Privacy Policy
This Privacy Policy explains how SkedCast collects, uses, shares, and protects personal data, the legal bases we rely on, the choices and rights you have, and how to reach us about privacy. It applies to our marketing site, the SkedCast application, and the data we access from the social platforms you connect.
1. Who we are & how to contact us
SkedCast is a product of Alpha Exotic Tech LLC, a limited liability company organized in the State of Wyoming, USA, with a registered office at 30 N Gould St Ste R, Sheridan, WY 82801, United States. In this policy, “we”, “us”, and “our” refer to Alpha Exotic Tech LLC.
For any privacy question, to exercise your rights, or to reach our privacy team, email [email protected] or write to us at the address above.
EU and UK representative (GDPR / UK GDPR Art. 27)
Alpha Exotic Tech LLC has no establishment in the European Economic Area or the United Kingdom. Where Art. 27 requires a controller outside those territories to designate a representative within them, we designate one and name them here, with their address, so that data subjects and supervisory authorities have an addressee in their own territory.
No Art. 27 representative is designated at this time. Until one is named above, EU and UK data subjects and supervisory authorities should contact us directly at [email protected] or at the postal address above; we answer within the timeframes the GDPR and UK GDPR require.
2. Our role: controller and processor
SkedCast is a multi-tenant service used by agencies, brands, and creators to schedule and publish content. Our role under data-protection law depends on whose data is involved:
- As a data controller — for personal data about our own account-holders (our direct customers): identity, login, billing, and usage data. This policy describes how we handle that data.
- As a data processor — for the connected-account data, post content, media, and analytics that a customer processes through the service on behalf of their own clients. The customer is the controller; we process that data only on the customer’s documented instructions, under our Data Processing Addendum.
Where you are an end user of one of our customers, that customer’s own privacy notice governs their use of your data; this policy explains the processing we carry out on their behalf.
3. Personal data we collect
We collect the following categories of personal data. We practise data minimization: we request only the data and platform permissions the service needs, and we do not intentionally collect special-category (“sensitive”) personal data.
| Category | Examples | Source |
|---|---|---|
| Account & identity data | name, work email, hashed password, organization/agency name, and role | You provide it |
| Connected-account data | for each social account you connect, the platform username/handle, account or channel identifiers, and OAuth access and refresh tokens (never your platform password) | Received from the connected platform with your authorization |
| Content & media | the post text, captions, schedules, and the images or video you upload or supply by URL for publishing | You provide it |
| Billing data | billing contact, plan, and subscription/usage metadata; card numbers are entered directly into Stripe and never stored on our servers | You provide it (processed by Stripe) |
| Usage & device data | log data, IP address, approximate (city-level) location, device and browser information, and pseudonymous product-analytics events | Collected automatically |
| Support communications | the messages you send us and their metadata | You provide it |
| Referral program data | if you take part in the referral program: which link or code brought an account to us, and technical signals we use only to check that a referral is genuine, held as one-way fingerprints that cannot be turned back into the original values | Collected automatically when a referral link is used |
We store OAuth tokens, never your platform passwords. Tokens are held in an encrypted vault — see Security and the OAuth-token section below.
4. How we use data & our legal bases
We use personal data to provide, secure, and improve the service, to bill for it, to communicate with you, and to comply with law. Where the EU/UK GDPR applies, we rely on the following legal bases:
| Legal basis | GDPR article | What it covers |
|---|---|---|
| Performance of a contract | Art. 6(1)(b) | creating and operating your account, connecting accounts, scheduling and publishing your content, and providing support |
| Legitimate interests | Art. 6(1)(f) | securing the service, preventing fraud and abuse, pacing your publishing so your connected accounts stay within platform limits, and improving the product through analytics (you may object) |
| Legal obligation | Art. 6(1)(c) | keeping records the law requires, such as tax and accounting records, and responding to lawful requests |
| Consent | Art. 6(1)(a) | non-essential cookies and any optional communications; you can withdraw consent at any time |
For connected-account data we process on a customer’s behalf, the customer (as controller) is responsible for establishing the legal basis for that processing.
5. Connected accounts & OAuth token handling
When you connect a social account, you authorize SkedCast through the platform’s official OAuth flow to act on that account on your behalf. We request the minimum scopes needed to publish — typically the permission to create posts plus a read scope to identify the connected account — and nothing more. We never receive or store your platform password.
