Privacy
What this website and the MarketThing app do with personal data, including the data they receive from LinkedIn and Bluesky.
Last updated: 18 September 2026
- Controller
- Sophie Maier and Camila Cifuentes, Rapperswil SG
- Correspondence address
- Im Grund 10A, 9012 St. Gallen, Switzerland
- hoi@marketthing.ch
The short version
This website sets no cookies, runs no analytics and loads nothing from other servers. The MarketThing app stores its data in Zurich. What the app receives from LinkedIn and Bluesky is used only to publish the posts your team approved and to show how they performed. It is never sold, never used for advertising, never used to train AI models and never sent to an AI provider. Everything else is below, in full.
Who is responsible
MarketThing is run by Sophie Maier and Camila Cifuentes, a simple partnership with a GmbH in formation and its registered office in Rapperswil SG, Switzerland. They are responsible for the processing of personal data on this website and in the app. For questions, access requests and deletions, write to hoi@marketthing.ch or to Im Grund 10A, 9012 St. Gallen, Switzerland.
This website
The website runs on Cloudflare Pages, a service of Cloudflare, Inc. When you open a page, Cloudflare processes the technical details your browser sends with every request: IP address, time of the request, the address requested, browser type and operating system. This is needed to deliver the page and to detect faults and attacks. We build no profile from it and do not combine it with other data. Cloudflare processes it on our behalf and may do so outside Switzerland.
The website sets no cookies and stores nothing in your browser. Its fonts are served from our own address, so loading a page opens no connection to Google Fonts or any other provider.
Your account in the app
The app at app.marketthing.ch is a tool for planning, approving and publishing marketing content. It is not open for sign-up: we create every account ourselves. For each account we store the email address, the workspaces it belongs to and its role in each. We store no names.
Sign-in is handled by Supabase Auth, which keeps the password in hashed form, the active sessions and the authenticator app registered as a second factor. The second factor is required for everything in the app. While you are signed in, the session is kept in your browser’s local storage; the app sets no cookies of its own. Sign-in links and codes are sent by email through Resend, Inc. The sign-in page uses Cloudflare Turnstile to tell people from bots, which processes technical details about your browser and device for that purpose.
Where the app keeps its data
The app’s database and file storage are a Supabase project in the Zurich region (eu-central-2), operated by Supabase, Inc. on our behalf. It holds workspaces, brands and audiences, ideas and drafts, pictures, approvals, publishing records, post statistics and the audit log. The app itself is delivered by Cloudflare Pages, like this website.
A workspace can connect a LinkedIn company page or a personal LinkedIn profile, so that approved posts go out without anyone copying them over. You connect on LinkedIn itself: you sign in there and grant access. We never see your LinkedIn password.
For a company page the app asks for w_organization_social, to publish posts as the page; r_organization_social, to read the page’s own posts; and rw_organization_admin, to read the statistics of the page’s posts. For a personal profile it asks for w_member_social, to publish posts as you, and r_member_postAnalytics, to read the statistics of those posts. It asks for no access to your profile details, email address, connections or messages.
The app sends LinkedIn the text of each approved post and, where the channel supports them, its pictures. It stores the ID LinkedIn gives the published post, and the post’s statistics as totals: impressions, unique impressions or members reached, clicks, reactions, comments and shares, taken 1 hour, 24 hours, 7 days and 30 days after publishing. It stores nothing about the individual people who saw, liked or commented on a post. The name and LinkedIn ID of the connected page or profile are typed in by your team, not fetched from LinkedIn.
If it is unclear whether a post went out, for instance because the connection dropped mid-request, the app reads the company page’s most recent posts to find it rather than risk posting twice. It compares them in memory and keeps only the ID of the matching post.
The access tokens LinkedIn issues are stored encrypted in Supabase Vault. Only the app’s backend can read them; no one sees them in the app. You can withdraw the app’s access at any time in your LinkedIn settings, after which nothing more is published to that channel until someone connects it again. On request, we delete the stored tokens straight away.
