Privacy Policy
This policy explains what personal data Bark collects, why, who it is shared with, and how to get it deleted. It covers both the people who use Bark and the people whose data reaches Bark through a connected social media account.
Last updated
Who is responsible
The controller for the processing described here is Blue Paw Labs, operating as Bark:
Blue Paw Labs
Rheinstrasse 3
8500 Frauenfeld
Thurgau, Switzerland
Bark is operated from Switzerland and processes data under the Swiss Federal Act on Data Protection (FADP). Where the EU General Data Protection Regulation (GDPR) applies to a user, the rights described below apply in the form the GDPR grants them.
Data you give us directly
| Data | Why we hold it | Retention |
|---|---|---|
| Name and email address | To create and identify your account, and to send service email such as invitations and notifications. | For the life of the account, then deleted. |
| Password | Never held by Bark. Authentication runs through Keycloak, which stores a salted hash; Bark receives only an identity token. | Held by Keycloak for the life of the account. |
| Profile photo | Shown in the interface so collaborators can recognise each other. Optional. | Until you replace or remove it, or the account is deleted. |
| Brand, campaign, and post content you author | It is the product. We store it so you can edit, schedule, and publish it. | Until you delete it, or the account is deleted. |
| Files you upload (images, video, documents) | Stored as assets so they can be organised, versioned, and published. | Until you delete them, or the account is deleted. |
| Billing details | Subscription tier and billing status. Card details are handled by the payment processor and never reach Bark. | Retained for the statutory Swiss accounting period of ten years. |
Data from connected social media accounts
When you connect a social media account, you authorise Bark to act on that account through the platform's official API. Bark requests the narrowest set of permissions that lets the product work, and reads only what those permissions cover. Connecting an account is always your choice, and disconnecting it stops all further access immediately.
Instagram and Facebook (Meta)
Bark uses the Instagram API with Instagram Login and the Facebook Graph API. The permissions requested, and what each one is used for:
| Permission | What Bark reads or does with it |
|---|---|
instagram_business_basic | The connected professional account’s ID, username, display name, and profile picture, so the connection can be labelled in the interface; and per-post metrics (likes, comments count, views, saves, reach) shown on the analytics and post pages. |
instagram_business_content_publish | Publishes the posts you compose in Bark to your own account, at the time you schedule. Bark never publishes anything you have not created and scheduled. |
instagram_business_manage_comments | Reads comments left on your own posts — the commenter’s username, the comment text, its timestamp, and its like count — so they appear in the unified inbox, and posts the replies you write there back to Instagram. |
instagram_business_manage_messages | Reads and sends direct messages on your connected account, so conversations can be handled alongside comments. |
Bark stores the comment and message content it retrieves, together with the commenting account's public username, because a unified inbox is not possible without holding them. It does not store commenters' email addresses, phone numbers, follower lists, or any profile data beyond the username shown next to the comment. It does not build advertising profiles of commenters, does not sell or license this data, and does not use it to train machine learning models.
Access tokens issued by Meta are encrypted at rest and used only to make API calls on behalf of your connected account. Disconnecting the account in Bark, or removing Bark from your Instagram account's Settings → Apps and Websites, revokes the token and ends all access.
Other platforms
The same principles apply to every other connector — X (Twitter), LinkedIn, TikTok, YouTube, and Google Business Profile. For each, Bark holds an encrypted access token, the connected account's public identifiers, the content you publish through it, and the engagement figures and public responses (such as reviews or comments) attached to that content.
Data collected automatically
- Operational logs and traces. Requests to the application are logged with a timestamp, the endpoint called, and an account identifier, so faults can be diagnosed. Retained for 30 days.
- Aggregate usage analytics. Page views and performance timings, collected without cookies and without cross-site tracking.
- Session cookies. Strictly necessary cookies that keep you signed in. Bark sets no advertising or third-party tracking cookies.
Artificial intelligence features
Bark offers optional AI assistance for drafting captions and suggesting content. When you use one of those features, the prompt and the relevant brand context are sent to the configured model provider — OpenAI, Anthropic, or Google — to generate a response. Bark does not send your social media inbox, your uploaded files, or your customer data to a model provider unless a feature you invoke plainly requires it. Providers are used under their commercial API terms, which do not permit training on submitted content. If you would rather no data reach a model provider, leave the AI features switched off.
Who we share data with
Bark does not sell personal data and does not share it for advertising. Data is shared only with the service providers needed to run the platform, each bound by a data processing agreement:
| Provider | Purpose | Location |
|---|---|---|
| Cloudflare | Object storage for uploaded assets, and content delivery | EU / global edge |
| Bird | Transactional email delivery | European Union |
| Meta, Google, LinkedIn, X, TikTok | Publishing to, and reading from, the accounts you connect | Per each platform’s own policy |
| OpenAI, Anthropic, Google | AI generation, only when you use an AI feature | United States |
Data may also be disclosed where the law requires it, or to establish or defend a legal claim. Transfers outside Switzerland and the EEA rely on the European Commission's standard contractual clauses or an adequacy decision.
How data is protected
- Traffic to and from the platform is encrypted in transit with TLS.
- Platform access tokens are encrypted at rest with a key held outside the database.
- Access within an organisation is governed by roles, so a member sees only the brands they have been granted.
- Passwords never reach Bark; authentication is delegated to Keycloak.
No system is perfectly secure. If a breach affects your personal data and is likely to result in a high risk to your rights, you will be notified without undue delay.
Your rights
You can ask for access to the personal data held about you, correction of anything inaccurate, deletion, restriction of processing, a portable copy, or you can object to a particular processing activity. Where processing rests on consent — AI features and platform connections — you may withdraw that consent at any time, without affecting what was lawful beforehand.
Write to privacy@barkpublish.com. Requests are answered within 30 days. If you believe your data has been handled unlawfully you may complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC), or to your local supervisory authority in the EEA.
To delete your data, see the data deletion instructions.
Children
Bark is a business tool and is not directed at children. Accounts are not knowingly created for anyone under 16. If you believe a child has provided personal data, write to privacy@barkpublish.com and it will be deleted.
Changes to this policy
Material changes will be announced by email or in the application before they take effect. The date at the top of this page records the last substantive revision.