Privacy. What we collect from your LinkedIn account, why, who else touches it, and how to delete it.
Last updated 14 September 2026
Who runs this
GoodSocials, operated from Amsterdam, Netherlands. We are the data controller for everything described on this page. Write to privacy@goodsocials.co for anything here.
GoodSocials writes LinkedIn posts, shows them to you on a board, and publishes the ones you approve at the time you scheduled. That is the whole product, and it sets the limit of what we collect.
What we collect
- LinkedIn identityYour LinkedIn member id, name, profile picture URL, and email address, received when you sign in with LinkedIn
- LinkedIn access tokenEncrypted at rest with AES-256-GCM, used only to publish posts you approved
- ContentIdeas, drafts, generated images, your comments, your brand principles, scheduled times, and the id of each published post
- BillingStripe customer id, plan, and subscription status. Card details go to Stripe and never reach our servers
- Product usagePages viewed and actions taken, through PostHog, plus generation cost per account
- EmailReceipts, and the warning we send before your LinkedIn connection expires
We do not ask for a date of birth, a phone number, a home address, or anything about people other than you.
What we do with each LinkedIn permission
You grant four scopes in one consent screen. Each one has a single use.
- openidSigns you in. No password to store
- profileShows your name and picture in the app so you can tell which board belongs to which profile
- emailReceipts and the re-authorization warning before the connection dies
- w_member_socialPublishes a post you approved to your own feed, once, at the time on the card
What we never do with that access: read your feed, your connections, your messages, or other members' posts. Post anything you have not approved on a specific card. Like, comment, follow, or send invitations. Post to a company page. Sell or hand your content to anyone outside the processors listed below.
A LinkedIn access token lasts 60 days. When it expires, scheduled posts stop and we email you to reconnect. We cannot renew it without you.
Who else touches it
These processors receive the minimum they need to do their job. No one else gets your data, and we sell it to nobody.
- VercelHosting and the cron that publishes posts
- NeonPostgres database holding your account and board
- LinkedInSign-in, and publishing the posts you approve
- AnthropicGenerates and revises post text from your brand principles and comments. Anthropic does not train models on this input
- ReplicateGenerates images from the prompt for a card
- StripePayments and subscriptions
- LoopsReceipts and expiry warnings
- PostHogProduct analytics
We also disclose data if the law requires it, and to a buyer if the business is ever sold, in which case this page is updated first.
Where it lives and how long we keep it
- Your account and boardKept while your account is open, deleted 30 days after you cancel
- LinkedIn access tokenDeleted the moment you disconnect the profile or close the account
- Generated imagesHeld until the post publishes, then deleted within 30 days
- InvoicesKept 7 years, because Dutch tax law requires it
- AnalyticsKept 12 months, tied to an account id rather than to your name
Data is stored in the European Union. Some processors above operate in the United States under standard contractual clauses.
Deleting your data
Two buttons, both in settings. Disconnect a profile removes the LinkedIn token and stops every scheduled post for it. Delete account removes the account, every board, every card, every image, and the tokens, within 30 days, invoices excepted.
You can also revoke our access from LinkedIn: Settings, Data privacy, Other applications, Permitted services. Revoking there stops publishing immediately. It does not delete what is stored here, so email privacy@goodsocials.co if you want that too, and we answer within 30 days.
Your rights
Under the GDPR you can ask for a copy of your data, correct it, take it elsewhere, have it deleted, or object to how we use it. Email privacy@goodsocials.co and we reply within 30 days, at no cost.
Our legal bases: performing the contract you signed up for, for the account, board, publishing, and billing. Your consent, for the LinkedIn permissions, withdrawable at any time as described above. Legitimate interest, for analytics, fraud prevention, and keeping the service running.
If we handle a request badly you can complain to the Dutch data protection authority, Autoriteit Persoonsgegevens, at autoriteitpersoonsgegevens.nl.
Cookies
One cookie keeps you signed in. PostHog sets an analytics cookie so we can count how a feature is used. No advertising cookies, no third-party trackers, no data sold to brokers.
Security
LinkedIn tokens are encrypted at rest with AES-256-GCM and a key held outside the database. Tokens are never logged and never sent to the browser. Everything runs over HTTPS. If a breach affects you, we tell you and the regulator within 72 hours of finding it.
Children
GoodSocials is for people running a LinkedIn profile for work. It is not intended for anyone under 18, and we do not knowingly collect their data.
Changes
When this page changes, the date at the top changes with it. If a change affects what we collect or who receives it, we email you before it takes effect.
Contact
privacy@goodsocials.co. A person reads it.