Privacy Policy
Last updated: September 29, 2026
This policy explains what Mabel, operated by Arham Shah, collects when you use Mabel, why, who we share it with, and how to delete it.
1. What we collect
Information you give us
- Account details: email, name, password (stored only as a bcrypt hash), and your plan. A Google sign-in account may have no password.
- Your content: videos you upload, links you save, captions, scripts, brands you track, notes and feedback you send us.
- Billing: nothing. The app does not take payments, so we do not receive a plan charge, a billing status, or any part of a card number from Stripe, Apple, or Google.
Waitlist
If you join the waitlist at trymabel.co, we store your email, whether you signed up as a creator or an agency, and any name, company, roster size, and page source you send. We store a hash of your IP address, not the address itself, and the browser user agent. The studio owner can read and export that list.
Information from connected accounts
Only if you connect them.
TikTok. We request:
user.info.basic: your TikTok open ID and display name, so we can show which account is connected. This call does not read an avatar, username, bio, or follower count.video.list: your public videos (ID, title, share link, cover image, date, and view, like, comment and share counts), so we can track your posts and give feedback.video.uploadandvideo.publish: to upload and post videos to your TikTok account only when you connect that account with posting permission and confirm each post.
Mabel does not request user.info.profile or user.info.stats. We don't read your direct messages, drafts or followers list. You can disconnect the account at any time. Mabel never posts without your confirmation.
Instagram. This works with professional (Creator or Business) accounts linked to a Facebook Page you manage. Personal accounts are not supported. Mabel uses Facebook Login, not Instagram Login. We request:
pages_show_listandpages_read_engagement, to find that Page and the linked Instagram account;instagram_basic: account ID and username, plus each post's caption, link, date and thumbnail;instagram_manage_insights: like, comment and view counts when Instagram returns them;- content publishing access, to post Reels only when you connect that account with posting permission and confirm each post.
We don't read your direct messages. Stories aren't imported. You can disconnect the account at any time. Mabel never posts without your confirmation.
YouTube. We use YouTube API Services with these scopes:
https://www.googleapis.com/auth/youtube.readonly, to see your channel ID and name and each upload's ID, title, date, thumbnail and view, like and comment counts;https://www.googleapis.com/auth/youtube.upload, to upload videos to your channel only when you connect that account with posting permission and confirm each post.
We don't read watch time or revenue. You can disconnect the account at any time. Mabel never posts without your confirmation. Google's privacy policy is at https://policies.google.com/privacy, and you can revoke Mabel's access anytime at Google account permissions.
Facebook. Mabel can read Facebook Pages you manage, not a personal timeline. The permissions are pages_show_list and pages_read_engagement. Mabel stores the Page id and name, and for each published post the id, message, link, time, picture URL, and like, comment, and share counts when Facebook returns them. View counts are not read. Mabel does not post to Facebook.
Google sign-in (if enabled). We receive your Google account ID and email to sign you in, and we store those with your Mabel account. Google access tokens are not kept. This doesn't give us access to Gmail, Drive, Calendar or YouTube. Connecting a publishing platform is a separate choice.
Snapchat. There is no Snapchat login. If you paste a public URL, we store that URL. For a YouTube or TikTok URL we also ask that platform's public oEmbed endpoint, without an account token, for the title and thumbnail. A missing title is not invented.
Information collected automatically
- Usage data: pages you open, features you use, errors, and what kind of device and browser you're on. We use this to fix bugs and improve Mabel. Signed-in events can include your account id, email and plan.
- Cookies: a login cookie (
cs_session) keeps you signed in. A device cookie (cue_device) remembers this browser during sign-in. A first-party cookie (cue_anon) holds a temporary id before you have an account. Short-lived cookies are set while you sign in with Google or connect a social account, then removed. Dark mode is saved in this browser's local storage, not in a cookie. We don't use advertising cookies. PostHog does not set its own cookie in your browser; our server sends it the events.
Public data. Radar shows public videos and their public stats (views, likes, comments) from TikTok, Instagram and YouTube. TikTok and Instagram results are collected through Apify. YouTube results are collected with the YouTube Data API and a public search on our server.
