Skip to content

Trust

How we protect your accounts

You are trusting us with access to your audience, so here is exactly what we do and don’t do.

We never ask for your social passwords
YouTube, LinkedIn, Instagram and Facebook connect through each platform’s own login page, so your password goes to them and never to us. Bluesky has no such login page, so it uses an app password that you create and can revoke at any time; we use it once to sign in and keep only a session token. We never ask for your main Bluesky password.
Your Beaquaro password is hashed, so we cannot read it
When you set a password it is turned into a salted one-way hash (bcrypt) before it is stored. There is no way to turn the hash back into your password, so nobody at Beaquaro can see it, and a support request will never ask you for it. We cannot look it up or send it to you. If you sign in with Google, we never get a password at all.
Connection tokens are encrypted
The tokens that let Beaquaro act on your behalf, and any AI key you add, are encrypted before they are stored, and they are never shown back in the app.
Sign in in your own browser
Connecting Instagram or Google should happen in your phone’s real browser, not inside another app’s built-in one. If you open Beaquaro from Instagram, we show a button to move to your browser, so you can check the address bar and sign in on the platform’s own page.
You approve what goes out
Nothing is published or scheduled until you confirm it. The same applies when you use Beaquaro from Claude or ChatGPT: your assistant asks you first, and a read-only connection cannot post at all.
Automations are limited
An hourly send cap, a cooldown per person and no duplicate sends. They only answer people who comment or message you first, and you can pause any of them instantly.
Your uploads are short-lived
Photos and videos are kept only until the post has gone out, then deleted. Anything never posted is removed within a couple of days.
Assistants get limited, revocable access
Connections for AI assistants use tokens that are stored only as hashes, can be read-only, and can be removed in Brand Profile at any time. Daily limits cap what an assistant can do.
Disconnect and delete any time
Disconnecting an account deletes its automations, contacts and message history. Deleting your account removes your data, including uploaded files.
Everything travels over HTTPS
The site only works over encrypted connections, and pages cannot be embedded in other sites.
Privacy-friendly analytics
We count page views and button clicks on our own, with no cookies and no visitor tracking, and we ignore “Do Not Track”.

Found a security problem? Please tell us through the contact page. We read every message and will respond quickly. See also the privacy policy and data deletion page.