Last updated: March 24, 2026
1. Introduction
Sjenkie B.V. ("we", "us", "our") operates PattrIQ. This Privacy Policy explains how we collect, use, and protect your personal information when you use our Service.
2. Information We Collect
Information you provide:
- Email address (for authentication and communication)
- Social media post data you choose to import for analysis
- Brand profile details (tone of voice, topics, audience)
- Campaigns, content plans, and drafts you create
- Feedback and support communications
Information from connected accounts:
If you choose to connect a third-party account (such as X/Twitter, LinkedIn, or BookmarksIQ) via OAuth, we may receive the following data, depending on the permissions you authorize:
- Your public profile information (username, display name, account ID)
- Your public posts and their engagement metrics (likes, reposts, replies, impressions)
- OAuth access and refresh tokens (stored encrypted at rest; see Section 6)
We access only the data you authorize during the OAuth consent flow. The legal basis for this processing is your explicit consent (GDPR Article 6(1)(a)) when connecting the account. You can disconnect at any time from your Account settings, which immediately deletes your stored tokens and revokes our access.
Information collected automatically:
- Usage data (features used, interactions with the Service)
- Device information (browser type, operating system)
- Log data (IP address, access times)
3. How We Use Your Information
We use your information to:
- Provide and maintain the Service
- Authenticate your identity
- Process and analyze your imported post data
- Power AI-driven pattern detection, strategy, ideation, and draft generation
- Send important service notifications (e.g. authentication codes, billing receipts)
- Send product onboarding and lifecycle emails triggered by your in-product activity (e.g. setup reminders, analysis completion notifications). These emails include an unsubscribe link and you can opt out at any time.
- Respond to your requests and support inquiries
- Improve and optimize the Service
4. AI Processing
PattrIQ uses AI services to analyse posts, detect patterns, generate strategies, ideas, content plans, and post drafts.
What data is processed by AI:
- Post text content from your imported datasets
- Brand profile information
- Content preferences and strategy context
AI Service Providers:
We use OpenRouter API for text generation, which may route requests to sub-processors including:
- Anthropic (Claude models)
- Google (Gemini models)
- OpenAI (GPT models)
For AI image generation, we use Replicate (Recraft V4 model). Image generation prompts and brand context are sent to Replicate to produce visuals for your social media posts. Generated images are stored in DigitalOcean Spaces (object storage) and optimized server-side before delivery.
How your data is protected:
- Data is sent to AI providers only to process your request and deliver features
- We configure provider settings to restrict model training where available, and rely on provider terms for handling and retention
- Data is encrypted in transit (HTTPS/TLS)
5. Data Sharing and Processors
We do not sell your personal information. We may share data with:
- Service providers who assist in operating the Service (hosting, AI processing)
- Legal authorities when required by law
- Third parties in connection with a merger, acquisition, or sale of assets
For a full list of our third-party vendors, see our Subprocessors page.
Third-Party Data Processors:
| Processor | Purpose | Data | Location |
|---|---|---|---|
| OpenRouter | AI Processing | Post content, prompt context | USA |
| X (Twitter) API | Post Import & Metrics | OAuth tokens, post content, engagement data | USA |
| LinkedIn API | Publishing & Scheduling | OAuth tokens, post publishing | USA |
| BookmarksIQ | Bookmark Import | OAuth tokens, bookmark content | EU |
| Replicate | AI Image Generation | Image prompts, brand context | USA |
| DigitalOcean Spaces | Media Storage | User-uploaded and AI-generated images | USA/EU |
| VPS Hosting | Application Hosting | All user data | EU/USA |
6. Data Security
We implement appropriate technical and organizational measures to protect your personal information:
Encryption
- In Transit: All data is encrypted using TLS (HTTPS)
- Authentication Tokens: Securely stored with cryptographic best practices
- OAuth Tokens: Third-party access and refresh tokens (e.g. X/Twitter) are encrypted at rest using AES-256-GCM with server-side keys and are never exposed to client-side code
Access Controls
- Passwordless authentication via secure 6-digit email verification codes
- HttpOnly session cookies (not accessible to JavaScript)
- Rate limiting to prevent brute-force and abuse
7. Data Retention
We retain different types of data for different periods:
| Data Type | Retention | Basis |
|---|---|---|
| Active Account Data | While account is active | Service provision |
| Deleted Account Data | User-owned content deleted upon account deletion; personal data deleted or anonymized | Erasure obligation |
| Anonymous Aggregate Analytics | Retained indefinitely (non-identifiable) | Legitimate interest in product improvement |
| Billing Records | Retained with anonymized user reference as required by law | Legal/financial obligation |
| Connected Account Tokens | Deleted immediately when you disconnect the account or delete your PattrIQ account | Consent (revocable) |
| Session Cookies | Up to 7 days | Authentication |
8. Your Rights Under GDPR (EU Residents)
If you are located in the European Union, you have the following rights under the General Data Protection Regulation (GDPR):
Right to Access (Article 15)
You can export all your personal data at any time from your Account page. The export includes your profile, brand profiles, campaigns, analyses, ideas, plans, drafts, and billing summary in machine-readable JSON format.
