Epoch1Marketing

Privacy policy

Epoch1 Marketing and Epoch1 Runner

Last updated: 28 September 2026

Who we are

Epoch1 Pty Ltd operates Epoch1 Marketing, our internal marketing application, and Epoch1 Runner, the connected application used to research, create, publish and promote content for brands we manage, including LHFX.

This policy explains how we handle information through these applications. It does not replace the privacy policies of Facebook, Instagram, TikTok, Google or the brands' customer-facing services.

For privacy questions or requests, contact team@epoch1.ai.

Information we handle

  • Staff account information. Google sign-in information, including name, email address, account identifier and available profile image, together with application membership, role and session information.
  • Connected social accounts. Identifiers and details for authorised Facebook Pages, Instagram professional accounts, business portfolios and advertising accounts; access credentials and granted permissions needed to operate those connections.
  • Content and performance. Drafts, captions, images, videos, published post identifiers and links, advertising campaign settings, budgets and spending, and available metrics such as views, reach, likes, comment counts and clicks.
  • Public research material. Public news and social posts, account handles, public profile biographies, post text, links, thumbnails, publication dates and available engagement or follower counts used to identify relevant topics and trends.
  • Operational and correspondence records. Job history, diagnostic logs, configuration changes, and information you include when contacting us. Hosting and authentication providers may process connection information such as IP addresses, browser details and access logs.

The current application does not provide a direct-message inbox or a customer messaging service. Enabling a platform permission does not mean that every category of information covered by that permission is collected.

How we use information

We use this information to authenticate authorised staff, manage connected brand accounts, research relevant public topics, prepare and publish content, create and manage advertising, measure performance, troubleshoot jobs, protect the service and respond to requests.

Service providers and AI processing

We use service providers to operate the applications. These include Render for hosting, Supabase for authentication, database and file storage, Google for staff sign-in, Meta for Facebook and Instagram publishing, advertising and reporting, and Apify for public social-content research.

Anthropic's Claude and TypeSafe's Jev help assess research material, generate content and check language or relevance. Relevant research text, public-post details, brand instructions, draft captions and episode content may be sent to these services. This can include personal information present in public source material. These tools assist our marketing workflow; they do not determine eligibility for employment, credit or other services.

We share information with authorised staff and service providers as needed for these purposes, and may disclose information where required by law or to address fraud, security incidents or legal claims. Content we publish to social platforms is public and is also subject to the relevant platform's policies.

Cookies and security

The application uses session cookies to support staff sign-in and maintain authentication. It does not currently include third-party advertising pixels on the marketing dashboard or this privacy page.

We use access controls, authenticated service connections and restricted storage to protect information. Access to the operational dashboard is limited to authorised staff. No online service can guarantee complete security.

Storage, retention and international processing

Our service providers may store or process information outside Australia, including in the United States. Applicable privacy protections can differ between countries. Contact us for information about the providers and arrangements relevant to your information.

We retain information according to its purpose: account and connection records while needed to manage access; content and performance records while needed to operate campaigns and assess results; and logs while needed for troubleshooting, security and accountability. Legal obligations, disputes and the need to maintain backups may affect retention. The application does not currently apply one fixed automatic deletion period to all records.

Disconnecting an account prevents future access through that connection once its credentials are revoked, but does not automatically erase previously stored information or remove posts already published on a social platform.

Your choices and data deletion

You can request access to, correction of, or deletion of personal information we hold about you. Depending on the law that applies, you may also have rights to object, restrict processing, receive a portable copy of your information or withdraw consent.

To request deletion of information obtained through Facebook, Instagram or another connected service, email team@epoch1.ai with the subject "Privacy or data deletion request". Include the relevant account handle or profile URL, how you interacted with the application, and what you want deleted. Do not send passwords or access tokens.

We may ask for information to verify your identity or authority over an account before acting. We will explain the outcome and any information that must be retained for legal or security reasons. Requests are handled by our team, rather than an automated deletion form. You can also revoke the application's access through the relevant platform's settings; account owners can ask us to remove a connection.

We can address information in our own systems. A request to us does not automatically delete your social-media account or copies held independently by a platform or other people.

Questions, complaints and updates

Contact Epoch1 Pty Ltd at team@epoch1.ai to raise a concern about how we handle information. We will review your complaint and respond. You may also contact the privacy regulator in your jurisdiction, including the Office of the Australian Information Commissioner where applicable.

We may update this policy as the applications or our information practices change. The date above identifies the current version.