Niche2SM
Niche2SM is a service that helps creators research topics, generate video and image content, and publish it to their own social media accounts on a schedule.
The data controller is [[LEGAL ENTITY NAME]], tax identification number [[CIF]], registered at [[REGISTERED ADDRESS]], Spain. You can reach us at info@niche2sm.com.
It covers the Niche2SM web application at niche2sm.com, its API, and the background services that generate and publish content on your behalf. It explains what we collect, why, how long we keep it, who we share it with, and how you can get it deleted.
| Category | What it includes | Where it comes from |
|---|---|---|
| Account data | Email address, display name, authentication identifiers, the date of your last sign-in | You, or the identity provider you sign in with (Google, Facebook) |
| Content data | The niches, topics, scripts, images, videos, captions, hashtags and brand assets you create or upload | You, and content our systems generate at your request |
| Connected account data | Access and refresh tokens for the social accounts you connect, plus the account's identifier, display name and avatar | The platform, once you grant consent |
| Publishing data | Scheduled and completed publications, the identifier and URL the platform returns, error reasons and a step-by-step activity log | Generated by the service and by the platforms |
| Analytics data | Aggregate performance metrics for content you published through us — views, watch time, likes, comments, shares and similar | The platform's analytics APIs |
| Technical data | Server logs, IP address, browser and device information, error reports | Automatically, when you use the service |
We do not collect special categories of personal data, and we do not knowingly collect data from anyone under 18.
When you connect an account, the platform issues us a token scoped to the permissions shown on its consent screen. We use that access solely to operate features you asked for: to identify which account or page you selected, to publish the content you approved, and to read back performance metrics for that content.
We do not:
Access tokens are encrypted at rest with AES-256-GCM. Disconnecting an account in Niche2SM deletes the stored token immediately. You can also revoke our access from the platform itself at any time — see Delete my data.
Niche2SM uses YouTube API Services. By connecting a YouTube channel you also agree to the YouTube Terms of Service, and the Google Privacy Policy applies to Google's handling of your data. You can review and revoke Niche2SM's access to your Google account at myaccount.google.com/permissions.
Where you connect an Instagram professional account or a Facebook Page, we use Meta's Graph API to publish the content you approved and to read its performance. Meta's own handling of your data is governed by the Meta Privacy Policy. You can review and remove Niche2SM's access under Settings → Business Integrations on Facebook.
We do not sell personal data. We share it only with service providers who process it on our behalf, under contract, and only as far as they need to:
| Purpose | Providers |
|---|---|
| Hosting, database and authentication | Supabase (PostgreSQL and authentication, hosted in the EU), Railway (application and background workers), Vercel (web front end) |
| File storage and delivery | Cloudflare (R2 object storage and CDN) |
| Content generation | AI providers used to produce text, images, speech and video from your instructions — including OpenAI, Anthropic, ElevenLabs, Replicate, fal.ai and similar. Your instructions and the resulting content are sent to them for processing. |
| Stock media | Pexels, Pixabay, Freesound, Jamendo |
| Transactional email | Resend, Cloudflare Email Routing |
| Publishing and analytics | The social platforms you connect (Google/YouTube, Meta, TikTok) |
We may also disclose data where legally required, or to establish, exercise or defend legal claims.
Our primary database is hosted in the European Union. Some providers listed above operate outside the European Economic Area, mainly in the United States. Where that happens we rely on the European Commission's Standard Contractual Clauses or an adequacy decision, together with the provider's own safeguards.
Data is transmitted over TLS. OAuth tokens and third-party credentials are encrypted at rest with AES-256-GCM. Database access is restricted by row-level security so one account cannot read another's data. Administrative access is limited to the people who need it. No system is perfectly secure, but if a breach affects your rights we will notify you and the supervisory authority as the law requires.
Under the GDPR you can request access to your data, correction of inaccurate data, erasure, restriction of processing, portability in a machine-readable format, and you can object to processing based on legitimate interest. Where processing rests on consent, you can withdraw it at any time without affecting what was done beforehand.
