MediaShark

Privacy Policy

Last updated 2026-10-06

This policy explains what MediaShark collects, why, who processes it, and the choices you have. MediaShark is operated by TCM Group ("we", "us").

What we collect

Account details: your name, email address and a hashed password, or the email your Google or Facebook sign-in provides.

Workspace content: brand details, website text we read when you ask us to, products, campaigns, posts, images and videos you create or upload.

Connected social accounts: when you connect a platform (Facebook, Instagram, LinkedIn, X, YouTube or TikTok) we store the access tokens that platform issues, encrypted at rest, plus the account name, picture and ID.

Platform data you ask us to show: results for posts published through MediaShark (such as reach, impressions and engagements), account follower counts, and comments or messages on your accounts when you use the engagement features. This can include the public name and message of people who interact with your posts.

Usage and device data: in-app events, error reports and approximate request information, recorded by MediaShark itself. We do not use third-party advertising trackers.

Billing: plan, credit balance and payment status. Card details are handled by our payment provider and never reach our servers.

How we use it

To run the service: write and schedule posts, publish them to the accounts you connect, show results, and handle comments and messages you choose to automate.

To bill you, prevent abuse and keep the service secure.

To support you and to improve MediaShark. We do not sell your data and we do not use your connected-account data for advertising.

Data received from platform APIs is used only to provide the features you use, in line with each platform's terms.

Who processes it

AI providers (OpenAI, Anthropic, Google) process the text and images needed for a generation request. When you add your own AI key, the request goes to that provider under your account.

Social platforms receive the posts and media you publish.

Paddle acts as our merchant of record and processes payments.

Infrastructure providers host our database, files and network (including Neon and Cloudflare).

Each provider only receives what it needs for its part of the service.

How long we keep it

We keep your data while your account is open. When you delete your account we delete your workspaces, content and connected-account tokens straight away, and remove remaining copies from backups within 30 days. We may keep billing records for as long as the law requires.

Your choices and rights

You can edit or delete content at any time, disconnect any social account (which deletes its stored tokens), and delete your whole account from Settings.

You can ask for a copy of your data, a correction, or deletion by emailing privacy@mediashark.app. We reply within 30 days.

Depending on where you live you may have further rights under laws such as the GDPR, the UK GDPR, the NDPA or the CCPA, including the right to complain to your data protection authority.

Security

Traffic is encrypted in transit, platform tokens and AI keys are encrypted at rest, and access to production data is restricted. No system is perfectly secure; tell us at privacy@mediashark.app if you find a problem.

Children

MediaShark is for businesses and is not meant for anyone under 16.

Changes

If we change this policy in a meaningful way we will tell you in the app or by email before it takes effect.

Contact

Questions about privacy: privacy@mediashark.app.