Privacy Policy
Effective 25 August 2026.
Data accessed
When a user authorises a social account, SCRIBE Investigations may receive the minimum account information and permissions required for the selected features. Depending on the platform and permissions granted, this can include an account identifier, display name or username, access or refresh token, owned media identifiers, comments, direct-message metadata or message content needed to respond, mentions, and account or content performance metrics.
How data is used
Connected-account data is used only to verify the authorised account and provide the features the account owner has enabled, such as publishing approved content, reading performance information, moderating or replying to comments, responding to messages, and performing controlled brand-relevant engagement. It is not sold or used for third-party advertising profiling.
Data minimisation
SCRIBE Investigations is designed to keep operational audit records without copying unnecessary social content into long-term logs. Access-token values are not written to public logs or issue records. Read-only capability checks record pass/fail status rather than message contents or insight values.
Credential security
Passwords are not collected. Platform access credentials are treated as secrets and stored in encrypted deployment or automation secret storage rather than public source code, issue bodies or public documents.
Retention
Credentials are retained only while needed to operate an authorised connection. Social content and messages remain primarily on the originating platform; any operational data retained by SCRIBE Investigations is limited to what is necessary for authentication, safety auditing, requested actions and fault diagnosis.
Sharing
Data is sent to the relevant social platform as necessary to authenticate requests and provide authorised features. Infrastructure providers may process technical data as service providers. SCRIBE Investigations does not intentionally disclose connected-account data to unrelated third parties.
Control and deletion
Users can revoke platform access at any time through the relevant platform. SCRIBE Investigations credentials associated with that connection can then be removed from encrypted secret storage, stopping future access. Detailed deletion instructions are available at https://www.scribeinvestigations.com/perry-white/data-deletion.