expressly requested by the user. Where the law permits, Coconut uses them without optional-cookie consent because the relevant service cannot operate as requested without them.

Preference

Preference technologies remember choices such as interface, display, or other settings where those features are enabled.

Analytics

PostHog analytics may initialize in the authenticated app and use local storage and cookies according to the active configuration to help Coconut understand sessions, feature use, and performance. The current authenticated runtime does not gate that initialization on a recorded consent choice.

This current behavior does not establish compliance with UK PECR, GDPR, or another applicable privacy or electronic-communications rule. Optional analytics must be consent-gated where applicable law requires it before publication or operation in that jurisdiction. Implementing and proving that runtime consent gate is a publication and operation blocker for the affected jurisdiction.

Marketing

If Coconut uses advertising, attribution, or marketing technologies that are not strictly necessary, it will provide the notice and choice required for that use. This category does not state that a particular marketing technology is active on every Coconut surface.

Coconut does not currently provide a dedicated in-product cookie-settings control. You can use browser or device controls to reject, clear, or limit cookies and storage, although doing so may affect sign-in or requested features. You may also contact [email protected] to ask about an analytics technology, exercise an applicable privacy right, or request withdrawal where processing is based on Consent. Withdrawal does not affect earlier lawful processing.

Your choices and privacy rights

Rights depend on location, the processing, and Coconut’s role. Coconut may need to verify identity, authority, and the request’s scope. Do not send passwords, access tokens, government identity documents, or unnecessary sensitive information in an initial request. Submit a request to [email protected].

UK and EU rights

Where UK or EU data-protection law applies, you may have rights to access personal data, correct inaccurate data, delete data, restrict processing, object to processing based on legitimate interests or direct marketing, exercise data portability for qualifying data, withdraw consent, and complain to a supervisory authority. These rights can be limited by applicable exceptions and the rights of others.

Where applicable law gives you these rights, a direct-marketing objection will cause Coconut to stop the covered direct marketing. For a legitimate-interest objection, Coconut will make a reasoned assessment of the objection and whether applicable law permits the processing to continue.

Verification and response

Coconut will use proportionate steps to verify the requester and any representative, clarify the requested scope where needed, search relevant systems, and respond within the period required by applicable law. Coconut may retain a limited record of the request and response for compliance, security, and dispute purposes.

Requests involving customer-controlled data

If a request concerns information controlled by a workspace customer and Coconut acts only as processor, the workspace customer should normally receive the request. Coconut may route the request to that customer and assist it rather than independently deciding the outcome.

Connected-account disconnect and provider revocation

Disconnecting in Coconut and Revoking at the provider are separate actions. Their effects depend on provider state and whether work has already entered processing.

Disconnecting in Coconut

A Coconut disconnect asks Post for Me to disconnect the account, stops supported future collection and actions when successful, cancels eligible scheduled work, and marks the local connection as disconnected. Work already processing may not be cancellable. Coconut may retain limited connection, publication, metric, reconciliation, security, and audit records where needed and lawful.

Revoking at the provider

You may separately remove Coconut access through the native platform’s connected-app or security settings. This is relevant to Google and YouTube, Meta services, TikTok, X, and LinkedIn. Native revocation stops future authorised requests after the platform processes it, but Coconut may not learn of an off-platform revocation immediately.

Existing posts and retained platform data

Disconnect or revocation does not delete posts already published, remove a native social account, or erase information that the native platform independently controls. Delete a published post using the native platform when that is the required outcome.

If disconnect or revocation is incomplete

Contact [email protected] with the workspace, brand, platform, handle, approximate time, and error shown. Do not send credentials or tokens. Coconut can assess local and provider state, but a platform may require the account holder to act through its own controls.

Account, workspace, and privacy deletion

Closing a Coconut identity, closing or removing a workspace, deleting a native post, and making a privacy erasure request have different scopes and do not automatically perform one another.

Closing a Coconut identity

Closing a Coconut identity removes or disables the user’s authentication access. Workspace-owned content and connected channels may remain available to other authorised members, and records may remain where needed for workspace continuity, billing, security, audit, legal, or request handling. Identity closure is not proof of complete legal erasure.

