Legal
Privacy Policy
This policy describes what Antenna collects, why it collects it, who else processes it, and how you can get it back or have it deleted. It is written to describe the product as it actually behaves.
1Who we are
Antenna is a social media management tool operated by Antitropy LLC ("Antitropy", "we", "us"). The hosted service runs at app.antenna.sh; this marketing site is antenna.sh. For the hosted service, Antitropy LLC is the data controller.
You can reach us about anything in this policy at hello@antenna.sh.
2What this covers
This policy covers the hosted service at app.antenna.sh and this website.
Self-hosting is different. Antenna's core is open source (AGPL-3.0). If you run your own instance, your data stays on your infrastructure, we never receive it, and you — not Antitropy — are the controller. This policy does not apply to your instance.
3What we collect
Account information
- Your name and email address.
- A salted hash of your password. We never store your password itself.
- If you enable two-factor authentication, the secret needed to verify your codes.
- If you sign in with Google or Apple, the account identifier and email that provider returns. We never receive your password for those accounts.
- Session records so you can review and revoke active sessions, including approximate connection metadata such as IP address and browser user agent.
Content you create
- Workspaces, brands, and the members you invite.
- Posts, drafts, captions, threads, polls, comments you send, scheduling times and approval state.
- Media you upload — images, video, and the clips produced by the video slicing engine — along with the provenance we record for each asset (where it came from, and which generator and prompt produced it, when you tell us).
- Reports, templates, strategy documents, automation rules and the settings for each brand.
Sites and analytics you connect
- If you point a brand at your own website, we fetch its public pages to build the brand profile and to run the SEO and AI-visibility checks you asked for.
- If you connect Google Analytics or Google Search Console, we read the metrics for the properties you select. We never write to them.
- If you connect a WordPress site, we create drafts on it using the application password you supply.
Billing
Payments are processed by Stripe. We never see or store your card number. We keep your plan, subscription status, billing period, and the customer and subscription identifiers Stripe issues, so we know what your workspace is entitled to.
Technical and usage data
- Server and application logs, including error diagnostics, needed to run and debug the service.
- Usage counters we meter against your plan: connected channels, video source-minutes processed, AI calls made, and storage used.
4Data from connected networks
When you connect a social account — Facebook, Instagram, Threads, LinkedIn, X, TikTok, YouTube, Pinterest, Bluesky or Mastodon — you authorise Antenna to act on that account on your behalf. We then receive and store:
| What | Why we hold it |
|---|---|
| Access and refresh tokens | To publish, read and reply on your behalf. Encrypted at rest. |
| Account identity — id, handle, display name, avatar | So you can tell your connected channels apart in the interface. |
| Posts published through Antenna, and their platform ids | To show status, resume threads, and attach metrics to the right post. |
| Insights and metrics — impressions, reach, engagement, follower counts | To render the analytics and reports you asked for. |
| Comments, mentions and direct messages | Only where you enable the unified inbox, so you can read and reply from Antenna. |
Platform data is used only to provide the features you asked for. Specifically, we do not:
- sell it, rent it, or share it with data brokers;
- use it for advertising, ad targeting, or to build advertising profiles;
- use it to train machine-learning models — ours or anyone else's;
- use it for any purpose beyond operating Antenna for you.
Our handling of data obtained from each platform also follows that platform's own developer terms and policies. Disconnecting a channel deletes its stored tokens; see Data deletion.
5How we use it
- To run the service — publish your posts at the times you set, sync metrics, deliver your inbox, slice your video, and generate your reports.
- To secure accounts — authenticate you, verify second factors, show you your sessions, and detect abuse.
- To bill correctly — meter usage against your plan's limits.
- To support you — investigate problems you report to us.
- To comply with law — where we are legally required to.
We do not sell personal data, and we do not use your content or your audience's data for advertising.
6AI features
Antenna's AI features — drafting and rewriting, strategy documents, Ask CMO, AI search visibility, and transcription — run on a key you supply in Settings. Nothing is sent to a model provider unless you have configured a key and used a feature that calls one; without a key those features tell you they are unavailable rather than guessing.