2. How we use it
- to run Mabel: saving videos, making transcripts and scripts, giving feedback, showing Radar, and posting when you ask;
- to manage your plan and, once an email provider is connected, send account emails such as password resets;
- to keep Mabel secure and prevent abuse;
- to understand how people use Mabel so we can improve it;
- to follow the law.
We don't sell your personal information or share it for targeted advertising.
3. Who we share it with
We share only what each service needs to run Mabel:
- Railway: hosts the app and the disk where the database is stored.
- Whisper runs on our own server and makes transcripts, along with captions the platform already published. Gemini does not make transcripts.
- Google Gemini and Anthropic receive script and analysis text when that provider is the one configured for Mabel. Mabel uses paid API access, and each provider's API data terms apply. Gemini API terms. Anthropic Commercial Terms.
- PostHog: product analytics. For a signed-in account this can include the account id, email and plan. A waitlist signup is sent as an event whose id is a hash of the email, plus creator or agency and the page source. The email itself stays in our database.
- Apify: collects public TikTok and Instagram posts for Radar. It is not the downloader for videos you save to the Library. Those downloads, and a Radar file whose saved link has expired, run on our server.
- Email: no email provider is connected, so Mabel does not send password resets or other account email yet.
- TikTok, Instagram and YouTube: receive a video and caption only when you connect an account with posting permission and confirm that post. You can disconnect an account at any time. Mabel never posts without your confirmation.
- Studio owner: there is no agency view of your videos or posts. The studio owner can see each account's email, name, plan, created date, last active time, and Radar request counts, and can pause an account or change its plan.
- Legal reasons: we may disclose information if the law requires it, or to protect people's safety or our rights.
- Business transfer: if Mabel is sold or merged, your information would transfer under this policy.
4. How we protect it
Connected-account login tokens are encrypted before they're stored, and the encryption key is kept separate from the database. Passwords are stored as hashes. Data is sent over HTTPS. No system is perfectly secure, but we work to keep your data safe and will tell you if a breach affects you.
5. How long we keep it
- Account data and your content: while your account is open. The app does not delete an account on its own.
- Saved reference videos: the video file may be deleted after 14 days, while its transcript and thumbnail stay until you delete them.
- Backups: we keep recent copies of the database. Local backups are protected by our hosting provider's access controls. When off-site backup storage is turned on, those copies are encrypted. Deleted data can remain in a backup until that backup is replaced.
- Payments: we don't store billing records, because the app does not take payments.
- Waitlist entries: until you ask us to delete them.
6. Your choices and rights
- Disconnect any social account on the Posts screen in Mabel. This deletes its saved login and stops future imports. Posts already imported stay until you remove them in Posts. Also remove Mabel in that platform's connected-apps settings. Disconnect does not, by itself, revoke the app on TikTok, YouTube, Instagram, or Facebook.
- Delete your account by contacting us through the app. There is no delete button in Settings, and an account is not erased on a timer. Include enough detail for us to find the account.
- Access or correct your data by contacting us through the app.
- Depending on where you live (for example California, the EU or the UK), you may have extra rights, such as getting a copy of your data, objecting to certain uses, or complaining to a data-protection authority. Email us to use them. We won't treat you differently for doing so.
Deleting data from a connected platform
TikTok, Meta and Google reviewers, and anyone who connected an account, can use either of these. Both work without a special form:
- In Mabel, open Posts and disconnect Instagram, Facebook, TikTok, or YouTube. That deletes the saved login from our server and stops later imports. Then remove any imported posts you do not want kept, and remove Mabel in the platform's own connected-apps settings.
- Contact us through the app and ask us to delete your data. Name the platform and the account if you can. We will delete the connected-account data we hold and reply when it is done.
7. Children
Mabel isn't for children under 13, and we don't knowingly collect their information. If you believe a child under 13 has an account, email us and we'll delete it.
8. International users
Your account and content are stored and processed on the servers that host Mabel.
9. Changes
If we make significant changes to this policy, we'll let you know in the app or by email before they take effect.
10. Contact
Mabel, operated by Arham Shah
Contact us through the app.