Official Legal & Compliance
Privacy Policy
Effective Date: August 28, 2026 • Application: ChatCoat
1. Introduction
ChatCoat, operated by Sami Ullah, provides a multi-platform social media campaign automation, publishing, and lead capture software application. Our platform allows users to connect and manage their accounts on Meta (Facebook & Instagram), YouTube (Google), TikTok, LinkedIn, Snapchat, and Pinterest, and create or export visual media through Canva.
This Privacy Policy describes how we collect, use, store, process, and disclose your personal and account information when you visit our website, register for an account, connect social media platforms or design integrations, or use our services.
2. YouTube API Services & Google User Data Policy
ChatCoat integrates with and utilizes YouTube API Services to allow users to connect their YouTube channels, upload videos and YouTube Shorts, manage video metadata, schedule publishing, and manage comments.
- YouTube Terms of Service: Users must comply with applicable YouTube Terms and policies when using ChatCoat. In accordance with YouTube API Services Developer Policies, users are informed that by connecting or using YouTube features within ChatCoat, you agree to be bound by the YouTube Terms of Service.
- Google Privacy Policy: Our application accesses and processes Google and YouTube user data in accordance with the Google Privacy Policy.
- Device Information & Cookies (Policy III.A.2.g): ChatCoat discloses that our API Client stores, accesses, or collects information directly or indirectly on or from users' devices, and allows essential technical infrastructure providers (such as authentication and cloud hosting) to place, access, or recognize cookies or similar technology (such as local storage and session tokens) on users' devices or browsers solely to operate, authenticate, and secure the service. These technologies maintain authenticated sessions, safeguard OAuth state verification, and preserve user dashboard settings.
- Data Refreshing & 30-Day Storage Limits (Policy III.E.4.a-g): ChatCoat refreshes stored channel profile data from YouTube API Services at least every 30 days (or on-demand via the "Refresh Channel Data" action). In strict compliance with YouTube Developer Policy III.E.4.c, ChatCoat does NOT display or store any statistics or analytics retrieved from YouTube (such as view counts, like counts, watch time, or subscriber metrics) for more than 30 days. ChatCoat does not track or store historical YouTube statistics. Any temporary comment interaction logs are automatically purged within 30 days.
- Data Collected from YouTube: When you authenticate via Google OAuth 2.0, we collect your YouTube Channel ID, channel title, profile information, video upload metadata (titles, descriptions, privacy status, tags), and comment threads for user-initiated campaign automation.
- Google API Services User Data Policy Compliance: ChatCoat's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- Revoking Google / YouTube Access: You may view or revoke ChatCoat's access to your Google and YouTube data at any time via the Google Security Settings Permissions page. You can also disconnect your YouTube channel directly in your ChatCoat Integrations dashboard to immediately purge all stored tokens.
3. Meta (Facebook & Instagram) Platform Integration
ChatCoat connects with the Meta Graph API and Instagram Graph API to enable Facebook Page management, Instagram professional account publishing, comment monitoring, lead creation, and automated direct messages (private replies).
- We access Facebook Page IDs, Page access tokens, connected Instagram account IDs, campaign media, post comments, and comment author IDs required to execute private messaging and comment responses.
- All Meta data processing complies with the Meta Platform Terms, the Meta Terms of Service, and the Meta Privacy Policy.
- You can manage or revoke ChatCoat's permissions at any time via Facebook Business Integrations Settings.
4. TikTok Open API & Direct Post Integration
ChatCoat connects with TikTok Open APIs (including TikTok Login Kit and TikTok Content Posting API) to enable direct video publishing to your TikTok profile.
- We collect your TikTok Open ID, Union ID, display name, avatar URL, creator video posting limits, duet/stitch preferences, and commercial/branded content declaration settings.
- Use of TikTok features is governed by the TikTok Terms of Service and the TikTok Privacy Policy.
- You may revoke ChatCoat's access at any time through the TikTok mobile application under Settings → Security → Manage App Permissions.
5. LinkedIn API Integration
ChatCoat utilizes official LinkedIn Member APIs (including Share on LinkedIn / w_member_social) to enable automated scheduling and publishing of professional posts and articles.
- We collect your LinkedIn Member ID, profile name, email, avatar URL, post text, media attachment metadata, and share urns to monitor publication status.
- LinkedIn data usage complies with the LinkedIn User Agreement and LinkedIn Privacy Policy.
- You can revoke ChatCoat's access to your LinkedIn account via LinkedIn Permitted Services Settings.
6. Pinterest API Integration & Developer Policy
ChatCoat integrates with official Pinterest APIs to enable authenticated business users and creators to securely connect their Pinterest accounts via OAuth 2.0, view available boards, and create and schedule image and video Pins from the ChatCoat dashboard.
