Privacy Policy
Last updated: 26 May 2026 · Effective immediately
This Privacy Policy explains how Mora (“we”, “us”, “our”) collects, uses, shares, and protects information when you use our social-media scheduling and AI content service at www.morapost.com. By using Mora you agree to the practices described here.
1. Information we collect
1.1 Account information
When you create an account we collect:
- Email address (required)
- Display name (optional)
- Hashed password (PBKDF2 with per-user salt — we never store plaintext)
- Workspace / company name (optional)
- Profile picture, locale, and timezone (optional, sourced from social login)
1.2 Social account connections
To publish content on your behalf you may connect third-party accounts (Facebook, Instagram, LinkedIn, Pinterest, Google Business, YouTube). When you connect we receive and store, encrypted at rest with AES-256-GCM:
- OAuth access tokens, refresh tokens, and token expiry times
- Public account identifiers (page IDs, account IDs, handles)
- Display names and avatars of the connected pages
We do not receive or store passwords for any third-party platform.
1.3 Content you create
- Post captions, hashtags, alt-text, and scheduling times
- Images and videos you upload — stored as object URLs in Cloudflare R2; the raw bytes are never written to our application database
- AI-generated content you request (e.g. captions)
- Drafts, labels, and notes you save
1.4 Usage and technical data
- API request counts, AI quota consumption (for billing and rate limiting)
- Last sign-in timestamp, browser user-agent (for security)
- IP address (only retained for 30 days, used for abuse detection)
- Approximate location derived from IP (country only)
1.5 What we do NOT collect
- We do not read your private messages on connected platforms
- We do not sell your data to advertisers or data brokers
- We do not track you across other websites
- We do not use third-party analytics that profile users (no Facebook Pixel, no Google Analytics)
2. How we use information
- Provide the service: store your drafts, publish to connected accounts at scheduled times, generate AI content you request
- Account security: verify your identity, prevent unauthorized access
- Customer support: respond when you contact us
- Improve the product: aggregated, anonymous metrics on which features are used
- Legal compliance: respond to lawful requests from authorities
3. Sharing — subprocessors and platforms
We use the following service providers to operate Mora. Each receives only the minimum data necessary and is contractually bound to confidentiality.
| Subprocessor | Purpose | Data shared | Region |
|---|---|---|---|
| Supabase | Primary database (Postgres) | Account, drafts, settings | EU / US |
| Cloudflare R2 | Image / video object storage | Media files you upload | Global |
| Upstash Redis | Rate limiting, OAuth state, cache | Session IDs, request counts | EU / US |
| OpenAI | AI content generation (e.g. captions) | The prompt you submit (no account data) | US |
| Meta Platforms | Publishing to Facebook / Instagram | Post content + connected page tokens | Global |
| LinkedIn, Pinterest, Google, YouTube | Publishing to your connected accounts | Post content + tokens for connected accounts only | Global |
| Stripe | Payment processing (if you subscribe) | Billing email, last-4 of card (Stripe holds the card) | US |
We do not share your content with any party other than the social platforms you explicitly connect, the subprocessors listed above, and law enforcement when legally compelled.
4. Data retention
- Account data: retained while your account is active
- Drafts and media: retained until you delete them or close your account
- IP logs: 30 days
- Auth logs: 90 days
- Backups: 35 days (rolling), after which deleted account data is purged from backups too
When you delete your account (see Delete data), all of the above is permanently erased within 30 days, except where we are legally required to retain it longer (e.g. tax records: 7 years).
5. Your rights
Regardless of where you live, you have the right to:
- Access the data we hold about you — email us
- Correct inaccurate data — edit in Settings, or email us
- Delete your data — use the Delete data page or Settings → Delete Account
- Export a copy of your data in JSON — email us
- Withdraw consent for AI processing — disable AI features in Settings
- Object to processing — contact us
- Lodge a complaint with your local data protection authority
EU/UK residents: this includes rights under GDPR. California residents: rights under CCPA.
6. Security
- All traffic is encrypted in transit (HTTPS / TLS 1.3)
- Database connections use SSL
- OAuth tokens are encrypted at rest with AES-256-GCM
- Passwords are hashed with PBKDF2 + per-user random salt (never stored or transmitted in plaintext)
- Auth tokens use constant-time comparison to defeat timing attacks
- Per-tenant rate limiting prevents abuse
- No employee has direct access to user content without a documented, audited justification
7. Cookies
We use a single first-party cookie / localStorage entry to keep you signed in (mora_session_token). We do not use third-party cookies, advertising trackers, or fingerprinting.
8. Children
Mora is not directed at children under 13 (16 in the EU). We do not knowingly collect data from children. If you believe we have collected such data, please contact us so we can delete it.
9. International transfers
If you access Mora from outside the United States or European Union, your data may be transferred to either of those regions. We use Standard Contractual Clauses (SCCs) as the legal basis for transfers under GDPR.
10. Changes to this policy
If we make material changes we will email account holders at least 7 days before the change takes effect, and update the “Last updated” date above. Continued use after the effective date constitutes acceptance.
11. Contact
For any privacy question, data request, or complaint:
- Email: founder@morapost.com
- Postal: data sent on request
/api/meta/data-deletion-callback endpoint. We will delete all associated account data within 30 days and provide you with a confirmation code at /delete-data.