- Your company decides. In a workspace we handle data for the company that has it, under our data processing terms.
- Your LinkedIn, your call. You connect with LinkedIn’s own sign-in. We never see your password, and Speakfold posts only what you approved, when you chose.
- Never for sale. We don’t sell data, use it for our own ads or recruiting, or show one company’s data to another, and our AI provider doesn’t train its models on it.
- Kept in the EU. Workspaces are stored in a database in the EU. Every company that handles data for us is listed below.
- Yours to take or delete. Download your data or leave a workspace any time, from Settings.
Who we are
Speakfold is run by Speakfold, Finland. Write to hello@speakfold.com about anything in this policy, or to use your rights.
Our two roles
For data in a workspace, we act for the company that has the workspace. The company (our customer) decides who is in it and what it’s used for, and is the controller under the GDPR. We are its processor: we use the data only to provide Speakfold to it, as our data processing terms set out. If you use Speakfold at work, your employer decides about your workspace data; ask your admin, or write to us and we’ll pass it on and help.
For our own business, we decide. We are the controller for our website, demo requests, the contact details of our customers’ admins (for service notices and billing), security records, and counts of how the product is used, which we look at in aggregate to make Speakfold better.
What a workspace holds
- Your profile: name, role, work email, time zone, language, the topics you want to be known for, and your settings.
- What you tell Speakfold: interview answers, notes, ideas and takes. Voice clips are turned into text, and only the text is kept.
- Your writing: drafts, the versions you approve, and the changes you make, which teach Speakfold your voice. Comments colleagues approve for each other’s posts, and visuals.
- Your LinkedIn files: the data archive and post analytics you download from LinkedIn and add yourself: your own posts, comments and numbers.
- Posts you reply to: when you paste someone else’s post or a comment to write your reply, we keep that text with your reply.
- People who react to your posts: only when your company turns on Who engaged, the public names, headlines and comments of people outside the team who reacted to or commented on the team’s posts (see People who react to your posts).
- Your company: what Speakfold reads on your company’s public website, documents you add, the brand kit, the house style and the guardrails.
- Use of the app: what you approved, changed or skipped, and when. Speakfold uses it to prepare your Desk and reminders, and admins see a summary on the Pilot page. It never ranks people.
- Connections: the keys for LinkedIn and Slack, encrypted and never sent to your browser.
Please don’t put special categories of data (health, beliefs and the like) into Speakfold. It doesn’t need them.
Your LinkedIn
How you connect. You connect your own LinkedIn account through LinkedIn’s official sign-in (OAuth). We never ask for or see your LinkedIn password. Speakfold has no browser extension. It reads the public reactions and comments on your team’s posts only when your company turns on Who engaged, and then not through your connection (see People who react to your posts).
What LinkedIn shares with Speakfold.
| Permission | What it gives | When |
|---|---|---|
openid, profile | Your LinkedIn member ID and your name, so Speakfold knows which account is yours | When you connect |
w_member_social | Posting as you: the posts you approved, and reshares | When you connect |
w_member_social_feed | Likes and comments as you, on posts you chose | Only once LinkedIn approves it for Speakfold and you turn it on |
What we do with it. Speakfold posts what you approved, at the moment you chose, from your own account. It likes, comments on or reshares a colleague’s post only as you approved, one by one or with a standing choice you set in Settings, and you can take a comment down. When a post names your company or a colleague who connected LinkedIn, Speakfold tags them.
What we don’t do. Through your connection, Speakfold doesn’t read your feed, messages, connections or other members’ profiles. We never use what LinkedIn’s API gives Speakfold for sales prospecting, recruiting, advertising or lead lists, never combine it to build profiles of people, and never sell or share it.
Your numbers. Results come from the files you download from LinkedIn and add yourself. If Speakfold later receives statistics for your own posts from LinkedIn directly, we’ll say here what it receives and how long it’s kept before that starts.
Keeping and deleting. The connection is kept while you’re connected. Disconnect any time in Speakfold under Settings, LinkedIn and privacy (Speakfold also cancels the key at LinkedIn and deletes it), or in LinkedIn under Settings, Data privacy, Permitted services. Posts already on LinkedIn stay there until you delete them on LinkedIn.
Speakfold isn’t affiliated with, endorsed or sponsored by LinkedIn. LinkedIn is a trademark of LinkedIn Corporation.
People who react to your posts
Only when your company turns it on. With Who engaged, Speakfold looks at the public reactions and comments on the posts your team made with Speakfold, 3 hours, a day, 3 days and a week after each one goes live. It keeps what LinkedIn shows signed-in members on the post: each person’s name, headline, profile link and picture, the kind of reaction, and their comment and its time. A provider, Apify, reads them for Speakfold; nobody’s LinkedIn connection is used for it. Members of the team are left out.
What it’s for. To show the post’s author and the company’s admins who engaged and which of them may be the kind of people the company sells to, judged from the headline alone. The author can have a reply to a comment written in their voice, which they post themselves. An admin can send a person to the company’s CRM.
What we don’t do. We don’t look up anyone’s email or phone number, combine this with other sources, follow anyone around LinkedIn, or use it for anything else. Each company sees only the people on its own posts, and nothing is sold.