The OAuth access and refresh tokens we receive are stored encrypted with AES-256-GCM in our token vault, under a key derived separately for every workspace, are decrypted only by our backend to carry out your instructions, and are never logged, sold, or shared except with the originating platform to publish on your behalf. We do not use platform data for advertising, and we do not build profiles unrelated to providing the service.
You stay in control. You can disconnect any account at any time, which immediately erases the stored tokens for that account and, where the platform offers a revocation endpoint, asks the platform to revoke them as well; where it does not, remove SkedCast from that platform’s own connected-apps settings. You can also request deletion of your account and all platform-derived data (see our Data Deletion page).
6. Acting on your behalf & your consent
SkedCast acts on a connected account only with your express, informed consent, captured through the platform’s OAuth consent screen and made clear in our connect experience. Publishing is an explicit, user-initiated action: we do not take actions on your account that you have not directed. Before you connect an account, we tell you what we will access, how we will use it, when we collect it, and how to withdraw consent or request deletion; where a platform’s token expires, we ask you to re-authorize. You can withdraw consent at any time by disconnecting the account.
7. Data from the platforms you connect
We access only the account identifiers and the OAuth tokens needed to publish, and we use that access solely to schedule and publish the content you compose, at your direction. What we access, the purpose, and the retention/deletion behavior, per platform, is set out below and on our Platform API Data Use & Compliance page.
- Meta — Facebook, Instagram & Threads — we access your Page/professional-account identifiers and the OAuth access and refresh tokens needed to publish to the Facebook Pages, Instagram, and Threads you connect, solely to schedule and publish the content you compose to your connected Meta accounts, at your direction. tokens are held encrypted while the account is connected and are erased on disconnection or on a deletion request; you can also remove SkedCast from your Meta account settings at any time; we honor Meta’s data-deletion requirements through our data-deletion page and callback. On deletion: we delete the relevant Platform Data on request, on disconnection, and when your workspace closes, through the data-deletion callback and instructions URL registered with Meta.
- Google — YouTube Data API — we access your YouTube channel identifiers and the OAuth tokens needed to upload and schedule videos to the channel you connect, solely to upload, schedule, and publish the videos you provide to your connected YouTube channel, at your direction. tokens are held encrypted while the channel is connected; disconnecting the channel in SkedCast erases the token immediately, and we ask Google to revoke it once we can confirm this is the last channel using that Google sign-in — for channels connected before we began recording that sign-in we cannot confirm it, so we skip the revoke rather than risk cutting off channels you never touched, and you can withdraw the grant yourself from your Google account permissions page; 18 months after a channel is left disconnected we automatically purge the audience and per-video figures we recorded for it, and a deletion request removes them sooner — apart from the day-by-day history behind their charts, which stays with the publish record and is erased with it; the channel identifiers stay attached to the record of what we published for you, and closing your workspace takes that record out of service at once — erasing it is a manual step our team completes within 30 days of the closure or of a verified deletion request, not one a job performs; if you instead revoke access from your Google account permissions page, publishing stops and we mark the channel as needing reconnection, but that alone deletes nothing here — disconnect it, or send us a deletion request, to have the stored data removed. On deletion: disconnecting the channel erases our copy of the token immediately, and we ask Google to revoke it once we can confirm no other channel under the same Google sign-in is still connected — where we cannot confirm that, we skip the revoke rather than cut off channels you never touched, and you can withdraw the grant yourself in your Google security settings. 18 months after a channel is left disconnected we automatically purge the audience and per-video figures we recorded for it. That automatic purge covers the analytics and the stored credentials only: the channel identifiers, the uploads you published through SkedCast, and the day-by-day history behind their charts are kept as your publishing record until you close your workspace or make a verified deletion request; erasing them is then a manual step our team completes within 30 days, not one the purge above reaches. Revoking SkedCast in your Google security settings stops our access immediately, but it does not by itself erase what we already stored: disconnect the channel, close the workspace, or email us to have it removed.
