Privacy policy
Last updated: 21 September 2026
Data controller
Publiqo Media, S.L., tax number B93820306, registered at Avenida de les Marines 36, bloque C, escalera A, planta 2, puerta 3, 08195 Sant Cugat del Vallès (Barcelona), Spain, and filed with the Registro Mercantil de Barcelona, is the controller of the personal data described in this policy. GoFeed is the trading name it provides the service under.
You can write to us at support@gofeedapp.com about anything to do with your data, including exercising the rights set out below.
Two roles are worth telling apart, because they are not the same. For the data of whoever contracts the service and of the people who access their workspace, GoFeed is the controller. For the content a workspace uploads to the platform and the data of that workspace own clients, GoFeed is a processor: the workspace decides what goes in and what for, and we handle it on their instructions.
Data we process
Account data: your name, your email address, the language you choose and, if you upload one, your photo. Passwords are stored as a hash, so nobody at GoFeed can read yours.
If you sign in with Google, we receive from Google your account identifier, your name, your email address and your profile photo. Your Google password never reaches us.
Billing data: the company name, tax number and address you give us, along with your subscription and payment history. Your card details are handled by Stripe directly and are not stored on our servers.
Workspace content: the posts, images, videos, documents, tasks, comments and messages you and your team create or upload, including data about your own clients when you choose to put it there.
Data from the social accounts you connect: profile identifiers, the access credentials the network hands us, and the metrics of your posts. We only reach what the permission you granted allows, and you can revoke it at any time from the network itself or from the application.
Technical data needed to run and protect the service: IP address, browser type and account activity logs.
Audience measurement data, on the marketing site only: we use Google Analytics and PostHog to see how many people arrive, where from, and which pages they read. Their cookies are set when you visit the site. None of them is needed for it to work and you can block or delete them whenever you want: every cookie, and how to do that, is listed in our cookie policy, at /en/legal/cookies.
Product usage data, inside the application: which features you use, when, and from which workspace. PostHog collects it, tied to your account, and it never includes the content: not the text of a post, not a file, not a message. It tells us which parts of the product are used and which are not, and lets us test a change on some accounts before rolling it out to all of them.
The cookies we set in the application are the one for that measurement and three strictly necessary ones: the one that keeps you signed in, the one that remembers the language you picked and the one that remembers the last workspace you opened.
On the marketing site we also use advertising cookies, from Google Ads, to tell which adverts bring visits that go on to register. We do not sell this data, we build no commercial profiles, and we take no automated decisions producing legal effects for you.
Purposes of processing
Providing the service you contracted: creating and maintaining your account and workspace, letting your team and your clients in with the role each of them has, and keeping the content you upload.
Publishing to the social networks you have connected, at the time you schedule, and returning the metrics for those posts.
Handling sign-up, payments, renewals and invoicing.
Answering your support requests and telling you what affects your account: email verification, invitations, billing notices, changes to the service.
Keeping the platform secure, preventing abuse and fraud, and diagnosing faults.
Improving the product: knowing which features are used and which are not, and testing a change on a sample of accounts before rolling it out to all of them, by comparing how each group uses it.
Attributing advertising: knowing which campaigns bring accounts that go on to start a trial or pay. To do that, when an account is created, a trial starts or the first invoice is paid, the application reports that fact to Google Analytics, and through it to Google Ads, with the measurement identifier the marketing site cookie assigned to your visit and, if you arrived from an advert, with the identifier of that click.
Meeting our legal obligations, in particular accounting and tax ones.
Legal basis
Performance of the contract (article 6.1.b GDPR) covers everything needed to provide the service: your account, your workspace, the content you upload, publishing to the networks you connect and collecting the subscription.
Compliance with legal obligations (article 6.1.c) covers keeping accounting and tax records and responding to requests from competent authorities.
Our legitimate interest (article 6.1.f) covers platform security, fraud and abuse prevention, and fault diagnosis. We have weighed that interest against your rights and it is limited to what the service needs in order to work and not to be used against other people.
The same legitimate interest (article 6.1.f) covers measuring how the product is used and testing changes on a sample of accounts. Weighing it against your rights, what tips the balance is what is not done: we process usage data and never the content, we build no profiles for advertising, and none of it is passed to anyone other than the provider that hosts it. You can object to this processing by writing to us at the address below.
Your consent (article 6.1.a) covers connecting third party accounts, such as your social networks, Google Drive or Google Calendar. You give it when you authorise the connection and you can withdraw it whenever you want, without affecting the lawfulness of processing before that.
Legitimate interest (article 6.1.f) also covers audience measurement on the marketing site, advertising attribution, and the reporting to Google of the three facts described under the purposes above. Our interest is knowing which campaigns bring customers so we do not spend the budget on the ones that do not; weighing it against your rights, what counts is that no content is processed, that no profile producing effects on you is built, and that what travels is a click and measurement identifier, never your name or your email address. You can object at any time and free of charge: the cookie policy explains how to block those cookies from your browser and how to write to us so we stop processing them.
