Skip to content

Privacy Policy

Last updated: August 24, 2026

This summary is a plain-language guide only. It is not a substitute for the full policy below, which governs how we handle your data.

1. Introduction

Content Rabbit ("we", "us", or "our") operates the social media management platform at contentrabbitai.com. Content Rabbit is operated by BeeHouse Foundation, a Canadian federal not-for-profit corporation (Corporation Number 1432440-4) with its registered address at 1290 Howe Street, Suite 158, Vancouver, BC V6Z 0C2, Canada. This Privacy Policy explains how we collect, use, share, and protect your personal data when you use our platform and services.

By using Content Rabbit, you agree to the practices described in this policy. If you do not agree, please do not use our services.

2. Data Controller

BeeHouse Foundation, operating as Content Rabbit, is the data controller responsible for your personal data. For privacy inquiries or to exercise your rights, contact us at privacy@contentrabbitai.com.

3. Personal Data We Collect

3.1 Account Information

When you create an account, we collect:

  • Name (first name, last name)
  • Email address
  • Password (stored as a cryptographic hash, never in plaintext)
  • Profile picture (if provided or imported from a social login provider)

3.2 Authentication Data

Depending on how you sign in, we may collect:

  • Google account identifier (when using Google Sign-In)
  • Passkey/WebAuthn credentials (public key, device type)
  • Session tokens and session metadata (IP address, user agent)

3.3 Social Media Integration Data

When you connect a social media account (e.g., Twitter/X, LinkedIn, Instagram, Facebook, TikTok, Threads, Pinterest, Bluesky, Google Business, WordPress, Dev.to, or Mastodon), we collect:

  • Platform access tokens and refresh tokens (stored encrypted using AES-256-GCM)
  • Platform username, display name, and profile image URL
  • Platform-specific account identifiers

We use these tokens solely to perform actions you authorize, such as publishing, scheduling, and managing content on your connected accounts.

3.4 Content and Media

We store content you create or upload through our platform:

  • Posts, captions, and scheduling data
  • Images and videos uploaded for publishing
  • AI-generated content created using our tools
  • AI character personas and knowledge base items you configure

3.5 Payment Information

Payment processing is handled by Stripe. We do not store your full credit card number or payment details. We store:

  • Stripe customer and subscription identifiers
  • Plan type and billing status
  • Credit balance and transaction history

3.6 Usage and Technical Data

We automatically collect:

  • IP address at account registration and per session
  • Browser user agent per session
  • Pages visited and features used (via analytics, only with your consent)

3.7 Social Media Commenter Data

When you use our comment management features, we cache publicly available information about users who comment on your social media posts, including their display name, handle, profile image URL, and follower count. This data comes from the respective social media platforms and is used solely to help you manage and respond to comments.

3.8 SMS / Text Messaging

If you opt in to text messaging, we collect your mobile phone number and the content of the messages you send us. We use this information to operate our conversational assistant and to provide customer support.

Mobile information (phone numbers) and SMS consent will not be shared with or sold to third parties or affiliates for marketing or promotional purposes. No mobile information is shared with third parties for their own marketing.

You can opt out at any time by replying STOP to any message. We handle the mobile information you provide in line with the rest of this policy.

4. How We Use Your Data

We process your personal data for the following purposes:

PurposeLegal Basis (GDPR)
Providing and operating the platformContractual necessity (Art. 6(1)(b))
Authenticating your identity and managing sessionsContractual necessity (Art. 6(1)(b))
Publishing and scheduling content on your behalfContractual necessity (Art. 6(1)(b))
Processing payments and managing subscriptionsContractual necessity (Art. 6(1)(b))
AI-powered content generation and suggestionsContractual necessity (Art. 6(1)(b))
Sending transactional emails (OTPs, notifications)Contractual necessity (Art. 6(1)(b))
Sending marketing and product update emailsConsent (Art. 6(1)(a))
Analytics and product improvementConsent (Art. 6(1)(a)), via cookie consent
Preventing fraud and ensuring securityLegitimate interest (Art. 6(1)(f))
Complying with legal obligationsLegal obligation (Art. 6(1)(c))

5. Cookies and Analytics

We use the following types of cookies:

  • Essential cookies: Session cookies for authentication. These are strictly necessary and do not require consent.
  • Consent cookie: cr_cookie_consent stores your cookie preference (accept or reject). Lasts 1 year.
  • Analytics cookies (consent required): We use PostHog, Google Analytics (GA4), and Microsoft Clarity for product analytics. These only load after you accept cookies via our cookie banner.

