Setblue Social

Data Security

Last Updated: June 12, 2026

Our Commitment to Security

At Setblue Social, security is a core part of how we build and operate our platform.

We understand that users trust us with their social media accounts, content, media assets, and publishing workflows. We take that responsibility seriously and implement technical, administrative, and operational safeguards designed to protect customer information and maintain the integrity of our services.

This Security Policy provides an overview of our security practices, vulnerability reporting process, and infrastructure protections.

Security Principles

Our security program is guided by the following principles:

Protect customer data

Secure connected social media accounts

Safeguard authentication credentials

Minimize unauthorized access

Continuously monitor and improve security controls

Respond quickly to security incidents

Maintain platform reliability and availability

Infrastructure Security

Setblue Social utilizes modern cloud-based infrastructure to operate and deliver our services.

Data Storage

Our platform currently utilizes:

Cloudflare R2 for media storage

MongoDB for user account data

MongoDB for OAuth credentials and authorization data

Network Security

We implement security controls including:

HTTPS encryption for all web traffic

TLS encryption during data transmission

Secure API communications

Network access controls

Monitoring of suspicious activity

Automated security protections where available

Authentication and Account Security

We implement safeguards designed to protect user accounts, including:

Secure authentication mechanisms

Password encryption and hashing

Session management controls

Access control restrictions

Login validation processes

Protection against unauthorized account access

Users are responsible for maintaining the confidentiality of their login credentials.

OAuth and Social Media Account Security

Setblue Social allows users to connect third-party social media platforms, including:

Facebook

Instagram

Threads

LinkedIn

Pinterest

YouTube

When users authorize platform connections:

OAuth access tokens are stored in encrypted form.

We request only permissions necessary to provide publishing and scheduling functionality.

Connected account access can be revoked by users at any time.

Credentials are never shared with unauthorized third parties.

We do not store social media account passwords.

Data Encryption

We employ encryption measures to protect sensitive information.

Data in Transit

All communications between users and Setblue Social are encrypted using HTTPS and TLS protocols.

Sensitive Credentials

Sensitive authorization credentials, including OAuth tokens, are stored using encrypted storage mechanisms.

Application Security

We follow secure development practices designed to reduce security risks, including:

Security reviews during development

Access control enforcement

Authentication validation

Input validation

Error handling controls

Dependency and software maintenance

Ongoing platform updates

Media Security

User-uploaded images and videos are stored using cloud-based object storage services.

Access to stored media is restricted through application-level authorization controls and storage security mechanisms.

Access Controls

Access to internal systems and customer information is restricted to authorized personnel who require access to perform operational responsibilities.

Access permissions are granted according to business needs and reviewed periodically.

Monitoring and Incident Response

We monitor platform operations and investigate security-related events when identified.

Our response process may include:

Investigation of reported issues

Containment of security threats

Service remediation

User notification where required by applicable law

Security improvements following incident review

Responsible Vulnerability Disclosure

We appreciate the efforts of security researchers who help improve the security of our platform.

If you believe you have discovered a security vulnerability affecting Setblue Social, we encourage responsible disclosure.

Please Include

When reporting a vulnerability, please provide:

A summary of the issue

Detailed reproduction steps

Potential security impact

Proof-of-concept information (if available)

Browser and operating system details

Screenshots or supporting evidence where appropriate

Reporting Email

Please report security vulnerabilities to:

 HYPERLINK "mailto:security@setblue.com" security@setblue.com

If this email address changes, the updated contact information will be published on our website.

Responsible Disclosure Guidelines

When conducting security research involving Setblue Social, we request that you:

Avoid accessing data belonging to other users

Avoid modifying customer information

Avoid disrupting platform availability

Avoid performing denial-of-service attacks

Avoid social engineering attacks against users or staff

Give us a reasonable opportunity to investigate and resolve issues before public disclosure

We will make reasonable efforts to acknowledge legitimate reports and investigate reported vulnerabilities promptly.

Third-Party Services

Our platform relies on third-party providers and social media platform APIs.

While we evaluate providers carefully, we cannot guarantee the security practices of third-party services outside of our direct control.

Users should also review the security and privacy practices of any connected social media platforms.

User Security Responsibilities

Users can help protect their accounts by:

Using strong, unique passwords

Protecting account credentials

Reviewing connected social media accounts regularly

Revoking unused integrations

Keeping devices and browsers updated

Reporting suspicious activity immediately

Security Limitations

While we implement commercially reasonable safeguards, no system can guarantee absolute security.

No method of electronic transmission, storage, or internet-based communication is completely secure.

Accordingly, Setblue Social cannot guarantee that unauthorized access, data loss, or security breaches will never occur.

Security Policy Updates

We may update this Security Policy periodically to reflect changes in our services, infrastructure, legal requirements, or security practices.

The updated version will be posted on our website with a revised "Last Updated" date.

Contact Us

For security-related questions or vulnerability reports:

Setblue Social

Website:  "https://social.setblue.com" || “setblue.com”

Email: info@setblue.com

Address: 2nd Floor, D House, 21st Century Building, Above HDFC Bank, Ring Rd, near WTC, Udhana Darwaja, Surat, Gujarat 395002