Trust
How we protect your accounts
You are trusting us with access to your audience, so here is exactly what we do and don’t do.
- We never see your social passwords
- YouTube, X, Instagram and Facebook connect through each platform’s own login page. Bluesky uses an app password that you can revoke at any time; we use it once to sign in and keep only a session token.
- Connection tokens are encrypted
- The tokens that let Beaquaro act on your behalf, and any AI key you add, are encrypted before they are stored. Your Beaquaro password is stored as a salted hash, never as text.
- You approve what goes out
- Nothing is published or scheduled until you confirm it. The same applies when you use Beaquaro from Claude or ChatGPT: your assistant asks you first, and a read-only connection cannot post at all.
- Automations are limited
- An hourly send cap, a cooldown per person and no duplicate sends. They only answer people who comment or message you first, and you can pause any of them instantly.
- Your uploads are short-lived
- Photos and videos are kept only until the post has gone out, then deleted. Anything never posted is removed within a couple of days.
- Assistants get limited, revocable access
- Connections for AI assistants use tokens that are stored only as hashes, can be read-only, and can be removed in Brand Profile at any time. Daily limits cap what an assistant can do.
- Disconnect and delete any time
- Disconnecting an account deletes its automations, contacts and message history. Deleting your account removes your data, including uploaded files.
- Everything travels over HTTPS
- The site only works over encrypted connections, and pages cannot be embedded in other sites.
- Privacy-friendly analytics
- We count page views and button clicks on our own, with no cookies and no visitor tracking, and we ignore “Do Not Track”.
Found a security problem? Please tell us through the contact page. We read every message and will respond quickly. See also the privacy policy and data deletion page.