Right to Rectification (Article 16)
You can edit your brand profile, campaigns, and imported data directly in the Service. For account detail corrections (such as email), contact us via the privacy contact form.
Right to Erasure (Article 17)
You can delete your account from your Account page. When you delete your account, we delete or anonymize your personal data and user-owned content. We may retain non-identifiable aggregate analytics, benchmark statistics, and product-improvement data that can no longer be linked to you as an individual. We do not keep deleted users' raw content in normal product storage. Billing records may be retained as required by law.
Right to Data Portability (Article 20)
You can export your data in machine-readable JSON format from your Account page. Alternatively, contact us at privacy@pattriq.com.
Right to Restrict Processing (Article 18)
You can restrict certain processing activities by contacting us at privacy@pattriq.com.
Right to Lodge a Complaint (Article 77)
You have the right to lodge a complaint with your local data protection authority. In the Netherlands, this is the Autoriteit Persoonsgegevens (AP).
9. Cookies
Essential Cookies
These cookies are required for the Service to function and cannot be disabled. Under the ePrivacy Directive (Article 5(3)), consent is not required for strictly necessary cookies.
| Cookie | Type | Purpose | Duration |
|---|---|---|---|
| spa_session | Strictly necessary | Maintains your authenticated session after login. This cookie is HttpOnly (not accessible to JavaScript) and is required for the application to recognise you as a signed-in user. | 7 days |
| spa_consent | Strictly necessary | Stores your cookie consent preferences so we can remember your choice without showing the banner on every visit. | 1 year |
Analytics Cookies (optional)
If you consent, we use Google Analytics 4 to collect anonymized usage data. These cookies are only set after you give explicit consent via our cookie banner. IP anonymization is enabled.
| Cookie | Type | Purpose | Duration |
|---|---|---|---|
| _ga | Analytics | Distinguishes unique users by assigning a randomly generated number as a client identifier. | 2 years |
| _ga_* | Analytics | Used by Google Analytics 4 to persist session state. | 2 years |
Cookie Consent Banner
When you first visit PattrIQ, a consent banner lets you Accept all cookies, Reject non-essential cookies, or Manage preferences individually. Your choice is recorded and stored in the spa_consent cookie. You can change your preferences at any time from your Account → Privacy & Data settings.
How to Control Cookies
You can control and delete cookies through your browser settings. Please note that disabling the session cookie will prevent you from signing in.
- Chrome: Settings → Privacy and security → Cookies and other site data
- Firefox: Settings → Privacy & Security → Cookies and Site Data
- Safari: Preferences → Privacy → Manage Website Data
- Edge: Settings → Cookies and site permissions → Manage and delete cookies and site data
Third-Party Cookies
The only third-party cookies on PattrIQ are the Google Analytics cookies listed above, and they are only loaded if you consent. We do not use advertising, marketing, or social media tracking cookies.
10. Third-Party Links
The Service may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.
11. Children's Privacy
The Service is not intended for users under 16 years of age, unless local law permits a lower minimum age with required parental or guardian consent. We do not knowingly collect personal information from children. If you believe we have collected such information, please contact us immediately at privacy@pattriq.com.
12. International Data Transfers
Your data may be transferred to and processed in countries other than your own. Where required, we implement safeguards intended to meet applicable data protection requirements, such as contractual protections and access controls.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or through the Service. The updated policy will be effective upon posting.
14. Contact Us
For questions about this Privacy Policy or our data practices, please contact us at:
- Email: privacy@pattriq.com