You can change your cookie preferences at any time using the "Cookie Preferences" option in the footer of our website.

6. Third-Party Services and Data Sharing

We do not sell your personal information. We do not share it for cross-context behavioral advertising, and we do not disclose it to third parties for their own marketing. Mobile information and SMS consent are never shared with or sold to third parties or affiliates for marketing or promotional purposes.

We share your data with the following categories of service providers, only as needed to operate the Service, and with providers that are contractually bound to protect it. We may also disclose data when required by law, to enforce our terms, or as part of a merger, acquisition, or sale of assets. For a complete list, see our Subprocessors page.

CategoryProvider(s)Purpose
InfrastructureCloudflareHosting, CDN, database, file storage, bot protection
PaymentsStripePayment processing and subscription management
EmailCloudflare EmailTransactional and marketing email delivery
SMS / messagingText-messaging and chat providersDelivering account and support messages you opt in to
AnalyticsPostHog, Google Analytics, Microsoft ClarityProduct analytics and session recordings (consent required)
AIGoogle (Gemini), OpenAI, Anthropic, Replicate, WavespeedContent generation, image generation, AI-powered features
Social platformsTwitter/X, LinkedIn, Instagram, Facebook, TikTok, and othersPublishing and managing content on your connected accounts

7. AI Data Processing

Our platform uses AI services to generate content, images, and suggestions. When you use AI features:

  • Your prompts and content context are sent to the AI provider to generate results
  • We do not send your name, email, or other direct identifiers to AI providers — only the content you choose to generate
  • AI-generated content is stored in your account and treated the same as your other data
  • Each AI provider has their own data processing terms — see our Subprocessors page for the list

8. Data Retention

  • Account data: Retained while your account is active. When you delete your account, we soft-delete it with a 14-day grace period (during which you can recover it), then permanently and irreversibly delete all associated data.
  • Session data: Sessions expire after 7 days. Expired sessions are automatically purged.
  • Verification tokens: Expire after 10 minutes and are deleted within 24 hours of expiry.
  • Payment records: Retained as required by applicable tax and financial regulations.
  • Analytics data: Retained according to each analytics provider's retention policy, and only collected with your consent.

9. Data Security

We implement the following security measures to protect your data:

  • All data transmitted over HTTPS with HSTS preload
  • Social media OAuth tokens encrypted at rest using AES-256-GCM
  • Passwords hashed using PBKDF2 with 100,000 iterations
  • Session cookies marked HttpOnly, Secure, and SameSite
  • Role-based access control for team data
  • Rate limiting on authentication and API endpoints
  • Content Security Policy and standard security headers enforced

10. International Data Transfers

Your data may be transferred to and processed in countries outside the EU/EEA, including the United States, where our infrastructure providers and AI services operate. We ensure appropriate safeguards for such transfers, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions where applicable
  • Data processing agreements with all subprocessors

11. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Request correction of inaccurate data via your account settings or by contacting us.
  • Erasure: Delete your account from Settings, which triggers permanent deletion of all your data after a 14-day grace period.
  • Restrict processing: Request that we limit how we use your data.
  • Data portability: Request your data in a machine-readable format.
  • Object: Object to processing based on legitimate interests or for direct marketing.
  • Withdraw consent: Withdraw consent at any time (e.g., cookie preferences, marketing emails) without affecting prior processing.

The rights above apply in particular to users in the European Union, the European Economic Area, and the United Kingdom under the GDPR and UK GDPR. To exercise any of these rights, contact us at privacy@contentrabbitai.com. We will respond within 30 days.

11.1 California Residents (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you the following rights:

  • Right to know: Request the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of third parties we share it with.
  • Right to delete: Request deletion of the personal information we hold about you, subject to legal exceptions.
  • Right to correct: Request correction of inaccurate personal information.
  • Right to opt out: We do not sell your personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of.
  • Right to non-discrimination: We will not discriminate against you for exercising any of these rights.

To exercise your California rights, contact us at privacy@contentrabbitai.com. We will verify your request using the account information we hold. You may use an authorized agent to submit a request on your behalf.

12. Marketing Communications

We may send you product updates and marketing emails. You can unsubscribe at any time using the link in any email, or by updating your notification preferences in your account settings.

13. Children's Privacy

Content Rabbit is not intended for use by anyone under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a new "Last updated" date. For significant changes, we may also notify you by email.

15. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at:

If you are in the EU/EEA, you also have the right to lodge a complaint with your local data protection supervisory authority.