Privacy Policy
LarkBeat helps you write, schedule, publish and analyze posts on X, Instagram and TikTok. This policy explains what we collect when you use LarkBeat at larkbeat.com, why we collect it, and the choices you have. We only collect what the product needs to work, and we don't sell your data.
What we collect
- Account details. You sign in with Google, and Google shares your name, email address and profile picture with us.
- X connection. If you connect an X account, we store the access tokens X issues so we can publish on your behalf, and the account's public profile (handle, display name, avatar and follower count).
- Instagram connection. If you connect an Instagram professional account, we store the access tokens Instagram issues and the account's profile (username, name, profile picture and follower count).
- TikTok connection. If you connect a TikTok account, we store the access tokens TikTok issues and the account's profile (display name, username and avatar). Right before each post we also read your current posting settings: which privacy options you can choose and whether comments, duets and stitches are allowed.
- Your workspace. The posts, threads, drafts, schedules, queue, ideas, templates, settings and notifications you create in LarkBeat, plus your credit balance and what your credits were used for.
- Media. Images, videos and GIFs you upload, along with the alt text you add.
- Post analytics. Numbers for the posts you publish through LarkBeat, and only those. From X: impressions, likes, replies, reposts and bookmarks. From Instagram: views, likes, comments, shares and saves, plus profile visits, follows and link clicks where Instagram provides them. From TikTok: views, likes, comments and shares.
- Links you add. When a post contains a link, our server fetches that page's title, description and image to show a preview card.
- Technical data. Like most websites, our hosting provider processes IP addresses and basic request logs to deliver and protect the service. We use IP addresses briefly to rate-limit AI requests.
We don't use advertising trackers. We count page views with Vercel Web Analytics, which doesn't use cookies (see below).
How we use it
- To sign you in and keep your workspace in sync across devices.
- To publish to X, Instagram and TikTok the posts you schedule, queue or choose to publish now, and only those. Our servers check for posts that are due every minute, so posts go out even when LarkBeat isn't open.
- To hand a post over to you when a platform requires it, for example when you add a song on Instagram or a sound on TikTok, which can only be done in their apps.
- To show how your posts perform and suggest better times to post.
- To generate drafts when you use the AI studio.
- To track and charge credits, and to send you notifications about your posts and your balance.
- To keep the service secure, prevent abuse and fix problems.
Google user data
When you sign in with Google, LarkBeat requests only your basic profile (name and profile picture) and your email address. We use them only to create your account, sign you in and show who is signed in. We don't request access to your Gmail, Drive, Calendar, contacts or any other Google data.
We don't sell Google user data, use it for advertising, or use it to train AI models, and we don't share it with anyone except the providers that run LarkBeat (listed below). LarkBeat's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Services we rely on
- Supabase hosts our database and sign-in, and runs the scheduler that triggers publishing, analytics updates and cleanup. Your workspace is stored there, and each account can only access its own data.
- Cloudflare stores the photos and videos you upload (Cloudflare R2, in a private bucket). Files are only reachable through short-lived links.
- X receives the posts and media you publish, and we read your profile and post analytics through its API.
- Instagram (Meta) and TikTok receive the photos, videos and captions you publish to them. To post, they download your media from a private, time-limited link to our storage. We read your profile and post analytics through their APIs.
- Google handles sign-in. When you use the AI studio, your brief and settings are sent to Google Gemini. If you turn on "Write like me", a few of your published posts are sent as voice samples too.
- Vercel hosts LarkBeat. Its Web Analytics counts page views and records the page path, referrer, country, browser and device type, without cookies and without identifying you across sites. Query strings are stripped before anything is sent.
X, Meta, TikTok and Google have their own privacy policies, which apply to anything you post or share with them. We share data with these providers only so they can run LarkBeat for you, never so they can market to you. They may process data in the United States and other countries.
Cookies and local storage
We use essential cookies to keep you signed in and to complete the X, Instagram and TikTok connection flows securely. LarkBeat also keeps a copy of your workspace in your browser's local storage so the app loads quickly. If you turn on desktop notifications, that choice is saved in your browser too. We don't use cookies for advertising.
Security
X, Instagram and TikTok access tokens are stored server-side and never sent to your browser. Data travels over HTTPS, and database access is restricted per account. No system is perfectly secure, but we work to protect your information and limit who can access it.
Keeping and deleting your data
- We keep your account and workspace for as long as your account is active.
- Uploaded photos and videos are deleted 7 days after the last post using them is published. Uploads you never attach to a post are deleted 7 days after upload. Files on drafts or scheduled posts are kept until then.
- Notifications are deleted after 60 days.
- Disconnecting an account in Settings removes its tokens from our database and, for X and TikTok, revokes them. For Instagram, also remove LarkBeat under Instagram → Settings → Apps and websites.
- You can export your workspace from Settings at any time.
- To delete your account and all associated data, contact the LarkBeat team, and we'll delete it within 30 days.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, or to object to how it's used. To exercise any of these rights, contact the LarkBeat team.
Children
LarkBeat isn't meant for anyone under 13, or under the minimum age for using X, Instagram or TikTok where they live, and we don't knowingly collect their data.
Changes to this policy
If we make meaningful changes, we'll update the date at the top of this page and let you know in the app.
Contact
Questions about this policy? contact the LarkBeat team.