Who decides, and how long. The company is the controller, relying on its legitimate interest in knowing who engages with its own posts; we process the data for it. Reactions and comments are deleted 90 days after they happened, and a person with nothing left is deleted with them. Apify’s copy is deleted as soon as Speakfold has read it. If you reacted to one of these posts and want to be left out, write to hello@speakfold.com or to the company: Never show deletes what was kept at once and keeps only a fingerprint, not your name, so you aren’t added again.
Slack
When your company adds Speakfold to Slack, Speakfold finds people by their work email and writes to them in a direct message. It receives what you write to it there or with /speakfold, and files you drop in that conversation (LinkedIn files, voice clips). It never reads channels. Sign in with Slack tells Speakfold only who you are: your name and email. An admin can disconnect Slack in Settings, or remove the app in Slack.
The AI model
Speakfold uses Anthropic’s Claude models through Anthropic’s API to write drafts, openings, comments and ideas, and to read your company’s website, documents and notes. Each request carries what that task needs, such as the company context, your voice profile and the post. Under Anthropic’s commercial terms, Anthropic may not train its models on our customers’ content. We keep a record of which task ran, how long it took and its size, never the text.
Voice clips use Slack’s own transcript. When there is none and the feature is switched on, OpenAI’s speech-to-text turns the clip into text; only the text is kept.
Speakfold’s text is a suggestion. Nothing is posted until a person approves it, and drafts never invent facts: a detail only you know is left as a gap for you to fill.
Our website
We count visits to speakfold.com without cookies and without anything personal: which page, how far people read, which buttons they press, and which site or campaign tag sent the visit. No IP address, no browser fingerprint, and nothing at all when your browser asks not to be tracked.
When you book a demo, we receive your name, work email, company, team size, your message and the page you sent it from. We use them to reply and to arrange the demo.
Who helps us
These companies process data for us, under contracts that bind them to the same protection. We tell admins before we add a new one.
| Provider | What for | Where | When |
|---|---|---|---|
| Vercel | Runs the app and the website | USA, with servers in the EU and worldwide | Always |
| Supabase | The database where workspaces are kept | EU | Always |
| Anthropic | The AI model (Claude) that writes drafts, ideas and comments and reads websites and documents | USA | Always |
| Resend | Sends sign-in links, invites and reminders by email | Sent from the EU (Ireland); company in the USA | Always |
| OpenAI | Turns voice clips into text when Slack hasn’t | USA | Only when switched on for voice clips |
| Stripe | Card payments and invoices | EU (Ireland) and USA | Only when a workspace pays by card |
| Apify | Reads the public reactions and comments on the team’s LinkedIn posts for Who engaged | Company in the EU (Czech Republic); may process in the USA | Only when a company turns on Who engaged |
These are services you or your company choose to connect. They act under their own terms and privacy policies.
| Service | What for | Who | When |
|---|---|---|---|
| Posting, likes, comments and reshares you approved, from your own account | LinkedIn Ireland | When you connect your LinkedIn | |
| Slack | Speakfold’s messages to you, and what you send to it | Slack (Salesforce) | When your company adds Speakfold to Slack |
When data goes outside the EU and EEA, it goes under the EU–US Data Privacy Framework where the provider is certified, and otherwise under the European Commission’s standard contractual clauses.
Legal bases
For workspace data, your employer’s legal basis applies. For what we decide ourselves:
- Contract (GDPR article 6(1)(b)): running a customer’s account, service notices and billing.
- Legitimate interests (article 6(1)(f)): counting website visits, answering demo requests, keeping Speakfold secure, and improving it from aggregate use.
- Legal obligation (article 6(1)(c)): keeping accounting records.
How long we keep data
- Workspace data is kept as long as the workspace exists. When an admin removes a person, their profile and writing go with them. When an admin deletes the workspace, everything in it is deleted at once, the plan is cancelled and every LinkedIn connection is removed.
- Who engaged: reactions and comments are deleted 90 days after they happened, and the people with nothing left with them. Never show deletes someone at once.
- Backups made by our database provider roll over within 30 days.
- LinkedIn and Slack keys are kept until you disconnect, the key expires, or the workspace is deleted.
- Sign-in links work once and expire after 20 minutes; invites after 7 days.
- Demo requests are kept while we’re in touch about a demo, and deleted when you ask.
- Accounting records are kept as long as Finnish accounting law requires.
Your rights
You can ask to see the data about you, get a copy, correct it, delete it, limit its use or object to it, and take it with you. In Speakfold, Download my data under Settings, LinkedIn and privacy gives you your profile, voice, expertise, writing history and posts as one file, and Leave workspace is at the bottom of the same page.
For workspace data your employer decides, so ask your admin or write to hello@speakfold.com; we’ll pass it on and help them answer within the time the GDPR sets. You can also complain to the Data Protection Ombudsman in Finland (tietosuoja.fi) or the authority where you live or work.
Security
- Everything travels encrypted (HTTPS), and the database is encrypted at rest.
- LinkedIn and Slack keys are sealed with AES-256-GCM and never reach the browser.
- Sign-in is by single-use links; only a fingerprint of each link is stored.
- Every request checks the person and their workspace, so one company never sees another’s data. Admins can look at the app as a colleague to help them.
- Our team opens workspace data only to run and secure Speakfold, or when you ask us for help.
Changes
When this policy changes, the date at the top changes. If a change matters for how your data is used, we tell admins in Speakfold or by email before it applies.