Skip to content
Aboveboard
EN
  • English EN
  • Español ES
  • Polski PL
  • 简体中文 ZH
  • Deutsch DE
  • Français FR
Product
Product overview See the complete review-first workflow. Brand setup Build editable brand context from evidence, with review before save. Ideas Find post ideas, conversations and rising signals with evidence attached. Native composer Generate or find visuals, then shape the real post for each destination. Inbox Manage supported conversations with clear ownership. Content intelligence Turn evidence-backed patterns into the next reviewed draft. Platforms Compare official connections, costs and limits.
Pricing
Sign in Start free
Product overview Brand setup Ideas Native composer Inbox Content intelligence Platforms Pricing How it works For creators For marketing teams For agencies Security Start free Sign in
Aboveboard app icon Aboveboard
On this page
Summary (plain-language overview)1. About this policy and who it covers2. Information we collect3. How we collect information4. How we use information5. AI features and model training6. Connected platforms and your control over them7. How and with whom we share information8. Information about people who are not our users9. Legal bases for processing (EU/EEA and UK users)10. International data transfers11. Data retention12. How we keep information secure13. Your privacy rights (all users)14. EU/EEA, UK and United States rights15. Cookies and tracking technologies16. Children’s privacy17. Third-party links and services18. Team and organisation accounts19. Changes to this policy20. How to contact us

Aboveboard — Privacy Policy

Last updated: 10 August 2026 | Effective date: 10 August 2026

Summary (plain-language overview)

  • Who we are: JB Learning Systems Pty Ltd (ABN 96 696 942 935), an Australian company and the owner and operator of “Aboveboard” — a tool for drafting, approving and publishing social media content.
  • What we collect: account details, the social accounts you connect and the access tokens for them, the content you write or generate, media you upload, the engagement data we read back from platforms, usage and device data, and payment information (handled by a payment processor).
  • Why: to draft and schedule posts, publish them to the channels you connect, report on how they performed, take payment, keep the service secure, and improve the product.
  • AI: your briefs, drafts and research prompts may be processed using models accessed through Amazon Bedrock or other approved AI providers, including OpenAI. Your content is not used to train AI models — see Section 5.
  • Connected platforms: when you connect a channel we act on your behalf under the permissions you grant. You can revoke that at the platform at any time — see Section 6.
  • Who governs: the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles, with extra protections for users in the EU/EEA and UK (GDPR) and the US (CCPA/CPRA).
  • Your rights: access, correct, delete, export, object, and complain. Contact privacy@aplora.org.
  • We do not sell your personal information.

1. About this policy and who it covers

This Privacy Policy explains how JB Learning Systems Pty Ltd (“Aboveboard”, “we”, “us”, “our”) collects, uses, discloses and protects personal information when you use the Aboveboard web application, our website at aboveboard.social, and related services (together, the “Service”).

This policy applies to all users worldwide. Where local law gives you additional rights, the relevant country and region sections below apply to you in addition to the general terms.

This policy covers the personal information of our users. It also touches information about other people that necessarily passes through the Service — for example the authors of public posts our discovery features surface, or people who reply to content you publish. Section 8 deals with that separately, because your obligations and ours differ there.

2. Information we collect

2.1 Information you provide

  • Account and profile: name, email address, and the identifier from the sign-in provider you use. Optionally an organisation name, a display name and a profile image.
  • Workspace configuration: project names, brand briefs, tone-of-voice instructions, topics you mark as off limits, approval rules and team member invitations.
  • Content: posts and replies you write, edits you make to generated drafts, comments left during review, and the prompts and topics you supply to research and discovery features.
  • Media: images, video and other files you upload for attachment to posts.
  • Communications: messages you send to support, and survey or feedback responses.
  • Payment details: when you subscribe or buy credits, our payment processor collects your card and billing details. We receive confirmation and limited transaction data — the last four digits, the amount, the date — and never hold full card numbers.

2.2 Connected social accounts

When you connect a channel, we receive and store:

  • An OAuth access token and, where the platform issues one, a refresh token. These are held encrypted and are used only to perform the actions you have asked for.
  • Basic profile information for the connected account: the handle, display name, account identifier, and avatar.
  • The scopes you granted, so the app can tell you what it is and is not able to do on that channel.

We request the narrowest permission each platform offers for the features you use. We do not ask for, receive or store your password for any connected platform.

