Effective date: June 23, 2026
This Privacy Policy explains how WithSocialAI Inc ("WithSocialAI", "we", "us", or "our") collects, uses, discloses, and protects information in connection with MissionAligned Connect (the "Service"), available at connect.missionaligned.net.
MissionAligned Connect is a business-to-business platform that helps nonprofit organizations operate their programs, publish public pages and feeds, coordinate funding, and engage their communities. This policy applies to information we process when nonprofits and their teams use the Service, when members of the public visit organization pages, and when constituents submit information through the Service.
1. Our two roles: controller and processor
The Service is offered to nonprofit organizations ("Customer Organizations"). Depending on the data involved, we act in one of two capacities:
- As a processor / service provider. For data that a Customer Organization uploads, imports, collects from its constituents, or otherwise manages within its workspace ("Customer Data"), the Customer Organization is the data controller. We process Customer Data only on the Customer Organization's behalf and according to its instructions and our agreement with it. If you are a constituent, volunteer, donor, or community member of a nonprofit that uses the Service, that nonprofit — not WithSocialAI — determines how your information is used. Please direct requests about that data to the relevant organization; we will support them in responding.
- As a controller. For the account and contact information of the individuals who administer or use the Service (for example, organization administrators and team members), for billing information, and for usage and device data we collect to operate and improve the Service, WithSocialAI is the controller.
2. Information we collect
Account and profile information. Name, email address, password credentials, role, organization affiliation, job title, profile details, and pronouns when provided.
Organization and workspace content. Organization profiles, programs, posts, feeds, funding records, distributions, activity types, and related content that Customer Organizations create or upload.
Constituent and submission data. Information submitted through public data-collection forms and distributions, such as survey responses and contact details that constituents choose to provide. This is Customer Data processed on behalf of the relevant organization.
Socially connected content. When an organization connects an Instagram or LinkedIn account, we import that account's own public posts and aggregate engagement counts to generate reviewable feed drafts and platform signals. We import only the connected account's content; we do not scrape third-party accounts, and we do not map likes or comments to individual people. Access tokens for connected accounts are encrypted at rest.
Usage, log, and device data. IP address, browser and device type, pages viewed, referring pages, timestamps, and similar diagnostic data, including aggregate analytics collected via Vercel Analytics.
Cookies and similar technologies. We use strictly necessary cookies to keep you signed in and to secure the Service. See Section 8.
We do not intentionally collect special categories of personal data, and we ask that organizations not collect them through the Service unless they have a lawful basis to do so.
3. How we use information
We use information to:
- Provide, operate, secure, and maintain the Service;
- Authenticate users and enforce tenant isolation and access controls;
- Process constituent submissions and social imports on behalf of Customer Organizations;
- Generate dashboards, analytics, and "Mission Pulse" signals for organizations about their own activity;
- Communicate with administrators about their account, security, and Service updates;
- Provide support and respond to requests;
- Detect, prevent, and investigate fraud, abuse, and security incidents;
- Comply with legal obligations and enforce our agreements.
For account data we control, our legal bases (where the GDPR or similar laws apply) are performance of a contract, our legitimate interests in operating and securing the Service, and compliance with legal obligations.
4. How we share information
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
We disclose information only as follows:
- Within a Customer Organization's workspace. Content is visible to authorized members of that organization according to its roles and permissions.
- With service providers (subprocessors). We use vetted vendors to host and run the Service, including Supabase (database, authentication, and storage), Vercel (application hosting and analytics), and the Instagram/Meta and LinkedIn platform APIs for accounts an organization connects. These providers process data on our behalf under contractual confidentiality and security obligations.
- For public pages. Content an organization chooses to publish — such as a public organization page (`/o/...`), the network directory, or a public data-collection form — is intentionally visible to the public.
- For legal and safety reasons. Where required by law, legal process, or to protect the rights, property, or safety of WithSocialAI, our customers, or the public.
- In a business transfer. In connection with a merger, acquisition, financing, or sale of assets, subject to this policy.
5. Data retention
We retain account and Customer Data for as long as an organization's account is active or as needed to provide the Service. The Service uses a two-stage deletion model: records are first soft-deleted (archived) and then hard-deleted with a snapshot retained in an archival store for a limited period to support recovery, audit, and legal obligations. When an organization ends its use of the Service, we will delete or return Customer Data in accordance with our agreement and applicable law, except where retention is required.
6. Security
We maintain administrative, technical, and organizational safeguards designed to protect information, including row-level security for tenant isolation, encryption in transit, encryption of sensitive secrets at rest, role-based access controls, and audit logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
7. International data transfers
The Service is operated from the United States, and information may be processed in the United States and other countries where we or our subprocessors operate. Where required, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses — for transfers of personal data from the European Economic Area, the United Kingdom, or Switzerland.
8. Cookies
We use only strictly necessary cookies to provide secure authentication and to keep you signed in. We do not use advertising cookies. Aggregate usage analytics are collected in a privacy-preserving manner via Vercel Analytics. You can control cookies through your browser settings, but disabling necessary cookies will prevent you from signing in.
9. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, port, or restrict the processing of your personal information, to object to certain processing, and to withdraw consent. Residents of the EEA, UK, and Switzerland have rights under the GDPR; California residents have rights under the CCPA/CPRA, including the right not to be discriminated against for exercising them.
- For account data we control, contact us at privacy@missionaligned.net and we will respond as required by law. We will verify your identity before acting on a request.
- For Customer Data held on behalf of a nonprofit (for example, your constituent submission to an organization), please contact that organization directly. As a processor / service provider, we will assist the organization in fulfilling your request.
We do not "sell" or "share" personal information as those terms are defined under the CCPA/CPRA.
10. Children's privacy
The Service is intended for nonprofit administrators and is not directed to children under 16. We do not knowingly collect personal information from children under 16 through accounts we control. If an organization uses the Service to collect information from minors, it is responsible for obtaining any required parental or guardian consent.
11. Third-party services and links
The Service integrates with and links to third-party platforms, including Instagram/Meta and LinkedIn. Your use of those platforms is governed by their own terms and privacy policies. We are not responsible for the practices of third parties.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version with a new effective date and, where appropriate, provide additional notice. Your continued use of the Service after an update constitutes acceptance of the revised policy.
13. Contact us
WithSocialAI Inc Operator of MissionAligned Connect Email: privacy@missionaligned.net
If you are in the EEA or UK and have an unresolved concern, you have the right to lodge a complaint with your local data protection authority.