LEGAL

Privacy Policy

Last updated: 15 September 2026

1. Who is responsible and what this policy covers

OwnFeed operates the website, dashboard and related services available through getownfeed.com. The OwnFeed Privacy Office is responsible for reviewing privacy matters. For a privacy question, complaint, access request or deletion request, email privacy@getownfeed.com or use the OwnFeed privacy request form.

This policy covers OwnFeed accounts, the website and dashboard, authorized Instagram connections, public feeds and media served by OwnFeed, billing references, and service communications. The customer operating a website decides which authorized content to publish there and is responsible for that website's own collection and use of information. When we handle content for that customer, we act on its instructions for the feed service; we also have responsibilities for our own account, security and billing processing. A customer's privacy notice does not replace our responsibilities.

OwnFeed supplies synchronized JSON feeds, cached images, configurable display layouts, hosted widgets and a Site Sync connector for customer-controlled Cloudflare hosting. Site Sync delivers selected JSON, optimized images, rendered HTML, styles and an interaction script in the background. Public status reports aggregate observations; authenticated status reports are limited to the relevant customer. Features are available only when they are enabled and appropriately configured.

2. Information we collect and why

Account and organization information. You supply your name, email address and password; organization setup can include a business name, website, country and timezone. We keep account identifiers, membership roles, verification state and account settings to create and administer access, apply plan limits and provide support. Passwords are processed to verify access and stored as salted password hashes, rather than readable passwords.

Authentication and security information. We keep session access tokens in hashed form, session creation/activity/expiry times, a shortened browser user-agent string, and a keyed hash derived from an IP address. We process the incoming IP address to create that hash and may send it to Cloudflare for a security check. A keyed hash is pseudonymous information, not a guarantee of anonymity. We keep temporary verification, password-reset and authorization records, rate-limit records, and security audit events. If you enable an authenticator, we store an encrypted authenticator secret and hashed recovery codes with their use state. These records help authenticate you, prevent abuse, investigate incidents and manage recovery.

Instagram information. After you authorize your professional Instagram account through Meta, we receive its account identifier and username, authorization tokens and token expiry/refresh information. We request profile and media access using instagram_business_basic. We retrieve the media identifiers, captions, post links, timestamps, media types and image or thumbnail URLs needed for the feed. We download source image/thumbnail bytes, create optimized image versions and keep feed snapshots. Videos and Reels are represented by thumbnails; the current feed is not a video-hosting service. We do not request Instagram passwords, direct messages, follower lists, comments or posting permissions through this implementation.

Feed settings and content. We store feed names, slugs, public keys, allowed website origins, display limits, image-size choices, post visibility overrides and snapshot metadata. Public output includes selected post identifiers, captions, links, dates, media types and image URLs. People may be identifiable in images or captions even though they do not have an OwnFeed account.

Site Sync information. We keep the selected display, destination URL, connection identifier, update schedule, encrypted scoped connection key, delivery versions, hashes, timestamps and safe failure summaries. The key authorizes only the connector protocol and saved feed area; it is not a Cloudflare administrator credential. One-time setup shows the key to the authorized customer. The receiver downloads complete packages during background delivery and serves its saved content and assets locally. Ordinary visitor rendering does not call OwnFeed after successful delivery. Deliberate Instagram links and customer-added code have their own behavior.

Policy acceptance and privacy requests. Signup records the terms and privacy-notice versions, exact document hashes, acceptance time and account identifier, with archived copies of the documents. Privacy requests record the request type, verified contact, encrypted details, replies, reviewer notes, status and timestamps. Public intake verifies access to an email address; that alone does not prove every claim in a removal or access request.

Billing information. If you select a paid plan, we send Stripe your email, organization name and internal organization reference to create a billing customer. Stripe-hosted pages collect payment information. OwnFeed retains Stripe customer, subscription and price identifiers, billing-period dates, subscription/cancellation state and payment-failure status. Our implementation does not collect or store full card numbers or card security codes. Stripe may collect additional billing, device, fraud-prevention or legally required information directly under its own terms.

Service messages and support. Account verification, password recovery, security, payment and eligible sync-failure notices contain your email address and the information needed for that notice. We queue messages in encrypted form and use Resend for configured live delivery. If you contact us, we use the information you provide to address your request. Do not include passwords, authentication codes, raw access tokens, full payment details or confidential patient information in a support request.

