Privacy Policy
Last updated: August 17, 2026
This policy describes how the personal data of users of the Publiqo platform (www.publiqoapp.com) is processed, pursuant to Regulation (EU) 2016/679 (the «GDPR») and applicable Italian law.
Data controller
The data controller is Niccolò Scotellaro, sole proprietorship, VAT no. 02818680031. For any request regarding the processing of data: info@publiqoapp.com.
What data we collect
- Registration and account data: first name, last name, company, phone number, email address.
- Credentials: the password is stored exclusively in encrypted form (hash) and is never visible to the Provider or to third parties. If you enable two-factor authentication, we store the technical data needed (e.g. the authenticator app secret; codes sent by email are stored only as a temporary hash).
- Brand data and content: the information you enter about the brands you manage (name, description, tone of voice, website, social profiles, editorial notes), the media you upload (images, videos) and the generated content (editorial plans, texts, visuals).
- Usage and technical data: information relating to your use of the Service (e.g. number of plans generated, consumption metrics) and technical data needed for operation and security.
- Contact preferences: your optional consent to receive marketing communications.
We do not intentionally request or process special categories of data («sensitive» data). Please do not enter unnecessary data or special-category data in the content you upload.
Purposes and legal bases
- Providing the Service (account management, content generation, support): legal basis is the performance of the contract (art. 6.1.b GDPR).
- Security and abuse prevention (authentication, 2FA, technical logs): the Provider's legitimate interest in a secure Service (art. 6.1.f GDPR).
- Service communications (transactional emails such as welcome, verification, password reset): performance of the contract and legitimate interest.
- Marketing (only if you give consent): consent of the data subject (art. 6.1.a GDPR), revocable at any time.
- Legal obligations (e.g. accounting and tax obligations for paid plans): legal obligation (art. 6.1.c GDPR).
Administrative access by the controller
A restricted number of people authorised by the Controller — currently the Service administrator alone — can access the data held in accounts, including brands, uploaded photos and videos, editorial plans and generated content. This access exists solely to provide support, verify that the platform works correctly and diagnose reported faults.
It is not used for commercial purposes, it does not feed model training, and it does not involve disclosing content to third parties beyond the processors listed in this notice. Authorised people are bound by confidentiality.
Processing through artificial intelligence (AI Act)
The Service uses artificial intelligence systems for: the generation of editorial plans and texts, the automatic recognition of the content of uploaded photos and videos, the composition of visual content and the conversational customer assistant — which is an AI system, not a human operator, and is identified as such in the interface, in accordance with Art. 50 of Regulation (EU) 2024/1689 (the «AI Act»).
Assistant conversations are logged (question and answer) for service quality, security and usage-limit purposes; they are included in your data export and deleted when the account is closed. Generated content is always subject to your review and approval before publication: no decision with legal or similarly significant effects on you is taken in a solely automated way (Art. 22 GDPR).
Public site assistant: an AI assistant, identified as such, is also available on the public pages. Visitors' conversations are logged without any identity (question and answer only), for the sole purpose of improving the assistant, and are deleted within 30 days. To prevent abuse we keep, for the same period, an encrypted fingerprint (hash) of the IP address, which cannot be traced back to the person. Please do not enter personal data in conversations on the site.
To this end, the materials you provide (brand information, texts, uploaded images and videos, questions asked to the assistant and the account state needed to answer) are transmitted to the model provider listed below (OpenAI), via API and under a Data Processing Agreement executed by the Controller, solely to produce the requested output. Under that agreement and the provider's business terms, data sent through the API is not used to train the models. Please avoid entering unnecessary personal data in such content.
Providers and data processors
To provide the Service we rely on third-party providers that process data on our behalf, as data processors, on the basis of specific agreements:
- Railway — Hosting and infrastructure for the application.
- Supabase — Managed database (hosted in the European Union) where account and content data are stored.
- OpenAI — Text and content generation, automatic analysis of uploaded media and conversational assistant, via API, under a Data Processing Agreement executed by the Controller.
- Resend — Sending of transactional emails (welcome, verification codes, password reset).
Transfers outside the EU
The database where account and content data is stored is hosted in the European Union. Some other providers — in particular the artificial intelligence models and the email sending service — may also process data outside the EU (e.g. in the United States). In that case, the transfer takes place on the basis of adequate safeguards provided for by the GDPR, such as the European Commission's Standard Contractual Clauses or, where applicable, adequacy decisions. You can ask us for more information about the safeguards adopted.
Retention periods
We retain account data and content for as long as necessary to provide the Service and while the account is active. When the account is closed, data and content are deleted within a reasonable time, unless a different legal obligation applies (e.g. retention of accounting documents). Data processed on the basis of consent (marketing) is retained until consent is withdrawn. Temporary verification and reset codes expire and are invalidated automatically.
Security
We adopt appropriate technical and organizational measures to protect the data: encrypted connections (HTTPS), passwords stored only as a hash, protected temporary tokens, optional two-factor authentication and separation of data between accounts. However, no system is 100% secure: we urge users to choose strong passwords and to safeguard their credentials.
Cookies
The Service uses technical cookies necessary for operation (e.g. to maintain the login session and security), which require no consent. We also use Google Analytics to measure how the site is used: this tool sets measurement cookies and transfers data to Google (Google Ireland Limited, with possible transfer to the United States). Google Analytics is NOT loaded until you give consent through the banner shown on your first visit: if you decline, the script is not even downloaded and no data leaves your device. You can change your mind at any time by clearing this site's data in your browser. We do not use advertising profiling cookies and we do not sell data to third parties.
Rights of the data subject
As a data subject you have the right, within the limits provided by the GDPR, to obtain: access to your data, rectification, erasure, restriction of processing, portability and objection to processing; you also have the right to withdraw at any time the consent given (without affecting the lawfulness of prior processing). To exercise these rights, write to info@publiqoapp.com. Finally, you have the right to lodge a complaint with the supervisory authority (in Italy, the Garante per la protezione dei dati personali — www.garanteprivacy.it).
Minors
The Service is aimed at professionals and companies and is not intended for minors under 18. We do not knowingly collect data from minors.
Changes to this policy
We may update this policy to align it with developments in the Service or in the law. Material changes will be communicated by appropriate means and the «last updated» date at the top will be updated accordingly.
See also our Terms of Service.
