APEX legal
Privacy Policy
Last updated: August 14, 2026
Who we are
APEX Automation and Technology Solutions LLC operates APEX, a client workspace platform for content operations, media uploads, social media planning, and social analytics.
Data we collect
- Account information such as name, email address, workspace membership, role, and sign-in activity.
- Workspace information such as client name, workspace preferences, brand settings, uploaded media, captions, content notes, calendar items, and approval status.
- Support information submitted through bug reports, suggestions, restyling requests, or direct support communication.
- When a user connects a social platform, authorization data and approved platform data needed to sync account, content, and performance information.
- Technical information such as basic logs, error reports, device/browser information, and security events used to keep the service reliable.
Meta, Instagram, and Facebook data
If a user connects Facebook, APEX requests access to list the Facebook Pages that person manages and to read the selected Page's profile details and Page-owned posts. If a user connects Instagram, APEX requests access to find the professional account linked to an eligible Facebook Page and read that professional account's profile details and owned media. The selected account and content appear only in the authorized private workspace.
APEX does not ask users for their Facebook or Instagram password. Users authorize access through Meta's login and permission screen. The current connector is read-only: APEX does not publish, edit, delete, message, run advertisements, or access unrelated personal accounts through these permissions.
APEX does not use connected Meta data for advertising, audience enrichment, lead generation, individual marketing profiles, resale, or generalized artificial-intelligence model training.
TikTok data
If a user connects TikTok, APEX reads only the authorized account's basic profile information, such as display name and avatar, plus that account's public video list, video metadata, source links, thumbnails, and public counts made available by TikTok's Display API. APEX does not ask for the user's TikTok password.
The current TikTok connector is read-only. It does not upload or publish videos, read private content or messages, manage advertisements, or change the TikTok account. TikTok data is not sold or used for unrelated advertising, profile enrichment, or generalized artificial-intelligence model training.
YouTube API Services and Google data
APEX uses YouTube API Services when a user connects an eligible YouTube channel. The current connector reads the authorized channel's identity, owned video metadata, thumbnails, source links, and official channel and video analytics available through the user-approved read-only scopes. APEX labels this information as YouTube data and does not present it as an official metric from another platform.
APEX does not upload, edit, publish, or delete YouTube videos; download a video's audiovisual content; ask for a Google password; sell YouTube data; use it for advertising or audience enrichment; or use it for generalized artificial-intelligence model training or an unrelated purpose. Deleting data from APEX does not delete the user's channel or videos from YouTube.
In a real client workspace, YouTube channel identity, content, and analytics are visible only to authorized client-workspace members. APEX operators can view redacted connection health but cannot open the channel identity, videos, metrics, or YouTube reports.
Use of YouTube features is also subject to the YouTube Terms of Service. Google's handling of information is described in the Google Privacy Policy.
APEX's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
APEX-controlled connector review
APEX's controlled connector-review process is limited to one isolated connector-review workspace for development, security testing, and evidence required by social-platform reviewers. In that workspace only, the verified APEX owner may connect and inspect an account that APEX owns or is explicitly authorized to use for testing. This exception does not authorize APEX to open a real customer's connected account or data.
Outside that exact review workspace, APEX operators receive the same provider-neutral, redacted connection-health view across Facebook, Instagram, TikTok, and YouTube. They cannot see account identity, content, metrics, reports, or connection controls through that health-only view.
How we use data
- To provide the workspace, upload, calendar, approval, content library, and analytics features.
- To keep each client workspace separated from other client workspaces.
- To prepare client-facing reports and operational recommendations based on approved workspace data.
- To diagnose bugs, security issues, failed uploads, failed platform connections, and sync problems.
- To comply with user deletion, disconnect, legal, security, and platform-policy requirements.
How we share data
APEX does not sell client workspace data. Data is shared only with service providers needed to operate the platform, such as authentication, database hosting, private object storage, application hosting, security/error monitoring, support email delivery, and the approved platform APIs themselves. These providers are used only for operating the product and supporting client workspaces.
Connected-account controls
- Workspace owners can review connection health and the capabilities authorized for an eligible social account.
- A user can disconnect an account in APEX and can also revoke access from the social platform's own account settings.
- APEX does not sell connected-platform data or use it for unrelated advertising.
Google and YouTube access can be reviewed or revoked from Google third-party access settings.
Public authority requests
APEX reviews requests from public authorities for legal validity, may challenge unlawful or overbroad requests, minimizes any required disclosure, and documents the request and response. The current process is described in the Government Requests Policy.
Security and tenant separation
APEX uses authenticated sessions, workspace membership checks, role checks, private storage, and workspace-scoped database records to keep client data separated. Platform tokens are treated as secrets and are stored server-side.
Retention and deletion
Users may disconnect social platform accounts or request deletion of provider data. An in-product disconnect attempts provider revocation, removes the stored authorization credentials and provider-authorized workspace data, and retains only a minimal receipt needed to prove that deletion was handled. That receipt does not keep access tokens, provider content, analytics, captions, thumbnails, or account profile details.
YouTube authorization is checked on a daily lifecycle, with healthy connections scheduled for revalidation after six days. Invalid or removed access is deleted as soon as detected, and the lifecycle fails closed within the applicable seven-calendar-day limit. After a successful refresh, APEX removes local YouTube content records not seen during a successful refresh for more than 30 days, together with their linked metrics. Other connected-platform data is retained only while the connection and its disclosed workspace purpose remain active.
Contact
For privacy, deletion, or security requests, contact aidan.kolar@apexsolutionslive.com.