- X (Twitter) — we access your X account identifier and the OAuth tokens needed to post on your behalf, solely to publish the posts you compose to your connected X account, at your direction. tokens are held encrypted while the account is connected, and on disconnection we erase the token and ask X to invalidate it through its revocation endpoint; the only X content we hold is the posts you composed in SkedCast and the performance figures we recorded for them; a daily sync covering posts from the last 30 days marks any post you have deleted on X as removed and stops retrieving it, freezing rather than updating the figures we already hold; we keep our own record that the post was published, and delete it on request. On deletion: the token is erased when you disconnect the account or when your workspace closes, and because X offers a revocation endpoint we ask X to invalidate it as well; the posts you composed here go out of service the moment your workspace closes, and erasing the stored records themselves is a manual step our team completes within 30 days of that closure or of a verified deletion request — no job erases them for you. SkedCast has no per-post delete control: you can cancel a post before it goes out, and removing one we have already stored is a request you make to us. We do read X on a schedule — we read the public counters of your recent posts daily — so it does notice when a post you published through SkedCast is no longer there, but noticing is all it does: we stamp that post as gone and keep the figures we last recorded as its final ones. Taking a post down on X therefore does not by itself erase our copy; tell us and we will remove it.
- TikTok — we access your basic TikTok creator info and the OAuth tokens needed to post content on your behalf, solely to publish the videos and photos you compose to your connected TikTok account, at your direction. tokens are held encrypted while the account is connected, and disconnecting the account erases the token immediately; the creator identifier we store stays attached to the record of what we published for you, and erasing that record is a manual step our team completes within 30 days of your workspace closing or of a verified deletion request. On deletion: disconnecting the account erases our copy of the token immediately, and closing your workspace erases the tokens for every connected account at once; the creator identifier stays attached to the record of what we published for you, and that record goes out of service the moment your workspace closes — erasing it, and the rest of the TikTok Platform Data we hold, is a manual step our team completes within 30 days of the closure or of a verified deletion request, not one a job performs.
- LinkedIn — we access your member or organization identifier and the OAuth tokens needed to publish to your personal profile or to a Company Page you administer, solely to publish the content you compose to your connected LinkedIn profile or Page, for your benefit and at your direction. we store only the member data needed to provide the posting feature, within LinkedIn’s storage limits; disconnecting erases the stored credential immediately and the cached LinkedIn figures are deleted 18 months later at the latest, apart from the day-by-day history behind their charts, which stays with the publish record and is erased with it; the member or organization identifier stays attached to the record of what we published for you, and erasing that record is a manual step our team completes within 30 days of your workspace closing or of a verified deletion request. On deletion: the stored credential is erased immediately when you disconnect the account or close your workspace, and the member or organization identifier stays attached to the record of what we published for you — erasing that record is a manual step our team completes within 30 days of your workspace closing or of a verified deletion request.
- Pinterest — we access your Pinterest business-account identifier and the OAuth tokens needed to create Pins and boards on your behalf, solely to publish the Pins you compose to the boards you choose on your connected Pinterest account, at your direction. tokens are held encrypted while the account is connected, and disconnecting the account erases the token immediately; the business-account identifier and the board references we store stay attached to the record of what we published for you, and erasing that record is a manual step our team completes within 30 days of your workspace closing or of a verified deletion request; the only other Pinterest data we hold is the audience and per-Pin figures our analytics job records, and 18 months after the account is left disconnected we automatically purge the current figures — the day-by-day history behind their charts stays with the publish record and is erased by the same manual step. On deletion: disconnecting the account erases our copy of the token immediately, and closing your workspace erases the tokens for every connected account at once; the business-account identifier and the boards you pinned to stay attached to the record of what we published for you, and erasing that record is a manual step our team completes within 30 days of the closure or of a verified deletion request; the audience and per-Pin figures our analytics job recorded are the only other Pinterest data we hold, and 18 months after the account is left disconnected we automatically purge the current figures — the day-by-day history behind their charts stays with the publish record and is erased by the same manual step.
- Bluesky (AT Protocol) — we access your handle/DID and the per-account credential or session needed to post on your behalf, solely to publish the posts you compose to your connected Bluesky account, at your direction. credentials are held encrypted while the account is connected, and disconnecting the account erases the stored credential immediately; the account identifiers we store — your handle and DID — stay attached to the record of what we published for you, and erasing that record is a manual step our team completes within 30 days of your workspace closing or of a verified deletion request. On deletion: disconnecting the account erases our copy of the credential immediately, and closing your workspace erases the credentials for every connected account at once; the account identifiers — your handle and DID — stay attached to the record of what we published for you, and erasing that record is a manual step our team completes within 30 days of the closure or of a verified deletion request, not one a job performs.
