Vector — a CAI Systems product

PRIVACY POLICY

Last updated: 6 September 2026

This policy covers Vector, a product of CAI Systems LLC, and describes what Vector processes when a social account is connected to it. It describes what Vector actually does — not everything the platform APIs would permit.

1What Vector processes

When you connect a social account, Vector processes:

Account identityThe platform's own identifier for the connected account or Page, and its display name or handle. Vector keeps the platform's stable ID rather than the handle alone, because handles can be renamed.
Authorization metadataWhich platform was connected, when, the permissions (scopes) granted, and whether the authorization is still valid. Vector records the scopes it was granted so it can refuse a task the account holder did not permit.
Access credentialsAccess and refresh tokens issued by the platform. These are held in a secured credential store outside the application database; the database holds only a reference to them, never the token itself.
Content and its metadataThe media you put through Vector and the information that goes with it — title, description, tags, visibility setting, and whether it contains synthetic media.
Publication recordsWhat was submitted, to which account, when, the outcome, and the platform's own ID for the resulting post or video.
Performance analyticsFigures the platform reports for the connected account's own content — for example views and engagement counts.
Operational logsRecords of what the system did and any errors, kept so faults can be diagnosed. Credential values are stripped from log records automatically before they are written.

What Vector does not do: it does not read other people’s private data, does not collect the contents of your inbox or messages, does not scrape platforms, and does not request revenue or monetisation data.

2This website

The pages under caisystems.dev/vector are informational and do not require an account or a login. They do not set advertising or tracking cookies.

Like any website, requests to caisystems.dev are handled by our hosting provider, which processes ordinary technical request information such as IP address, user agent and timestamps in order to serve the site and protect it from abuse. If you email us or use the CAI Systems contact form, we process what you send in order to reply.

3Why Vector processes it

AuthenticateTo confirm which account is connected and that the authorization is still valid.
PublishTo submit the content you asked Vector to publish, to the account you authorized.
ReconcileTo find out what actually happened to a submission, and to avoid publishing the same thing twice.
AnalyticsTo retrieve performance figures for the connected account's own content.
Operate and secureTo diagnose faults, prevent abuse, and keep the service working.

Vector does not use connected-account data to build advertising profiles, and does not use it to train models.

4Who it is shared with

The platforms themselves. To publish or read analytics, Vector sends requests to the platform you connected — YouTube (Google), Instagram and Facebook (Meta), or TikTok. Their handling of that data is governed by their own privacy policies.

Service providers. We use infrastructure providers to host the website and run the service, and they process data on our behalf and under our instructions.

Legal. We may disclose information where the law requires it, or to establish or defend a legal claim.

We do not sell your data, and we do not share it with third parties for their own advertising.

5How long it is kept

Publication records and the analytics attached to them are kept for as long as the account remains connected, because they are the record of what was published and how it performed. Credentials are held only while the authorization is live: when an account is disconnected or its access is revoked, the stored credential reference stops resolving and is removed.

We have not set a fixed retention period for operational logs, and rather than state a number we have not committed to, we will say plainly that they are kept for as long as they are useful for diagnosing faults and then cleared. If you want data removed sooner, the Data Deletion process is how to ask.

6Security

Credentials are held in a secured store separate from the application database, which holds only a reference to them. Log records are stripped of credential-shaped values before they are written. Access to production systems is limited to people who need it. Traffic to this site and to the platform APIs is encrypted in transit.

No system is perfectly secure, and we do not claim otherwise. If we become aware of a breach affecting your data, we will act on it and notify where we are required to.

7Your controls

DisconnectAsk us to disconnect an account. Vector stops acting on it and its stored credential is removed.
Revoke at the platformRemove Vector's access in the platform's own settings — Google Account permissions, Meta business or app settings, or TikTok's connected-apps settings. This works whether or not you contact us, and it takes effect immediately.
Access and correctionAsk what we hold about a connected account, and ask us to correct it if it is wrong.
DeletionAsk us to delete what Vector holds. See the Data Deletion page for exactly what that covers.

Depending on where you live you may have further rights over your personal data. Tell us what you want and we will do what applies.

8Changes to this policy

If this policy changes, the date at the top of the page changes with it. Where a change materially affects someone whose account is connected and we hold a way to reach them, we will make reasonable efforts to tell them.

9Contact

Privacy questions and requests: support@caisystems.dev, or the CAI Systems contact page.