Privacy Policy
Last updated: July 21, 2026
Mainspring Social is a product of Mainspring Software LLC ("Mainspring Social," "we," "us," or "our"). This Privacy Policy explains what information we collect when you use our website and application (the "Service"), how we use it, and the choices you have. By using the Service you agree to this policy.
Information we collect
We collect the following categories of information:
- Contact information. When you join our waitlist or create an account, we collect your email address and any name you provide.
- Account information. Accounts are managed through our authentication provider, which stores your login credentials and basic profile details.
- Content you create. The posts, captions, images, videos, and schedules you compose in the Service.
- Connected accounts. When you connect a social account (such as Facebook, Instagram, Threads, LinkedIn, Bluesky, Google Business Profile, or Mastodon), we store the access tokens needed to publish on your behalf. These tokens are encrypted at rest.
- Usage information. Basic technical and usage data, such as log data and feature usage, to keep the Service reliable and secure.
How we use your information
- To provide, operate, and maintain the Service.
- To publish and schedule the content you create to the social accounts you connect, at your direction.
- To generate content suggestions when you use our AI features, based on the drafts and brand profile you provide.
- To communicate with you, including waitlist and product updates.
- To protect the Service against fraud, abuse, and security issues.
Service providers
We rely on trusted third parties to run the Service, and share information with them only as needed to operate it. These include hosting and database providers, an authentication provider, an AI provider for content generation, and the social platforms you connect. Each processes data under its own terms and privacy commitments.
Analytics
We measure how our pages are used with Vercel Web Analytics, which counts page views and the site someone arrived from. It sets no cookies, assigns no identifier that follows you between websites, and does not build a profile of you. We use it to learn which pages people find useful, nothing more.
Data retention
We keep your information for as long as your account is active or as needed to provide the Service. You may request deletion of your account and associated data by contacting us. Some information may be retained as required by law or for legitimate business purposes such as security and record-keeping.
Security
We take reasonable measures to protect your information, including encrypting connected-account credentials at rest and restricting access to data. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Your choices and rights
You can access and update your account information, disconnect social accounts, and unsubscribe from non-essential emails at any time. Depending on where you live, you may have additional rights over your personal data, such as the right to access, correct, or delete it. To exercise these rights, contact us at the address below.
Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us information, please contact us so we can remove it.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above. Continued use of the Service after changes take effect means you accept the revised policy.
Contact us
If you have questions about this Privacy Policy or your data, contact Mainspring Software LLC at social@mainspringsoftware.com.
Social media connections
When you connect a social account, you authorize us to access and use that account only to perform the actions you request, such as publishing a post or reading your profile name and picture for display. We do not sell your connected-account data, and we do not post without your instruction. You can disconnect any account at any time from the Channels page, which removes the stored access token.
Our use of information received from Meta APIs (Facebook, Instagram, and Threads) adheres to the Meta Platform Terms and Developer Policies. Data obtained through these platforms is used solely to provide the Service's publishing and scheduling features.
Our use of information received from the LinkedIn APIs adheres to the LinkedIn API Terms of Use and the Additional Terms for the LinkedIn Marketing API Program. Data obtained through LinkedIn is used solely to publish and schedule content to the profiles or Pages you manage and to show you the performance of your own posts. We do not use LinkedIn data for advertising, sales, or recruiting; we do not sell it, share it between customers, export it from the Service, or combine it with third-party data to build or enrich profiles; and we do not display a public feed of LinkedIn content.
Our use of information received from Google APIs (Google Business Profile) adheres to the Google API Services User Data Policy, including its Limited Use requirements. Data obtained through Google is used solely to publish and manage the posts and updates you direct us to send to the Business Profiles you connect. We do not use it for advertising, sell it, or transfer it to others except as needed to provide the Service or as required by law.
When you connect a Mastodon account, we use the access token you provide only to publish the posts you direct us to send to your Mastodon instance and to read your profile name and picture for display. Your use of Mastodon is also governed by the terms of the instance you belong to.