OxChannels

Privacy policy

This policy describes what OxChannels does with personal data, including data received from the social platforms you connect. It describes how the service behaves today, not how we intend it to behave.

Last updated: 12 August 2026

Who we are

OxChannels is a social publishing and automation service operated by CodeFormers. This policy explains what personal data the service processes, why, on what legal basis, and how long it is kept.

For data you place in the service as a customer, you are the controller and OxChannels acts as your processor. For account, billing and service-security data, OxChannels is the controller.

What data we process

Account data
Email address, display name, password hash, and the workspaces you belong to. Used to authenticate you and to decide what you may see and do.
Connection data
The social accounts and pages you connect, their provider identifiers, display names, and the health of each authorization. Used to publish on your behalf and to tell you when a connection needs attention.
Provider credentials
Access and refresh tokens issued by the platforms you connect. Held encrypted in a credential vault on the server. They are never sent to your browser and never shown in the interface.
Content you publish
Posts, media, schedules and their delivery results. Retained so the service can show what was published, when, where, and with what outcome.
Engagement and analytics
Aggregate counts and, where a platform exposes them, comments and reactions on your own posts. Used to produce the analytics you see in the product.
Operational records
An audit log of who changed what and when, plus technical logs, error traces and request identifiers. Used for security, billing accuracy and incident investigation.

Data from connected platforms

When you connect an account, the platform asks you to approve a specific list of permissions. The consent screen shown by the platform is authoritative: OxChannels can only receive what you approve there, and only for as long as the grant remains valid.

The authorization code returned by the platform is exchanged for a token by our server, not by your browser. The browser is told only that a connection succeeded and which account it belongs to.

Data received from a platform is used to operate the features you asked for. It is not sold, not used to build advertising profiles, and not used to train machine learning models.

Revoking access at the platform, or revoking the connection inside OxChannels, stops further collection. Data already received is deleted according to the retention rules below.

Who else sees it

We do not sell personal data and we do not share it for advertising.

Data is disclosed to the social platforms you connect, but only what is needed to carry out the action you requested, such as the content of a post you chose to publish.

Infrastructure providers
Hosting, object storage and content delivery, acting as processors under contract.
Payment provider
Handles billing. Card numbers do not reach OxChannels servers.
Authorities
Only where the law requires it, and only to the extent required.

How long we keep it

Provider tokens
Deleted when a connection is revoked or when the platform invalidates the grant.
Published content and delivery results
Kept while the workspace exists, so the record of what was published stays accurate.
Audit log
Kept for the retention period configured for your workspace, because an audit record you can shorten at will is not an audit record.
Technical logs
Kept for a short operational window and then discarded.
Account data
Deleted within 30 days of account closure, except records that billing or tax law requires us to keep.

How it is protected

Encryption in transit
All traffic runs over TLS.
Encrypted credentials
Provider tokens are encrypted with a managed key and are readable only by the backend service that needs them.
Least exposure in the browser
The panel never receives provider tokens, so a compromised browser session cannot leak them.
Workspace isolation
Every read and every change is scoped to a workspace and checked against your role in it.
Change records
Actions that alter a connection, a publication or a permission are written to the audit log.

The local agent

OxChannels offers an optional agent that runs on your own machine. Data it holds locally stays on that machine unless you explicitly send it to the service. Using the agent is not required to use OxChannels, and declining it does not reduce the rest of the product.

Your rights

Under the GDPR you may request access to your personal data, correction, deletion, restriction of processing, portability, and you may object to processing based on legitimate interest. Where processing rests on consent, you may withdraw it without affecting what was lawful before.

Write to the address below and we will respond within one month. You also have the right to complain to a supervisory authority; in Poland that is the President of the Personal Data Protection Office (UODO).

International transfers

Service infrastructure is operated in the European Union. Some connected platforms and processors operate outside the EEA; where data reaches them, the transfer relies on the European Commission standard contractual clauses or an adequacy decision.

Children

OxChannels is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will remove it.

Changes to this policy

When this policy changes, the date at the top of the page changes with it. Changes that materially affect how we handle your data are announced in the product before they take effect.

Contact

Questions about this policy, or a request to exercise your rights:[email protected].