Who We Are and What This Policy Covers
Kunpilot, formerly Bluesky Copilot ("the Service", "we", "us"), is a social media scheduling and analytics tool operated by Henrique Sousa, established in Portugal. The Service was renamed in August 2026; the operator, and the data controller named below, did not change. For the purposes of the General Data Protection Regulation (GDPR), Henrique Sousa is the data controller for the personal data described in this policy. The Service connects to more than one social network, and is published on some platforms under the name "Social Media Copilot". Both names refer to the same service, operated by the same controller, and this policy applies to both. This policy explains what we collect, why, who else sees it, and what you can do about it. You can contact us using the details at the bottom of this page.
What We Collect
We collect the following categories of data.
Account information
Your email address and login credentials for the Service itself, used to identify you and to contact you about your account.
Connected social accounts
When you connect a social account, we store the identifiers and credentials needed to act on your behalf: the account identifier issued by that platform, your handle and display name, your profile picture URL, and an access token (and where applicable a refresh token). Access tokens and passwords are stored encrypted at rest. We never display a stored credential back to you.
Content you create
Posts, threads, drafts and scheduled posts you write in the Service, along with any images and alt text you attach, and the schedule you set for them.
Content and metrics we retrieve from connected platforms
Where the platform allows it and you have authorized it, we retrieve your own published posts and their engagement metrics so we can show you your analytics. This includes the post text, the time it was published, its permanent link, and metrics such as views, likes, replies, reposts and quotes. We retrieve this only for accounts you have connected. We do not retrieve other people's private data.
Technical and usage data
Server logs, error reports, and privacy-friendly usage analytics. Where we record an IP address for rate limiting, we store a hashed form of it rather than the address itself.
Connected Platforms
The Service integrates with the social networks listed below. In every case, access begins only when you explicitly authorize it, is used only for the features you use, and can be revoked by you at any time.
Bluesky (AT Protocol)
We use your authorization to publish posts you have scheduled or composed, to read your own posts and their public engagement metrics for analytics, and, where you use those features, to read your follower and following lists for network analysis. Bluesky is an open network and much of this data is public; we treat it as your personal data regardless.
Meta Threads
We request three permissions from Meta, and use them only as described here. threads_basic - to identify the Threads account you connected. We call Meta's /me endpoint once after you authorize, and store your Threads account id, username, display name and profile picture URL so you can tell your connected accounts apart. threads_content_publish - to publish posts you have composed or scheduled in the Service to your own Threads account, including chaining your own posts into a thread. We publish only content you have written and queued, to the account that authorized us. threads_manage_insights - to read your own posts and their metrics (views, likes, replies, reposts, quotes) so we can show you your analytics, your best and worst performing posts, and a best-time-to-post view. This data is shown only to you. We do not read any Threads account other than the one you connected, and we have no means of doing so. We do not use Threads data for advertising, profiling, or any form of cross-user aggregation, and we do not sell it. We honour Meta's deauthorization and data deletion callbacks: if you remove the app from your Threads account, or submit a data deletion request through Meta, we delete the credentials and the Threads content and metrics we hold for that account.
X
Where X is enabled for your account, we use your authorization to publish posts you have composed or scheduled to your own X account. We do not read your X analytics, timeline, followers or direct messages. Publishing to X is metered by X and may be limited or offered only on a paid plan.
Not affiliated
We are not affiliated with, endorsed by, or sponsored by Bluesky, Meta Platforms, Inc., or X Corp. Your use of each network remains subject to that network's own terms and privacy policy.
Why We Use Your Data, and Our Legal Basis
We process your data to perform the contract you entered into when you signed up: publishing the posts you schedule, showing you your analytics, and maintaining your account. We process technical and error data on the basis of our legitimate interest in keeping the Service secure, available and working correctly. Where we ask for consent - for example when you authorize a social account - you may withdraw it at any time by disconnecting that account. We do not use your data for advertising, and we do not sell it to anyone.
AI Features
The Service offers optional AI features: post suggestions grounded in your own posting history, rewriting, and profile insights. These features are "bring your own key": you supply your own Anthropic or OpenAI API key, stored encrypted, and requests are made against your own account with that provider. When you use one of these features, the content sent to the provider includes your handle and a sample of your own posts, including posts retrieved from your connected accounts, together with their engagement metrics. We do not train any model on your content. Under the API terms of both providers, content submitted through the API is not used to train their models by default. The public demo on our homepage analyses Bluesky handles only, using our own API key, and never involves Threads or X data.
Service Providers Who Process Data For Us
We use the following providers to run the Service. Each processes data only on our instructions and only as needed to provide their service. Hetzner Online GmbH (Germany) - hosts the application and database, and therefore holds all of the data described above at rest. Anthropic, PBC and OpenAI, L.P. - process the content described under "AI Features" when you use an AI feature. If you do not use AI features, no content is sent to them. Stripe, Inc. - processes payments. Stripe receives your payment details and email address; it does not receive your social account data or your posts. Resend (or our configured email provider) - delivers transactional email such as account and password messages. Where an error occurs, a diagnostic report containing the request details and a stack trace may be sent to our error tracking service. Credentials are redacted from logs before they are written. We do not otherwise share your personal data with third parties, except where we are required to by law.
International Transfers
Some of the providers above are established outside the European Economic Area, principally in the United States. Where personal data is transferred outside the EEA, that transfer is made under the safeguards permitted by the GDPR, such as the European Commission's Standard Contractual Clauses or an adequacy decision, as provided for in each provider's data processing terms.
How Long We Keep It, and How To Delete It
We keep your data for as long as your account exists. Disconnecting a social account deletes the stored credentials for it. Deleting your account deletes your account data, your posts and drafts, your connected account credentials, and the platform content and metrics we retrieved for those accounts. For Threads specifically, we also act on Meta's deauthorization and data deletion callbacks, as described above. Server logs are retained only as long as needed for diagnosis and security, and are then discarded. You can ask us to delete your data at any time using the contact details below.
Your Rights
Under the GDPR you have the right to access the personal data we hold about you, to have it corrected, to have it erased, to restrict or object to how we process it, and to receive it in a portable form. You also have the right to withdraw consent at any time, and the right to lodge a complaint with a supervisory authority. In Portugal this is the Comissao Nacional de Proteccao de Dados (CNPD). To exercise any of these rights, contact us using the details below. We will respond within the time limits set by the GDPR.
Security
Social account credentials and your AI provider keys are encrypted at rest. Credentials are redacted from application logs before they are written. Access to production systems is restricted. No system is perfectly secure, and we cannot guarantee absolute security, but we will notify you and the relevant authority of a personal data breach where the law requires it.
Children
The Service is not directed at children, and you must be old enough to hold an account on the social networks you connect. We do not knowingly collect personal data from children.
Changes to This Policy
We may update this policy as the Service evolves. Where a change is material we will notify you by email or through the Service before it takes effect. The date of the current version is shown at the bottom of this page.
Contact us
If you have any further questions, you may contact me using the information below.
Email: henrique@sousadev.com
Bluesky: @sousadev.com
LinkedIn: https://linkedin.com/in/henriquecsousa
Last Updated: 26th of August, 2026