adeli
  • How it works
  • Pricing
  • Blog
  • Docs
  • FAQ
Get started

Privacy Policy

Last updated October 5, 2026

Adeli, a product of King's Cross Labs, Inc.

175 West 90th Street, New York, NY 10024, United States

ask@tryadeli.com · tryadeli.com

Effective date: October 2, 2026

This Privacy Policy explains what personal information King's Cross Labs, Inc. ("King's Cross Labs," "we," "us") collects through Adeli, why we collect it, and what you can do about it. It covers our website at tryadeli.com, the Adeli API, our Model Context Protocol (MCP) server and agent skills, and any other service that links to this policy (together, the "Service").

Adeli is one API for publishing, scheduling, and measuring posts across social platforms. Using it means connecting social accounts, so the parts of this policy that matter most are the ones about connected platforms. Where we connect to a platform on your behalf, we say which platform, what we read, what we write, how long we keep it, and how you revoke it.

1. Who This Policy Applies To

Adeli is used in two ways, and your relationship with us differs depending on which one applies to you.

  • You use Adeli for your own accounts. You are a creator, marketer, or business connecting social accounts you hold, whether through the API, an automation tool, or an AI assistant. King's Cross Labs is the controller of your personal information, and this policy describes in full what we do with it.
  • You embed Adeli in your product. You are a company or developer using Adeli so that your users can connect their own social accounts. For your own account data — your name, email, billing details, and API usage — we are the controller. For the data of your users, you are the controller and we act as your processor, handling it on your documented instructions under Section 2.
  • You are an end user of a product built on Adeli. You connected a social account inside someone else's app. That company decides what happens with your data; we process it for them. Direct your access, correction, and deletion requests to that company first. If you cannot reach them, email us at ask@tryadeli.com and we will route your request or act on it where the law requires us to.

2. Controller and Processor Roles

Where we act as your processor, we process personal data only on your documented instructions — which, in practice, means the API calls you make and the settings you configure. We keep it confidential, apply the security measures in Section 9, use only the subprocessors listed in Section 6.1, assist you with data subject requests and breach notification to the extent reasonable, and delete or return the data on termination, subject to the retention periods in Section 10.

If you need a signed Data Processing Agreement or the European Commission's Standard Contractual Clauses, email ask@tryadeli.com and we will provide them.

If you embed Adeli, you are responsible for giving your users their own privacy notice, for obtaining the consent required before they connect a social account, and for passing through the platform terms described in Section 7.

3. Information We Collect

3.1 Information you provide

  • Account information — your name, email address, company name where you give one, and the identifier of the account you sign in with.
  • Billing information — where you are on a paid plan. Card details are collected and processed by our payment processor; we do not store full card numbers on our systems.
  • Communications — messages you send us by email, through forms on our site, or on onboarding and support calls.
  • Content you submit for publishing — the captions, images, videos, links, scheduling times, and other post payloads you send to the API for delivery to a connected platform.

3.2 Information collected automatically

  • API request logs — the endpoint called, the API key or token used, the connected account targeted, the timestamp, and the result. We use these to operate the Service, enforce rate limits, debug failures, and investigate abuse.
  • Log data — IP address, browser type and version, pages viewed on our website, time and date of access, and referring page.
  • Device and diagnostic data — technical details captured when an error occurs, including what was being attempted at the time.
  • Usage data — which features and endpoints are used and how often, used to operate and improve the Service.

3.3 Information from platforms you connect

When a social account is authorized through Adeli, we receive data from that platform's API. Depending on the platform and the permissions granted, that may include:

  • Authorization credentials — OAuth access tokens and refresh tokens issued by the platform. These are encrypted at rest. We never receive or store the password for a connected platform.
  • Account and profile data — the account, page, or channel identifier, display name, handle, profile image, and follower or subscriber counts.
  • Published content and metadata — the posts we publish on the account's behalf, plus their identifiers, captions, media references, publish timestamps, and delivery status.
  • Analytics and insights — the performance metrics the platform makes available for that account, such as reach, impressions, views, saves, shares, watch time, and engagement.

We request the narrowest set of permissions that lets the requested feature work.

