Privacy Policy, named, not vague.
What Shunry collects when you connect an X account, what it sends to its AI provider, which companies receive your data, how long anything is kept, and how to have it all deleted.
In effect from
Contents
- 01Who is responsible for your data
- 02What we collect
- 03Other people's public posts
- 04How we use it
- 05What our AI provider receives
- 06Who else receives your data
- 07What we do not do
- 08Cookies and local storage
- 09How long we keep it
- 10How we protect it
- 11Your rights
- 12Where your data is processed
- 13Children
- 14Changes to this policy
Clause 01
Who is responsible for your data
Shunry is operated by [full legal name — to be filled in], a sole proprietor in India, at [postal address — to be filled in]. That person decides how your personal data is used and is responsible for it.
This policy covers the Shunry app, this website, and the emails we send. Questions and requests go to [email protected], which is also the contact for grievances under India’s Digital Personal Data Protection Act, 2023.
Clause 02
What we collect
Your account
- Your name and email address, and your password stored only as a one-way hash. If you sign in with Google, the name, email and profile picture Google shares.
- For each signed-in session, the IP address and browser it came from, so sessions can be secured and signed out.
- Your plan and subscription status, and an identifier from our payment provider.
Each X account you connect
- Its X user id, handle, display name and profile picture.
- The access tokens X issues so Shunry can act for you, stored encrypted.
- Up to 200 of your recent posts: their text, when they were posted, and their public engagement figures, such as likes and reposts.
- What you tell Shunry about that account in Context: a bio, rules, reply instructions, subjects, creators you admire, and links to things you make. For a link, we fetch the page’s title, description and icon.
- Its style guide, your posting times and timezone, and your workers’ settings.
What you create
- Your drafts, the prompts you gave, the versions generated, when you approved each post and a fingerprint of its exact approved text.
- Scheduled times, and a record of each post published to X.
How the service is used
- A record of each request made to X on your behalf and what it cost, which is how we price and protect the service.
- Product analytics: the pages you view and actions you take. In the app these are linked to your account’s email and name; on this website they are not linked to you unless you sign in.
- If you delete your account, a short record that the deletion happened and when, kept after the account itself is gone.
Clause 03
Other people's public posts
When you pick creators you admire, or ask a worker to write in another account’s style, Shunry reads that account’s publicposts from X and keeps a copy. The copy is shared across Shunry, so the same creator is not read twice, and it is used only to help write drafts. We do not read anyone’s private posts or messages.
Clause 04
How we use it
- to run your account and sign you in securely;
- to import your posts, count how you write and draft your style guide;
- to write drafts, and to publish the posts you approve at the time you choose;
- to show you analytics about your own posts;
- to bill you and send the emails your account needs: a welcome, a password reset, and notices when a subscription starts, renews, has a payment problem or ends;
- to understand how the product is used, fix what breaks, and prevent abuse and overspending;
- to meet legal obligations, such as keeping tax records.
We process your data because you asked us to provide the service, and, for analytics and security, because it is needed to run it well. We do not sell your data, show you ads, or use it for anything other than Shunry.
Clause 05
What our AI provider receives
Shunry writes drafts, style guides and bios with a model from Anthropic. To do that, each request sends Anthropic the relevant parts of: your imported posts, your Context, the prompt you gave, and, where you chose one, a creator’s public posts.
The numbers in your style guide — how often you use emoji, open in lowercase, ask questions — are counted by Shunry’s own code, not estimated by the model.
Anthropic processes this under its commercial terms for API customers and its privacy policy. Shunry does not train models of its own on your data.
Clause 06
Who else receives your data
These are the companies that receive personal data from Shunry, what for, and what they get. Each processes it only to provide their part of the service.
| Provider | What for | What they receive |
|---|---|---|
| [hosting provider — to be filled in] | Runs the service and its MongoDB database | Everything in clause 2 of the privacy policy that we store |
| X (X Corp.) | The account you connect: reading your posts and publishing the ones you approve | Your access tokens, the posts you approve, and requests to read your own posts and profile |
| Anthropic | The model that writes drafts and your style guide | Your imported posts, your Context (bio, rules, links, subjects) and the prompt for each draft |
| Google (Sign in with Google) | Signing you in, if you choose that route | Your name, email address and profile picture |
| Dodo Payments | Payments, as merchant of record | Your name, email, billing country and card details — held by them, never by us |
| Resend | Account and billing emails | Your email address and name, and the content of the email |
| PostHog | Product and site analytics | Pages viewed and actions taken; in the app, linked to your account's email and name |
Posts you approve are published on X and become subject to X’s own privacy policy. Beyond this list we share data only if the law requires it, or to protect the safety of people or the service.
Clause 07
What we do not do
- We do not publish anything you have not approved.
- We do not ask X for access to your direct messages, and we do not like, follow, reply or repost for you.
- We do not sell or rent your data, or use it for advertising.
- We do not see or store your card details; our payment provider does.
Clause 09
How long we keep it
| Data | Kept until |
|---|---|
| Your account and everything in it | You delete your account, plus a 30-day window to restore it |
| An X account's tokens, imported posts, Context, style guide and workers | You disconnect that account, or delete your Shunry account |
| Drafts and published-post records | You delete them, or delete your account |
| Sessions | They expire, or you sign out |
| Other creators' public posts | Kept while Shunry uses them; they are public on X |
| The record that an account was deleted | Kept after deletion, as evidence the request was carried out |
| Payment and tax records | As long as the law requires, held by our payment provider |
When the 30-day window ends, the account and its data are permanently deleted. Disconnecting an X account also revokes Shunry’s access at X straight away.
Clause 10
How we protect it
- Traffic between you and Shunry is encrypted in transit.
- X access tokens are encrypted before they are stored, and passwords are stored only as hashes.
- Connecting X uses OAuth 2.0 with PKCE, so a stolen redirect cannot be turned into access.
- Only the operator has access to production data, and only to run and support the service.
Clause 11
Your rights
You can, at any time:
- see and correct most of your data yourself — your Context and style guide are editable in the app;
- get a copy of your data, by emailing us;
- withdraw accessto an X account by disconnecting it, or from X’s settings;
- delete your account from the account screen, or ask us to;
- object to analytics, or complain about how we handle your data.
Write to [email protected]. We reply within 30 days, and we may ask you to confirm the request comes from your account. If you are not satisfied, you can complain to the Data Protection Board of India, or to the authority where you live.
Clause 12
Where your data is processed
Shunry is operated from India, and the providers in clause 6 may store and process data in other countries, including the United States. Where that happens, it is under their contractual and legal safeguards for international transfers.
Clause 13
Children
Shunry is not for anyone under 18. We do not knowingly collect data from children, and we delete an account we learn belongs to one.
Clause 14
Changes to this policy
The date at the top of this page says which version you are reading. If a change affects how your data is used in a way you would care about — a new provider, a new use — we will tell you by email or in the app before it takes effect.
Anything unclear here, or a request about your data, goes to [email protected].
