Trust
How we protect your accounts
You are trusting us with access to your audience, so here is exactly what we do and don’t do.
- We never ask for your social passwords
- YouTube, LinkedIn, Instagram and Facebook connect through each platform’s own login page, so your password goes to them and never to us. Bluesky has no such login page, so it uses an app password that you create and can revoke at any time; we use it once to sign in and keep only a session token. We never ask for your main Bluesky password.
- Your Beaquaro password is hashed, so we cannot read it
- When you set a password it is turned into a salted one-way hash (bcrypt) before it is stored. There is no way to turn the hash back into your password, so nobody at Beaquaro can see it, and a support request will never ask you for it. We cannot look it up or send it to you. If you sign in with Google, we never get a password at all.
- Connection tokens are encrypted
- The tokens that let Beaquaro act on your behalf, and any AI key you add, are encrypted before they are stored, and they are never shown back in the app.
- Sign in in your own browser
- Connecting Instagram or Google should happen in your phone’s real browser, not inside another app’s built-in one. If you open Beaquaro from Instagram, we show a button to move to your browser, so you can check the address bar and sign in on the platform’s own page.
- You approve what goes out
- Nothing is published or scheduled until you confirm it. The same applies when you use Beaquaro from Claude or ChatGPT: your assistant asks you first, and a read-only connection cannot post at all.
- Automations are limited
- An hourly send cap, a cooldown per person and no duplicate sends. They only answer people who comment or message you first, and you can pause any of them instantly.
- Your uploads are short-lived
- Photos and videos are kept only until the post has gone out, then deleted. Anything never posted is removed within a couple of days.
- Assistants get limited, revocable access
- Connections for AI assistants use tokens that are stored only as hashes, can be read-only, and can be removed in Brand Profile at any time. Daily limits cap what an assistant can do.
- Disconnect and delete any time
- Disconnecting an account deletes its automations, contacts and message history. Deleting your account removes your data, including uploaded files.
- Everything travels over HTTPS
- The site only works over encrypted connections, and pages cannot be embedded in other sites.
- Privacy-friendly analytics
- We count page views and button clicks on our own, with no cookies and no visitor tracking, and we ignore “Do Not Track”.
Found a security problem? Please tell us through the contact page. We read every message and will respond quickly. See also the privacy policy and data deletion page.