Privacy policy
Last updated 21 September 2026
Lyra is a tool agencies use to run social media accounts on behalf of their clients. That means we handle two different kinds of information: data about the people who use Lyra, and data belonging to the social accounts they connect. This page says exactly what we hold, why, and for how long.
Who we are
Lyra is operated by ניקולאי בטורין ורומן ופרינסקי, a partnership trading as כוכבים ברשת and registered in Israel as an עוסק מורשה (VAT-registered business), number 558625729.
2 Yehadut Sfarad St, Apt. 26, Ashkelon 7868030, Israel (יהדות ספרד 2, דירה 26, אשקלון 7868030). For anything on this page, write to [email protected].
For the accounts an agency connects, the agency is the controller and we act on their instructions. For the agency's own users — the people who sign in to Lyra — we are the controller.
What we store
People who sign in
- Email address, name, and profile picture if you have one.
- A password, stored only as a scrypt hash with a per-account salt. We cannot read it and cannot recover it.
- If you sign in with Google, the Google account identifier — never your Google password.
- When you last signed in.
Connected social accounts
When you connect a platform account, that platform gives us an access token. We never see or ask for your platform password. We store:
- The account's public identifiers: its platform id, handle, display name and avatar.
- The access and refresh tokens, and the permissions they carry.
- Whether the connection is still working.
You can disconnect any account at any time — from inside Lyra, from the client portal link if you were sent one, or from the platform's own settings. Disconnecting clears the tokens immediately.
Content you publish
- Media you upload or link, its captions and titles, and when it is scheduled.
- What each platform did with it — succeeded, failed, and the link to the live post.
Messages and comments
Where an agency uses the inbox, we store direct messages and comments belonging to the connected accounts so the inbox can show a conversation rather than a single line. That includes the message text, the sender's platform name and id, and when it was sent.
This is the most sensitive data Lyra holds, and it is the reason for the retention limits below rather than keeping everything.
Numbers
- Reach, views, likes, comments and shares, as the platform reports them.
- Advertising spend and campaign settings, for agencies that connect an ad account. We never receive card or bank details — those stay with the platform.
Client portal links
A client portal link records how often it was opened, roughly when, and whether the visitor was on a phone, tablet or desktop. To count people rather than requests we store a one-way keyed hash of the visitor's address and browser, salted separately for every link. It cannot be reversed into an address and produces unrelated values for the same person on two different links, so it cannot be used to follow anybody around.
How long we keep it
| What | Kept for |
|---|---|
| Direct messages | 60 days, then deleted automatically |
| Comments | 30 days in the inbox; a dismissed comment is forgotten after 7 |
| Client portal visit records | 180 days |
| Published posts, media and results | While the workspace exists |
| Account and sign-in details | While the account exists; deleted on request |
Who else sees it
We do not sell data and we do not use it for advertising. It reaches only:
- The platforms themselves — Meta, Google, TikTok — when we publish on your behalf or read your figures, and only what that action requires.
- Our hosting and storage providers, who store it for us and do not use it.
- An AI provider, if a workspace turns on automatic replies. Only the single incoming message being judged is sent, using the workspace's own API key. It is off by default.
Google user data
When you connect a Google account, Google asks you to grant specific permissions and then gives us a token. What we do with what that token reaches is limited to the feature you connected it for:
- Signing in —
openid,email,profile. To recognise you and show your name. Nothing else. - YouTube —
youtube.readonly,youtube.upload,youtube.force-ssl,yt-analytics.readonly. To list the channel's videos, upload the ones you schedule, read and answer their comments in the inbox, and show you their figures. - Google Ads —
adwords. To read an ad account's campaigns and what they cost, and to make the changes you ask for: pausing, budgets, schedules, and building campaigns. Google has no read-only advertising permission, so this one always carries both reading and changing.
Lyra's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell it, we do not use it for advertising, we do not use it to train models, and no person reads it except where you ask us to, where the law requires it, or to investigate a security incident.
Disconnecting a Google account inside Lyra clears its tokens immediately. You can also revoke our access yourself at myaccount.google.com/permissions, which stops it from our side too.
Where it is held, and who reaches it
The application and its database run on servers rented from Hetzner Online GmbH in Germany, and uploaded media is stored in Cloudflare R2 in its EU jurisdiction, so it stays in the European Union. The partnership operates from Israel and reaches that data from there; the European Commission has recognised Israel as providing an adequate level of data protection, so no additional transfer safeguards are required.
Your rights
You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Write to [email protected], or use the deletion page, which explains how to do it yourself and how to ask us. We answer within 30 days.
If you are in the EU or UK you also have the right to complain to your data protection authority. Because we hold data in the European Union and offer this service to people there, the GDPR applies to us in full regardless of where our company is registered.
Security
Traffic is encrypted in transit. Passwords are hashed and never recoverable. The access tokens for your connected accounts, and any API key you save, are encrypted at rest with AES-256-GCM — a copy of the database on its own does not yield a working credential. Every request is scoped to a single workspace, so one agency cannot reach another's data, and a client portal link reaches exactly one client's profile and nothing else.
Children
Lyra is a business tool and is not for anyone under 18. We do not knowingly hold data about children.
Changes
If this policy changes materially we will say so here and update the date at the top before the change takes effect.