Recipients and processors
We do not sell your data and we do not pass it to third parties for commercial purposes. We share it only with the providers we need in order to run the service, who act as processors, under a signed agreement and only on our instructions.
Neon: hosts the database your workspace lives in.
Cloudflare: stores the files you upload, through its R2 service.
Vercel: hosts and runs the application. Our execution region is Frankfurt, in the European Union.
Stripe: handles payments, subscriptions and invoicing. It is also the party that processes your card details, which never reach our servers.
Resend: sends the service email: verifications, invitations, alerts and notifications.
Zernio: publishes to the networks you connect and retrieves the metrics for those posts.
Google: identifies you when you choose to sign in with Google, gives access to Drive and Calendar only if you connect them, and measures the audience of the marketing site through Google Analytics. It also receives, from the application itself, three facts: that an account was created, that a trial started, and that the first invoice of a subscription was paid. We report them to Google Analytics, and from there they pass to Google Ads, together with the measurement identifier the marketing site cookie assigned to your visit, so we can tell which campaigns bring accounts and stop spending on the ones that do not; with the invoice travels the amount paid, net of tax. Your name, your email address and your content never travel. The provider is Google Ireland Limited.
PostHog: measures how the product is used inside the application: which features are used, when, and from which workspace, never the content. On the marketing site it also measures the audience. The provider is PostHog Inc., and the data is hosted in its European cloud, in Frankfurt.
On top of that, when you publish to a social network, the content you publish and the data attached to it reach that network and become subject to its own terms and privacy policy, over which we have no control.
We will also disclose data to public authorities where we are legally required to.
International transfers
The application runs in the European Union, specifically in Frankfurt. The product usage data PostHog processes is also hosted in Frankfurt, in its European cloud.
Some of the providers listed above are United States companies or process data outside the European Economic Area. Where that happens, the transfer relies on the safeguards set out in chapter V of the GDPR: the standard contractual clauses approved by the European Commission and, where the provider is certified, the EU to US Data Privacy Framework.
If you want to know the specific safeguards that apply to a given provider, write to us at support@gofeedapp.com and we will send them to you.
Retention
We keep your account data and your workspace content for as long as the relationship lasts. When you ask us to close the account, by writing to support@gofeedapp.com, we delete or block that data within a reasonable period of your request, other than what we are legally required to keep.
Accounting and tax records are kept for the periods required by commercial and tax law, which oblige us to hold the documentation for several years from the close of the relevant financial year.
Files you send to the bin are permanently deleted thirty days later, and you can restore them at any point during those thirty days.
If a workspace is locked, either because the trial ended without a subscription or because payment is still outstanding after the grace period, the files stored in its Drive, bin included, and in its post media library are permanently deleted once fourteen days of continuous lock have passed, after notice by email. The rest of the workspace content is kept.
Operational series, such as historical post metrics, activity logs and alerts, are kept for as long as the purpose behind them requires and are pruned according to the maximum windows we have defined, ranging from a few days for auxiliary counters up to thirteen months for metrics, a period that allows one stretch of time to be compared with the same stretch a year earlier.
Your rights
You can exercise the rights of access, rectification, erasure, restriction of processing, objection and data portability, and you can withdraw any consent you have given, at any time and free of charge.
To exercise them, write to us at support@gofeedapp.com saying which right you want to exercise. We may ask you to prove your identity if we have reasonable doubts about who is asking. We will answer within one month of receiving your request, extendable by two further months if the request is complex, in which case we will tell you.
If the data you want corrected or erased sits inside a customer workspace, it is that workspace that decides about it, as controller. In that case we will pass your request on to whoever is responsible and let you know.
Security measures
All communication with the platform travels encrypted over TLS. Passwords are stored as a hash and cannot be recovered.
Access to information is separated by workspace and by role within it: each person sees only what their role allows, and the data of one workspace is not reachable from another.
We apply technical and organisational measures appropriate to the risk and review them periodically. If a security breach occurred that posed a high risk to your rights, we would tell you and notify the supervisory authority within the periods the law sets.
Complaints to the supervisory authority
If you believe the processing of your data does not comply with the law, you can lodge a complaint with the Agencia Española de Protección de Datos, at C/ Jorge Juan 6, 28001 Madrid, or through its website at www.aepd.es.
We would be grateful for the chance to sort it out first, at support@gofeedapp.com. That is not a requirement and you give up nothing by going straight to the authority.
Changes to this policy
We may update this policy when the service changes, when the providers we use change, or when the applicable law changes. The date of the last update is shown at the top of this page.
If a change materially affects how we handle your data, we will tell you by email or through a visible notice in the application before it takes effect.
Contact
For any question about this policy or about how we handle your data, write to us at support@gofeedapp.com or to Publiqo Media, S.L., Avenida de les Marines 36, bloque C, escalera A, planta 2, puerta 3, 08195 Sant Cugat del Vallès (Barcelona), Spain.