Privacy Policy
This policy covers the SOMDA product. The Kickstarter waitlist at /crowdfunding has a separate waitlist privacy notice.
1. Who we are
AGF USA LLC (“SOMDA,” “we,” “us”) operates the SOMDA service from Florida, USA. Contact: privacy@somda.live.
2. What SOMDA is
SOMDA is an AI companion for creators: Mission Control (web/desktop SaaS) and, when assigned, a physical desk device that shows presence and insights. SOMDA connects to Instagram through Meta’s official APIs to read metrics and insights. SOMDA does not post, comment, or message as you.
3. Data we collect
- Account data — email, display name, password hash (we never store plaintext passwords), locale, and whether Access Granted is enabled (subscription billing may replace this flag later).
- Instagram / Meta data — profile identifiers, usernames, metrics and insights permitted by the scopes you authorize (e.g. business basic + manage insights). Access tokens are encrypted at rest.
- Product usage — dashboard/session activity needed to run Mission Control; device heartbeats (connectivity, presence mode, optional approximate location from IP) when a physical or paired device is used.
- Communications — emails we send (invite to set password, password reset, product notices you opt into).
- Site analytics — standard analytics/cookies on somda.live (e.g. Google Tag Manager) as disclosed on those pages.
4. How we use data
- Authenticate you and provide Mission Control and device presence.
- Collect and derive social metrics, significance signals, and AI-generated insights/reports for your account.
- Operate, secure, and improve the service; prevent abuse.
- Comply with law and Meta Platform terms.
We do not sell your personal data. We do not use your Instagram content to train public models for unrelated advertising.
5. Legal bases (where applicable)
Depending on your location: contract (providing the service you requested), legitimate interests (security, product improvement), consent (where required for cookies/marketing), and legal obligation.
6. Sharing
We share data only with processors needed to run SOMDA (e.g. cloud hosting such as AWS, email delivery, analytics) under appropriate agreements; with Meta as required to complete OAuth and API calls you authorize; or when required by law. We do not sell data to data brokers.
7. Retention
We retain account and metrics data while your account is active and for a reasonable period afterward for backups, disputes, and legal compliance. You may request deletion of your account; some records may remain where law requires.
8. Security
Passwords are hashed; Meta tokens are encrypted; admin and user sessions use separate secrets. No method of transmission or storage is 100% secure — we take industry-appropriate measures.
9. Your rights
Depending on your jurisdiction (including GDPR/CCPA-style rights where they apply), you may request access, correction, deletion, portability, or restriction, and opt out of certain processing. Contact privacy@somda.live. For step-by-step deletion instructions, see our User Data Deletion page. You may disconnect Instagram at any time through the product flows we provide or by revoking access in Meta settings.
10. Children
SOMDA is not directed to children under 13 (or the minimum age required in your country). We do not knowingly collect their data.
11. International transfers
Data may be processed in the United States and other countries where our providers operate. Where required, we use appropriate safeguards.
12. Changes
We may update this policy; the effective date above will change. Material changes will be highlighted on this page or by email when appropriate.
13. Related documents
Terms of Use · User Data Deletion · Crowdfunding waitlist: Privacy / Terms