4. Legal Bases for Processing

Where the GDPR or UK GDPR applies, we rely on the following lawful bases:

  • Performance of a contract — to provide the Service, authenticate you, publish and schedule the content you send, keep connected accounts in sync, and process payments.
  • Consent — to connect a third-party platform, to send marketing email, and to set non-essential cookies. Consent may be withdrawn at any time; withdrawal does not affect processing that already took place.
  • Legitimate interests — to secure the Service, prevent fraud, spam, and abuse, debug errors, and understand aggregate usage so we can improve the product. We balance these against your rights and do not rely on legitimate interests where your interests override ours.
  • Legal obligation — to meet tax, accounting, and regulatory requirements, and to respond to lawful requests from authorities.

5. How We Use Your Information

  • To provide, operate, and maintain the Service
  • To authenticate you and keep connected accounts in sync
  • To publish and schedule the content you submit, and to retry failed deliveries
  • To return delivery status, webhooks, and performance metrics
  • To monitor API usage and enforce rate limits and quotas
  • To process payments and manage plans
  • To respond to support requests and communicate about the Service
  • To detect, investigate, and prevent security incidents, spam, fraud, and abuse
  • To understand aggregate usage patterns and improve the product
  • To comply with legal obligations and enforce our Terms of Service

What we do not do. We do not sell your personal information. We do not sell, license, or otherwise transfer data obtained from a connected platform's API to a data broker, advertising network, or any third party for their own purposes. We do not use data obtained from a connected platform's API to build or serve advertising targeting, and we do not use it to train generalized machine learning or AI models.

6. Information Sharing and Disclosure

We disclose personal information only in the following circumstances:

  • Service providers (subprocessors) — vendors that host, secure, or operate parts of the Service on our behalf, under contract, and only for that purpose. See Section 6.1.
  • Platforms you connect — where publishing, scheduling, or reading metrics requires us to send a request to that platform on your behalf.
  • At your direction — where you ask us to share, export, or publish something, including through an AI assistant you have authorized. See Section 8.
  • Legal requirements — where we are required by law, court order, or a valid request from a public authority, or to establish, exercise, or defend legal claims.
  • Business transfers — if we are involved in a merger, acquisition, or sale of assets, in which case we will give notice before your information becomes subject to a different privacy policy.

We do not sell, trade, or rent personal information to third parties.

6.1 Subprocessors

We use the following subprocessors to operate the Service. This list is current as of the date at the top of this policy.

SubprocessorPurposeLocation
Vercel, Inc.Website and application hosting, content deliveryUnited States
Neon, Inc.Managed database hostingUnited States
Amazon Web Services, Inc.Object storage for media awaiting publication, and background job executionUnited States
Stripe, Inc.Payment processing and subscription billingUnited States
PostHog, Inc.Product analytics and error monitoringUnited States
Resend, Inc.Transactional email deliveryUnited States

We will update this list before adding a new subprocessor that processes personal information. To be notified of changes, email ask@tryadeli.com.

7. Connected Platform APIs

This section covers each platform Adeli integrates with today. A subsection applies to you only if an account on that platform has been connected. Across all of them, the following commitments hold:

  • We access only the account that is explicitly connected.
  • We request the minimum permissions the feature requires.
  • We do not sell, rent, or transfer platform data to data brokers, advertising networks, or any third party for their own purposes.
  • We do not use platform data for advertising targeting or for model training.
  • Disconnecting an account deletes the stored tokens for it immediately and the associated platform data on the schedule in Section 10.

7.1 Meta Platforms — Instagram and Facebook

Adeli connects Instagram professional accounts (business or creator) and Facebook Pages through the Instagram Graph API and the Facebook Graph API. Personal Instagram profiles are not supported, because publishing and insights are only available for professional accounts.

With authorization we access and store:

  • The Instagram account or Facebook Page identifier, username or page name, profile image, and follower count
  • The content submitted for publication — captions, media, and scheduling time — and the media container and post identifiers Meta returns
  • Media objects published through Adeli, including their captions, media URLs, media type, and publish timestamps
  • Insights metrics for the connected account and its media, such as reach, impressions, saves, shares, profile views, and video watch metrics
  • Where a connection is made through a linked Facebook Page, the Page identifier and name required to complete the Instagram authorization

Our use of Meta Platform Data complies with the Meta Platform Terms and Developer Policies. We do not use Meta Platform Data to build user profiles for advertising, to evaluate eligibility for credit, insurance, employment, or housing, or for surveillance purposes.

