Sarvavidhi

Privacy Policy

Effective Date: January 1, 2025  ·  Last updated: August 13, 2026

1. Introduction

Welcome to Sarvavidhi ("we", "our", or "us"), a B2B social media management platform available at sarvavidhi.com. We provide digital marketing agencies and their clients with tools to schedule and publish social media posts, manage client workspaces, run AI-assisted content plans, and send automated messaging campaigns.

Sarvavidhi is an MSME-registered business in India, operating as part of Getnovative. Together we are the data controller responsible for the personal data described in this policy, and the operator of our Facebook and Instagram integrations. You can reach us at support@sarvavidhi.com.

This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and your rights regarding that data. By using Sarvavidhi, you agree to the practices described in this policy.

2. Who This Policy Applies To

This policy applies to:

  • Agency owners and team members who create accounts and use the Sarvavidhi dashboard.
  • Client contacts whose workspace information is managed within the platform by their agency.
  • End users who interact with social media content published via Sarvavidhi on platforms such as Facebook, Instagram, Twitter/X, or LinkedIn.

Sarvavidhi is a business tool. We do not knowingly collect data from individuals under 18 years of age.

3. Data We Collect

3.1 Account & Identity Data

  • Full name
  • Email address
  • Profile picture (retrieved via Google OAuth on sign-in)
  • Password hash (for email/password accounts, stored using bcrypt)

3.2 Social Media OAuth Tokens

When you connect a social media account, we store OAuth access tokens and associated metadata (page IDs, account IDs, token expiry) to publish content on your behalf. Specifically:

  • Facebook / Instagram: Page access tokens, app-scoped Meta user ID, Page IDs and names, Instagram Business Account IDs and usernames.
  • Twitter / X: OAuth 2.0 access and refresh tokens, Twitter user ID.
  • LinkedIn: OAuth access tokens, LinkedIn Person URN.
  • YouTube / Google: OAuth tokens for YouTube channel access (if connected).

Access and refresh tokens are encrypted with AES-256-GCM before being written to our database, so they are unreadable without a key held separately in our application environment. They are transmitted only over TLS, are never returned to the browser or exposed to third parties beyond the platform each token belongs to. When you disconnect an account or remove the app from Facebook, we immediately delete the corresponding access tokens, app-scoped Meta user ID, Page or channel identifiers, account names, and related connection metadata.

3.3 Content & Scheduling Data

  • Post text, images, and media uploaded or generated within the platform.
  • Scheduled publish times and platform targets.
  • AI-generated content plans and prompts you submit.

This is content you create or upload within Sarvavidhi; it is not imported from your Facebook or Instagram feed. Disconnecting a social account stops future publishing through that connection but does not delete this content. It is hidden from AI Autopilot and Content Calendar by default and can be shown as saved history. Delete the workspace or your Sarvavidhi account to remove the saved content.

3.4 Client Workspace Information

  • Client name, brand details, and workspace configuration.
  • Client-specific social accounts linked to a workspace.

3.5 Messaging & Campaign Data

  • Email subscriber lists, email content, and delivery/open/click logs (via Brevo).
  • WhatsApp contact lists and message logs (via Meta WhatsApp Business API).

3.6 Usage & Technical Data

  • Server-side logs (IP address, request paths, timestamps) retained for security and debugging.
  • Browser/device type derived from HTTP User-Agent headers.
  • Aggregate site-usage statistics (pages viewed, session duration, approximate location, referring site) collected through Google Analytics 4, which sets its own first-party cookies on your browser.

Cookies we set: Next-Auth secure HTTP-only session cookies (required to keep you logged in) and Google Analytics measurement cookies (used only for aggregate product analytics). We do not use advertising cookies, and we do not sell or share your data with advertising networks.

You can opt out of Google Analytics at any time using Google's browser opt-out add-on or by blocking analytics cookies in your browser settings. Doing so does not affect your ability to use Sarvavidhi.

4. How We Use Your Data

PurposeData UsedLegal Basis
User authentication & account managementName, email, profile picture, password hashContract performance
Publishing social media posts on your behalfOAuth tokens, post content, scheduling dataContract performance / explicit consent
Managing client workspacesClient details, linked platform accountsContract performance
Sending email / WhatsApp campaignsSubscriber lists, message content, delivery logsLegitimate interest / consent
AI content generationPrompts and plan requests (sent to Google Gemini API)Contract performance
Security, fraud prevention, debuggingServer logs, IP addressesLegitimate interest
Transactional emails (account alerts)Email addressContract performance

We do not sell your data. We do not use your data for advertising profiling or share it with data brokers.

5. Third-Party Services We Use

Sarvavidhi integrates with the following third-party services. Each service's own privacy policy governs how they handle data passed to them.

ServicePurposeData Shared
Meta (Facebook / Instagram)Publishing posts, reading page stats, WhatsApp messagingPage tokens, post content, WhatsApp messages
Google OAuth / Gemini APIUser sign-in, YouTube integration, AI content generationOAuth tokens, content prompts
Twitter / X APIPublishing tweets, reading Twitter analyticsOAuth tokens, tweet content
LinkedIn APIPublishing LinkedIn postsOAuth tokens, post content
Brevo (Sendinblue)Sending transactional and drip emailsRecipient email, name, email content
Upstash QStashReliable background job queue for scheduled postsJob payloads (post IDs, timestamps)
Neon PostgreSQLPrimary database hostingAll application data stored in database
ImgBBImage hosting for post media uploadsUploaded images
VercelApplication hosting and CDNServer-side rendering and short-lived request or diagnostic metadata. OAuth access tokens are not intentionally logged.
Google Analytics 4Aggregate website usage statisticsPages viewed, session duration, approximate location, referrer
GroqLlama-based AI chat assistant responsesChat prompts you type into the assistant
ElevenLabsText-to-speech for the voice/call bot demoText submitted for speech synthesis

6. Facebook & Instagram Data Use

Sarvavidhi uses the Meta Platform APIs (Facebook Graph API and Instagram Graph API) solely to:

  • Publish posts to Facebook Pages and Instagram Business accounts you have authorized.
  • Display Facebook Page follower and published-post counts, plus Instagram account reach, engagement, and media insights, within your dashboard.
  • Send and receive WhatsApp Business messages via the Meta WhatsApp Cloud API.

