Privacy Policy

Last updated: August 13, 2026

Haznox AI Media Tool ("Haznox", "we", "us", or "our") is a software-as-a-service platform for generating, designing, scheduling, publishing, and analyzing social media content on behalf of the businesses and individuals who create an account ("you", "your account"). This policy explains what information we collect through the Service at media.haznox.in, how we use it, and the choices available to you. It applies to the Service only and does not describe the privacy practices of Facebook, Instagram, LinkedIn, X, Google, or any other third-party platform you choose to connect.

1. Account Information

When you create a Haznox account, we collect and store:

  • Your email address and, if you sign up with a password, a bcrypt-hashed password (we never store your password in plain text).
  • If you sign in with Google, the profile information Google provides during that sign-in (name, email, avatar) and an internal reference to your Google account — this is separate from, and unrelated to, connecting a Facebook, Instagram, LinkedIn, or X account for publishing.
  • Your name and avatar, if you add them to your profile.
  • Account status flags such as whether your email is verified and whether your account is active.

2. Connected Social Accounts (Facebook/Meta, Instagram, LinkedIn, X)

Haznox supports publishing to Facebook, Instagram, LinkedIn, and X. Connecting one of these platforms uses that platform's own official OAuth authorization flow — you sign in and grant permission directly on the platform's own website; Haznox never asks you for your Facebook, Instagram, LinkedIn, or X password.

When you connect a platform, we receive and store:

  • The platform-issued account/page identifier and username or display name for the account you connected.
  • An OAuth access token, and a refresh token when the platform issues one, scoped to the permissions you granted during that authorization.
  • The token's expiry information and a connection health status, so we can tell you when a reconnection is needed.

Access and refresh tokens are encrypted at rest in our database using symmetric encryption before they are ever written to disk, and are only decrypted in-memory at the moment a request needs to be made to that platform on your behalf. We use these tokens solely to publish the content you schedule to the accounts you connected, and to read basic connection-health and post-performance information for those same accounts — never to act on your social accounts outside of what you've scheduled or requested inside Haznox.

Disconnecting a social account (available at any time from Social Accounts in the app) immediately and permanently deletes the stored access/refresh tokens and connection record for that account from our database. See the Data Deletion page for details.

3. Content and Media You Provide

We store the post text, uploaded images/video, and any media metadata (file size, dimensions, folder, tags) you add to your Media Library or attach to a post, for as long as your account and that content remain active. Media files are stored using an S3-compatible object storage service configured by Haznox.

4. AI-Generated Content

When you use Haznox's AI-assisted caption/hashtag/copy generation or AI image generation, your prompt/input and the generated output are sent to and returned from a third-party AI provider (for text: Anthropic, OpenAI, or Google Gemini; for images: OpenAI, Stability AI, or Google Gemini — whichever provider the platform is configured to use for that request) and stored in your account so you can review and reuse past generations. Each generation consumes credits from your account's credit balance.

5. Scheduling and Publishing Information

For each post you create, we store its content, the platforms/accounts you targeted, the scheduled time and timezone, any recurrence rule, and the resulting publish status, platform-assigned post ID, retry count, and error details for each targeted platform — so you can track and troubleshoot delivery of your own posts.

6. Analytics and Usage Information

For posts you publish through Haznox, we periodically fetch and store engagement metrics made available by the connected platform's own API (impressions, reach, likes, comments, shares, clicks, and similar figures) so you can view performance inside the app. Haznox does not use third-party website-analytics or advertising-tracking scripts on the Service.

7. Payment and Billing Information

Subscription payments are processed by Razorpay. Haznox stores your plan, subscription status, billing period dates, and invoice records (amount, currency, status, and a link to the Razorpay invoice) — we do not receive or store your full card or bank account number; that information is handled directly by Razorpay's payment infrastructure.

8. Data Security

We apply the following safeguards to the data described above:

  • Passwords are hashed (never stored in plain text).
  • Social-platform OAuth access and refresh tokens are encrypted at rest.
  • Inbound webhook notifications from Razorpay and connected social platforms are cryptographically signature-verified before we act on them.
  • Access to your account's data within the Service is scoped to your account; every API request is authenticated.

9. Data Retention

We retain your account data for as long as your account remains active, so the Service can function (e.g. showing your publishing history and past AI generations). When you request deletion of your account (see Data Deletion), your profile, connected social account tokens, posts and scheduling data, media library, AI generation history, brand kits, and billing/subscription records tied to your account are permanently deleted from our production database.

10. Third-Party Services We Use

Depending on the features you use, the following third parties process data on our behalf or at your direction:

  • Meta (Facebook and Instagram), LinkedIn, and X — only for accounts you choose to connect, to publish and read metrics for your own content.
  • Google — for "Sign in with Google", if you use it.
  • Razorpay — for subscription billing and payment processing.
  • Anthropic, OpenAI, and Google Gemini — for AI text generation, when you request it.
  • OpenAI, Stability AI, and Google Gemini — for AI image generation, when you request it.
  • Resend — to deliver transactional emails (e.g. verification, password reset, billing notices).
  • An S3-compatible object storage provider — to store your uploaded and AI-generated media files.

11. Your Rights and Choices

  • You can view and update your profile information from Settings at any time.
  • You can disconnect any connected social account at any time from Social Accounts, which deletes its stored tokens immediately.
  • You can request access to, or deletion of, your account and associated data by contacting us — see Section 12 and the Data Deletion page.

12. Contact Us

For questions about this Privacy Policy, or to request access to or deletion of your data, contact us at info@haznox.com.