Security & Data
This page states what the current product and configuration can support. It is not a certification claim or a promise that any online service is perfectly secure.
Access and permissions
Magnetiq uses passwordless or Google sign-in, server-side sessions, and workspace-scoped authorization. Connected social permissions are limited to the actions enabled by each platform and connection provider. Publishing remains review-first unless a workspace deliberately enables an eligible automation setting.
Storage and transport
Application data is stored in PostgreSQL on Railway. Connection secrets stored by Magnetiq are encrypted where the integration requires local storage. Browser sessions use secure, HTTP-only cookies in production. Public responses use transport and browser security headers. Provider credentials are supplied through deployment environment variables, not the public client bundle.
AI and customer content
Prompts and the workspace context needed for a generation request are sent through OpenRouter to the selected model provider. Magnetiq does not use one customer's private workspace content to train a shared Magnetiq model for other customers. Provider handling remains subject to each provider's terms.
Analytics and session replay
PostHog measures product usage and may record sessions when configured. Magnetiq identifies paid product activity by workspace and does not intentionally send social-account credentials or full payment-card data to PostHog. If PostHog is unconfigured, its browser script is not added. Requests to exercise privacy rights can be sent to the contact below.
Subprocessors
Current service roles include Railway for hosting and database infrastructure; Dodo Payments for merchant-of-record checkout, taxes, receipts, and billing; OpenRouter and selected model providers for AI generation; Zernio for supported social connections and publishing; Resend for service email; PostHog for configured analytics; Sentry for configured error monitoring; and Google for optional sign-in. The connected social platforms also process the data sent to them.
Retention, export, and deletion
Workspace owners can delete product data from workspace settings and can request an export or account deletion by email. Active application records are deleted or de-identified within 30 days of a verified request unless limited billing, tax, fraud, security, or dispute records must be retained. Provider systems, logs, and backups follow their own configured or contractual rotation; exact backup deletion timing is not yet independently verified by Magnetiq.
Incidents and responsible disclosure
Report a suspected vulnerability, privacy request, or security incident to support@magnetiq.cloud. Please do not include credentials, access tokens, or sensitive customer content in the first message. Support is asynchronous, with an initial response target of one business day. No public response-time guarantee is claimed today.