- We access Pinterest username, profile display name, profile image URL, board IDs, and published Pin metadata strictly within the permissions explicitly authorized by you (
user_accounts:read,boards:read,boards:write,pins:read,pins:write). - Your use of Pinterest features is governed by the Pinterest Terms of Service, the Pinterest Privacy Policy, and the Pinterest Developer Terms of Service.
- You may disconnect your Pinterest account at any time in your ChatCoat Integrations settings or revoke permissions directly in your Pinterest account under Settings → Security and logins → Apps.
7. Canva Connect API Integration & Developer Policy
ChatCoat integrates with official Canva Connect APIs to enable authenticated users to connect their Canva account via OAuth 2.0, browse their Canva designs, brand templates, and visual assets, create new designs with social media dimensions, and export rendered designs into their ChatCoat media library for use in marketing campaigns.
A. OAuth Authorization & Scopes Requested
You connect your Canva account voluntarily using Canva's OAuth 2.0 authorization flow featuring PKCE (Proof Key for Code Exchange) and cryptographically signed state verification to safeguard against cross-site request forgery. ChatCoat requests only the permissions necessary to enable our visual studio and campaign workflow:
profile:read: To retrieve your authenticated Canva user ID, team ID, and profile display name.design:meta:read: To list your designs and retrieve design titles, thumbnails, and URLs.design:content:read: To export design media files via Canva Connect export jobs.design:content:write: To initialize new designs with preset social media dimensions from ChatCoat.brandtemplate:meta:read&brandtemplate:content:read: To browse available brand templates and retrieve template URLs.asset:read&asset:write: To browse your visual assets in Canva and reference asset identifiers in design workflows.
B. Canva Data Accessed
ChatCoat accesses only the specific Canva data required to fulfill the features you interact with:
- Profile Information: Your Canva User ID, team ID, and profile display name.
- Design & Template Metadata: Design and template IDs, titles, preview thumbnail URLs, edit/view URLs, and created/updated timestamps.
- Asset Metadata: Asset IDs, titles, and thumbnail URLs.
- Exported Media Bytes: When you select "Use in Campaign" or initiate an export, ChatCoat downloads the rendered media file (PNG, JPEG, MP4, or GIF) via Canva's temporary download URL and stores it in your workspace media storage.
- Data Not Accessed: ChatCoat does NOT access, request, or store your Canva account password, email address, payment details, billing history, or personal contacts from Canva.
C. Purpose of Canva Data Processing
Canva data is processed exclusively to provide user-directed creative and campaign functionality within ChatCoat:
- Displaying your Canva designs, brand templates, and visual assets inside the ChatCoat dashboard.
- Allowing you to launch new Canva designs with optimized social platform dimensions (such as Instagram Post, Story, Facebook Post, YouTube Thumbnail, etc.).
- Exporting completed Canva designs and attaching them to scheduled social media posts and publishing automations.
D. Storage, Security & Encryption
All Canva OAuth access tokens and refresh tokens are encrypted at rest in our database using strong AES-GCM encryption. Transmissions between your browser, ChatCoat servers, and Canva APIs are strictly encrypted in transit using HTTPS / TLS. All Canva data is segregated by organization and workspace to prevent unauthorized cross-tenant access. Exported media files are stored in our secure cloud storage and referenced in your workspace media asset library.
E. Disconnection, Revocation & Data Deletion
You can disconnect your Canva account at any time directly in your ChatCoat dashboard (under Tools → Canva or Settings). Disconnecting immediately and permanently deletes the stored encrypted access token, refresh token, and Canva connection record from our database, terminating all API access. You may also independently revoke ChatCoat's authorization at any time directly through your Canva account security and connected application settings. Exported media files previously saved to your campaigns remain in your workspace media library until you delete them or submit an account deletion request.
F. Third-Party Terms & No Affiliation
Canva is an independent third-party service provider. Your use of Canva remains subject to the Canva Terms of Use and Canva Privacy Policy. ChatCoat is an independent software application and is not affiliated with, sponsored, endorsed, or certified by Canva Pty Ltd.
8. Payment Processing & Merchant of Record (Paddle)
ChatCoat uses Paddle.com ("Paddle") as our Merchant of Record and payment processor for all paid subscription plans.
- No Direct Card Data Storage: ChatCoat does not directly collect, receive, process, or store credit or debit card numbers, expiration dates, or CVV/CVC codes. All payment card information and transaction credentials are submitted directly by you to Paddle within Paddle's encrypted checkout interface.
- Billing Metadata Received from Paddle: When you purchase or manage a subscription, Paddle transmits operational billing and subscription metadata to ChatCoat via secure webhooks and API calls. This data is limited to your Paddle Customer ID, Subscription ID, transaction status, active plan tier, price and product identifiers, currency, billing cycle dates, and customer email address necessary to activate and maintain your subscription access.
