Privacy policy
Last updated October 6, 2026
Somecal is a social media content calendar for creators and agencies. This page explains which personal data the service processes, why and for how long, who it is shared with, and what your rights are.
1. Who we are
The service is provided by SugarArt OÜ (registry code 16743720, Tartu maakond, Kastre vald, Roiu alevik, Kesktänav 4-2, 62122). For data protection questions, write to sugarart.ou@gmail.com.
Two roles. For your account data (name, email, sign-in) we are the controller. Content a workspace adds to the service (posts, files, clients, comments, notes, tasks, time entries) belongs to that workspace: its owner (e.g. an agency) is the controller of that data, and we process it on their behalf as a processor under the terms and this policy.
2. What we process
- Account: name, email address, a hash of your password (we never see the password itself), your Google account identifier if you sign in with Google, passkey public keys, two-factor settings.
- Sessions and security: IP address and browser description of active sessions, counters of sign-in attempts and share link use (to stop abuse).
- Workspace content: everything members add: posts, images and videos (we strip location and other metadata from images on upload), comments, approval decisions, ideas, notes, tasks, time entries, brand details and the activity log.
- Share link guests: the name a guest enters, their comments and decisions, and the cookie that remembers them.
- Technical error logs: when something breaks, we store the error, the page address (without tokens or query parameters) and the browser description so we can fix it. No names, emails or cookies are sent there.
- Emails: the recipient address and the kind of email (e.g. verification link, invitation, reminder).
We use no advertising, tracking cookies or third-party analytics, and we never sell data.
3. Why and on what basis
- Providing the service (contract): accounts, workspaces, storing and showing content, emails (invitations, approvals, reminders, task digests).
- Security and upkeep (legitimate interest): protecting sign-in, rate limits, tracking and fixing errors, backups, stopping abuse.
- Legal obligations where they arise (e.g. accounting once the service becomes paid).
4. Where data is kept and who processes it
Data is stored in the European Union. We use these providers (processors):
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | servers, database, files, backups, error logs | Germany / Finland (EU) |
| Resend | sending email | EU / USA (under EU standard contractual clauses) |
| sign-in with Google, only if you use it | per Google's terms |
The service administrator sees account and workspace metadata (e.g. email, creation date, number of posts, file size) but not workspace content. We only look at content when a workspace asks us to help with a problem or when the law requires it.
5. Cookies
We only use cookies the service needs to work, so there is no consent banner:
- your sign-in session (up to 30 days);
- the chosen language and the chosen client;
- a share link guest's name (so they don't have to type it every time).
6. How long we keep data
- Account data until the account is deleted.
- Workspace content until the workspace deletes it. Deleting a workspace also deletes its files.
- Sessions expire after 30 days; unused uploads are deleted after a day.
- Error logs for up to 90 days, backups for up to 30 days.
7. Your rights
You have the right to:
- get a copy of your data: Settings → Account → Download my data (machine-readable JSON, also for moving it elsewhere);
- correct your data (Settings → Account);
- delete your account: Settings → Account → Delete account;
- object to processing and ask us to restrict it;
- complain to the Estonian Data Protection Inspectorate (www.aki.ee).
If your data is part of a workspace's content (e.g. you are an agency's client), contact that workspace first: it decides about that data. We help the workspace owner where needed.
8. Security
Connections are encrypted, passwords hashed, and files private, opening only through short-lived links. Everyone can use two-factor authentication, and a workspace can require it from owners and admins. Workspaces are isolated from each other, and automated tests check this.
9. Changes
If we change this policy substantially, we tell you in advance by email or in the app. The current version is always on this page.