Traffic and operational information. Requests to OwnFeed infrastructure expose normal connection information, including IP address, requested resource and browser/request headers, to the serving infrastructure. The application estimates feed request totals by sampling and aggregating counts by feed and day. These counts are approximate, not individual visitor profiles or exact billing measurements. Sync logs record timing, results, counts and safe error categories. Application error logging is designed to omit secrets and full request URLs; provider logging settings require separate verification.

3. Cookies, security checks and website visitors

OwnFeed uses the first-party __Host-ownfeed_session cookie for production sign-in. It is restricted from JavaScript access and is configured for secure transport and same-site use. Its maximum lifetime is 30 days; server access also expires after 24 hours of inactivity and may be revoked earlier. Local HTTP development uses ownfeed_session. Blocking this cookie prevents normal account access. Public feed delivery does not require a visitor to sign in or set this account cookie.

Cloudflare Turnstile protects account forms. It processes security signals such as IP address, browser information and technical connection characteristics. Cloudflare acts as a processor for protecting our site and as a controller when improving its bot-detection capabilities. Its Turnstile Privacy Addendum explains those activities. Actual widget mode and any related cookies must be checked before launch.

OwnFeed does not include advertising pixels, cross-site advertising analytics or persistent bearer-token storage in localStorage or sessionStorage. Privacy request access keys can be held temporarily in page memory and explicitly copied by the requester. Its example feed integration fetches OwnFeed JSON and images and links to Instagram. Loading those resources sends requests to the relevant host; following an Instagram link takes you to Meta. Customer websites can add their own analytics, embeds and cookies, which their operators must disclose.

4. How information is shared

Public feed recipients. Creating and enabling a feed makes the selected content available for website display. A feed URL is a public access link. Browser-origin restrictions are not confidential access controls: a server-side client can omit the Origin header. Anyone obtaining accessible content may download or redistribute it. Do not publish material intended to remain private.

Cloudflare. The configured hosting design uses Workers for requests and jobs, D1 for records, R2 and caching for media/snapshots, Images for image transformations, and Turnstile for abuse prevention. These services process the information needed for their functions. Cloudflare's processing role depends on the activity; its Privacy Policy and customer data processing addendum describe its terms.

Meta/Instagram. Meta supplies authorized account and media information and processes the login and API interactions on its own platform. It is not simply OwnFeed's hosting processor. Review the Meta Privacy Policy for its independent services. Authorizing an account does not automatically grant rights in every person's image or third-party material within a post.

Stripe. Stripe processes payments and subscriptions and can act as a processor or an independent controller, including for fraud prevention, compliance and its own service operations. See its Privacy Policy and data processing agreement.

Resend. Resend processes recipient addresses, message content and delivery information for transactional email. Its customer-content processing is addressed in its data processing addendum; its own account and usage processing is addressed by its Privacy Policy. Providers may use subprocessors under their agreements. Those lists do not mean OwnFeed directly uses every product they name.

Authorized people and legal disclosures. Organization permissions control account access, while authorized OwnFeed operators can administer customers and investigate service or security issues. We may disclose information where required by law or where legally permitted and necessary to protect rights, safety or service security. Any legally permitted business transfer must preserve applicable privacy protections. These are limited purposes, not permission for unrelated reuse. The reviewed application has no functionality for selling personal information, advertising audience creation or AI model training.

5. Processing outside your country

The service uses providers with international operations. Processing may occur outside Canada, including in the United States, and information may be subject to the lawful access powers of authorities where it is processed. OwnFeed does not promise Canadian-only storage or access.

Resend, Cloudflare, Stripe and Meta operate internationally, and their processing locations can vary by service and account configuration. You can request information about OwnFeed's provider practices through the privacy request form. We remain responsible for the protections applicable to information under our control when using service providers.

6. Retention

The following periods describe current application cleanup settings. They are not promises of completed deletion on an exact day. Background processing, outstanding vendor actions and infrastructure copies can affect completion.

A legal requirement, active dispute or valid preservation obligation can require limited records to be retained longer, with access and use restricted to that purpose.