- Telegram (Bot API) — we access the bot token you configure and the channel/chat identifiers needed to post where your bot is an administrator, solely to publish the messages you compose to the Telegram channels you choose, at your direction. the bot token is held encrypted while the integration is configured, and disconnecting it — or closing your workspace — erases the token immediately; what neither erases is the identifiers around it — the bot identifier on the connection, and the channel identifiers stored with each post you sent — which stay attached to the record of what we published for you, and erasing that record is a manual step our team completes within 30 days of your workspace closing or of a verified deletion request. On deletion: disconnecting the integration erases the stored bot token immediately, and closing your workspace erases it as well; what neither erases is the bot identifier on the connection or the channel identifiers stored with each post you sent — they stay attached to the record of what we published for you, and erasing that record is a manual step our team completes within 30 days of the closure or of a verified deletion request, not one a job performs.
Google API Services / YouTube — Limited Use
Where you connect a Google service (the YouTube Data API), SkedCast makes the affirmative commitment required by the Google API Services User Data Policy:
SkedCast’s use of information received from Google APIs (including the YouTube Data API) will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
SkedCast uses YouTube API Services. Consistent with the Limited Use requirements, we limit our use of YouTube API data to the upload and scheduling features that are visible in SkedCast; we do not transfer it to third parties except as that policy permits (for example, to provide those features with your consent, for security, or to comply with law); we do not allow humans to read it except in the narrow cases that policy allows; we never use it to serve advertisements or to determine credit-worthiness; and we never use it to train generalized artificial-intelligence or machine-learning models. The Google Privacy Policy is available at policies.google.com/privacy, and the YouTube Terms of Service apply to your use of YouTube. You can review or revokeSkedCast’s access to your Google account at any time via the Google security-settings permissions page at myaccount.google.com/permissions. Disconnecting the channel erases our copy of the token immediately, and we ask Google to revoke it once we can confirm no other channel under the same Google sign-in is still connected — where we cannot confirm that, we skip the revoke rather than cut off channels you never touched, and you can withdraw the grant yourself in your Google security settings. 18 months after a channel is left disconnected we automatically purge the audience and per-video figures we recorded for it. That automatic purge covers the analytics and the stored credentials only: the channel identifiers, the uploads you published through SkedCast, and the day-by-day history behind their charts are kept as your publishing record until you close your workspace or make a verified deletion request; erasing them is then a manual step our team completes within 30 days, not one the purge above reaches. Revoking SkedCast in your Google security settings stops our access immediately, but it does not by itself erase what we already stored: disconnect the channel, close the workspace, or email us to have it removed.
Meta Platform Data
Where you connect a Meta account (Facebook, Instagram, or Threads), we handle Platform Data in line with the Meta Platform Terms and Developer Policies: we use it only to provide the features you authorize, we do not sell or license it, we do not use it for surveillance, we keep it only as long as the feature needs it, and we delete it on request or when you no longer have an account, through the mechanism described on our Data Deletion page — the data-deletion instructions / callback URL we provide to Meta.
X (Twitter) content
For X, we act only with your express consent, our handling is no less protective than the X Privacy Policy, and we do not redistribute or sell X content or match it to off-X data. The token is erased when you disconnect the account or when your workspace closes, and because X offers a revocation endpoint we ask X to invalidate it as well; the posts you composed here go out of service the moment your workspace closes, and erasing the stored records themselves is a manual step our team completes within 30 days of that closure or of a verified deletion request — no job erases them for you. SkedCast has no per-post delete control: you can cancel a post before it goes out, and removing one we have already stored is a request you make to us. We do read X on a schedule — we read the public counters of your recent posts daily — so it does notice when a post you published through SkedCast is no longer there, but noticing is all it does: we stamp that post as gone and keep the figures we last recorded as its final ones. Taking a post down on X therefore does not by itself erase our copy; tell us and we will remove it.
8. Sharing & sub-processors
We do not sell personal information, and we do not “share” it for cross-context behavioral advertising. We share personal data only with:
- Vetted sub-processors that process data on our behalf under a signed data-processing agreement — including Alpha Exotic Tech (Private) Limited, our intra-group engineering and support sub-processor. The current list is on our Sub-processors page.
- The social platforms you direct us to publish to, to carry out your instructions.
