Who provides the service
Auctra and SeerFlow are products of Tetheric Systems Private Limited. Auctra is a hosted brand, creative and marketing workspace, with SeerFlow as its current pilot brand. Access to the hosted pilot is by invitation; each account has its own workspace with projects, chats and saved assets. This notice describes Auctra’s handling of information when you research a brand, create marketing materials or connect an account.
For privacy questions, access or correction requests, or deletion requests, contact hitarthdesai01@gmail.com. This notice covers Auctra. Connected platforms and AI services also have their own data practices.
Information used in the workspace
- Your workspace account
- Your name, email address, workspace name, password hash and sign-in session records. These identify your account and control access to its workspace. Account registration is separate from connecting a social, email or advertising account.
- Work you provide
- Prompts, brand briefs, approved facts, reference materials, draft copy, review decisions and feedback. These support the work you request and its revision history.
- Public research
- Website addresses, page text, source links, quotations, public social links, brand colours, logos and reference images. Public sources may include names or other information about people.
- Creative outputs
- Research notes, ideas, plans, copy, images, scripts, generated audio, rendered video, website or app source files, build and deployment records, quality checks and approval history.
- Connected accounts
- Provider identity and email where returned, account or channel names and identifiers, granted permissions, roles, destination selections, token expiry and connection status. Ad-account reads may include currency, time zone and status.
- Requested social reads
- Instagram post identifiers, captions, permalinks, dates and available like/comment counts; LinkedIn member-level impressions, reach, reactions, reshares or comments, when the relevant account and permission are available.
- Access credentials
- Provider access and refresh tokens. Custom email connections can store an app password and server settings. Provider sign-in is handled by the provider; do not send us your ordinary account password.
- Operational records
- Actions, timestamps, status and error summaries, usage and cost estimates, campaign proposals and any configured delivery results. Saved performance observations and approved feedback can inform later ideas for the same brand.
AI processing and other services
OpenAI processes the prompts and relevant workspace context needed to generate or review text, images and narration. This can include recent conversation history, brand facts, source excerpts, feedback, reference images, selected project source and the script to be spoken. When saved marketing observations exist, relevant project evidence can also be sent for planning, writing, research and new ideas. For Instagram, this can include media identifiers, project labels, reporting dates and returned like/comment counts. Provider access tokens are not part of that observation context. Generated media is saved in the workspace.
The text-generation integration requests that responses are not stored as retrievable response history by OpenAI. This is not a promise of zero provider retention. OpenAI’s endpoint-specific retention and safety practices still apply; see OpenAI’s API data controls.
Render hosts the current workspace application, database and saved files. It processes sign-in, workspace and provider-connection requests. The hosted application receives provider authorization responses and exchanges valid codes on the server; connection secrets are encrypted in application storage and decrypted server-side when needed.
Legacy local-pilot relay: the separate foundry.seerflow.in site on Vercel still supports fixed LinkedIn, Meta Business and Instagram return routes for the local pilot. When that route is used, Vercel receives the authorization code or cancellation response and request state before redirecting the same browser to Auctra on the same Mac. The relay application code does not exchange tokens or store or log that query, but Vercel still processes the request under its infrastructure practices. Current hosted connections return to the workspace on Render.
Firecrawl receives search terms and public URLs for requested research and brand discovery. Those sites may receive the resulting page requests. Do not place private credentials in a research URL or prompt.
HeyGen receives narration audio and the selected presenter identifier for requested presenter-video rendering. The fictional-presenter workflow can also send a generated portrait. This optional service is distinct from narrated motion-design reels rendered by the Auctra application.
Connected publishing platforms receive the approved caption and media file or delivery URL, selected publishing identity and requests needed to publish and check the result. Supported Instagram, LinkedIn and Facebook Page publishing requires the relevant granted access and approval of the exact content, destination and time.
Project code services: when you request a source export or deployment, GitHub receives the selected source and repository, branch or pull-request details. A selected Vercel or Render deployment receives the project code and settings needed to host it in the connected hosting account. These actions are separate from connecting a marketing account.
An optional delivery service, configured by the workspace operator, can receive approved content, its selected account, channel and schedule for publishing. Connecting a platform does not configure or authorize this delivery service.
Connected providers receive the sign-in and account-read requests necessary for features you choose. Content sent to an external provider is subject to that provider’s processing and retention practices. Removing a local file does not automatically remove a provider’s copy.