Write to info@niche2sm.com and we will respond within one month. If you believe we have not handled your request properly, you can complain to the Spanish Data Protection Agency (AEPD), www.aepd.es.
Full instructions — including how to revoke our access from Facebook, Instagram and Google — are on the Delete my data page.
If we change this policy materially we will update the date at the top and notify account holders by email before the change takes effect.
Niche2SM es un servicio que ayuda a creadores a investigar temas, generar contenido en vídeo e imagen y publicarlo de forma programada en sus propias cuentas de redes sociales.
El responsable del tratamiento es [[RAZÓN SOCIAL]], con CIF [[CIF]] y domicilio en [[DOMICILIO SOCIAL]], España. Puedes escribirnos a info@niche2sm.com.
No tratamos categorías especiales de datos ni recogemos conscientemente datos de menores de 18 años.
Cuando conectas una cuenta, la plataforma nos entrega un token limitado a los permisos que aparecen en su pantalla de consentimiento. Usamos ese acceso únicamente para identificar la cuenta o página que elegiste, publicar el contenido que aprobaste y leer las métricas de ese contenido.
No vendemos ni cedemos esos datos, no construimos perfiles publicitarios con ellos, no leemos tus mensajes privados, no publicamos nada que no hayas aprobado, no automatizamos likes, seguimientos, comentarios ni mensajes directos, y no accedemos a cuentas distintas de las que conectaste expresamente.
Los tokens se cifran en reposo con AES-256-GCM. Desconectar una cuenta en Niche2SM borra el token de inmediato. También puedes revocar nuestro acceso desde la propia plataforma: ver Eliminar mis datos.
Niche2SM utiliza los Servicios de la API de YouTube. Al conectar un canal aceptas también los Términos del Servicio de YouTube, y a Google le aplica su Política de Privacidad. Puedes revocar nuestro acceso en myaccount.google.com/permissions. En el caso de Meta, puedes hacerlo en Configuración → Integraciones empresariales de Facebook.
No vendemos datos personales. Solo los compartimos con proveedores que los tratan por cuenta nuestra y bajo contrato: alojamiento, base de datos y autenticación (Supabase, Railway, Vercel), almacenamiento y distribución de ficheros (Cloudflare), proveedores de IA que generan el contenido a partir de tus instrucciones (entre otros OpenAI, Anthropic, ElevenLabs, Replicate, fal.ai), bancos de recursos (Pexels, Pixabay, Freesound, Jamendo), correo transaccional (Resend, Cloudflare Email Routing) y las plataformas sociales que conectes.
Nuestra base de datos principal está alojada en la Unión Europea. Algunos proveedores operan fuera del Espacio Económico Europeo, principalmente en Estados Unidos; en esos casos nos apoyamos en las Cláusulas Contractuales Tipo de la Comisión Europea o en una decisión de adecuación.
Los datos de cuenta y contenido, mientras tu cuenta esté activa. Los tokens, hasta que desconectes la cuenta o la elimines. Los archivos intermedios de generación se purgan automáticamente al publicar. Tras eliminar tu cuenta, los datos personales se borran o anonimizan de forma irreversible en un plazo de 30 días, salvo lo que debamos conservar por obligación legal.
Los datos viajan cifrados por TLS. Los tokens y credenciales de terceros se cifran en reposo con AES-256-GCM. El acceso a la base de datos está restringido por seguridad a nivel de fila, de modo que una cuenta no puede leer los datos de otra.
Puedes ejercer los derechos de acceso, rectificación, supresión, limitación, portabilidad y oposición, y retirar tu consentimiento cuando el tratamiento se base en él. Escríbenos a info@niche2sm.com y te responderemos en el plazo de un mes. Si consideras que no hemos atendido bien tu solicitud, puedes reclamar ante la Agencia Española de Protección de Datos, www.aepd.es.
Si modificamos esta política de forma sustancial, actualizaremos la fecha y avisaremos por correo antes de que el cambio surta efecto.