7. Disconnecting, removal and account deletion

Stop synchronization. Disconnecting an Instagram account removes OwnFeed's stored authorization token and stops future authenticated synchronization. The last cached feed remains available for up to seven days, with a displayed removal deadline. Repeating disconnect does not extend it. An explicitly confirmed immediate purge disables public output and queues stored-content cleanup. Revoking access in Meta can cause reconnection to be required and does not, by itself, guarantee deletion from OwnFeed.

Change what a feed displays. Hiding a post changes selected feed output; it does not delete the underlying Instagram post or necessarily remove stored image files. A source post removed from Instagram is reflected after the next successful complete synchronization of the relevant result set. Failed syncs preserve the last successful snapshot. Disable a feed to stop new authorized feed responses, or rotate its public key to invalidate the old feed address.

Delete an OwnFeed account. The authenticated account-deletion flow requires confirmation and reauthentication. It ends sessions, disables feeds and synchronization for solely owned organizations, clears their stored Instagram tokens, and queues subscription cancellation and eventual data removal. Shared ownership must be resolved first. Purging is scheduled to begin after 30 days, rather than guaranteed to finish at that time. Content removal retries in batches and can be delayed by storage errors or scheduler backlog. Stripe cancellation failures do not prevent the content purge: minimal billing reconciliation continues separately. It does not automatically delete the Stripe customer or all records held by vendors. The grace period does not provide a promised self-service account-restoration facility.

Existing copies. OwnFeed checks current publication, suspension and deletion restrictions before serving public JSON or media, including cached, conditional and HEAD requests. Browser responses revalidate; local cache invalidation is not a worldwide recall. Site Sync queues removal from its verified receiver and records publication or purge acknowledgment. An unreachable receiver, withdrawn credential, independent browser/CDN, website backup or third-party copy may prevent immediate removal. Outstanding removals require customer or operator action. Key rotation cannot recall independent copies. We must take legally required steps for information under our control and seek appropriate provider action; technical limits do not waive deletion duties.

For removal of information about you from a customer's content, contact that website's operator and/or submit an email-verified request to OwnFeed with the relevant post or feed link. Verified account holders can use the dashboard request page. A reviewer must assess identity, authority and the requested action; submission does not automatically export or delete information.

8. Your choices and privacy rights

You can edit available organization settings, manage sessions and optional two-factor authentication, control post visibility and feed access, disconnect Instagram, and request account deletion through the dashboard. Deleting a cookie does not delete server records; disconnecting Instagram does not cancel a paid subscription.

Depending on the law that applies, you may request access to your personal information and how it has been used or disclosed, correction, withdrawal of consent and deletion where available. Other rights, such as objection, restriction or portability, may apply in some jurisdictions. We will verify identity proportionately, protect other people's information, explain any lawful refusal or extension, and respond within applicable deadlines. An agency or organization representative must show authority for requests affecting others.

Withdrawing information needed to provide a requested feature may prevent us from providing that feature. We do not treat acknowledgement of this policy as permission for unrelated purposes. Service and security notices are used for operating your account; optional promotional communications would require a separately reviewed consent and unsubscribe process before introduction.

Send requests or complaints to privacy@getownfeed.com or through the privacy request form. You may also complain to the privacy regulator that applies where you live or where OwnFeed operates. The Office of the Privacy Commissioner of Canada and the Alberta Information and Privacy Commissioner provide complaint information.

9. Security and incidents

Implemented safeguards include access controls, password hashing, encryption of stored Instagram tokens and authenticator secrets, optional two-factor authentication, request checks, throttling and restricted application logging. Encryption does not make published feed content confidential. No service can guarantee absolute security. OwnFeed has not represented this release as independently audited, legally certified or production-approved.

If a privacy incident occurs, applicable assessment, reporting and notification duties will be followed. Do not report a vulnerability by sending secrets or exposing other customers' information.

10. Children and sensitive content

The product is designed for professional-account website publishing and is not intended for use by children. Its current signup does not verify age. A photo or caption can contain information about a child or sensitive matters even when posted by an adult business account. Customers must have the necessary authority and permissions for publication. OwnFeed is not designed to store confidential patient records or other private case files. If inappropriate personal information has been published, use the removal process in section 7.

11. Changes to this policy

Material changes will be communicated through a suitable notice, and new consent obtained where required, before new incompatible uses begin. Proposed features require an updated processing assessment and notice before activation.