Access can be revoked at any time from Facebook Settings → Business Integrations, or from Instagram under Settings → Website Permissions → Apps and Websites.

7.2 TikTok

Adeli publishes to TikTok through the TikTok Content Posting API and reads back metrics through the TikTok Display API. With authorization we access and store the account identifier, display name, avatar, and follower count; the videos and captions submitted for publication and the publish IDs TikTok returns; and the metadata and performance metrics TikTok exposes for the connected account.

Our use of TikTok data complies with the TikTok Developer Terms of Service. We do not use TikTok data for advertising targeting, we do not combine it with data from other sources to identify anyone beyond the account connected, and we delete it when the account is disconnected. Access can be revoked from TikTok under Settings and privacy → Security and permissions → Manage app permissions.

7.3 YouTube API Services

Adeli uses YouTube API Services. When you connect a YouTube channel, Adeli uses the YouTube Data API and the YouTube Analytics API to upload and schedule videos you choose, to edit or delete your videos, to read and manage the comments on your videos, and to show your channel's analytics. By connecting a channel or using any YouTube feature of the Service you agree to be bound by the YouTube Terms of Service, and Google's handling of your data is governed by the Google Privacy Policy.

What we access. With the permissions you grant on Google's consent screen, Adeli can see, edit, and delete your YouTube videos, comments, and related data (the youtube.force-ssl permission) and view YouTube Analytics reports for your channel (the yt-analytics.readonly permission, which is optional). We act only when you, or an API key or assistant you have authorized, ask us to: we never upload, comment, moderate, or delete anything automatically.

What we store.

  • Authorization tokens — the OAuth access and refresh tokens for the connected channel and the permissions granted, encrypted at rest
  • Channel profile data — channel identifier, title, handle, profile image, subscriber, view, and video counts, and the identifier of the channel's uploads list
  • Your recent videos — video identifiers, titles, thumbnails, links, publish times, and comment counts, kept so the Comments page can list your videos
  • Comments on your videos — the text, author display name, author channel identifier and link, author profile image, like and reply counts, time, and moderation status (for example, held for review) of comments and replies on your videos. These include information about the people who commented, which we use only to show you the conversation and let you respond to or moderate it.
  • Quota usage — a count of the YouTube API requests Adeli makes each day, which contains no personal information

What we do not store. Video files you upload pass through our servers to YouTube and are deleted as soon as the upload finishes or fails; we never keep a copy of YouTube audiovisual content. YouTube Analytics reports are fetched when you view them and are not stored.

How we use and share it. YouTube data is used only to provide the YouTube features of the Service to you: it is shown in your Adeli dashboard and returned to the API keys and AI assistants you authorize for your profile. It is not shown to other Adeli customers, sold, used for advertising, combined with data from other users, or used to train machine-learning models. It is shared only with the subprocessors in Section 6.1 that host and operate the Service.

How to delete YouTube data. Deleting data stored by Adeli does not delete or change anything on YouTube; your videos and comments stay on YouTube until you remove them there.

  • Disconnect the channel — on the Accounts page of the Adeli dashboard, or by calling the disconnect endpoint. Disconnecting revokes the OAuth grant with Google programmatically, so the authorization stops working at Google itself, and deletes the tokens and every stored video and comment record for that channel immediately.
  • Delete the profile — under Settings in the dashboard. Deleting a profile disconnects and revokes its YouTube channel and deletes its YouTube data immediately.
  • Ask us directly — email ask@tryadeli.com with "Data Deletion Request" in the subject line, including to delete your Adeli account. We delete stored YouTube data within seven days of your request.

Revoking access through Google. You can revoke Adeli's access at any time, independently of us, from the Google security settings page. We check that our access to each connected channel is still authorized, and when we find it has been revoked we delete all YouTube data we hold for that channel. Data for a channel revoked through Google is deleted within 30 days of the revocation; data for a channel you disconnect in Adeli is deleted immediately and in all cases within seven days.

