Privacy
This is draft copy prepared for Paul. It is not legal advice, and Paul has not commissioned a paid legal review of it yet.
What we collect
Account data. When you sign in, we collect your email address. We use magic links, not passwords, so there is no password to store. Your session stays active for 30 days.
LinkedIn connection. When you connect LinkedIn, we store an access token that lets Candent post to your LinkedIn feed on your behalf. The token is encrypted at rest. We use it only to publish the posts you schedule. LinkedIn issues the token for 60 days; after that you reconnect. If your token stops working, we mark the connection as needing reconnection rather than deleting your history. If you ask us to delete your account, we delete the token, as LinkedIn's rules require.
Tell-check. When you enter your email on the tell-check page, we store it right away in an unconfirmed state and send you a confirmation link. We don't send you anything further, or treat your address as subscribed, until you click it. The text you paste in to be checked is never stored. It is scored and the result is returned to you; nothing about the content of that text is written to a database, a log, or an error report. This guarantee covers the text you submit to be checked. It does not extend to other parts of the product, such as the tell-check email capture described above, which does store your email address on purpose.
Your writing, over time. As you edit drafts Candent writes for you, we record those edits so future drafts can better match how you actually write and talk. We collect this as a by-product of using the product, not as something you fill out directly. As of this draft, that learning does not yet feed back into every draft you see. We are describing the intent here, not claiming every flow already uses it.
Why we collect it
To run the product: to sign you in, to post on your behalf, to send the tell-check result you asked for, and to make your drafts sound more like you over time. We do not collect anything beyond what each of those needs.
Who receives it
LinkedIn receives the posts you choose to publish, because that is what publishing means. Stripe receives your billing details when you subscribe; we do not store your card details ourselves. We do not sell your data, and we do not share it with anyone else.
Access and correction
You can ask us to see what we hold on you, correct it, or delete it, by contacting support@candent.app. Self-serve account deletion is not built into the product yet; until it is, a deletion request goes through that address and we action it by hand.
Questions
Questions or requests: support@candent.app