Privacy Policy

Effective 17 August 2026

Remux turns your website into short-form social posts. This policy explains what we collect to do that, who else touches it, and how to get it back or get it deleted. It is written to be read, not to be survived.

Remux is operated from San Francisco, California. Questions about anything here go to hello@getremux.com.

What we collect

  • Your account. Email address and name, handled by our authentication provider when you sign up. If you sign up with Google, that name and email come from your Google account — see the Google section below.
  • The website you paste. We fetch that public page and derive a brand profile from it — your positioning, tone, and the words you use. We store the profile and the source URL.
  • What you make. Generated posts, your edits, and which ones you kept or rejected.
  • Connected social accounts. See the TikTok, Instagram, and YouTube sections below.
  • Billing. Plan, subscription status, and usage counts. Card details go straight to our payment processor — we never see or store them.
  • Basic technical data. Logs and error reports produced by running the service.
  • Analytics. We use Google Analytics 4 to count visits to the marketing pages and see which of them lead to a sign-up. Google Signals and ad personalization are off everywhere. In the EEA, the UK and Switzerland it runs in consent mode with storage denied, so no analytics cookie is set there unless you grant one.

How we use it

To generate posts in your voice, to show you your library, to enforce your plan's limits, to send content to a social account you connected, and to fix things when they break. That is the entire list. We do not build advertising profiles and we do not sell your personal information.

Signing in with Google

Using “Continue with Google” is optional — email and password gets you the same account. If you do use it, this is the whole of what happens to the Google data we receive. Remux's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

  • What we receive. Three scopes: openid, email, and profile. From them we get your Google account identifier, email address, name, and profile picture. Nothing else. We do not request and cannot read your Gmail, Drive, Contacts, Calendar, Photos, or any other Google service.
  • What we use it for. Creating your account, signing you back in, showing your name and picture in the app, and emailing you about your account and billing. That is the entire list. We do not use Google user data for advertising, we do not sell it, and we never use it — or any content you create — to train AI models, ours or anyone else's.
  • Who we share, transfer, or disclose it to. Only these three processors, each acting on our instructions and only for the purpose named: Clerk, our authentication provider, which receives and stores your Google identifier, email, name, and picture in order to run sign-in and billing; Supabase, our database provider, which stores your account identifier so your brands and posts can be linked to you; and Vercel, our host, which processes the requests carrying that data and keeps short-lived request logs. No one else receives it. Google user data is never sent to Anthropic, fal.ai, Unsplash, Pexels, TikTok, or Google Analytics, and is never shared with advertising networks, data brokers, or any other third party.
  • Beyond that, only when the law forces it. We would disclose Google user data if we were legally required to by valid process, or to a successor entity in a merger or acquisition — in which case the data stays subject to this policy and we will notify account holders by email before it transfers.
  • Getting rid of it. Revoke Remux's access at any time from myaccount.google.com/permissions, or email hello@getremux.com to delete your account outright. Deleting your account erases the Google profile data we hold within 30 days, at Clerk and at Supabase both.

Your TikTok account

Connecting TikTok is optional and everything about it is opt-in.

  • You authorize through TikTok's own OAuth screen. We never see or store your TikTok password.
  • We request three scopes: user.info.basic (so we can show you which account will receive your content), video.upload, and video.publish.
  • We store the access and refresh tokens TikTok issues, your display name, and your avatar. Tokens are encrypted with AES-256-GCM before they are written to our database, so a database dump yields ciphertext rather than usable accounts.
  • Content is delivered to your TikTok inbox for you to review and publish from the TikTok app. Nothing is posted without a post you approved in Remux first.
  • You can revoke Remux's access at any time. Disconnect on the Connections page inside the app: that deletes our copy of your tokens and asks TikTok to revoke the grant. You can also revoke from TikTok's own app settings, or email hello@getremux.com and we will do it for you. Revoking stops all scheduled delivery.

Your Instagram account

Connecting Instagram is optional and everything about it is opt-in.

  • You authorize through Instagram's own login screen. We never see or store your Instagram password.
  • We request two permissions: instagram_business_basic (so we can show you which account will receive your content — its username and avatar on the Connections page) and instagram_business_content_publish (so we can publish the Reels and photo posts you schedule).
  • We store the access token Instagram issues, your username, and your account identifier. Tokens are encrypted with AES-256-GCM before they are written to our database, so a database dump yields ciphertext rather than usable accounts.
  • Posts you schedule in Remux are published to your Instagram profile at the time you chose. Nothing is posted without a post you approved and scheduled in Remux first.
  • You can revoke Remux's access at any time, and revoking deletes the Instagram data we hold. Disconnect on the Connections page inside the app: that deletes our copy of your token, your username, and your account identifier. You can also remove Remux from Instagram's own settings (Settings → Website permissions → Apps and websites), or email hello@getremux.com and we will delete it for you. Revoking stops all scheduled publishing.

Your YouTube channel

Connecting YouTube is optional and everything about it is opt-in. Remux uses YouTube API Services to do it, so by connecting a channel you also agree to the YouTube Terms of Service, and Google's handling of that authorization is described in the Google Privacy Policy.