Refresh or delete every 30 days. YouTube data we store is refreshed from the YouTube API, or deleted, at least every 30 days. This includes the comments and commenter information described above: a comment that has not been read again from YouTube within 30 days is deleted. We do not keep a stale copy of YouTube data past that window.

Google Limited Use disclosure. Adeli's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for serving advertisements, we do not transfer it to third parties except as necessary to provide or improve the Service, to comply with applicable law, or as part of a merger or acquisition, and we do not allow humans to read it except with your affirmative consent, for security purposes, to comply with applicable law, or where the data has been aggregated and anonymized.

Questions or complaints about how Adeli handles YouTube data can be sent to ask@tryadeli.com.

7.4 Platforms we add later

We intend to support additional networks, including LinkedIn, X, Threads, Reddit, Pinterest, Bluesky, and Google Business Profile. We will update this policy with the platform-specific disclosures for each network before that integration is available to you, and no data is collected from a platform that is not listed above.

8. AI Assistants and MCP Access

Adeli is designed to be usable from an AI assistant — for example Claude, ChatGPT, or a coding agent — through our MCP server, an agent skill, or the API directly. This section explains what that access means in practice.

8.1 How authorization works

An assistant is authorized either with an API key you issue or through a standard OAuth 2.0 flow with PKCE, where a consent screen describes the access being requested and access begins only if you approve it. Access tokens are short-lived and expire automatically. Refresh tokens are stored encrypted at rest and are used only to obtain new access tokens for the account that granted them. API keys remain valid until you delete them.

8.2 What a connected assistant can do

Authorization is scoped to your Adeli account and the platform connections made under it. An authorized assistant can:

  • Read, create, schedule, edit, and cancel posts
  • Read delivery status and the performance metrics we have synced
  • View, connect, and disconnect social accounts

It cannot reach another customer's account. It cannot read direct messages or inboxes, and it cannot create or spend money on advertising, because Adeli does not offer those capabilities.

Authorization is account-wide. An assistant you authorize can act on any account connected to your Adeli account, and publishing is a public, effectively irreversible act. Authorize only assistants you trust, and review what an agent intends to post before it posts.

8.3 What we can see

We log the API and tool calls made on your behalf — the endpoint or tool called, its parameters, the client identity, the timestamp, and the result — for operations, rate limit enforcement, abuse detection, and support.

8.4 Data shared with the assistant provider

When a connected assistant requests data, that data is transmitted to the provider operating the assistant. Once it leaves Adeli it is handled under that provider's own privacy policy and terms, and we do not control how they store, process, retain, or further disclose it. We are not responsible for how a third-party assistant handles data after it leaves our systems.

8.5 Model training

We do not use the content accessed through our MCP server or API to train machine-learning models, we do not use your personal information or connected-platform data for that purpose, and we do not permit our subprocessors to do so.

8.6 Ending access

You can revoke an assistant's authorization at any time from your Adeli dashboard under Connected apps, by deleting the API key it uses, or by emailing us. Revocation takes effect immediately: the access token, the refresh token, and any pending authorization are invalidated, so the assistant loses access on its very next request and cannot renew it.

9. Data Security

We protect personal information using measures appropriate to its sensitivity, including encryption in transit (TLS) and at rest, encrypted storage of OAuth tokens and API keys, access controls limiting internal access to those who need it, and logging of administrative access.

No method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for the strength and confidentiality of your own credentials, including your API keys. If we become aware of a breach affecting your personal information, we will notify you and the relevant supervisory authorities as required by applicable law.

10. Data Retention

We keep personal information only as long as we need it for the purposes described in this policy, or as long as the law requires.

DataRetention
Account informationFor the life of your account; deleted within 30 days of account deletion
OAuth tokens for a connected platformDeleted immediately when the account is disconnected or access is revoked
Media awaiting publicationDeleted once the post is delivered or cancelled, and within 30 days at the latest
Published post records, delivery status, and synced metricsDeleted within 30 days of disconnecting the platform or deleting your account
YouTube channel, video, and comment data, including commenter informationRefreshed from the YouTube API at least every 30 days or deleted; deleted immediately on disconnection, and within 30 days of a revocation made through Google
Videos uploaded to YouTubeDeleted from our servers as soon as the upload to YouTube finishes or fails
Payment and billing recordsRetained as required by tax and accounting law, typically 7 years
API request, server, and security logsUp to 12 months, then deleted or aggregated
Support correspondenceUp to 24 months after the request is resolved

Backups are retained on a rolling schedule and are overwritten in the ordinary course. Data deleted from live systems on the schedule above expires from backups within 90 days. A post already published to a social platform lives on that platform under its own policies; deleting your Adeli account does not remove it, and you should delete it on the platform itself.

