Fika
  • Product
  • Pricing
  • FAQ
Sign In
Start Trial
Fika

The complete social media operation for growing companies. Research, writing, publishing, and reporting — so founders can stay focused on building.

© Copyright 2026 Fika. All Rights Reserved.

Product
  • Features
  • Pricing
  • FAQ
Start Trial
  • Sign In
  • Sign Up
Legal
  • Terms of Service
  • Privacy Policy
  • Cookie Policy

Privacy Policy

Last updated: March 2026

Fika ("we", "us", or "our") operates an automated social media management platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services (collectively, the "Service"). Please read it carefully. By using the Service you agree to the practices described here.

1. Information We Collect

1.1 Account Information

When you register, we collect your name, email address, company name, and password. Operators who manage client accounts may additionally provide billing contact details.

1.2 Client Profile Data

To generate content we ask for information about your business: product description, target audience, brand voice, competitors, industry, and content guidelines. This data is used exclusively to inform your content production and is never shared with other clients.

1.3 Social Media Tokens

When you connect a social account (LinkedIn, Twitter / X, Facebook) via OAuth, we store the resulting access token in encrypted form using AES-256 (Fernet) encryption. We store only what is necessary to publish and retrieve analytics on your behalf. We do not store your social media passwords.

1.4 Content & Analytics Data

We store all Fika-produced content, your revision notes, approval decisions, scheduled posts, and post-publication analytics (impressions, likes, comments, shares, reach, clicks). This data is used to generate your monthly performance reports.

1.5 Usage & Log Data

We automatically collect IP addresses, browser type, pages visited, and timestamps when you interact with the Service. This is used for security monitoring, debugging, and service improvement.

1.6 Cookies

We use essential session cookies to keep you signed in and functional cookies to remember your preferences. See our Cookie Policy for full details.

2. How We Use Your Information

  • Providing the Service — producing and scheduling content, scheduling and publishing posts, retrieving analytics, and producing monthly reports.
  • Account management — authenticating you, processing your subscription, and sending service-related communications.
  • AI processing — your brand data and content preferences are passed to large language model APIs (Anthropic Claude, OpenAI) solely to generate content for your account. We do not use your data to train third-party foundation models.
  • Research & reporting — competitor and trend research is conducted using public data sources (Tavily search, DuckDuckGo) combined with your brand context. Results are stored only for your account.
  • Security & fraud prevention — detecting and preventing unauthorised access to your account.
  • Legal compliance — meeting our obligations under applicable law.

3. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA) or United Kingdom, we process your personal data on the following legal bases:

  • Contract — processing necessary to deliver the Service you have subscribed to.
  • Legitimate interests — security monitoring, fraud prevention, and improving the Service.
  • Consent — where you have explicitly opted in, such as marketing emails.
  • Legal obligation — where we are required by applicable law.

4. Sharing of Information

We do not sell your personal data. We share data only as follows:

  • AI providers — Anthropic and OpenAI receive your brand context and content briefs to generate posts. Both are bound by data processing agreements that prohibit use of your data for model training.
  • Social platforms — LinkedIn, Twitter / X, and Facebook receive published post content via their APIs when you schedule a post.
  • Infrastructure providers — we use cloud infrastructure (hosting, databases, Redis cache) that may process data in the course of providing compute services. All providers are under contractual data protection obligations.
  • Legal requirements — we may disclose information if required by law, court order, or to protect the rights and safety of Fika or others.
  • Business transfers — in the event of a merger, acquisition, or asset sale, your data may be transferred. We will notify you before such a transfer and give you the opportunity to delete your account.

5. Data Retention

We retain account and content data for as long as your account is active. If you cancel, we delete your data within 90 days except where we are required by law to retain it longer. If your free trial expires without subscribing, we retain your data for 30 days to allow you to return and subscribe, after which it is deleted. Analytics data aggregated at the report level may be retained for up to 3 years for historical benchmarking purposes, but will be anonymised within 90 days of account deletion.

Encrypted social media access tokens are deleted immediately upon disconnecting a platform or deleting your account.

6. Security

We implement the following measures to protect your data:

  • OAuth tokens encrypted at rest with AES-256 (Fernet)
  • All data in transit encrypted with TLS 1.2+
  • Role-based access control — client users can only access their own data; operators access only the clients they manage
  • JWT authentication with short-lived access tokens (15 min)
  • Regular security reviews and dependency audits

No method of electronic storage or transmission is 100% secure. If you believe your account has been compromised, contact us immediately at security@usefika.com.

7. Your Rights

Depending on your location, you may have the right to:

  • Access — request a copy of your personal data.
  • Rectification — correct inaccurate data.
  • Erasure — request deletion of your data ("right to be forgotten").
  • Portability — receive your data in a machine-readable format.
  • Restriction — request that we limit processing while a dispute is resolved.
  • Objection — object to processing based on legitimate interests.
  • Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing.

To exercise any of these rights, email privacy@usefika.com. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

8. International Transfers

Your data may be processed in countries outside your own, including the United States, where our cloud infrastructure and AI providers operate. When transferring data from the EEA or UK, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or equivalent safeguards.

9. Children

The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at privacy@usefika.com and we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by a prominent notice on the Service at least 14 days before changes take effect. Continued use of the Service after changes are in effect constitutes acceptance of the updated policy.

11. Contact Us

If you have questions about this Privacy Policy or how we handle your data, contact our Data Controller at:

Fika AI

Email: privacy@usefika.com