Privacy Policy
Last updated: August 24, 2026
This summary is a plain-language guide only. It is not a substitute for the full policy below, which governs how we handle your data.
1. Introduction
Content Rabbit ("we", "us", or "our") operates the social media management platform at contentrabbitai.com. Content Rabbit is operated by BeeHouse Foundation, a Canadian federal not-for-profit corporation (Corporation Number 1432440-4) with its registered address at 1290 Howe Street, Suite 158, Vancouver, BC V6Z 0C2, Canada. This Privacy Policy explains how we collect, use, share, and protect your personal data when you use our platform and services.
By using Content Rabbit, you agree to the practices described in this policy. If you do not agree, please do not use our services.
2. Data Controller
BeeHouse Foundation, operating as Content Rabbit, is the data controller responsible for your personal data. For privacy inquiries or to exercise your rights, contact us at privacy@contentrabbitai.com.
3. Personal Data We Collect
3.1 Account Information
When you create an account, we collect:
- Name (first name, last name)
- Email address
- Password (stored as a cryptographic hash, never in plaintext)
- Profile picture (if provided or imported from a social login provider)
3.2 Authentication Data
Depending on how you sign in, we may collect:
- Google account identifier (when using Google Sign-In)
- Passkey/WebAuthn credentials (public key, device type)
- Session tokens and session metadata (IP address, user agent)
3.3 Social Media Integration Data
When you connect a social media account (e.g., Twitter/X, LinkedIn, Instagram, Facebook, TikTok, Threads, Pinterest, Bluesky, Google Business, WordPress, Dev.to, or Mastodon), we collect:
- Platform access tokens and refresh tokens (stored encrypted using AES-256-GCM)
- Platform username, display name, and profile image URL
- Platform-specific account identifiers
We use these tokens solely to perform actions you authorize, such as publishing, scheduling, and managing content on your connected accounts.
3.4 Content and Media
We store content you create or upload through our platform:
- Posts, captions, and scheduling data
- Images and videos uploaded for publishing
- AI-generated content created using our tools
- AI character personas and knowledge base items you configure
3.5 Payment Information
Payment processing is handled by Stripe. We do not store your full credit card number or payment details. We store:
- Stripe customer and subscription identifiers
- Plan type and billing status
- Credit balance and transaction history
3.6 Usage and Technical Data
We automatically collect:
- IP address at account registration and per session
- Browser user agent per session
- Pages visited and features used (via analytics, only with your consent)
3.7 Social Media Commenter Data
When you use our comment management features, we cache publicly available information about users who comment on your social media posts, including their display name, handle, profile image URL, and follower count. This data comes from the respective social media platforms and is used solely to help you manage and respond to comments.
3.8 SMS / Text Messaging
If you opt in to text messaging, we collect your mobile phone number and the content of the messages you send us. We use this information to operate our conversational assistant and to provide customer support.
Mobile information (phone numbers) and SMS consent will not be shared with or sold to third parties or affiliates for marketing or promotional purposes. No mobile information is shared with third parties for their own marketing.
You can opt out at any time by replying STOP to any message. We handle the mobile information you provide in line with the rest of this policy.
4. How We Use Your Data
We process your personal data for the following purposes:
| Purpose | Legal Basis (GDPR) |
|---|---|
| Providing and operating the platform | Contractual necessity (Art. 6(1)(b)) |
| Authenticating your identity and managing sessions | Contractual necessity (Art. 6(1)(b)) |
| Publishing and scheduling content on your behalf | Contractual necessity (Art. 6(1)(b)) |
| Processing payments and managing subscriptions | Contractual necessity (Art. 6(1)(b)) |
| AI-powered content generation and suggestions | Contractual necessity (Art. 6(1)(b)) |
| Sending transactional emails (OTPs, notifications) | Contractual necessity (Art. 6(1)(b)) |
| Sending marketing and product update emails | Consent (Art. 6(1)(a)) |
| Analytics and product improvement | Consent (Art. 6(1)(a)), via cookie consent |
| Preventing fraud and ensuring security | Legitimate interest (Art. 6(1)(f)) |
| Complying with legal obligations | Legal obligation (Art. 6(1)(c)) |
5. Cookies and Analytics
We use the following types of cookies:
- Essential cookies: Session cookies for authentication. These are strictly necessary and do not require consent.
- Consent cookie:
cr_cookie_consentstores your cookie preference (accept or reject). Lasts 1 year. - Analytics cookies (consent required): We use PostHog, Google Analytics (GA4), and Microsoft Clarity for product analytics. These only load after you accept cookies via our cookie banner.