11. Your Rights Under the GDPR and UK GDPR

Where we are the controller, as described in Section 1, and you are in the European Economic Area, the United Kingdom, or Switzerland, you have the right to:

  • Access — obtain confirmation of whether we process your personal information and a copy of it
  • Rectification — have inaccurate or incomplete information corrected
  • Erasure — request deletion of your personal information
  • Restriction — request that we limit processing in certain circumstances
  • Portability — receive your personal information in a structured, commonly used, machine-readable format
  • Objection — object to processing based on our legitimate interests, and to direct marketing at any time
  • Withdraw consent — where processing is based on consent, without affecting processing already carried out
  • Complain — lodge a complaint with your local supervisory authority

To exercise any of these rights, email ask@tryadeli.com. We will respond within 30 days. We may ask you to verify your identity before we act on a request. We will not discriminate against you for exercising your rights. Where we act as a processor for a company that embeds Adeli, we will forward your request to that company and assist them in responding.

12. Your Rights Under California Law

If you are a California resident, the California Consumer Privacy Act as amended by the CPRA gives you the right to know what personal information we collect, to access and delete it, to correct inaccuracies, to opt out of the sale or sharing of personal information, and to limit the use of sensitive personal information.

We do not sell or share personal information as those terms are defined under the CCPA, and we have not done so in the preceding 12 months. We do not knowingly sell or share the personal information of consumers under 16.

In the preceding 12 months we have collected the categories of personal information described in Section 3: identifiers, commercial information, internet or network activity information, and audio or visual information in the form of media submitted for publication. We collect it from you, from your devices, and from platforms you authorize, for the business purposes described in Section 5.

To exercise your rights, email ask@tryadeli.com with "California Privacy Request" in the subject line. An authorized agent may submit a request on your behalf with proof of authorization. We will respond within 45 days and may extend once by a further 45 days with notice.

Do Not Track. We do not currently respond to browser Do Not Track signals, because no common standard for them has been adopted.

13. Cookies and Tracking

We use cookies and similar technologies for two purposes: essential cookies that keep you signed in and secure the Service, and analytics cookies that help us understand aggregate usage of our website and dashboard. The Adeli API itself does not set cookies. Most browsers let you refuse or delete cookies; refusing essential cookies may prevent parts of the Service from working.

14. Children's Privacy

The Service is not directed at children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, email us and we will delete it.

15. International Data Transfers

We are based in the United States, and personal information we collect is stored and processed in the United States and in other countries where our subprocessors operate. These countries may not offer the same level of data protection as your own.

Where we transfer personal information out of the EEA, the UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism, together with supplementary measures where appropriate.

16. Changes to This Policy

We may update this Privacy Policy to reflect changes to the Service, our practices, or the law. We will post the updated policy at this address and revise the "Last updated" date. If the changes are material, we will give you at least 30 days' notice by email or through the Service before they take effect, and where the law requires it we will ask for your consent.

17. Contact Us

For privacy questions, requests, or complaints:

King's Cross Labs, Inc.
175 West 90th Street
New York, NY 10024, United States
ask@tryadeli.com
tryadeli.com

See also our Terms of Service.

adeli

One social media API for publishing, scheduling, and measuring on Instagram, TikTok, YouTube, Facebook, and X.

Talk to us

Platforms

  • Instagram API
  • TikTok API
  • YouTube API
  • Facebook API
  • X API

By type

  • Posting API
  • Analytics API
  • Comments API
  • Messaging API

Compare

  • Adeli vs. Ayrshare
  • Adeli vs. Upload-Post
  • Buffer API alternative

For agents

  • Agents & MCP

Adeli is a product of King's Cross Labs, Inc. · © 2026

PricingBlogPrivacy PolicyTerms of Service