Privacy Policy
Last updated: 8 September 2026
This Privacy Policy explains how Fugu Marketing Services Pvt Limited (“the Company”, “we”, “us”, or “our”) collects, uses, stores, shares, and deletes information in connection with Fugu Social — our social-media content platform, also branded Tokyo Labs (the “Service”). It includes specific detail about data we access from Meta Platforms (Facebook and Instagram), because our users connect their own Facebook Pages and Instagram Business accounts to publish content through the Service.
Fugu Social is a business-to-business tool used by agencies and brand teams to plan, create, review, schedule, and publish social-media content to accounts they own or are authorised to manage. By using the Service, you agree to the practices described in this policy.
1. Who we are
The Service is operated by Fugu Marketing Services Pvt Limited, a company incorporated in India, which also operates the Fugumobile brand. The Company is the data controller for the account and business information described below. Where our customers (for example, an agency) connect their own or their clients’ social accounts and load content into the Service, that customer is the controller of the content and audience data, and the Company acts as a processor handling that data on their behalf and under their instructions.
2. Information we collect
We collect the following categories of information:
a. Account and team information
- Names, email addresses, and roles of the people you invite to a workspace.
- Authentication data, including a securely hashed password. We never store passwords in plain text.
- Workspace, organisation, and brand details you create (for example, brand name, category, market, and brand guidelines).
b. Content you create or upload
- Draft and published posts, captions, hashtags, and notes.
- Images you upload or generate within the Service, and their descriptions and tags.
- Review and approval decisions, comments, and scheduling details.
c. Connected channel data
- The access credentials and tokens needed to publish to the channels you connect (for example, Facebook Pages, Instagram Business accounts, Bluesky, and Telegram). These credentials are encrypted at rest.
- Basic account identifiers and display information for the connected channels (for example, a Page name and ID, or an Instagram Business account username and ID).
- Publishing results and performance metrics that a connected platform returns for content published through the Service.
d. Technical and usage information
- Log data such as IP address, browser type, timestamps, and actions taken in the Service, used to operate, secure, and troubleshoot the Service.
- Strictly necessary cookies and similar technologies used to keep you signed in and to remember basic preferences. We do not use the Service to serve third-party advertising.
3. Facebook & Instagram data
When you choose to connect a Facebook Page or an Instagram Business account, you authorise the connection through Facebook Login. We request only the permissions we need to provide the publishing features you use:
| Permission | Why we use it |
|---|---|
pages_show_list | To show you the Facebook Pages you manage so you can choose which one to connect. |
pages_read_engagement | To read basic Page information needed to confirm the connection is healthy and to display it in the Service. |
pages_manage_posts | To publish and schedule the posts you create to the Facebook Page you connected. |
instagram_basic | To identify the Instagram Business account linked to your Page and confirm the connection. |
instagram_content_publish | To publish and schedule the images and captions you create to your Instagram Business account. |
We use this data only to provide the features you request within the Service — connecting an account, showing its status, and publishing or scheduling the content you approve. Access tokens obtained through Facebook Login are stored in encrypted form and are used solely to act on your instructions.
We do not sell data obtained through Facebook or Instagram; use it for advertising or profiling; transfer it to data brokers; or use it for any purpose other than operating the features described here, consistent with the Meta Platform Terms and Developer Policies.
4. How we use information
We use the information above to:
- Provide, maintain, and secure the Service and your account.
- Create, review, schedule, and publish the content you produce to the channels you connect.
- Generate optional AI-assisted content drafts and image suggestions at your request. To do this, the text prompts and content you submit for generation may be processed by third-party AI providers acting as our service providers, solely to return the requested draft.
- Show connection status, publishing results, and performance metrics.
- Respond to your requests and provide support.
- Detect, prevent, and address abuse, security incidents, and technical problems.
- Comply with legal obligations.
5. How we share information
We do not sell your personal information. We share information only as follows:
- With the platforms you connect. When you publish or schedule content, we send that content and the necessary tokens to the relevant platform (for example, Facebook or Instagram) to carry out your instruction.
- With service providers (subprocessors). We use trusted providers for hosting/infrastructure and for the optional AI drafting features. They may process information only to provide services to us and under obligations of confidentiality and security.
- Within your organisation. Content and activity are visible to the members of your workspace according to their roles.
- For legal reasons. We may disclose information if required by law or to protect the rights, safety, and security of users, the public, or the Company.
- In a business transfer. If the Company is involved in a merger, acquisition, or asset sale, information may be transferred subject to this policy.
6. Data retention
We keep information for as long as your account or workspace is active and as needed to provide the Service. Connected-channel access tokens are retained only while the channel remains connected; when you disconnect a channel, its stored credentials are deleted from the Service. We may retain limited records where necessary to comply with legal obligations, resolve disputes, or enforce our agreements. When information is no longer needed, we delete or de-identify it.
7. Data deletion & your choices
You are in control of the data you connect and create:
- Disconnect a channel at any time from the Channels page in the Service. Disconnecting removes the stored access credentials for that channel.
- Revoke access from Facebook at any time in your Facebook settings under Settings & privacy → Settings → Business Integrations (or Apps and Websites), which invalidates the tokens we hold.
- Request deletion of your data. You can ask us to delete your personal information and connected-platform data. Full instructions are on our Data Deletion page.
Depending on where you live, you may also have rights to access, correct, port, or object to the processing of your personal information. To exercise any of these rights, contact us using the details below.
8. Security
We take reasonable technical and organisational measures to protect information. Data in transit is protected with encryption (HTTPS/TLS). Connected-channel credentials and access tokens are encrypted at rest, and the encryption key is stored separately from the database. Access to production systems is limited to authorised personnel. No method of transmission or storage is completely secure, but we work to protect your information and to respond promptly to any incident.
9. International transfers
The Company operates internationally, including for the China and India markets. Your information may be processed in countries other than your own. Where required, we take steps to ensure appropriate safeguards are in place for such transfers.
10. Children
The Service is intended for business use by adults and is not directed to children. We do not knowingly collect personal information from anyone under the age of 16. If you believe a child has provided us with personal information, please contact us and we will delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Service after an update means you accept the revised policy.
12. Contact us
If you have questions about this policy or wish to exercise your rights, contact us at:
Fugu Marketing Services Pvt Limited — Privacy
Email: privacy@fugumobile.com
India · www.fugumobile.com