You can change your cookie preferences at any time using the "Cookie Preferences" option in the footer of our website.
6. Third-Party Services and Data Sharing
We do not sell your personal information. We do not share it for cross-context behavioral advertising, and we do not disclose it to third parties for their own marketing. Mobile information and SMS consent are never shared with or sold to third parties or affiliates for marketing or promotional purposes.
We share your data with the following categories of service providers, only as needed to operate the Service, and with providers that are contractually bound to protect it. We may also disclose data when required by law, to enforce our terms, or as part of a merger, acquisition, or sale of assets. For a complete list, see our Subprocessors page.
| Category | Provider(s) | Purpose |
|---|---|---|
| Infrastructure | Cloudflare | Hosting, CDN, database, file storage, bot protection |
| Payments | Stripe | Payment processing and subscription management |
| Cloudflare Email | Transactional and marketing email delivery | |
| SMS / messaging | Text-messaging and chat providers | Delivering account and support messages you opt in to |
| Analytics | PostHog, Google Analytics, Microsoft Clarity | Product analytics and session recordings (consent required) |
| AI | Google (Gemini), OpenAI, Anthropic, Replicate, Wavespeed | Content generation, image generation, AI-powered features |
| Social platforms | Twitter/X, LinkedIn, Instagram, Facebook, TikTok, and others | Publishing and managing content on your connected accounts |
7. AI Data Processing
Our platform uses AI services to generate content, images, and suggestions. When you use AI features:
- Your prompts and content context are sent to the AI provider to generate results
- We do not send your name, email, or other direct identifiers to AI providers — only the content you choose to generate
- AI-generated content is stored in your account and treated the same as your other data
- Each AI provider has their own data processing terms — see our Subprocessors page for the list
8. Data Retention
- Account data: Retained while your account is active. When you delete your account, we soft-delete it with a 14-day grace period (during which you can recover it), then permanently and irreversibly delete all associated data.
- Session data: Sessions expire after 7 days. Expired sessions are automatically purged.
- Verification tokens: Expire after 10 minutes and are deleted within 24 hours of expiry.
- Payment records: Retained as required by applicable tax and financial regulations.
- Analytics data: Retained according to each analytics provider's retention policy, and only collected with your consent.
9. Data Security
We implement the following security measures to protect your data:
- All data transmitted over HTTPS with HSTS preload
- Social media OAuth tokens encrypted at rest using AES-256-GCM
- Passwords hashed using PBKDF2 with 100,000 iterations
- Session cookies marked HttpOnly, Secure, and SameSite
- Role-based access control for team data
- Rate limiting on authentication and API endpoints
- Content Security Policy and standard security headers enforced
10. International Data Transfers
Your data may be transferred to and processed in countries outside the EU/EEA, including the United States, where our infrastructure providers and AI services operate. We ensure appropriate safeguards for such transfers, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Data processing agreements with all subprocessors
11. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate data via your account settings or by contacting us.
- Erasure: Delete your account from Settings, which triggers permanent deletion of all your data after a 14-day grace period.
- Restrict processing: Request that we limit how we use your data.
- Data portability: Request your data in a machine-readable format.
- Object: Object to processing based on legitimate interests or for direct marketing.
- Withdraw consent: Withdraw consent at any time (e.g., cookie preferences, marketing emails) without affecting prior processing.
The rights above apply in particular to users in the European Union, the European Economic Area, and the United Kingdom under the GDPR and UK GDPR. To exercise any of these rights, contact us at privacy@contentrabbitai.com. We will respond within 30 days.
11.1 California Residents (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you the following rights:
- Right to know: Request the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of third parties we share it with.
- Right to delete: Request deletion of the personal information we hold about you, subject to legal exceptions.
- Right to correct: Request correction of inaccurate personal information.
- Right to opt out: We do not sell your personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of.
- Right to non-discrimination: We will not discriminate against you for exercising any of these rights.
To exercise your California rights, contact us at privacy@contentrabbitai.com. We will verify your request using the account information we hold. You may use an authorized agent to submit a request on your behalf.
12. Marketing Communications
We may send you product updates and marketing emails. You can unsubscribe at any time using the link in any email, or by updating your notification preferences in your account settings.
13. Children's Privacy
Content Rabbit is not intended for use by anyone under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a new "Last updated" date. For significant changes, we may also notify you by email.
15. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
- Email: privacy@contentrabbitai.com
- Support: support@contentrabbitai.com
- BeeHouse Foundation, 1290 Howe Street, Suite 158, Vancouver, BC V6Z 0C2, Canada
If you are in the EU/EEA, you also have the right to lodge a complaint with your local data protection supervisory authority.