Privacy
Last updated 17 August 2026
This describes exactly what we collect from a connected social account, what we do with it, and how to get rid of it. It is written to match what the software actually does.
Who we are
Sifa is a tool for creators and small businesses to run their social accounts and work with brands. We operate in Kenya, Brazil and the Philippines.
Sifa is operated by Syllable International Limited, a company registered in Kenya at P.O. Box 14349-00202, Nairobi. That company is the data controller for everything described below.
Contact: privacy@sifa.social
Where you are, if you tell us
You can state where you are so that campaigns filtered by distance can find you. It is optional, it is asked for, and nothing infers it — we do not read your IP address for this, and we do not look at the location inside a photo you upload.
For a creator we store an area, never an exact point. A neighbourhood or a ward, treated as accurate to no better than about two kilometres. A brand needs to know you can reach a shoot, not where you sleep, and the difference is enforced in our database rather than left to whoever writes the next screen.
A business may store an exact point, because a shop or a venue is an address it already publishes.
You can remove it at any time and we keep no copy. Not stating it costs you distance-matched campaigns and nothing else.
What we collect when you connect an account
Only what the permission you granted allows, and only for the features below.
| Permission | What we read | What it is for |
|---|---|---|
| Basic profile and media | Your profile fields and your posts — captions, hashtags, timestamps, media type | Producing your audit, learning how you write, planning your calendar |
| Insights | Reach, impressions, and aggregate audience age and location | Showing your own numbers, and matching you to brand campaigns that filter on audience |
| Comments | Comments on your posts, read each time you open your inbox and never stored. Replies you send are stored; who wrote a comment never is | Telling you what people keep asking, drafting replies for you, and — only if you turn it on — sending simple ones automatically within limits you set |
| Content publishing | Nothing — this is write-only | Publishing posts you have scheduled or approved |
What we do not collect
- Direct messages. We do not request, read or send DMs on any platform.
- Health, biometric or biological data. Never, regardless of consent. This includes anything that would be special-category data under GDPR Article 9.
- Individual profiles of your followers. Audience information is only ever handled as aggregates.
- Payment card details. Payments are handled by our payment providers.
What brands can see about you
This is the part people ask about most, so it is stated plainly.
- Before a brand funds escrow, they see your public metrics, your category, your region and a match score. They do not see your handle, your name, your email or your phone number.
- After escrow is funded, they see your contact details, because you are working together and the money is committed.
- Your payout details are never shared with a brand, at any stage. We pay you; they pay us.
- Aggregate insights we sell to brands — such as what audiences in a category ask about — are pooled across many creators with a minimum threshold, and never contain your comments, your handle or anything traceable to you.
What we do not do with your data
- We do not sell your personal data.
- We do not feed data from your connected account into market reports sold to brands. Those are built only from public and licensed sources.
- We do not publish anything you have not scheduled or approved.
- We do not use your content to train models for anyone else.
Who else touches it
Named, because “trusted partners” tells you nothing.
| Who | What they handle | Where |
|---|---|---|
| Clerk | Your login, password and any social sign-in you use | United States |
| Supabase | The database holding your account, connections and imported posts | European Union |
| Railway | Runs the API that serves this product | United States |
| Vercel | Serves the website | Global edge network |
| Anthropic | Receives the text of a post to write captions, scripts and analysis | United States |
| OpenAI | The same, when Anthropic is unavailable | United States |
| Google (YouTube Data API) | Public search we run to read what is working in your niche. Nothing of yours is sent. | United States |
| Paystack | Processes brand payments and payouts. Not yet active. | Nigeria / South Africa |
Neither model provider is permitted to train on your data — that is a contractual term of the API tiers we use, not a preference we have set.
How long we keep it
- Posts — while your account is connected, and 30 days after you disconnect.
- Comments — not kept at all. They are read from the platform each time you open your inbox and are gone when you close it.
- Replies you sent — kept, so we can tell when a draft would repeat one you have already sent.
- Your audit history — kept so we can show you what changed, deleted with your account.
- Campaign and payment records — kept as long as tax and contract law requires, typically seven years.
- Everything else — deleted with your account.
Getting rid of it
Three ways, all of them real:
- Disconnect one account. Platforms page → Disconnect. Deletes the stored posts, comments and insights for that account.
- Delete everything. /data-deletion, or email us. Done within 30 days.
- Revoke from the platform. Removing our app in Instagram or TikTok settings also works — we stop receiving data immediately and delete what we hold.
Campaign and payment records survive deletion where the law requires us to keep them. We will tell you what those are.
Your rights
Depending on where you live, under Kenya’s Data Protection Act 2019, Brazil’s LGPD, the Philippines Data Privacy Act, or the GDPR:
- Ask what we hold about you, and get a copy
- Correct anything wrong
- Have it deleted
- Object to how we use it
- Take it elsewhere in a portable format
- Complain to your data protection authority
Email privacy@sifa.social. We answer within 30 days and do not charge.
Changes
If we change what we collect or what we do with it, we will tell you before it takes effect rather than quietly updating this page.
Questions about any of this
Write to privacy@sifa.social. We answer data requests within the statutory window for your country — 30 days under the Kenyan Data Protection Act and the GDPR, 15 days under Brazil’s LGPD.