Your feed is yours. Here is exactly what we hold, and what you can switch off.
This Privacy Policy explains what FeedPilot processes, why, how long we keep it, and how you can delete or control it. FeedPilot works after a feed is rendered and, to run a session, handles only what is needed to score the item you are looking at.
One part of the product deliberately keeps more than that, so we say it plainly here rather than in a footnote. If you are signed in and leave the research setting on, FeedPilot stores one record per feed item it evaluates, and by default that record includes the post's text. It is on by default, you can switch it off at any time, and you can delete everything it has collected. The Research data section below describes exactly what is in those records.
Who we are
The FeedPilot operating legal entity, registered address, and VAT number will be confirmed before paid launch. For any privacy question or to exercise your rights, contact support@steeryourfeed.com.
What we process
- On-device session data. Your goal, settings, action permissions, and the visible content of the single item being reviewed, such as caption, on-screen text, likely author, hashtags, mentions, engagement counts, media kind, duration, platform, and local classification state.
- Where classification runs is your choice. FeedPilot Cloud, the default, sends the item features needed for scoring to our API and our model provider. You can instead use your own OpenRouter key, in which case the request goes from your browser to OpenRouter and not through us; a model running inside your own browser on WebGPU, in which case no item content leaves your device at all; or your own OpenAI-compatible server, in which case it goes only to the address you configured. Keys you supply are stored on that device, are never synced to your account, and never reach our servers.
- Vision. If you enable vision, one downscaled frame of the item may be sent for that single classification. Frames are never stored, by us or by any engine, and are never part of the research data.
- Research data. For signed-in contributors, one record per evaluated feed item, including the post's extracted text unless you turn that off. See Research data below.
- Account data. Email, authentication identifiers, optional name, plan status, extension connection data, saved goals, synced settings, usage counters, and subscription status.
- Reports and analytics. Session summaries, goal-fit scores, risk scores, confidence scores, decisions, explanations, platforms, timestamps, report summaries, and feed convergence analytics.
- Billing data. Payment processing is handled by our payment provider. We receive and store subscription status, customer identifiers, invoice metadata, and entitlement information. We do not store full card numbers.
- Support and security data. Messages you send us, diagnostic details you provide, request metadata, security logs, and records needed to keep the Service reliable and secure.
- Website data. This marketing site uses only strictly necessary storage. We do not use advertising cookies or third-party tracking cookies. Any future optional analytics will be gated behind consent.
What we never do
- We never ask for or store your social media password.
- We never store social cookies or session tokens.
- We never run your social account from a server.
- We never sell your data or use it to build advertising profiles. The business runs on subscriptions.
- We never store sampled image frames, in any mode or setting.
- We never store a record of feeds you scrolled outside a session you started.
Research data
FeedPilot exists to study whether a person can steer a recommender feed toward a goal they wrote themselves. Answering that needs the feed items, not just totals: how long a feed takes to converge on a goal, how that differs per platform and per topic, what pulls it off course, and how reliably the agent can act on each surface. So, for signed-in contributors, we store one timestamped record per evaluated feed item.
Every record contains: a session identifier and the item's position in that session, the timestamp, the platform and surface, a one-way hash of the item and of the author's handle, the goal the item was judged against (its name and the objective you wrote, in full, as well as a hash of it), the strictness setting, which engine, model, and provider judged the item, how many milliseconds each stage took, the goal-fit, risk, and confidence scores, the decision and the action taken, the categories and reasons the model gave, the length of the text, the media type and duration, engagement counts, the position and scroll depth in the feed, which scrolling and action techniques were used, and your browser, operating system, and extension version.
Unless you turn "include content" off, it also contains the post's extracted text: title, caption, on-screen text, transcript, image alt text, hashtags, and mentions, truncated at a fixed length. This is the setting that matters most, so it is worth being blunt: with it on, the words of the posts you scrolled past during a session are stored on our servers. With it off, we keep how much text there was and not what it said.
Only if you additionally turn "include identifiers" on, which is off by default, does the record contain the post's URL and the author's handle in readable form. Otherwise those are stored only as one-way hashes, which let us count repeat exposure without recording who posted what.
Never included: sampled image frames, in any configuration.
The identifier setting covers the post and its author, not your goal. The goal text you wrote is stored on every record either way, because it is what the score is relative to. If a goal contains something you would rather not store, phrase it differently or switch contribution off.