Closing or removing a workspace

Closing or removing a workspace affects the workspace and access to it. Depending on lifecycle state and lawful retention needs, database records, objects, provider state, logs, audit history, billing records, or backups may follow different processes. Product removal alone is not a promise that every copy has been erased.

Deleting a native post

Content already published is controlled operationally by the native platform. Deleting a Coconut draft, schedule, workspace, connection, or account does not delete the native post. Use the platform’s deletion control, subject to its terms and retention.

Making a privacy erasure request

Email [email protected] and identify the Coconut account email, relevant workspace or brand, the information or relationship involved, and whether the request concerns a connected account, external creator information, workspace content, or the entire identity. Coconut will verify authority, determine whether it is controller or processor, assess applicable exceptions and lawful retention, coordinate with relevant providers where required, and delete, de-identify, restrict, or retain information as applicable.

Information that may remain

Subject to law, limited information may remain for billing and tax, security and fraud prevention, legal claims or holds, publication and approval integrity, audit, provider reconciliation, request compliance, or backup recovery. Access and use remain limited to the purpose supporting retention. The native platform independently controls its own posts and copies.

External creator rights

If Coconut holds public, licensed, or derived information about an external creator, that person may contact [email protected] to request access where applicable, correction of inaccurate data, objection to processing, deletion, or suppression. Include the platform, profile or content URL, the relevant information, and the requested outcome without sending unnecessary sensitive data.

Coconut will assess its source, role, purpose, lawful basis, accuracy, applicable exceptions, the rights of customers and others, and whether information should be corrected, removed, restricted, or placed on a suppression record. Where appropriate, a suppression record may be retained to support re-ingestion prevention so that removed information is not automatically collected again from the same source.

Source and derived information

A correction or suppression request may need separate treatment for source data and Coconut-derived insights. Coconut may ask the requester to identify the underlying source and explain an asserted inaccuracy so that provenance and downstream inferences can be assessed.

Children

The Services are intended only for people aged 18 or older and are not directed to children. Coconut does not knowingly invite anyone under 18 to create an account.

If you believe a person under 18 has provided personal data to Coconut, contact [email protected]. Coconut will assess the report, take proportionate steps to verify it, restrict access where appropriate, and delete or otherwise handle the information as required by law and any relevant customer instructions.

Regional disclosures

The disclosures below supplement the general rights section. They apply only where the relevant law covers the person and processing.

United Kingdom and EEA complaints

In the United Kingdom, you may complain to the Information Commissioner’s Office. In the EEA, you may complain to the competent data-protection supervisory authority, particularly in the country where you live, work, or believe an infringement occurred. Coconut encourages you to contact [email protected] first so it can try to address the concern, but you do not have to do so before contacting a regulator.

United States state rights

Residents of a US state with an applicable comprehensive privacy law may have rights to know or access categories and specific pieces of personal data, correct, delete, or obtain a portable copy, and to opt out of processing that the applicable law defines as sale, sharing, targeted advertising, or certain profiling. Applicability depends on the law, Coconut’s status, and the actual processing activity.

Where applicable, Coconut will use a process for request verification, an authorised agent, appeal of a denied request, and non-discrimination for exercising a privacy right. Submit the request or appeal to [email protected] and identify the state and request involved.

Sensitive data and marketing choices

Where a state law requires consent or a right to limit specified sensitive-data processing, Coconut will apply that requirement to covered processing. Electronic marketing can be declined through the message’s unsubscribe control where present or by contacting Coconut.

Changes, version, and contact

Coconut may update this Policy when its Services, providers, data uses, legal obligations, or operating practices change. Coconut will publish the revised version with its effective and last-updated dates and provide additional notice of a material change where required by law.

This version is effective July 24, 2026 and was last updated July 24, 2026.

Controller: Coconut App Ltd, company number 17124503, registered in England and Wales. Registered office: 3rd Floor, 86-90 Paul Street, London, England, United Kingdom, EC2A 4NE. Privacy, rights, support, and security contact: [email protected].

Contacting Coconut

When contacting Coconut, describe the question or request and the relevant account, workspace, brand, connected platform, or creator profile. Do not include passwords, access tokens, government identity documents, or unrelated sensitive information in the first message.