We request only the permissions necessary for these functions. We do not access your personal Facebook profile, your friends list, or any data beyond what is required for the above purposes.

Meta Connection Deletion:When you disconnect inside Sarvavidhi, we delete the selected connection directly. When you remove Sarvavidhi from Facebook's Apps and Websites settings, Meta sends a signed deauthorization callback to our servers. In either case, we delete the corresponding Facebook and Instagram tokens, app-scoped Meta user ID, Page IDs and names, Instagram Business account IDs and usernames, and related connection metadata. Future queued or scheduled publishing through that connection is cancelled when no matching account remains connected. A post already being published may finish.

User-created Sarvavidhi post text, uploaded media, schedules, and status information are stored separately from Meta connection data and are not imported from a Facebook or Instagram feed. They remain as saved history after disconnecting, hidden from AI Autopilot and Content Calendar by default. Disconnecting Meta does not delete your Sarvavidhi profile or other workspaces.

You can also revoke Sarvavidhi's access at any time via Facebook Settings → Apps and Websites.

7. Data Retention

  • Account data is retained for as long as your account is active.
  • OAuth tokens are retained until you disconnect the platform or delete your account.
  • Post content and scheduling data is retained for as long as the client workspace exists, including as saved history after a social account is disconnected.
  • Email and messaging logs are retained for up to 12 months for delivery tracking.
  • Server and diagnostic logs are retained by our Vercel Hobby hosting plan for up to 6 hours.

Upon account deletion, all personal data, OAuth tokens, posts, and client workspaces associated with your account are permanently deleted within 30 days.

8. Your Rights

Under applicable Indian data protection law (Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023 where applicable), and internationally under GDPR principles where relevant, you have the following rights:

  • Right to Access: Request a copy of the personal data we hold about you.
  • Right to Correction: Request correction of inaccurate or incomplete data.
  • Right to Deletion: Request deletion of your personal data and account.
  • Right to Portability: Request your data in a machine-readable format.
  • Right to Withdraw Consent: Disconnect social accounts or revoke OAuth permissions at any time through account settings or directly on the respective platform.
  • Right to Object: Object to processing of your data for specific purposes.

To exercise any of these rights, email us at support@sarvavidhi.com. We will respond within 30 days.

9. Account & Data Deletion

Full step-by-step instructions are on our Data Deletion Instructions page. In short, you can request complete deletion of your account and all associated data by:

  • Email: Sending a deletion request to support@sarvavidhi.com with the subject line "Account Deletion Request".
  • Account Settings: Using the "Delete My Account" option in Account Settings within the Sarvavidhi dashboard and confirming with your registered email address.

Upon deletion, we will remove your profile, all OAuth tokens, all client workspaces you own, all posts and content, all email subscriber lists, and application records directly associated with your account from our active systems within 30 days. Limited security and server logs age out under the retention periods stated in Section 7.

Facebook-specific: If you use the "Remove App" function within Facebook's app settings, our system automatically receives a deauthorization webhook and immediately deletes your Facebook and Instagram tokens, app-scoped Meta user ID, Page and Instagram account identifiers and names, and related connection metadata. Your user-created Sarvavidhi content remains as saved history until its workspace or your Sarvavidhi account is deleted.

10. Data Security

  • All data is transmitted over HTTPS / TLS.
  • Passwords are hashed using bcrypt and never stored in plain text.
  • OAuth tokens are stored in an encrypted PostgreSQL database hosted on Neon.
  • Authenticated user routes use session-based authentication. Public provider callbacks, webhooks, cron routes, and background workers use signed requests, scoped tokens, or server-held secrets appropriate to their purpose.
  • Background job queues (QStash) use cryptographic signature verification.
  • Access to production systems is restricted to authorized personnel.

Despite these measures, no system can guarantee absolute security. If you suspect unauthorized access to your account, contact us immediately at support@sarvavidhi.com.

11. International Data Transfers

Sarvavidhi is operated from India. Some third-party services we use (such as Meta, Google, Vercel, Neon, and Upstash) may process data in the United States or other countries. By using Sarvavidhi and connecting these services, you acknowledge that your data may be transferred to and processed in countries outside India. We ensure that our third-party processors maintain appropriate security standards.

12. Governing Law

This Privacy Policy is governed by and construed in accordance with the laws of India, including the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023 (DPDPA), to the extent applicable. Any disputes arising under this policy shall be subject to the exclusive jurisdiction of the courts in India.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of Sarvavidhi after changes are posted constitutes acceptance of the updated policy. For material changes, we will notify active users via email.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Sarvavidhi
Email: support@sarvavidhi.com
Website: sarvavidhi.com

We aim to respond to all privacy-related inquiries within 30 days.

© 2026 Sarvavidhi. All rights reserved.  ·  sarvavidhi.com