Effective Date: January 1, 2025 · Last updated: August 13, 2026
Welcome to Sarvavidhi ("we", "our", or "us"), a B2B social media management platform available at sarvavidhi.com. We provide digital marketing agencies and their clients with tools to schedule and publish social media posts, manage client workspaces, run AI-assisted content plans, and send automated messaging campaigns.
Sarvavidhi is an MSME-registered business in India, operating as part of Getnovative. Together we are the data controller responsible for the personal data described in this policy, and the operator of our Facebook and Instagram integrations. You can reach us at support@sarvavidhi.com.
This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and your rights regarding that data. By using Sarvavidhi, you agree to the practices described in this policy.
This policy applies to:
Sarvavidhi is a business tool. We do not knowingly collect data from individuals under 18 years of age.
3.1 Account & Identity Data
3.2 Social Media OAuth Tokens
When you connect a social media account, we store OAuth access tokens and associated metadata (page IDs, account IDs, token expiry) to publish content on your behalf. Specifically:
Access and refresh tokens are encrypted with AES-256-GCM before being written to our database, so they are unreadable without a key held separately in our application environment. They are transmitted only over TLS, are never returned to the browser or exposed to third parties beyond the platform each token belongs to. When you disconnect an account or remove the app from Facebook, we immediately delete the corresponding access tokens, app-scoped Meta user ID, Page or channel identifiers, account names, and related connection metadata.
3.3 Content & Scheduling Data
This is content you create or upload within Sarvavidhi; it is not imported from your Facebook or Instagram feed. Disconnecting a social account stops future publishing through that connection but does not delete this content. It is hidden from AI Autopilot and Content Calendar by default and can be shown as saved history. Delete the workspace or your Sarvavidhi account to remove the saved content.
3.4 Client Workspace Information
3.5 Messaging & Campaign Data
3.6 Usage & Technical Data
Cookies we set: Next-Auth secure HTTP-only session cookies (required to keep you logged in) and Google Analytics measurement cookies (used only for aggregate product analytics). We do not use advertising cookies, and we do not sell or share your data with advertising networks.
You can opt out of Google Analytics at any time using Google's browser opt-out add-on or by blocking analytics cookies in your browser settings. Doing so does not affect your ability to use Sarvavidhi.
| Purpose | Data Used | Legal Basis |
|---|---|---|
| User authentication & account management | Name, email, profile picture, password hash | Contract performance |
| Publishing social media posts on your behalf | OAuth tokens, post content, scheduling data | Contract performance / explicit consent |
| Managing client workspaces | Client details, linked platform accounts | Contract performance |
| Sending email / WhatsApp campaigns | Subscriber lists, message content, delivery logs | Legitimate interest / consent |
| AI content generation | Prompts and plan requests (sent to Google Gemini API) | Contract performance |
| Security, fraud prevention, debugging | Server logs, IP addresses | Legitimate interest |
| Transactional emails (account alerts) | Email address | Contract performance |
We do not sell your data. We do not use your data for advertising profiling or share it with data brokers.
Sarvavidhi integrates with the following third-party services. Each service's own privacy policy governs how they handle data passed to them.
| Service | Purpose | Data Shared |
|---|---|---|
| Meta (Facebook / Instagram) | Publishing posts, reading page stats, WhatsApp messaging | Page tokens, post content, WhatsApp messages |
| Google OAuth / Gemini API | User sign-in, YouTube integration, AI content generation | OAuth tokens, content prompts |
| Twitter / X API | Publishing tweets, reading Twitter analytics | OAuth tokens, tweet content |
| LinkedIn API | Publishing LinkedIn posts | OAuth tokens, post content |
| Brevo (Sendinblue) | Sending transactional and drip emails | Recipient email, name, email content |
| Upstash QStash | Reliable background job queue for scheduled posts | Job payloads (post IDs, timestamps) |
| Neon PostgreSQL | Primary database hosting | All application data stored in database |
| ImgBB | Image hosting for post media uploads | Uploaded images |
| Vercel | Application hosting and CDN | Server-side rendering and short-lived request or diagnostic metadata. OAuth access tokens are not intentionally logged. |
| Google Analytics 4 | Aggregate website usage statistics | Pages viewed, session duration, approximate location, referrer |
| Groq | Llama-based AI chat assistant responses | Chat prompts you type into the assistant |
| ElevenLabs | Text-to-speech for the voice/call bot demo | Text submitted for speech synthesis |
Sarvavidhi uses the Meta Platform APIs (Facebook Graph API and Instagram Graph API) solely to:
We request only the permissions necessary for these functions. We do not access your personal Facebook profile, your friends list, or any data beyond what is required for the above purposes.
Meta Connection Deletion:When you disconnect inside Sarvavidhi, we delete the selected connection directly. When you remove Sarvavidhi from Facebook's Apps and Websites settings, Meta sends a signed deauthorization callback to our servers. In either case, we delete the corresponding Facebook and Instagram tokens, app-scoped Meta user ID, Page IDs and names, Instagram Business account IDs and usernames, and related connection metadata. Future queued or scheduled publishing through that connection is cancelled when no matching account remains connected. A post already being published may finish.
User-created Sarvavidhi post text, uploaded media, schedules, and status information are stored separately from Meta connection data and are not imported from a Facebook or Instagram feed. They remain as saved history after disconnecting, hidden from AI Autopilot and Content Calendar by default. Disconnecting Meta does not delete your Sarvavidhi profile or other workspaces.
You can also revoke Sarvavidhi's access at any time via Facebook Settings → Apps and Websites.
Upon account deletion, all personal data, OAuth tokens, posts, and client workspaces associated with your account are permanently deleted within 30 days.
Under applicable Indian data protection law (Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023 where applicable), and internationally under GDPR principles where relevant, you have the following rights:
To exercise any of these rights, email us at support@sarvavidhi.com. We will respond within 30 days.
Full step-by-step instructions are on our Data Deletion Instructions page. In short, you can request complete deletion of your account and all associated data by:
Upon deletion, we will remove your profile, all OAuth tokens, all client workspaces you own, all posts and content, all email subscriber lists, and application records directly associated with your account from our active systems within 30 days. Limited security and server logs age out under the retention periods stated in Section 7.
Facebook-specific: If you use the "Remove App" function within Facebook's app settings, our system automatically receives a deauthorization webhook and immediately deletes your Facebook and Instagram tokens, app-scoped Meta user ID, Page and Instagram account identifiers and names, and related connection metadata. Your user-created Sarvavidhi content remains as saved history until its workspace or your Sarvavidhi account is deleted.
Despite these measures, no system can guarantee absolute security. If you suspect unauthorized access to your account, contact us immediately at support@sarvavidhi.com.
Sarvavidhi is operated from India. Some third-party services we use (such as Meta, Google, Vercel, Neon, and Upstash) may process data in the United States or other countries. By using Sarvavidhi and connecting these services, you acknowledge that your data may be transferred to and processed in countries outside India. We ensure that our third-party processors maintain appropriate security standards.
This Privacy Policy is governed by and construed in accordance with the laws of India, including the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023 (DPDPA), to the extent applicable. Any disputes arising under this policy shall be subject to the exclusive jurisdiction of the courts in India.
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of Sarvavidhi after changes are posted constitutes acceptance of the updated policy. For material changes, we will notify active users via email.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Sarvavidhi
Email: support@sarvavidhi.com
Website: sarvavidhi.com
We aim to respond to all privacy-related inquiries within 30 days.
© 2026 Sarvavidhi. All rights reserved. · sarvavidhi.com