Each record carries your account identifier, because it is what lets us apply row-level access rules and lets you delete your own data, together with a random identifier generated once by your browser and derived from nothing about you. Research extracts are taken through a view that drops the account identifier and both optional identifier fields, keeping only that random one, so records can be grouped over time without being tied back to an account. Only you and FeedPilot can read your records; they are readable and deletable by their owner and by nobody else, and they can only be written by our server.
How to turn it off. Open the FeedPilot extension's data and privacy settings and switch "Contribute anonymised research data" off. Recording stops immediately. You can keep contributing while withholding the post text by turning off "include content" instead. Nothing is collected at all while you are signed out. To remove what was already collected, use the delete controls on your account page and choose the research scope; closing your account deletes it too.
Why we process data
- To provide feed scoring, explanations, reports, account syncing, and plan entitlements.
- To study how recommender feeds respond to a stated goal, using the research data described above.
- To process payments, invoices, subscription status, and billing support.
- To secure the Service, prevent abuse, debug failures, and maintain reliability.
- To answer support requests and comply with legal obligations.
Legal bases under GDPR
- Performance of a contract, to provide the agent and account features you sign up for.
- Legitimate interests, to keep the Service secure, reliable, abuse-resistant, and useful.
- Consent, for optional features or future optional analytics where consent is required.
- Legitimate interests in research on how recommender feeds respond to a stated goal, for the research data described below. It is switched on by default for signed-in users, you can object at any time by switching it off in the extension, and you can delete what has already been collected from the account page.
- Legal obligation, for records we must keep for tax, accounting, payment, or compliance reasons.
Retention
- Local extension data. Goals, settings, local classification results, and local caches stay on your device until you clear them from the extension or uninstall it.
- Cloud session item data. Item features sent for scoring are processed transiently and are not kept once the verdict is returned. Sampled frames are not stored.
- Research records. Kept until you delete them, close your account, or ask us to delete them. Switching the setting off stops new records but does not remove earlier ones, so use the research delete scope on the account page for that.
- Cloud reports and account memory. Reports, feed convergence analytics, synced goals, and settings are kept until you delete them, close your account, or ask us to delete them.
- Account and authentication data. Kept while your account exists and deleted when you close the account, except for limited records we are legally required to retain.
- Billing and legal records. Kept only as long as required for tax, accounting, payment disputes, fraud prevention, security, or legal claims.
- Backups. Deleted data may remain in encrypted backups until those backups expire in the ordinary backup cycle.
Deletion and export
You can export or delete local extension data from the extension. In the account page, you can delete cloud reports, synced goals, settings, older usage history, and your research records, each as its own scope, and you can close your account. Account closure deletes product data such as cloud reports, saved goals, account settings, feed convergence analytics, research records, and extension connection data. We keep only the limited records we are legally required to keep, such as billing, tax, fraud-prevention, security, or legal-claims records. Sampled image frames, social passwords, cookies, and session tokens cannot be deleted from FeedPilot because FeedPilot does not store them.
Your rights
Subject to applicable law, you have the right to access, rectify, erase, restrict, and port your data, to object to certain processing, and to withdraw consent where processing is based on consent. You can exercise local data controls directly in the extension and account data controls from the account page. You can also contact support@steeryourfeed.com. You may lodge a complaint with your local supervisory authority. If FeedPilot is established in Belgium, the relevant authority is the Belgian Data Protection Authority.
Sub-processors and transfers
We use providers for hosting, authentication, model inference, payments, email, support, security, and infrastructure. Some providers may process data outside the EEA. Where required, we rely on adequacy decisions or appropriate safeguards such as Standard Contractual Clauses. A current sub-processor list is available on request and will be published before paid launch.
Security
We use technical and organizational measures designed to protect personal data, including encryption in transit, access controls, least-privilege handling of secrets, security logging, row-level access rules that let each account reach only its own records, and the option to run classification entirely on your own device. Model keys you supply stay on the device you entered them on. No internet service can be guaranteed perfectly secure, but the product is designed to reduce the amount of data at risk.
Children
FeedPilot is not directed to children under the age required by your jurisdiction. Parental-control use is designed to be configured and operated by an adult with the necessary authority.
Changes
We will update this policy as the product and our providers are finalized, and will note the version and date at the top.
See also our Terms of Service and Data Processing Agreement.