Privacy Policy
Last updated: 17 July 2026
1. Who we are
ASONET (the "Service"), available at https://asonet.app, is an AI-powered social media management and content creation platform operated for users worldwide, with particular attention to users in Iran and international markets.
This Privacy Policy explains what data we collect, how we use it, with whom we share it, and the rights you have under applicable laws — including GDPR/UK GDPR, CCPA where applicable, and Iranian rules on electronic commerce, computer crimes, and protection of personal data as they apply to online services.
Contact for privacy requests: [email protected]
2. Scope of the Service
ASONET helps you create, schedule, and publish content, generate AI text/images/video (including Nova, the ASONET AI assistant), connect social accounts via OAuth, view analytics, manage teams and billing, and optionally install the Service as a Progressive Web App (PWA).
3. Information we collect
3.1 Account & profile
- Email, password (hashed), name, phone (if you verify it), language, timezone, and profile picture
- Organization / workspace membership and roles
- Billing identity needed for invoices and tax records
3.2 Content you create
- Posts, captions, media uploads, drafts, templates, and brand assets you store in ASONET
- Prompts and parameters you submit to AI generation tools
- Scheduling and publishing history
3.3 Connected social platforms
When you connect Instagram, Facebook, LinkedIn, X, TikTok, YouTube, Pinterest, Threads, Telegram, or other supported networks, we receive OAuth tokens and the minimum profile/page data required to publish and fetch insights you request. We do not read your private DMs unless a feature you explicitly enable requires it and the platform permits it.
3.4 Technical & usage data
- IP address, device/browser type, approximate location derived from IP, and logs needed for security
- Feature usage, error logs, and performance metrics
- Cookies for session auth, preferences (language/theme), CSRF protection, and privacy-respecting analytics
3.5 Payments
Pack checkout is USD-only and processed by crypto providers (e.g. NOWPayments in USDC). ASONET does not store card numbers.
4. How we use data
- Provide account access, workspaces, scheduling, publishing, and analytics
- Run AI generation you request (text, image, video, voice/STT features where enabled)
- Secure the Service (fraud, abuse, rate limits, 2FA for privileged roles)
- Process subscriptions, invoices, refunds, and affiliate payouts where applicable
- Send transactional emails (activation, security, billing). Marketing emails only with consent or as allowed by law
- Improve product quality using aggregated / anonymized metrics — we do not sell your personal data
Important: We do not sell personal data or social-graph data to advertisers or data brokers.
5. Legal bases (international)
- Contract — to deliver the Service you signed up for
- Consent — e.g. optional cookies, certain marketing, some AI processing disclosures
- Legitimate interests — security, product improvement, abuse prevention (balanced against your rights)
- Legal obligation — tax, accounting, lawful requests
6. Iran-focused commitments
For users in Iran, we process personal data in line with applicable Iranian frameworks governing electronic commerce, computer crimes, and user rights in digital services. In particular we:
- Collect only what is needed to operate ASONET features you use
- Protect account credentials and OAuth tokens with industry-standard controls
- Provide channels to access, correct, or delete account data (subject to legal retention)
- Respond to lawful requests from competent authorities when required by Iranian law
- Avoid unlawful disclosure of private user content
If a local data-protection statute or regulator guidance imposes additional duties, we will update this Policy and our practices accordingly.
7. Sharing
- Infrastructure & vendors under contract (hosting, email, analytics, payment processors, AI inference providers)
- Social platforms — only to publish or fetch data you directed
- Affiliates / team members inside your workspace as configured by your organization admins
- Legal / safety — when required by law or to protect users and the Service
8. Retention & deletion
- Account data while your account is active
- OAuth tokens removed when you disconnect a network or delete the account
- Content and drafts deleted within 30 days after account deletion (backups up to ~90 days)
- Billing records retained as required by tax/accounting rules
9. Your rights
Subject to applicable law, you may request access, correction, deletion, export, restriction, or objection; withdraw consent; and disconnect social accounts at any time. Email [email protected]. EU/EEA/UK users may also complain to a supervisory authority. California residents have CCPA rights; we do not sell personal information.
10. Children
ASONET is not directed to children under 16 (or the higher age required in your country). We do not knowingly create accounts for younger users.
11. International transfers & security
Data may be processed on servers outside your country. We use HTTPS/TLS in transit, encryption for sensitive secrets at rest, hashed passwords, access controls, and monitoring. No method is 100% secure; we notify you of serious breaches as required by law.
12. Changes & contact
We may update this Policy; material changes will be reflected by the “Last updated” date and, where appropriate, an in-product or email notice. Questions: [email protected] — https://asonet.app