2.3 Content and results read back from platforms

To report on performance and to power discovery, we read data back from the platforms you connect:

  • Metrics for content you published through Aboveboard: impressions, likes, replies, reposts, clicks and similar counters the platform exposes.
  • Where you enable inbox or mention features, replies and mentions directed at your connected account.
  • Where you enable discovery, public posts matching the topics and sources you configure.

2.4 Information collected automatically

  • Device and technical: browser and operating system, app version, language and locale settings, IP address.
  • Usage: features used, drafts generated, credits consumed, pages viewed, session duration and in-app actions.
  • Diagnostics: error and crash logs, and performance data. Sensitive fields such as access tokens and payment details are excluded from diagnostic capture.
  • Cookies and similar technologies on our website — see Section 15.

2.5 Information from third parties

  • Sign-in providers (Section 2.1).
  • Connected social platforms (Sections 2.2 and 2.3).
  • Payment processors and fraud-prevention partners (transaction status).

3. How we collect information

We collect information directly from you when you register, configure a workspace, write or generate content, connect a channel or contact us; automatically through your use of the Service; and from the third parties listed in Section 2.5. Connecting a channel is always an explicit action you take through that platform’s own authorisation screen.

4. How we use information

PurposeExamples
Provide the ServiceGenerate drafts against your brief, run research and discovery, hold content for approval, schedule and publish to the channels you connect.
Report resultsRead back engagement for content you published and present it against the posts that earned it.
Accounts and paymentsCreate and manage your account and organisation, process subscriptions and credit purchases, send receipts, and meter credit usage.
CommunicateService and billing messages, support responses, and — where permitted — product updates you can opt out of.
Improve the ServiceDiagnose faults, analyse aggregated usage, and improve output quality (see Section 5 for the limits on AI training).
Safety and securityDetect, prevent and respond to fraud, abuse, platform-policy violations, and security incidents.
LegalComply with legal obligations and enforce our terms.

5. AI features and model training

How AI processing works. To generate drafts, replies and research summaries, the text you supply — your brief, your topics, your prompts and the drafts themselves — may be processed by models accessed through Amazon Bedrock within our AWS environment or by another approved AI provider, including OpenAI, as listed in Section 7. The provider used may change as we improve the Service. Research features may additionally send search queries to an approved web-search provider and retrieve public pages, which are then summarised with their sources cited.

Model training. Our approach is deliberately narrow:

  • We do not use your content to train AI models.
  • We configure and contract with AI providers so that text we send is not used to train their foundation models.
  • We do not sell your content, and we do not license it to third parties for any purpose.

What AI output is, and is not. Generated drafts are suggestions. They can be wrong, and they can restate a claim from a source incorrectly. Nothing is published without a person approving it, and you remain responsible for what you publish — see the Terms of Service.

Human review. We may review specific content when you ask us to for support, when we are investigating abuse or a security incident, or where law requires it. We do not routinely read customer content.

6. Connected platforms and your control over them

When you connect a channel, you authorise Aboveboard to act on your behalf within the permissions you granted. Publishing happens only for content that has been approved in the Service.

You can disconnect a channel in Aboveboard at any time, which deletes the stored tokens for it. You can also revoke our access from the platform’s own settings, which cuts us off immediately and independently of us.

Each connected platform is a separate controller of the information it holds about you and about the content you publish there. Its own privacy policy and terms govern what it does with that. Publishing content through Aboveboard makes it public on that platform, subject to that platform’s rules, and we cannot retract it once published beyond issuing a delete request the platform may or may not honour.

6.1 YouTube and Google API data

Aboveboard uses YouTube API Services when you connect a YouTube channel. With your authorisation, we identify the connected channel and retrieve and display its channel statistics, including view, subscriber and public-video counts, in your Aboveboard workspace. Aboveboard does not use this access to upload, edit, rate, comment on, reply to, moderate or delete YouTube content.

We store OAuth credentials securely and retain YouTube API Data only as needed to provide these user-facing features. We re-confirm at least every 30 days that authorisation remains valid. Channel metadata is deleted or refreshed within 30 days. Stored statistics are retained only while authorisation remains active and are displayed with their capture time.

