Privacy Policy
Effective date: August 22, 2026
This Privacy Policy explains how LuciCo LLC, a Delaware limited liability company, doing business as "Caravel" ("Caravel," "we," "us," or "our"), collects, uses, and protects information in connection with the Caravel social-media scheduling service (the "Service"). It applies to all users of the Service.
1. Information We Collect
We collect the following categories of information:
- Account information: your email address and authentication credentials, managed through Supabase Auth;
- Workspace information: your workspace name and settings;
- Content: media files and post text you upload or compose for scheduling;
- Platform connection data: OAuth access and refresh tokens, platform account identifiers, and handles for each social account you connect;
- Publish results: the outcome and permalink available from each platform's supported publishing flow;
- Audit records: a log of account-connection and billing events on your workspace; and
- Billing information: your Stripe customer and subscription identifiers. We never receive or store your card number — card data is handled entirely by Stripe.
2. Platform Data We Access
When you connect a third-party social account, the platform grants Caravel limited access appropriate to the connection type:
- Instagram professional accounts, via Meta's Instagram API with Instagram Login: permission to publish content you compose and to read basic account and post status;
- TikTok, via TikTok Login Kit and the Content Posting API: basic-profile access and the ability to upload an MP4 you select as a draft to your TikTok inbox; and
- Bluesky, via an app password you generate and provide: permission to publish content you compose.
3. How We Use Platform Data
We use platform data solely to run the supported flow you initiate, display connection status in your dashboard, and record the available result. For TikTok, this means basic-profile access and uploading your selected MP4 as a draft to your TikTok inbox; you, the creator, review or edit the draft and publish it in TikTok. We do not sell platform data. We do not share platform data with any third party except the service providers listed in Section 6, who process it on our behalf to operate the Service. We do not use platform data for advertising, do not build advertising or behavioral profiles from it, and do not use it to train machine-learning models.
4. How We Use Information Generally
We use the information described in Section 1 to:
- Operate, maintain, and improve the Service, including scheduling and publishing your posts;
- Authenticate you and secure your account;
- Process subscription payments and communicate about billing;
- Provide customer support and respond to your requests; and
- Detect, prevent, and investigate fraud, abuse, or security incidents.
5. Data Retention
We retain platform connection data (tokens, account identifiers, handles) only while an account remains connected to your workspace. Disconnecting an account from the Accounts page deletes its stored tokens immediately. Content, post history, and audit records are retained for as long as your workspace exists so you can review past activity. You can request deletion of your entire workspace and all associated data by emailing caravel@neomarcopolo.co from the email address on the account; we complete workspace deletion within 30 days and confirm by email.
6. Service Providers
We use the following service providers ("processors") to operate the Service:
- Supabase — database, authentication, and file storage;
- Vercel — web application hosting;
- Fly.io — scheduled-work processing;
- Stripe — subscription billing and payment processing; and
- Cloudflare — network delivery and security proxying for traffic routed through it.
These processors act on our instructions and only receive the information necessary to perform their function. We do not permit them to use your data for their own purposes.
7. Security
Platform access and refresh tokens are encrypted at rest using AES-256-GCM. We use industry-standard access controls to limit who can access stored data, and all traffic to the Service is encrypted in transit. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Data Storage and Location
The Service and the data described in this policy are hosted in the United States. By using the Service, you consent to the transfer and processing of your information in the United States.
9. Your Rights and Choices
You can manage your data directly:
- Disconnect any platform account at any time from the Accounts page — this deletes its stored tokens immediately;
- Request deletion of your entire workspace and all associated data by emailing caravel@neomarcopolo.co from the email address on the account — we complete workspace deletion within 30 days and confirm by email; and
- Email caravel@neomarcopolo.co to request access to, correction of, or deletion of your data. We honor such requests within 30 days.
You can also revoke Caravel's access directly from each platform: on Instagram, via the Apps and Websites section of your account; on TikTok, via Security → Manage app permissions in your account; and on Bluesky, by revoking the app password you created for Caravel. See our Data Deletion page for step-by-step instructions.
10. Platform Compliance
Our collection and use of platform data complies with the developer terms of each platform we integrate with, including Meta's Platform Terms, TikTok's Developer Terms, and Bluesky's terms of service.
11. Children's Privacy
The Service is not directed to, and may not be used by, anyone under 18 years old. We do not knowingly collect information from anyone under 18. If we learn that we have done so, we will delete that information.
12. Changes to This Policy; Contact
We may update this Privacy Policy from time to time. When we do, we will update the "Effective date" above and post the revised policy at this URL. If you have questions about this policy or how we handle your data, contact us at caravel@neomarcopolo.co.