- Merchant of Record Responsibilities: Paddle (Paddle.com Market Ltd or its local operating affiliates) is legally responsible for processing payments, fraud detection, calculating and remitting applicable sales tax, VAT, and GST, and generating official billing invoices and receipts.
- Paddle Privacy Policy: For complete information on how Paddle collects, protects, and processes your financial and billing data, please refer to the Paddle Privacy Policy.
9. Information We Collect
We collect information directly from you, through authorized platform APIs, and via our payment provider:
- Account Information: Your name, email address, password hash, and workspace identifier when creating an account.
- Billing & Subscription Identifiers: Paddle Customer IDs, Subscription IDs, plan status, and payment cycle timestamps received from Paddle to fulfill your paid plan tier. (ChatCoat never collects or stores credit card numbers).
- Platform OAuth Credentials: Access tokens, refresh tokens, expiration timestamps, and permission scopes granted by you during OAuth authorization for connected social platforms and Canva.
- Campaign & Media Content: Captions, titles, descriptions, hashtags, uploaded images, videos, Canva-exported media files, scheduling timestamps, keyword rules, and reply templates.
- Lead & Interaction Data: User comments containing matched campaign keywords, commenter identifiers, timestamps, reply delivery statuses, and lead records.
- Usage & Diagnostic Data: API request logs, error logs, and performance metrics necessary to maintain service reliability.
- Device & Browser Information (Policy III.A.2.g): Device identifiers, browser type, IP address, and session cookies stored directly or indirectly on users' devices to maintain secure access and support OAuth connections.
9b. Cookies, Local Storage, and Device Information (YouTube Developer Policy III.A.2.g Disclosure)
ChatCoat stores, accesses, and collects information directly or indirectly on or from users' devices, and allows essential technical infrastructure providers (specifically our authentication service and secure cloud hosting) to place, access, or recognize cookies, local storage, session storage, or similar technologies on users' devices or web browsers solely to operate, authenticate, and secure the service.
Operational Uses: These technologies are strictly necessary to authenticate your account, maintain active workspace sessions, prevent CSRF attacks during Google and YouTube OAuth authorizations, preserve user UI preferences, and ensure service reliability.
Third Parties: Authorized technical processors (specifically Clerk authentication and secure cloud hosting) place and access essential session cookies on your device strictly as data processors to execute session verification and DDoS protection.
Managing Cookies: You can manage or disable cookies via your browser settings. However, disabling essential cookies may degrade or prevent access to core ChatCoat functionality, including YouTube API channel management.
10. How We Use Your Information
We use collected information exclusively to:
- Authenticate your identity and manage your workspace sessions.
- Provision, maintain, and manage your paid subscription tier and billing status.
- Publish campaign media and text posts to your connected social channels at your direction.
- Facilitate creative design browsing, preset dimension initialization, and media export via the Canva Connect API.
- Process incoming comments via webhooks or polling to detect buyer intent and capture leads.
- Send automated private replies and public comment responses according to your configured rules.
- Automatically delete or archive promotional campaign posts when your set timer expires.
- Provide customer support, diagnose technical issues, and improve platform security.
11. Data Sharing and No-Sale Policy
We do not sell, rent, or trade your personal data or social media data to third parties.
We only share information under the following limited circumstances:
- Authorized Social & Creative Platforms: Transmitting campaign content, tokens, and replies to Meta, Google/YouTube, TikTok, LinkedIn, Pinterest, and Canva APIs to perform user-requested actions.
- Merchant of Record & Payment Processing: Sharing workspace and account identifiers with Paddle.com to initiate checkout sessions, track subscription entitlements, and process recurring billing.
- Infrastructure Service Providers: Trusted cloud hosting, database, and authentication providers (such as Clerk and secure cloud database servers) acting strictly as data processors under confidentiality agreements.
- Legal Requirements: When strictly required by law, regulation, subpoena, or valid legal process.
12. Data Security & Storage
We implement industry-standard administrative, physical, and technical safeguards. All OAuth tokens and sensitive connection secrets are encrypted at rest using strong cryptographic algorithms. All API transmissions are encrypted in transit via HTTPS / TLS.
13. Data Retention & User Deletion Rights
We retain your account data and connected platform records only for as long as your workspace account is active or as needed to provide you with the services.
You have the right to request deletion of your account and all associated platform data at any time. For detailed instructions, please visit our Data Deletion Instructions Page or email us at support@chatcoat.com. Requests are processed within 30 days.
14. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, integrations, or legal requirements. When changes are made, we will update the "Effective Date" at the top of this page.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Operator: Sami Ullah (ChatCoat)
Email: support@chatcoat.com
Business Activity: Information technology and computer service activities (Registered in Pakistan)