  • You authorize through Google's own consent screen. We never see or store your Google password.
  • We request two scopes: youtube.upload (so we can upload the videos you schedule to your channel) and youtube.readonly (so we can show you which channel will receive your content — its name and avatar on the Connections page).
  • We store the access and refresh tokens Google issues, your channel's name, handle, and identifier. Tokens are encrypted with AES-256-GCM before they are written to our database, so a database dump yields ciphertext rather than usable accounts.
  • Videos you schedule in Remux are uploaded to your channel at the time you chose. Nothing is uploaded without a post you approved and scheduled in Remux first. Until YouTube's review of Remux completes, uploads arrive as Private and you publish them from YouTube Studio.
  • You can revoke Remux's access at any time, and revoking deletes the YouTube data we hold. Disconnect on the Connections page inside the app: that deletes our copy of your tokens and asks Google to revoke the grant. You can also revoke it yourself from Google's security settings, or email hello@getremux.com and we will do it for you. Revoking stops all scheduled uploads.

Who processes your data

We use these providers to run Remux. They only ever see what they need for their part of the job.

  • Clerk — accounts, sign-in, and subscription billing.
  • Supabase — the database and file storage holding your brand profile and posts.
  • Vercel — hosting and request logs.
  • Anthropic and fal.ai — the AI models that write and render your posts.
  • Unsplash and Pexels — stock footage and imagery used inside generated posts.
  • Google — only if you choose to sign in with Google, and only as described in the Google section above.
  • TikTok — only if you connect an account.
  • Instagram (Meta) — only if you connect an account.
  • YouTube (Google) — only if you connect a channel, via YouTube API Services as described in the YouTube section above.
  • Google Analytics — anonymous, aggregate traffic measurement for our public pages: which page was viewed, roughly where from, on what kind of device. It never receives your name, your email, your Google account identifier, your brand profile, or anything you create in Remux.

We do not use your content to train our own models, and we do not sell or rent your data to anyone.

How we protect it

Some of what we hold is sensitive — the credentials that reach your social accounts, and the personal data behind your sign-in. These are the specific mechanisms protecting it, not a promise to be careful.

  • Encrypted in transit. Every connection to Remux and to each of our processors runs over TLS 1.2 or better. HTTP requests are redirected to HTTPS; there is no unencrypted path into the service.
  • Encrypted at rest. Our database, file storage, and backups are encrypted at rest with AES-256 by the providers listed above.
  • Access tokens encrypted twice over. Tokens for connected social accounts are sealed with AES-256-GCM by the application before they are written to the database, under a key held only in our server environment and never in the database. A stolen database credential or a leaked backup therefore yields ciphertext, not access to your accounts.
  • No passwords here. We never receive, see, or store a password — Google's, TikTok's, and Instagram's consent screens handle their own, and our authentication provider handles the rest. There is no password for us to lose.
  • Row-level isolation. Every table holding customer data has row-level security enabled in the database itself, with policies that scope each row to the brands you are a member of. Isolation is enforced by the database on every query, not by application code remembering to filter.
  • Least privilege. Privileged database keys exist only server-side and are never shipped to the browser. Internal admin surfaces are gated to an explicit allowlist of named accounts. Browser uploads use short-expiry, single-object signed URLs rather than any standing write credential.
  • Contained by design. Sensitive data is not copied into logs, not exported in bulk, and not sent to our AI or media providers — those receive your brand profile and the content being generated, never your credentials or your Google profile.
  • Breach notification. If a breach affects your personal data, we will email you and the relevant regulators without undue delay and within 72 hours of becoming aware of it.

How long we keep it

Your brand profile and posts stay until you delete them or close your account. Posts you reject are deleted. Logs roll off within 30 days. When you ask us to delete your account, we remove your data — including any stored social tokens — within 30 days, except where we are legally required to keep billing records.

Your choices

Email hello@getremux.com to get a copy of your data, correct it, disconnect a social account, or delete your account entirely. We answer within 30 days. If you are in California, the EU, or the UK, you have these rights under your local law and we honour them for everyone regardless of where you live. You will never be charged or degraded for exercising them.

Cookies

Remux sets the session cookies required to keep you signed in, and one cookie that remembers which brand you were last looking at.

We also use Google Analytics, which sets its own cookies to count visits and tell a returning visitor from a new one. It reports aggregate traffic to us — pages, referrers, device types, approximate region derived from a truncated IP address. We have not turned on Google's advertising features or its cross-device tracking, we do not send it any account or content data, and we do not use it to build a profile of you. You can opt out for every site at once with Google's browser add-on.

We run no advertising cookies and no cross-site ad tracking.

Children

Remux is for people 18 and over. We do not knowingly collect data from children. If you believe a minor has an account, tell us and we will remove it.

Changes

If we change this policy in a way that matters, we will update the effective date above and email account holders before it takes effect.

Contact

hello@getremux.com. This policy is governed by the laws of the State of California.