Privacy Policy
This explains what we collect, why, and the control you have over it. We kept it in plain language on purpose.
Last updated
GetGuth is a product of Guth Labs LLC. The current public release is a no-login Social editor for drafting, editing, previewing, and optionally publishing posts. It creates a private anonymous session so one browser's connected-provider records stay separated from another's; it does not ask for an email or password. Mail and Calendar are separate private preview services, not part of the open Social release.
What we collect
The current public editor is designed to keep draft work on your device.
- Drafts and media you choose. Photos, video, captions, and editor settings are handled in your browser and may remain in that browser's local storage until you remove them.
- Basic technical requests. The hosting service may process ordinary request data such as an IP address, browser information, requested path, and time so the site can load and be protected.
- Messages you send us. If you email us, we receive the address and content needed to answer you.
The editor does not require an email or password. You can optionally save an access email in Profile so the same workspace can be reopened later; it is used only to send you that sign-in link. If you choose to subscribe, payment details are collected by Stripe on Stripe's own checkout page and do not pass through GetGuth. If you choose to connect a social provider, the provider returns access credentials to GetGuth's server; those credentials are encrypted before storage and are not exposed back to the browser.
How we use it
- To load the Social editor and keep local drafts usable on your device.
- To maintain security, diagnose failures, and answer messages you choose to send.
We do not sell your data. The current release does not use your drafts or uploaded media for advertising, profiling, or model training.
Optional Luna assistance
Luna assistance is optional and runs only when you press a Luna caption or photo-edit suggestion control. GetGuth then sends the bounded material needed for that request to its server and OpenAI: your typed direction and relevant destination or voice context, plus a prepared image or one representative frame when media understanding is requested. Luna returns an editable draft or reversible editor settings; it cannot authorize or publish a post. If the request fails, the editor preserves your existing work.
Connected accounts
Every provider connection is optional and made per-provider: Meta (a Facebook Page and its linked professional Instagram account), TikTok, YouTube, LinkedIn, Pinterest, and Threads. When you approve one on that provider's own consent screen, GetGuth stores the provider account identifier, the provider-returned permission list, connection timestamps, and encrypted provider credentials needed to read what you authorized and to perform a publish action you explicitly approve. Credentials are encrypted before storage and are never exposed back to the browser. A successful disconnect deletes the saved credential and marks the connection disconnected. The account identifier and connection timestamps can remain until a deletion request is completed. Meta disconnect removes GetGuth's saved access; revoke the provider grant separately in Meta Business Integrations. YouTube attempts revocation with Google and reports if Google did not confirm it. You can also revoke GetGuth's access anytime in the provider's own security settings. Read the complete data-deletion instructions.
Google and YouTube data
YouTube connection is optional and inactive until you press Connect YouTube in Profile and approve Google's consent screen. GetGuth requests exactly two Google scopes: youtube.upload, used only to upload a video that you individually approve to your own channel, and youtube.readonly, used to identify your connected channel, confirm upload state, and display channel and video information you choose to inspect. The optional channel statistics view explains its data use and asks you to confirm before reading your channel name, visible subscriber count, video count, lifetime views, and a bounded sample of recent upload titles and their views, likes and comments. These are current YouTube Data API totals, not watch-time, revenue, or date-range YouTube Analytics reports. Existing account insight and comment views can read channel/video statistics and comments for display to you. The new channel statistics view does not save report results or send them to an AI service.
How Google user data is shared, transferred, or disclosed
Google user data is never sold, never used for advertising, and never used to train AI models, and it is never sent to any AI provider. It is not shared with, transferred to, or disclosed to any third party, with two narrow exceptions: the infrastructure processors that run GetGuth itself — the site's hosting service, and Supabase, where the Google-issued credential is stored encrypted with AES-256-GCM — and disclosure where required by law. All humans, including GetGuth staff, are unable to read stored Google credentials except as needed to operate or secure the service, resolve a problem you raise, or comply with law.
GetGuth's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting YouTube in Profile attempts to revoke the grant with Google, then deletes the stored credential and marks the connection disconnected. If Google does not confirm revocation, GetGuth reports that separately; local removal does not prove provider revocation. You can also revoke GetGuth's access at any time at myaccount.google.com/permissions.
