Last Updated: June 10, 2026 | Effective Date: June 10, 2026
Welcome to Cohera ("we," "us," or "our"). Cohera is a content creator platform that helps you create, schedule, and publish content across multiple social media platforms with AI-powered assistance.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, mobile applications, and services (collectively, the "Service"). Please read this policy carefully. By using Cohera, you agree to the collection and use of information in accordance with this policy.
If you do not agree with the terms of this Privacy Policy, please do not access or use the Service.
When you register for and use Cohera, we collect:
When you use our Service, we automatically collect:
We receive information when you connect your social media accounts (detailed in Section 3) and from analytics providers that help us understand how users interact with our Service.
We use the information we collect to:
Cohera uses artificial intelligence to enhance your content creation experience. Here's how we use AI and what data is involved:
We use AI models (including OpenAI and Anthropic) to generate content suggestions, captions, and hashtag recommendations. When you use these features:
To make suggestions sound like you, Cohera references examples of your own past posts at the moment a suggestion is generated (a technique known as retrieval). Your posts are used only as reference material to personalize suggestions for you — they are never used to train or fine-tune AI models, and they are never used to generate content for other users. You can also create "tone profiles" that help describe your preferred writing style; this data is stored in your account and used only to personalize suggestions for you.
We work with the following AI providers:
These providers are contractually prohibited from using your data to train their models when accessed through our API.
We do not sell your personal information. We share your information only in the following circumstances:
We share data with trusted service providers who help us operate our Service:
When you publish content through Cohera, your content is sent to the social media platforms you've connected. Each platform processes this data according to their own privacy policies.
We may disclose your information if required by law, including:
If Cohera is involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before your information becomes subject to a different privacy policy.
We retain your information only for as long as necessary to provide our Service and fulfill the purposes described in this policy. Here are our retention periods:
| Data Type | Retention Period |
|---|---|
| Account Information | Deleted when you delete your account |
| Social Media Tokens | Deleted when you disconnect the account or delete your Cohera account |
| YouTube API Data (non-analytics) | Refreshed or deleted every 30 days per YouTube API Developer Policies |
| Published Content | Until you delete it or delete your account |
| Draft Content | Until you delete it or delete your account |
| Media Files | Until you delete them or delete your account |
| Analytics Data | While your account is active |
| Activity Logs | While your account is active |
| Payment Records | 7 years (legal requirement) |
We implement industry-standard security measures to protect your information:
While we take extensive measures to protect your data, no method of transmission or storage is 100% secure. If you believe your account has been compromised, please contact us immediately.
You can:
Depending on your location, you may have the right to:
To exercise these rights, contact us at support@coheraapp.com. We will respond within 30 days (or as required by applicable law).
Cohera is based in Australia. If you access our Service from outside Australia, your information may be transferred to, stored, and processed in Australia or other countries where our service providers operate.
For transfers from the European Economic Area (EEA), UK, or Switzerland, we rely on:
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
We do not sell or share your personal information, including for cross-context behavioral advertising. We do not share your data with advertising partners. If our practices ever change, we will update this policy and provide an opt-out mechanism before doing so.
If you are located in the European Economic Area (EEA), UK, or Switzerland, you have rights under the General Data Protection Regulation (GDPR):
We process your data based on:
Cohera is not intended for users under the age of 18. We do not knowingly collect personal information from children under 18. If you believe we have collected information from a child, please contact us immediately at support@coheraapp.com, and we will take steps to delete such information.
We may update this Privacy Policy from time to time. When we make material changes, we will:
We encourage you to review this policy periodically. Your continued use of the Service after changes become effective constitutes acceptance of the updated policy.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
We aim to respond to all inquiries within 30 days.
© 2026 Cohera. All rights reserved.
3. Social Media Platform Data
Cohera allows you to connect various social media accounts to create and publish content. When you connect a social media account, we access specific data from that platform with your explicit authorization. Below is a detailed breakdown of what we access for each platform:
X
Authentication: OAuth 2.0 with PKCE
Data We Access:
How We Use It:
X's privacy policy: https://twitter.com/privacy
YouTube (Google)
Authentication: OAuth 2.0
Scopes Requested:
youtube.readonly- View your YouTube accountyoutube.upload- Upload videos on your behalfuserinfo.email- Your email address for identificationuserinfo.profile- Your basic profile informationHow We Use It:
Google's privacy policy: https://policies.google.com/privacy
YouTube Terms of Service: https://www.youtube.com/t/terms
Cohera's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Facebook
Authentication: OAuth 2.0
Permissions Requested:
public_profile- Your name and profile picturepages_show_list- List of Pages you managepages_read_engagement- Page engagement metricspages_manage_posts- Create and manage Page postsbusiness_management- Access business assetsHow We Use It:
Meta's privacy policy: https://www.facebook.com/privacy/policy
Instagram
Authentication: OAuth 2.0 (via Facebook)
Permissions Requested:
instagram_basic- Basic Instagram account infoinstagram_content_publish- Publish content to Instagraminstagram_manage_comments- Manage comments on your postsHow We Use It:
Instagram's privacy policy: https://privacycenter.instagram.com/policy
LinkedIn
Authentication: OAuth 2.0 with OpenID Connect
Scopes Requested:
openid- OpenID Connect authenticationprofile- Your basic profile informationemail- Your email addressw_member_social- Post content on your behalfHow We Use It:
LinkedIn's privacy policy: https://www.linkedin.com/legal/privacy-policy
TikTok
Authentication: OAuth 2.0
Scopes Requested:
user.info.basic- Basic profile informationuser.info.stats- Follower, following, and video countsvideo.list- Access your video listvideo.publish- Publish videos on your behalfHow We Use It:
TikTok's privacy policy: https://www.tiktok.com/legal/privacy-policy
How We Protect Your Social Media Credentials
Your social media access tokens are encrypted using AES-256-GCM encryption before being stored in our database. We never store your social media passwords. You can revoke Cohera's access at any time by:
When you disconnect a social account, we immediately delete the associated access tokens from our systems. We will delete all associated data within 7 calendar days of receiving a deletion request or access revocation.