- Google LLC (Google Analytics 4), our website-analytics provider, which receives your IP address and a pseudonymous client id from our marketing pages — but only if you accept analytics cookies. Its tag is not loaded before you do, and never when your browser asserts Global Privacy Control. The exact cookies are listed by name in our Cookie Policy.
- Authorities or third parties where required to comply with law, enforce our terms, or protect rights, property, and safety; and a successor in a merger, acquisition, or asset sale, subject to this policy.
9. International data transfers
Alpha Exotic Tech LLC is based in the United States and works with sub-processors in multiple regions, including Alpha Exotic Tech (Private) Limited in Pakistan. Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards — principally the European Commission’s Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum (IDTA), and we rely on the EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Framework where applicable — together with a transfer-impact assessment where required. These safeguards are incorporated into our Data Processing Addendum.
10. Data retention
We keep personal data only as long as needed for the purposes above. Most of the windows below are enforced by automated deletion jobs; where a step is ours to run by hand instead, the entry says so. In summary:
- Your posts and media — retained for the life of your account. You can delete a media file at any time, and the stored file itself is permanently removed from our storage 30 days after that. A published or scheduled post has no delete control: you can cancel one before it goes out, and removing one we have already stored is a request you make to us, which we complete by hand within 30 days.
- Connected-account credentials (OAuth tokens) — erased immediately when you disconnect an account, and revoked with the platform as well where the platform offers a revocation endpoint (see §7). As a safety net, any credentials belonging to an account that has remained disconnected for 18 months are automatically purged, along with that account’s stored analytics.
- The connected-account record itself — the channel, Page, or profile identifier is kept for as long as the posts we published to it are kept, because it is what says where each of those posts went. Disconnecting marks the record as disconnected and erases its credentials; the identifier is removed when the post history it annotates is removed — which no job does for you, so it is erased by hand after a workspace closure or a verified deletion request, within the 30 days our Data Deletion page commits to.
- Performance analytics — when you publish through SkedCast we keep performance snapshots of your content (impressions, likes, and similar figures) as part of your account’s historical reporting, including for content that is later removed from the platform — the last-recorded figures are kept as your historical record. They are automatically purged 18 months after a connected account is left disconnected, and go sooner than that only when we erase your records by hand on a workspace closure or a verified deletion request.
- Operational logs — webhook delivery logs and rate-limit records are kept for 90 days; email delivery logs for 180 days; in-app notifications for 180 days after you read them.
- Data-export (DSAR) bundles — an export we prepare for you is kept for 30 days after your request is fulfilled, then deleted.
We also honor each connected platform’s own retention rules; the commitment we make for each one is stated per platform in §7 above and on our Platform API Data Use & Compliance page. Some records (such as billing and tax records) are retained for the period required by law, and audit logs are retained for a bounded period for security and accountability. Deletion requests are handled as described on our Data Deletion & Account Removal page.
11. How we protect personal data
We protect personal data with row-level tenant isolation, an AES-256-GCM envelope-encrypted token vault that derives a separate key for every workspace, encryption in transit (TLS 1.2+) and at rest, least-privilege role-based access, a separate MFA-protected operator surface, and append-only audit logging. Read more on our Security page. No method of transmission or storage is perfectly secure, but we work to protect your data and to notify affected parties and authorities of incidents as required by law.
12. Your privacy rights
Depending on where you live, you may have the following rights over your personal data. We extend the core access and deletion rights to all users regardless of location.
- Access & portability — obtain a copy of the personal data we hold about you, in a portable, machine-readable format.
- Rectification & correction — have inaccurate or incomplete personal data corrected.
- Erasure / deletion — have your personal data deleted (the GDPR “right to be forgotten” and the CCPA right to delete), subject to limited legal exceptions.
- Restriction & objection — restrict or object to certain processing, including processing based on our legitimate interests.
- Opt out of sale or sharing — opt out of any “sale” or “sharing” of personal information — we do not sell or share personal information in this sense.
- Non-discrimination & complaint — exercise your rights without discriminatory treatment, and lodge a complaint with your data-protection supervisory authority.
EU / UK GDPR
You may submit a data-subject access request (DSAR) at any time, and you have the right to lodge a complaint with your supervisory authority. We verify your identity and respond within the timeframes the law requires, generally within one month (extendable for complex requests).