When you do use them, the relevant content — the text you are working on, or the audio being transcribed — is sent to the provider whose key you configured, under your account with that provider. Antenna does not train models on your content, and does not send your content to any model provider for any purpose you did not initiate.
7Who else processes it
We keep the list short on purpose. These are the only processors involved in running the hosted service:
| Processor | What for | Data involved |
|---|---|---|
| Google Cloud Platform | Hosting the application and database (United States) | All service data |
| Cloudflare | DNS, CDN, and encrypted off-site backups | Site traffic; database backups |
| Stripe | Payments and subscription management | Billing details and payment data — handled by Stripe, not by us |
| The networks you connect | Publishing, metrics and messages | Only what that connection requires |
| Model providers you configure | AI features, using your key | Only the content you submit to that feature |
| Google (optional) | Sign-in with Google; Analytics and Search Console when you connect them | Your account identifier; the metrics you select |
We may also disclose data if the law requires it, or to protect our rights or the safety of others. If Antitropy is ever acquired or merged, data may transfer as part of that transaction; we will say so before it takes effect.
8How it is protected
- In transit — everything is served over HTTPS.
- Channel tokens — access and refresh tokens for connected networks are encrypted at rest with AES-256-GCM. The application refuses to start without its encryption key configured.
- Passwords — stored only as a salted hash, never in readable form.
- Two-factor authentication — available on every account, with active sessions listed and individually revocable.
- Isolation — every request is scoped to your workspace, and brands are private by default: a member sees a brand only if they have been granted access to that brand. This is enforced on the server, not in the interface.
- Backups — encrypted and stored off-site.
No system is perfectly secure. If we discover a breach affecting your personal data, we will notify affected users and any regulator we are required to notify, without undue delay.
9How long we keep it
- Account and content — for as long as your account exists. Delete your account and it is removed from live systems immediately.
- Channel tokens — until you disconnect the channel, delete the brand, or delete your account, whichever comes first.
- Backups — deleted data can persist in encrypted backups until they rotate out, which takes up to 90 days.
- Billing records — kept as long as tax and accounting law requires.
- Logs — kept for a limited operational period and then discarded.
10Your rights
Wherever you live, you can ask us to:
- Access a copy of the data we hold about you.
- Export your content — Antenna exports posts, brands, analytics and reports from inside the product, whenever you want, without asking us.
- Correct anything inaccurate.
- Delete your account and its data — see Data deletion.
- Object to or restrict processing, and withdraw consent for anything you consented to.
If you are in the EEA or UK, our lawful bases are performance of our contract with you (running the service), legitimate interests (securing and improving it), consent (where you connect an account or enable an AI feature), and legal obligation. You have the right to complain to your local supervisory authority.
If you are in California, we do not sell or share personal information as those terms are defined by the CCPA, and we will never discriminate against you for exercising a privacy right.
Exercising any of these rights is free. Write to hello@antenna.sh and we will respond within 30 days.
11Deleting your data
You can delete your account yourself, at any time, from Settings → Account → Profile in the app. It takes effect immediately and costs nothing. Full step-by-step instructions — including how to remove a single connected channel instead of the whole account, and how to revoke Antenna's access from the network's own side — are on the data deletion page.
12Cookies
The app sets a session cookie so you stay signed in, and remembers your interface preferences such as light or dark mode. That is all — there are no advertising cookies and no cross-site tracking.
This marketing site loads no third-party scripts at all: no analytics, no tag manager, no advertising pixel, no session recorder. Nothing here follows you.
13Where it is stored
The hosted service runs in the United States. If you use it from outside the United States, your data is transferred there and processed under this policy. Where transfers from the EEA or UK require a legal mechanism, we rely on the European Commission's Standard Contractual Clauses with our processors.
14Children
Antenna is a tool for businesses and is not directed at children. It is not for anyone under 18, and we do not knowingly collect data from them. If you believe a child has given us data, write to us and we will delete it.
15Changes
We will update this policy as the product changes. The version and date at the top always reflect the current text. If a change materially affects your rights, we will tell account holders by email before it takes effect.
16Contact
Antitropy LLC — hello@antenna.sh
For deletion requests, the fastest route is the in-app path described on the data deletion page.