Legal

Privacy Policy

Effective September 19, 2026 · Last updated September 19, 2026
Wellkept Social LLC · 30 N Gould St, Ste N, Sheridan, WY 82801, USA

This policy explains what personal data Wellkept Social LLC (“Wellkept Social”, “we”, “us”) collects, why we collect it, how long we keep it, and how you can have it deleted. It covers our website, our social media management service, and our business messaging service.

1. Who we are

Wellkept Social LLC is a single-member limited liability company registered in the State of Wyoming, United States (Filing ID 2026-002032699). Our registered business address is 30 N Gould St, Ste N, Sheridan, WY 82801, USA. For any privacy question or request, write to hello@wellkeptsocial.com.

We act in two different roles depending on the data. For our own website visitors and for our business clients, we are the data controller. For the end customers who message one of our business clients, we are a data processor acting on that client’s instructions — the business owns that conversation, not us.

2. What we collect

CategoryWhat it includesWhy we have it
Client account data Business name, contact name, email address, phone number, business address, login credentials To create and operate the account, and to provide support
Billing data Subscription status, plan, invoice history, last four digits and card brand To take payment and issue receipts. Full card numbers are handled by Stripe and never reach our servers
Messaging data Message content, sender phone number or platform handle, display name, timestamps, delivery and read status, attached media To deliver the inbox and automated reply service our client has asked us to run for them
Channel credentials Access tokens, phone number IDs, and business account IDs issued by Meta To send and receive messages on our client’s behalf. Stored encrypted at rest
Social content data Posts, captions, images, scheduling dates, and published-post metrics To produce and publish the content our client has commissioned
Website data Standard server request data and, where enabled, aggregate analytics To keep the site available and understand which pages are read

We do not ask for and do not want special category data — health records, government identification numbers, biometric data, or financial account numbers. Please do not send it to us. If an end customer volunteers such information inside a message, it is stored only as part of that conversation and is deleted with it.

3. Data obtained through Meta platforms

Our commitment regarding Meta data.

Data we obtain through the Meta Graph API, the WhatsApp Business Platform, or the Instagram Messaging API is used solely to provide the messaging service to the business client who authorized that connection.

We do not sell it. We do not rent, trade, or transfer it to third parties for their own purposes. We do not use it to build advertising profiles, to train advertising models, or for any purpose unrelated to delivering the messaging service. We do not use it to enrich or resell contact databases.

Access is scoped to the authorizing client. One client can never read another client’s conversations, contacts, or credentials.

A client may disconnect a channel at any time from their account, or by removing our application’s access from within their own Meta Business Settings. When a channel is disconnected we stop receiving messages for it immediately and delete the stored access credentials for that channel.

4. Automated replies and AI processing

Where a client has enabled the automated assistant, the text of an incoming message and a short window of recent conversation history are sent to a third-party large language model provider so that a reply can be generated. This is done to perform the service the client has requested.

5. Who we share data with

We share personal data only with the service providers we need in order to run the service, and only to the extent required. As of the effective date these are:

We may also disclose data where we are legally required to, or where it is necessary to investigate abuse, fraud, or a security incident. We do not sell personal data, and we have never sold personal data.

6. International transfers

We are a United States company and our infrastructure is operated in the United States and the European Union. If you contact us from outside those regions, your data will be transferred to and processed there. Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on the European Commission’s Standard Contractual Clauses or an equivalent lawful transfer mechanism.

7. How long we keep it

DataRetention
Conversations and messagesFor as long as the client’s account is active, then deleted within 30 days of account closure
Channel access credentialsDeleted immediately when the channel is disconnected or the account is closed
Client account recordsDeleted within 30 days of account closure
Billing and tax recordsRetained as long as US tax law requires, currently seven years
Security and audit logs12 months

8. How to delete your data

If you are a business client. Email hello@wellkeptsocial.com from the address on your account with the subject Data deletion request. We will confirm within 3 business days and complete the deletion within 30 days. Closing your account also triggers deletion on the schedule in section 7.

If you messaged a business that uses our service. The business you wrote to controls that conversation. You can ask them directly, or email us at hello@wellkeptsocial.com with the phone number or handle you used and the name of the business. We will forward your request to that business and delete the conversation once they confirm, or sooner where the law requires us to act directly.

If you removed our app from your Meta account. Removing our application in Meta Business Settings revokes our access immediately. To also have the stored conversation history erased, send the deletion request above — revoking access stops new data, it does not by itself erase what was already received.

9. Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to have it deleted, to restrict or object to how we use it, to receive a portable copy, and to withdraw consent. Residents of California may additionally request disclosure of the categories of data collected and may opt out of any sale of personal data — we do not sell personal data, so there is nothing to opt out of.

To exercise any of these rights, email hello@wellkeptsocial.com. We respond within 30 days. We will never charge you for making a request or treat you differently for having made one. If you are in the EEA or UK and are not satisfied with our response, you may complain to your local data protection authority.

10. Security

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant supervisory authority as required by law.

11. Children

Our services are sold to businesses and are not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has sent us personal data, write to hello@wellkeptsocial.com and we will delete it.

12. Changes to this policy

If we change this policy we will update the effective date at the top of this page. Where a change materially affects how we use personal data, we will notify account holders by email at least 14 days before it takes effect.

13. Contact

Wellkept Social LLC
30 N Gould St, Ste N, Sheridan, WY 82801, USA
hello@wellkeptsocial.com