California (CCPA / CPRA)
California residents have the right to know, access, correct, and delete their personal information, and to opt out of any “sale” or “sharing”. We do not sell or share personal information and we do not use or disclose sensitive personal information beyond the purposes permitted by the CPRA. You can exercise the opt-out through the “Do Not Sell or Share My Personal Information” control in the footer of every page, and we honor the Global Privacy Control (GPC) browser signal. Exercising your rights will never result in discriminatory treatment. You may use an authorized agent to submit a request.
To exercise any right, email [email protected]. Where you are an end user of one of our customers, we may direct your request to that customer as the controller and assist them in fulfilling it.
13. Children
SkedCast is a business tool not directed to children. We do not knowingly collect personal data from anyone under 16.
Every account-creation surface states, immediately beside the control that creates the account, that by continuing you confirm you are at least 18 — the minimum age our Terms of Service require — and your acceptance is recorded with the version of the terms you accepted. We do not ask for a date of birth or verify age by document.
If you believe a child has provided us personal data — through an account or through the pre-launch waitlist — contact [email protected] with the email address concerned and we will delete it.
14. Cookies
We use a small number of essential cookies to run the service and, subject to your choices, analytics cookies from Google LLC (Google Analytics 4) to understand product usage. Our Cookie Policy lists every cookie and storage key by name, with its provider, purpose, and duration, and explains how to opt out.
15. The referral program
If you take part in the referral program, some personal data is processed that the rest of this policy does not describe. This section explains it. The program’s rules themselves are in the Referral Program Terms.
We never send invitations for you
We do not ask you for anyone else’s email address, and we never send an invitation on your behalf. You share your own link, in your own words, from your own account or mail client. This means we hold no personal data about a person you invite unless and until they choose to create an account themselves.
What the person who invited you learns
If you sign up through someone’s referral link, that person can see in their own account that a referral signed up and, later, that a first payment was made, because that is what their reward depends on. They are not shown your email address, in whole or in part, and they are never shown your name, your content, or the accounts you connect. You are told this on the referral page before you sign up, and the referral code stays visible and editable on the signup form so you can clear it.
In the other direction, the workspace name of the person who invited you is normally shown on their referral page so you can see who is inviting you. A referrer can turn that off, and the page then makes the offer without naming them.
Checking that a referral is genuine
A program that pays out has to be protected from people who set up second accounts to reward themselves. To check that a referral is genuine we record a small number of technical signals about the sign-up and the payment, and we hold them only as one-way fingerprints: the original values are not stored, and a fingerprint cannot be turned back into the value it came from. We do not publish which signals we use, because doing so would tell the people we are guarding against exactly what to avoid.
What we can tell you is what we do not do with them. They are never used to profile you, to advertise to you, to build a picture of your behaviour, or for any purpose beyond deciding whether a referral is genuine, and they are never sold or shared for anyone else’s marketing. Our legal basis is our legitimate interest in preventing fraud, which Art. 6(1)(f) GDPR and Recital 47 name explicitly. You may object to this processing, though we may then be unable to let you take part in the program.
Some referrals are refused automatically when these checks are clearly failed, and others are held for a member of our team to look at. If a referral of yours is refused, you can ask us to have a person review that decision by writing to [email protected], and you can contest the outcome. Being refused a referral reward does not affect your account, your subscription, or anything else you have paid for.
How long referral data is kept
Records of rewards are kept as long as our accounting obligations require, in the same way as invoices. Where a referral never turns into anything — the link was followed but no account or payment followed — the fingerprints of the address and browser it came from are erased 120 days later, once the offer could no longer have been used. The bare record that a referral was attributed stays, because that record is what stops the same one being counted twice.
There is one deliberate exception to erasure. Where a referral was refused for fraud, its fingerprints are kept on a fraud-prevention list even after the account itself is deleted, because a list that is erased on request stops nobody from simply starting again. That list holds no names, no addresses and no readable email addresses — only one-way fingerprints.
The referral cookie
Following a referral link sets one cookie, sk_ref, and only when you press the button on the referral page — never merely by opening it. It lasts 30 days, is read once when you sign up, and is listed with every other cookie in our Cookie Policy.
16. Changes & contact
We may update this policy from time to time; material changes will be reflected by the “Last updated” date above and, where appropriate, communicated to you. For any privacy question or request, contact our privacy team at [email protected] or write to Alpha Exotic Tech LLC, 30 N Gould St Ste R, Sheridan, WY 82801, United States.