You may disconnect YouTube in Aboveboard at any time. We immediately invalidate the Aboveboard connection, queue a programmatic Google token-revocation request for prompt delivery and retry temporary provider failures, stop further access, and delete the YouTube Authorized Data associated with that connection as soon as possible and no later than 7 calendar days. You may also revoke Aboveboard’s access through Google’s security settings. If we detect revocation through Google or an invalid authorisation token, we stop access and delete associated YouTube API Data as soon as possible and no later than 30 calendar days. If you ask us to delete stored YouTube data, we delete it as soon as possible and no later than 7 calendar days. Deleting data from Aboveboard does not delete data held by YouTube; use YouTube or an authorised client that supports deletion to delete data on YouTube.

Aboveboard’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. See the Google Privacy Policy and YouTube Terms of Service. Questions or deletion requests can be sent to privacy@aplora.org.

7. How and with whom we share information

We share personal information only as described below. We do not sell your personal information.

  • Service providers and subprocessors — vendors who host, power, secure and support the Service (table below).
  • Connected social platforms — content and instructions you have approved for publication.
  • Payment processors — to take payment and prevent fraud.
  • Legal and safety — to comply with law and lawful requests, or to protect rights, safety and property.
  • Business transfers — in a merger, acquisition or asset sale, subject to this policy.

Key categories of subprocessors:

CategoryPurposeProvidersData involved
Cloud hosting, storage and databaseRun and store the ServiceAmazon Web Services (AWS)All categories
AI — text generationGenerate drafts, replies and summariesAmazon Bedrock and approved AI providers, which may include OpenAIBriefs, prompts, drafts
AI — web searchRetrieve sources for research runsApproved AI and web-search providers, which may include OpenAISearch queries
PaymentsProcess subscriptions and credit purchasesStripeBilling data
AuthenticationSign-inGoogle OAuthAccount identifiers
EmailTransactional emailAmazon SES (AWS)Contact details
Social platformsPublish and read back resultsX, LinkedIn, Instagram, Threads, TikTok, YouTube, Reddit, Bluesky, MastodonContent you approve; connected-account data

8. Information about people who are not our users

Discovery and inbox features necessarily process information about people who are not Aboveboard users — the authors of public posts, and people who reply to or mention your connected accounts. For that information:

  • We process only what the platform makes available through its official API under the permissions you granted.
  • We use it to surface relevant conversations to you and to let you reply; we do not build advertising profiles, and we do not sell it.
  • We retain it only as long as it is useful for those features, and it is deleted with your workspace.

If you use the Service to contact people, you are responsible for doing so lawfully — including under anti-spam law such as the Australian Spam Act 2003, and under the rules of the platform you are contacting them on. See the Terms of Service.

9. Legal bases for processing (EU/EEA and UK users)

Where the GDPR or UK GDPR applies, we rely on:

  • Performance of a contract — to run your workspace, generate content, publish to your channels and take payment.
  • Legitimate interests — to secure, maintain and improve the Service, and to process information about third parties surfaced through discovery, balanced against their rights and yours.
  • Consent — for non-essential cookies and for marketing communications. You may withdraw consent at any time.
  • Legal obligation — to comply with applicable law.

10. International data transfers

Aboveboard is operated from Australia and uses providers located in other countries, including the United States. Your personal information may therefore be processed outside your country of residence.

  • Australian users (APP 8): before disclosing personal information overseas we take reasonable steps to ensure recipients handle it consistently with the Australian Privacy Principles.
  • EU/EEA and UK users: where we transfer data outside the EEA or UK we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses and the UK Addendum, or an adequacy decision.

11. Data retention

We keep personal information only as long as needed for the purposes in this policy, then delete or anonymise it. Indicative periods:

DataRetention
Account, workspace and brand briefWhile your account is active; deleted when you delete your account.
Drafts, posts and approval historyWhile your account is active; deletable by you in-app.
Connected-account tokensUntil you disconnect the channel or delete your account, whichever comes first.
Uploaded mediaWhile your account is active, subject to your plan’s media limits.
YouTube channel metadataDeleted or refreshed within 30 days while authorisation remains active; deleted within the timeframes in Section 6.1 after disconnect, revocation or a deletion request.
YouTube channel statisticsWhile authorisation remains active; each displayed snapshot includes its capture time and is deleted within the timeframes in Section 6.1 after disconnect, revocation or a deletion request.
Other engagement data read back from platformsWhile your account is active.
Discovery results about third partiesUp to 12 months, then deleted.
Payment and transaction recordsAs required by tax and financial law (commonly up to 7 years in Australia).
Support communicationsAs long as needed to resolve your enquiry and keep a support history.
Diagnostic and analytics logsUp to 24 months, aggregated where possible.

