Privacy Policy
Northfact is in beta and holds as little as it can. This describes what is actually stored and how, rather than reserving every right a lawyer could think of.
Northfact (“we”, “us”) provides social media publishing and analytics at northfact.com. This policy explains what we collect, why, and what you can ask us to do about it. It describes the system as it is currently built.
For any question about this policy, or to exercise any right described in it, write to contact@northfact.com.
Who is responsible
Northfact is operated by ARKA ZENITH IT CONSULTANTS - FZCO, a company registered in the United Arab Emirates. During the beta the service is operated by a small team; the contact address above reaches a person.
Which role that company plays depends on whose data it is, and the distinction is real rather than a formality:
- For our own users’ information - your email address, your Northfact account, your sessions, and the analytics on this website - ARKA ZENITH IT CONSULTANTS - FZCO is the data controller. We decided to collect it and we decide what happens to it.
- For the social media data you connect - the posts, metrics and audience information belonging to accounts you or your clients own - we act as a data processor on your instruction. You decide which accounts are analysed and why; we hold that data to do the work you asked for, and for no purpose of our own.
If you are an agency connecting a client’s account, you are the controller of that client’s data and we process it for you. Customers who need one can request a data processing agreement at the address above, covering the commitments in this policy: processing only on your instruction, the sub-processors named below, notice before we change one, deletion or return on request, and confidentiality.
We do not become a controller of your clients’ data by holding it, and we do not use it for anything other than serving your account.
What we collect
If you join the beta waitlist
Your email address, the page you signed up from, and the time you consented. Nothing else - we do not ask for your name, company or role.
Your address is encrypted at rest using authenticated encryption, and the key is held outside the database. To find or de-duplicate a record we use a keyed one-way identifier rather than decrypting anything, so ordinary operation never reads your address back.
We also store a one-way identifier derived from your IP address to limit abusive signup volume. It is not reversible and we cannot recover your IP from it.
If you connect a social account
When you connect an Instagram, Facebook or Threads account we receive, via Meta’s official APIs and only with your explicit authorisation:
- Your profile information for the connected account - username, display name, biography, follower and following counts, category
- Your posts - captions, hashtags, media type, timestamps
- Performance metrics for those posts - likes, comments, and where the platform provides them, reach, views, saves, shares and watch time
- Aggregate audience information where the platform provides it - age, gender and city distributions as percentages
We receive this because you asked us to analyse it. We do not receive, and cannot request, the identities of the people who follow you: no Instagram API exposes that.
Accounts you analyse but do not own
Competitor benchmarking compares your account with others in your category. Those accounts have not authorised anything, so this is worth being exact about.
For an account you do not connect we work only from information that account has made publicly visible - its public profile and public posts, and the counts on them. We do not use anyone’s private data, we cannot see metrics that Instagram gives only to an account’s owner (reach, views, saves and shares are all owner-only, which is why a competitor comparison in Northfact is always labelled as measured against followers), and we do not build a profile of a person from it.
What we retain is the post-level and account-level figures needed to produce the comparison you asked for, under the account handle you gave us. If you are the owner of an account somebody has benchmarked and you want it excluded, write to contact@northfact.com naming the handle and we will exclude it.
Information about people who are not our users
Analysing an account necessarily touches data about people who engage with it. We do not store the identity of anyone who likes or comments on a post. Where a sample of engaging accounts is used to assess audience quality, we retain only non-identifying derived attributes - for example whether an account is verified or private - under a one-way identifier, never a username or a name.
Technical and analytics data
Standard web request information, and Google Analytics 4 with IP anonymisation enabled, to understand which pages are useful. We do not use advertising cookies and we do not build advertising profiles.
What we do not do
- We do not sell your data. Not to anyone, in any form.
- We do not share your account data with other customers. Each customer’s data is isolated.
- We do not use your content to train machine learning models.
- We do not post to your accounts without your explicit instruction.
Why we are allowed to hold it
Where the law requires a basis: your consent for the waitlist and for connecting a social account, and our legitimate interest in operating and securing the service for abuse prevention and technical logs. You can withdraw consent at any time, and doing so does not affect anything done before you did.
Where it is held
Northfact runs on Google Cloud (Cloud Run and Firebase Hosting, United States), with a Neon PostgreSQL database (United States). Transactional email is sent through Resend. Analytics data is processed by Google.
Those four are our sub-processors, and that is the complete list. Where we process data on your instruction they process it on ours, under terms no weaker than these. We will tell customers with a connected account before we add or replace one, so there is an opportunity to object rather than a note after the fact.
If you are in the UK or EEA, this means your information is transferred outside your region; those transfers rely on the providers’ standard contractual clauses.
How long we keep it
| What | Kept for |
|---|---|
| Waitlist address | Until you unsubscribe or ask us to delete it |
| Connected account data | While the account is connected, and 30 days after you disconnect |
| Sampled audience attributes | 30 days, then regenerated if still needed |
| Abuse-prevention identifiers | 12 months |
| Analytics | Google Analytics default retention |
| Deletion request records | 24 months, so a confirmation code still resolves |
| Data in provider backups | Up to 7 days after deletion, then aged out |
A deletion request is acted on immediately rather than after the windows above: those describe how long data lives if nobody asks for it to go. We keep the record of the request - the platform, the identifier it named, what we deleted and when - because the confirmation code we hand back has to still mean something when you follow it, and because being able to show what we did is the point of having done it.
Your rights
You can ask us to show you what we hold, correct it, delete it, export it in a portable format, or stop a particular use of it. Email contact@northfact.com and we will respond within 30 days.
Every email we send includes an unsubscribe link. Disconnecting a social account in the app stops all further collection from it immediately.
Deleting the social data we hold has its own page, because it needs a single answer rather than a paragraph: see Deleting your data. You can start it from your own Facebook settings without asking us, in which case Meta sends us the request directly, we delete what we hold, and you get a confirmation code and a link to a page naming what went. Removing our access and deleting the data are different requests and we do not treat one as the other, which that page explains.
If you are in the UK or EEA and think we have handled your information badly, you can complain to your national data protection authority.
Children
Northfact is not intended for anyone under 16 and we do not knowingly collect their information. If you believe we have, tell us and we will delete it.
Security
Addresses and access tokens are encrypted at rest. Credentials are held in a managed secret store, never in our source code, and are readable only by the running service. Access to production is limited to the operators of the service.
No system is perfectly secure. If you find a vulnerability, please report it to contact@northfact.com - we will not pursue anyone who reports a genuine issue in good faith.
Changes
If we change this policy in a way that materially affects you, we will email anyone on the waitlist or with a connected account before the change takes effect. The date at the top always reflects the current version.