Google Mail and Calendar preview services
Mail and Calendar are separate private preview services. They remain disconnected unless you start a connection and complete Google's consent screen. Mail requests Gmail read-only and compose access to show the connected mailbox's threads and messages, create a plain-text reply draft for a supported thread, and send that exact Gmail draft only after you review and explicitly confirm it. Calendar requests access to list the connected account's calendars, read events and availability, and prepare event creates, edits, or deletes. Calendar shows a specific operation preview and requires a separate confirmation before it submits that change to Google.
Stored Google data, sharing, and security
For these preview services, GetGuth stores the Google access and refresh credentials needed to maintain the connection in encrypted form using AES-256-GCM. Mail keeps the limited connection, draft, review, and send-receipt records needed to enforce its manual review-and-send flow. Calendar keeps the connection and operation records needed to present and reconcile a previewed change. Cloudflare provides the hosting and Durable Object storage used by these services; Supabase provides sign-in verification. The services obtain message and calendar content from Google when you request it; they are not designed as a separate archive of your Google mailbox or calendar.
Google user data from Mail and Calendar is not sold, used for advertising or ad targeting, or used to train general AI models. It is not provided to AI providers. It is processed only by Google and the infrastructure and sign-in providers that operate these services, or disclosed where required by law. The services do not expose stored Google credentials to the browser.
GetGuth's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Retention, disconnection, and deletion
Google credentials remain only while the local connection is active and are deleted when you disconnect through the service. Disconnecting removes GetGuth's stored credential; it does not by itself prove that Google revoked a broader project grant. You can also remove GetGuth's Google access at myaccount.google.com/permissions. Operational records are retained only as needed to operate, secure, and reconcile the service or meet legal obligations; we do not state a fixed retention period for every record. To request deletion of retained connection or operation records, email hello@getguth.com and identify the connected Google account and service. We may verify ownership and will explain any required retention. Do not email passwords, access tokens, or other credentials.
Who else is involved
The current release uses these services only for the functions described here:
- Site hosting to deliver pages and ordinary security logs.
- Supabase for the private no-login session, connected-account records, and encrypted credential storage.
- Social providers you choose to connect — Meta (Facebook, Instagram, Threads), TikTok, Google (YouTube), LinkedIn, and Pinterest — each contacted only after you approve its consent screen, and only to read what you authorized or publish what you individually approve.
- Stripe to process payment if you choose to subscribe; card details are entered on Stripe's checkout page, not GetGuth's.
- OpenAI when you deliberately request optional Luna assistance.
- Anthropic when you press Draft my week in Autopilot; it receives the business name and recent post captions the drafting is asked to learn from, and never receives provider credentials or Google user data.
- Email to receive and answer messages you send.
Each service above is contacted only for its stated function and only following your action. OpenAI is contacted only when you deliberately use an optional Luna caption or photo-edit suggestion. No AI provider receives Google user data or stored provider credentials.
Your rights
Your information is yours. You can ask us to:
- Access a copy of the information we hold about you.
- Export your data so you can take it with you.
- Delete information we hold about you.
To make any of these requests, email hello@getguth.com and we will take care of it.
How long we keep it
Drafts stored by the editor remain in your browser until you remove them by deleting the draft or clearing that browser's site data. Saved provider credentials are removed after a successful GetGuth disconnect. A disconnected account record, including its identifier and timestamps, can remain until deletion is completed or operational retention removes it. Revoking access at the provider prevents use of that grant but does not itself prove every GetGuth record has been deleted. Ordinary hosting security logs and email records follow the retention practices needed to operate those services and meet legal obligations.
To request deletion, email hello@getguth.com with the subject “GetGuth data deletion request” and the provider and account or Page name. We may verify ownership before completing it. Do not send passwords or access tokens. Ask for completion confirmation; any required retention will be explained in the response. See step-by-step deletion instructions.
Keeping it safe
We take reasonable steps to protect your information and limit who can reach it. No system online is perfectly secure, but we treat your data with care and only hold what we need.
Changes to this policy
If we change how we handle your information, we will update this page. If a change is significant, we will let you know.
Contact
Questions about your privacy, or any of the requests above, go to hello@getguth.com. A real person will reply.