Backups are retained for up to 35 days. Data you delete may persist in a backup until it expires on that cycle.

12. How we keep information secure

We use technical and organisational measures including encryption in transit and at rest, encrypted storage of platform access tokens, access controls and least-privilege access, private (never public) media storage, monitoring, and staff confidentiality obligations.

No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme, and other regulators where applicable.

13. Your privacy rights (all users)

Subject to local law, you can: access a copy of your data; correct inaccurate data; delete your account and data; export your data; object to or restrict certain processing; and opt out of marketing. Much of this is available in-app under account settings; otherwise contact privacy@aplora.org. We will respond within the timeframe applicable law requires, and we will not discriminate against you for exercising your rights.

Australian users: under APP 12 and APP 13 you may request access to and correction of your personal information. If you have a complaint, contact us first; if you are unsatisfied you may complain to the OAIC (oaic.gov.au).

14. EU/EEA, UK and United States rights

EU/EEA and UK (GDPR). You have the rights of access, rectification, erasure, restriction, data portability and objection — including to processing based on legitimate interests and to direct marketing — and the right to withdraw consent. You may lodge a complaint with your local supervisory authority (in the UK, the ICO).

United States (CCPA/CPRA and other state laws). If you are a resident of a state with a comprehensive privacy law — for example California, Virginia, Colorado, Connecticut, Texas or Utah — you may have rights to know, access, delete and correct your information, and to opt out of “sale”, “sharing” and targeted advertising.

Categories collected under the CCPA: identifiers; customer records; commercial information (purchases); internet and usage activity; and user-generated content. We do not sell or share personal information as those terms are defined, and we do not knowingly collect the personal information of minors.

15. Cookies and tracking technologies

On our website we use essential cookies to make the site work, and — with your consent where required — analytics cookies. The application itself uses cookies and local storage strictly to keep you signed in and to remember interface preferences. You can manage non-essential cookies through our cookie banner and your browser settings. We honour Global Privacy Control (GPC) signals where required.

We do not run advertising or cross-site tracking pixels on this website.

16. Children’s privacy

Aboveboard is a business tool and is not directed to children. The Service is intended for users aged 16 and over, and we do not knowingly collect personal information from anyone under 16. If we learn we have collected such information without appropriate consent, we will delete it promptly. If you believe a child has provided us with information, contact privacy@aplora.org.

17. Third-party links and services

The Service links to third-party sites and platforms. We are not responsible for their privacy practices; review their policies before sharing information with them.

18. Team and organisation accounts

Aboveboard is designed for teams. If you join an organisation created by someone else — an employer, a client or an agency — the administrator of that organisation can see the workspaces you have access to, the content you draft and edit, and the approval actions you take. They may also remove your access. Where an organisation account is provided to you by an employer or client, that organisation may be an independent controller of some of that information, and its own privacy notice will also apply.

19. Changes to this policy

We may update this policy from time to time. We will revise the “Last updated” date and, for material changes, provide additional notice in-app or by email and, where required, seek your consent. Continued use after changes take effect means you accept the updated policy.

20. How to contact us

Aboveboard — Privacy

JB Learning Systems Pty Ltd | ABN 96 696 942 935 | ACN 696 942 935

Email: privacy@aplora.org

Australian users may also contact the OAIC (oaic.gov.au). EU/EEA and UK users may contact their local supervisory authority (UK: ICO, ico.org.uk).

On this page
Summary (plain-language overview)1. About this policy and who it covers2. Information we collect3. How we collect information4. How we use information5. AI features and model training6. Connected platforms and your control over them7. How and with whom we share information8. Information about people who are not our users9. Legal bases for processing (EU/EEA and UK users)10. International data transfers11. Data retention12. How we keep information secure13. Your privacy rights (all users)14. EU/EEA, UK and United States rights15. Cookies and tracking technologies16. Children’s privacy17. Third-party links and services18. Team and organisation accounts19. Changes to this policy20. How to contact us
Aboveboard

Turn cited ideas and supported conversations into reviewed posts and replies, with a person deciding what publishes or sends.

Start free

Product

Product tour Brand setup Ideas Native composer Inbox Content intelligence How it works Platforms Pricing Security

Solutions

For creators For marketing teams For agencies

Company & legal

Privacy policy (English) Terms of service (English) Sitemap Contact Sign in

© 2026 JB Learning Systems Pty Ltd. ABN 96 696 942 935 · ACN 696 942 935.