Privacy Policy
Last updated: June 17, 2026
Market or Die ("Market or Die", "we", "us", or "our") operates the Market or Die web application (the "Service"), a marketing-accountability tool that helps teams plan, write, schedule, and publish social media posts. This Privacy Policy explains what information we collect, how we use it, and the choices you have. By using the Service you agree to this policy.
Information we collect
Account information. When you sign up we collect your name, email address, time zone, and an optional profile photo and handle.
Content you create. Posts, drafts, threads, images, scheduling details, check-ins, and any style notes or prompts you enter for our AI writing features.
Connected social accounts. When you connect a third-party platform (X / Twitter, LinkedIn, YouTube, Instagram, or Meta), we receive and store, on secure servers, the access and refresh tokens that platform issues, plus basic profile details it returns (such as your username, display name, account ID, and avatar). We use these strictly to provide the features you requested.
Usage and technical data. Standard log and device data (such as IP address and browser type) generated when you use the Service, and the status of posts you schedule or publish.
How we use information
- To create and manage your account and team.
- To compose, schedule, and publish posts to the platforms you connect, on your behalf.
- To read basic profile and post data from connected platforms so we can display it and confirm what was published.
- To power optional AI writing assistance (rewriting your own drafts).
- To send account and accountability emails you have opted into.
- To secure, maintain, debug, and improve the Service.
We do not sell your personal information, and we do not use it for advertising.
Connected platforms and OAuth tokens
Connecting a platform is always optional and initiated by you through that platform's official OAuth flow. We request only the permissions needed to read your basic profile and to publish content you create. Tokens are stored server-side and are never exposed to your browser or to other users. You can disconnect any platform at any time from inside the app (the account menu in the composer), which deletes the stored tokens for that connection.
Google and YouTube data
If you connect YouTube, the Service uses YouTube API Services. By using these features you also agree to the YouTube Terms of Service and the Google Privacy Policy.
Market or Die's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google/YouTube data only to upload and manage the videos you choose to publish and to show you the result; we do not transfer it to others except as needed to provide the feature, do not use it for advertising, and do not allow humans to read it except with your consent, for security, or as required by law.
You can review and revoke Market or Die's access to your Google account at any time at myaccount.google.com/permissions.
Meta (Facebook and Instagram) data
If you connect Instagram or a Meta account, we use the Meta and Instagram APIs only to publish the content you create and to read the basic account information needed to do so, in accordance with the Meta Platform Terms. You can remove Market or Die's access from your Facebook or Instagram app settings, or disconnect it inside our app.
How we share information
We share data only with service providers that help us run the Service, under contracts that limit their use of it:
- Supabase: database, authentication, and file storage.
- Vercel: application hosting.
- OpenRouter and OpenAI: AI text and image generation for the optional writing and avatar features (we send only the draft text or image you submit).
- Resend: transactional and accountability email.
- The social platforms you connect, in order to publish your content.
We may also disclose information if required by law or to protect the rights, safety, and security of our users and the Service.
Data retention and deletion
We keep your information for as long as your account is active. You can disconnect any connected platform at any time, which deletes its stored tokens. To delete your account and associated personal data, email us at hadi@heffl.com and we will remove it within 30 days, except where we are required to retain it by law.
Security
We use industry-standard measures to protect your data, including encryption in transit, row-level access controls, and server-side-only storage of platform tokens. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Children
The Service is not directed to anyone under 16, and we do not knowingly collect their data.
Changes to this policy
We may update this policy from time to time. We will revise the "Last updated" date above and, for material changes, provide additional notice where appropriate.
Contact
Questions about this policy or your data? Email hadi@heffl.com.