Optional Google connections
Google connections are optional. Sign-in identifies the account and asks for the permissions associated with the selected feature.
- Gmail: an explicitly requested mailbox-header view can read message and thread identifiers, From/To/Subject/Date headers and unread status. It does not download message bodies or attachments. Email preparation creates a workspace draft; the current tool does not send mail.
- YouTube: Auctra uses YouTube API Services to discover the connected user’s channel and save its name, identifier and selection. Private-upload preparation does not upload a video.
- Google Ads: Auctra reads accessible account identifiers and account metadata so you can select an advertiser and prepare a workspace campaign proposal. It does not launch the proposed campaign.
Connected Google mailbox, channel and advertising-account reads are not automatically fed into the marketing AI prompts. If you independently paste information into an AI conversation, that submitted text follows the AI-processing flow described above.
The current pilot does not use Google account data to train general AI models, target advertisements or sell data. It uses that data for the connected features you request. See the Google API Services User Data Policy, including its Limited Use requirements, and Google’s Privacy Policy.
When you disconnect a Google account in Auctra, the app removes its saved workspace access and identified connection data, then asks Google to revoke the grant when a readable token is available. The result distinguishes confirmed revocation from an unsuccessful or unavailable attempt. If Google does not confirm, remove the grant through your Google Account permissions.
Google revocation can affect more than one service. It removes the permissions granted to the same Google app project for that account, so Gmail, YouTube, Google Ads or another connection using that project may need to be connected again. Auctra also disconnects connections it can identify as sharing that account and sign-in setup within the workspace, including other brands. It cannot identify every connection that Google may affect.
Storage, access and retention
The hosted pilot stores workspace records and generated files in persistent application storage on Render. Passwords are stored as hashes. Connection secrets are encrypted by the application at rest and decrypted on the server when used. The application does not apply this same encryption to every prompt, research record or creative file; it does not provide end-to-end encryption. The workspace operator can access saved content and operational records to run and support the pilot.
Saved work remains until removed by the workspace operator. The pilot currently has no general automatic deletion schedule. Disconnecting removes the saved connection credentials and permissions and cancels unstarted deliveries that explicitly refer to that connection. In-flight or uncertain delivery may need reconciliation.
For Google connections, Auctra also removes the saved account identity, cached channel or ad-account details and selections, and the provider details in recognized connection-related activity records. It does this for the connections it can identify as sharing the grant. A record that a disconnect occurred remains. Earlier briefs, creative files and unrelated activity are preserved; removing those requires a separate request.
When Meta or Instagram sends a supported signed deauthorization or data-deletion request, Auctra checks its signature and account association before removing matching connection-derived data. This covers credentials, provider identity and selections, stored provider observations and related activity and completed-delivery details. It disables affected publishing identities and cancels unstarted deliveries. It does not erase your Auctra login, workspace, user-authored drafts, uploaded files or posts already published on the platform.
Minimal keyed account associations and callback receipts remain to verify later requests and prevent replay. Already-dispatched or uncertain deliveries can retain limited receipts to prevent duplicate publishing. Ambiguous account matches or a deletion request older than a newer authorization require review rather than an automatic claim of completion. A signed data-deletion request returns a confirmation code and status page explaining the result.
There is no published fixed retention period for every category in this pilot. Whole-workspace and other manual requests use the data deletion instructions; ask the operator to confirm any remaining records and backup handling. Data already delivered to a platform or external service may require a separate request to that service.
External services may process data in locations outside your country. The pilot does not offer a guaranteed processing region or certified security standard.
Your choices
You can choose which account to connect, review the provider’s permissions, select a destination and disconnect it in Auctra. Google disconnect also attempts provider revocation; other providers require grant removal in their own settings. You can use provider settings yourself whenever you want to confirm that access has been removed. You can request access to, correction of, or deletion of workspace information at hitarthdesai01@gmail.com. Include the relevant brand or workspace and the account email or public channel identifier so the request can be located. Do not include passwords, access tokens or private customer lists.
Whole-workspace deletion and other requests outside the signed Meta/Instagram callback flow are handled manually in the current pilot. Verification of your authority over the workspace may be needed before data is released or removed. See what disconnecting and deletion each cover.
Updates and contact
This notice describes the current pilot. The revision date appears above. Contact the team with questions about this notice or the handling of your information.
Tetheric Systems Private Limited
Auctra privacy and support