Security, privacy, and data
How DataCue protects account access and data
DataCue uses platform OAuth, encrypted social tokens, role-based workspace access, secure account controls, and Stripe-hosted payment systems.
Social account authorization
For live integrations, users authorize DataCue through the social platform's OAuth flow. DataCue does not ask for or store social network passwords. Planning-only account records do not contain platform credentials.
Connected accounts can be disconnected in DataCue, and users can also revoke authorization through the social platform's own settings. DataCue requests the permissions required for supported actions such as publishing or analytics.
Encryption
OAuth token security
Tokens encrypted at rest. Social access and refresh tokens are encrypted before storage, kept separately from public social profile details, and are not displayed back in the browser.
Token encryption uses server-supplied keys and supports key rotation through multiple configured keys. Tokens are used for authorized platform actions including publishing, access refresh, supported history imports, and analytics synchronization.
Workspace permissions
Workspace access is role-based. Owners and administrators manage billing, team access, social account connections, and workspace settings. Member, approver, and viewer roles receive narrower permissions.
Workspaces can also limit a person's visibility to selected brands. Server-side workspace and brand access checks protect records rather than relying only on what the interface displays.
Account security
DataCue supports email verification, password reset controls, two-factor authentication, and recovery codes. Accounts with a confirmed second-factor method must complete that verification during sign-in.
Login, registration, password reset, and email actions are rate-limited. DataCue also expires inactive sessions and records security events for important account changes.
Payments
Subscription checkout, payment card collection, invoices, and billing management are handled through Stripe's hosted systems. DataCue stores the customer, subscription, status, and entitlement identifiers needed to control workspace access; Stripe handles card details.
Infrastructure
DataCue's production web application and database are hosted on Render. Production settings enforce HTTPS, secure session and CSRF cookies, HSTS, clickjacking protection, and same-site cookie controls.
Application credentials and encryption keys are supplied through protected environment configuration rather than being embedded in the application source.
For hosting-region or vendor-review questions, contact support@datacue.social.
Data deletion
Users can request account deletion from their account settings. A seven-day grace period allows an accidental request to be canceled before processing.
When deletion is processed, solo-workspace subscriptions are canceled and connected social credentials are revoked. Some records may remain when needed for security, legal, billing, abuse prevention, or shared-workspace continuity.
View data deletion instructionsReporting a concern
Report a security issue or ask about privacy, platform authorization, account access, or data handling by contacting DataCue support.
support@datacue.social