WSheet Social

Security & privacy at WSheet Social

How WSheet Social protects workspace data, platform OAuth connections, and privacy compliance.

We built WSheet Social for marketing teams and agencies that need control over content and access — with official platform connections and no stored social media passwords.

Data hosting location

Production data (database, files, and backups) is hosted on servers in the European Union — Germany — via the wsheet.com infrastructure provider. We do not move workspace data outside this region unless you explicitly request it or an external platform provider requires it for authorized publishing.

Data encryption & secure transport

We apply technical and organizational measures appropriate to the sensitivity of the data we process, including access controls, encryption in transit, and monitoring. No method of transmission or storage is completely secure.

All public endpoints use HTTPS. Sensitive credentials (OAuth tokens, API keys) are encrypted at rest using AES-256-GCM with an environment-specific data protection key.

Backups & retention

We take encrypted daily backups of the production database and retain them for 30 days. A workspace can be restored within that window after data loss. Audit and billing records are retained per legal and operational requirements (typically 12–24 months).

Deletion on cancellation

When a paid subscription is cancelled or a workspace account is deleted, active processing stops immediately. Workspace data (content, connections, media) is permanently deleted within 30 days of cancellation unless retention is legally required. You may request a data export before cancellation via privacy@wsheet.com.

OAuth — no platform passwords

Connect Instagram, Facebook, LinkedIn, TikTok, YouTube, X and Threads from Connections inside your workspace. You can disconnect a channel at any time. Publishing depends on the permissions you grant and each platform's availability.

Channels connect through each platform's official API using OAuth. We never ask for your social media passwords.

Availability & commitment

We commit to 99.9% monthly uptime for the API and publishing pipeline. Live operational status is at https://status.wsheet.com.

Access control & team permissions

Team roles and content approvals ensure each member only sees what they need. Remove members who no longer require access.

Use a strong unique password and keep invite links private. Remove members who no longer need access. Disconnect unused social accounts.

Your responsibilities

You must not attempt to probe, disrupt, or bypass security controls. Notify us promptly of suspected unauthorized access. We implement reasonable safeguards as described in our Privacy Policy.

Compliance & privacy

We use cookies and similar technologies for authentication, security, preferences, and product analytics. Details are in our Cookie Policy.

To exercise privacy rights, email privacy@wsheet.com

Key benefits

  • Use a strong unique password and keep invite links private.
  • Remove members who no longer need access.
  • Disconnect unused social accounts.
  • EU/Germany hosting
  • AES-256-GCM encryption at rest
  • Daily backups — 30-day retention
  • Deletion within 30 days of cancel
  • Disconnect unused channels
  • Strong unique passwords
  • Private invite links

Frequently asked questions

Is my account data secure?

Channels connect through each platform's official API using OAuth. We never ask for your social media passwords.

Where is my data hosted?

Production data runs on servers in Germany (European Union). See the hosting section above.

What happens to my data when I cancel?

Processing stops immediately and content plus connections are deleted within 30 days unless law requires otherwise.

Does AI publish automatically?

No. AI helps you plan campaigns, generate ideas and write variants — your team stays in control of review, approval and publishing.

Where is the Privacy Policy?

See /en/privacy for full details.