We do not sell data from LinkedIn or pass it to third parties, and we do not use it for advertising, for profiling or to train AI models. None of it is sent to an AI provider. It is used only to publish the posts your team approved and to show how they performed.
Bluesky
A workspace can connect a Bluesky account the same way, by signing in at Bluesky. The app asks only for permission to create posts and upload pictures: not to delete posts, follow accounts or read the account’s settings or email address. Its tokens are stored encrypted in Supabase Vault, like LinkedIn’s. Only accounts hosted by Bluesky itself can be connected.
The app sends the text of each approved post and its pictures to the account’s Bluesky server. To check whether a post went out and to show how it performed, it reads the account’s own recent posts and their counts of likes, reposts, replies and quotes from Bluesky’s public interface. It stores the post’s ID and those counts, and nothing about the people who replied or reacted.
Other channels
Instagram, Facebook, TikTok, YouTube, WhatsApp and newsletters are handled by hand: a person publishes the post and then enters its link and figures in the app. The app has no connection to these platforms and receives nothing from them.
AI providers
The app drafts text and pictures with an AI model. Each workspace brings its own API key for one of Anthropic, OpenAI, Google (Gemini), Groq or OpenRouter, and the key is stored encrypted in Supabase Vault.
When your team asks for drafts, the app sends the provider what the draft needs: the brand’s name, positioning, tone, approved claims and words to avoid; the target audiences; the idea, objective and format of the content item; the channel it is for; and any instruction typed in. For a picture it sends the brand’s name and the description of the picture from the draft’s plan. It sends no post statistics, no data from LinkedIn or Bluesky, and no email addresses.
The provider processes this under the terms of the workspace’s own account with it, and may do so outside Switzerland, in particular in the USA. The free tiers of some providers (Google, Groq, OpenRouter) may use what they receive to train their models; the app warns before such a key is stored.
Who else processes data
Supabase, Inc. (database, file storage and sign-in, Zurich region); Cloudflare, Inc. (delivery of the website and the app, and Turnstile); Resend, Inc. (sign-in emails); the AI provider the workspace chose; and LinkedIn and Bluesky, which receive the posts published to them. Cloudflare, Resend and the AI providers may process data outside Switzerland, including in the USA. Where they do, we rely on the data processing terms these providers offer, which include the standard contractual clauses recognised by the Swiss Federal Data Protection and Information Commissioner. We do not sell personal data to anyone.
How long we keep data
Accounts are kept until they are removed. If you leave a workspace or ask us to delete your account, we remove your access and your email address. LinkedIn and Bluesky tokens are kept while the channel is connected, and deleted on request.
Drafts, pictures, approvals, publishing records, post statistics, records of AI use and the audit log are kept for as long as the workspace exists. They are deliberately kept unchanged, because together they are the record of who approved and published what. When a workspace is closed, we delete it with all of its data.
Cloudflare and Supabase keep their own server logs for the periods they set.
Your rights
You can ask at any time whether we process data about you and which, have it corrected or deleted, receive it in a common format, or object to its processing. A short message to hoi@marketthing.ch is enough; no formal request is needed. If you are not satisfied with our answer, you can complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, if you live in the EEA, to your local data protection authority.
Legal basis
Processing is governed by the Swiss Federal Act on Data Protection (FADP). Where the GDPR applies as well, we rely on the performance of a contract for accounts and the app’s features (Art. 6(1)(b) GDPR); on our legitimate interest in running the website and the app securely and in keeping an audit trail (Art. 6(1)(f) GDPR); and on your consent when you connect a LinkedIn or Bluesky account (Art. 6(1)(a) GDPR), which you can withdraw at any time in that platform’s settings.
Changes
We update this policy whenever something changes in the website or the app that affects personal data. The version published here is the one that applies; its date is at the top.