Somera Privacy Policy
Last updated: 2026.07.07
1. Who we are
Somera Sosyal Medya Araştırma Ölçümleme ve Analiz Anonim Şirketi ("Somera", "we", "us") provides tools to connect, moderate, and manage your authorized third party online accounts and to monitor public digital media content in line with each platform's policies.
This Policy applies to the Services provided under this website's domain and under any other domain operated by Somera. This single Policy governs your use of the Services on any Somera domain.
Contact here. You can also contact us at this address with any inquiry or request regarding your information, including questions about what data we hold about you and requests to access, correct, or delete it.
2. How we connect to third party Platforms
When you connect a Platform account, you authorize our app via OAuth or an equivalent authorization flow. Somera requests only the permissions that are necessary to moderate accounts and content that you administer on each Platform. You can revoke Somera's access at any time from the relevant Platform's settings.
3. Categories of data we process
This section explains, clearly and comprehensively, what user information Somera accesses, collects, stores, and otherwise uses, including API Data relating to users that Somera obtains from connected Platforms such as YouTube.
"Account and profile": name, email address, organization details, account settings, and preferences that you provide when you register for or configure the Services.
"Connected accounts": OAuth identifiers, access and refresh tokens, the authorization scopes you grant, and the Platform account, page, and channel IDs you authorize. Somera does not collect or store your third party passwords.
"Service data": configuration settings, application and security logs, and usage events, including standard request metadata (such as IP address and browser type) recorded in server logs when you use the Services. Beyond the strictly necessary authentication cookies and local storage described in section 11, Somera does not collect information from your device through cookies or similar technologies.
"Platform": Third party service you connect to Somera.
"Platform Data": Content and metadata retrieved from or sent to a Platform through an authorized integration, including posts, comments, reviews, messages, usernames, ids, timestamps, reaction counts, and your moderation actions.
When you connect a Platform account, the Platform Data that Somera accesses, collects, and stores includes, depending on the Platform and the permissions you grant:
- Account, page, and channel information for the accounts you authorize: identifiers, names, handles, profile images, and connection status.
- Content metadata for the accounts you authorize: post, video, and review identifiers, titles, descriptions, captions, tags, thumbnails, publication dates, and privacy or visibility status.
- Engagement and audience content on the accounts you administer: comments, comment threads, replies, mentions, reviews, and messages, together with the public author display name, author identifier, text, timestamps, and reaction or like counts.
- Analytics, reporting, and statistical data for the accounts you authorize, such as view counts, engagement counts, and follower or subscriber counts.
- Content that you create or upload through Somera for publication on a Platform, such as posts, replies, and videos, including the title, description, and the privacy status you select.
- Your moderation actions, such as approving, replying to, hiding, or deleting content, and the related audit trail.
- Publicly available content collected for the monitoring features described in the Terms of Service, only as permitted by each Platform.
YouTube API Data specifically: where you connect a YouTube channel, Somera uses YouTube API Services to access and use the following API Data relating to you and your channel. Somera does not store this API Data in Somera systems: every time you open a channel, video, comment thread, or report in Somera, the data is queried fresh, in real time, from YouTube API Services, and historical data is likewise queried live at the moment you request it and is not retained. The only YouTube related item Somera stores is your authorization token, described below and in section 6.
- OAuth authorization tokens issued by Google when you connect your account, and the Google account identifier and granted scopes associated with them.
- Channel data for the channels you authorize: channel ID, title, description, thumbnails, and subscriber and view statistics.
- Video data for videos on the channels you authorize: video IDs, titles, descriptions, tags, thumbnails, durations, publication dates, view, like, and comment counts, and each video's privacy status (Public, Unlisted, or Private).
- Comments and comment threads on the videos and channels you authorize: comment text, author display name, author channel ID, timestamps, like counts, and moderation status.
- Videos and video metadata that you upload to YouTube through Somera, including the video file, title, description, and the privacy status you select before upload (this is content you provide to Somera for publication and is handled as Customer Content, not as data retrieved from YouTube).
- Analytics and reporting data for the channels you authorize, where you enable reporting features.
Somera does not access, collect, or store YouTube data outside the scopes you grant, and does not collect your YouTube viewing or watch history.
"Services": Somera websites, applications, APIs, dashboards, and related services.
"Policy": applies to Somera websites, applications, and services. Somera's Privacy Policy forms part of its wider Terms of Service. Both the Terms of Service and Privacy Policy apply to your use of the Services.
Somera does not collect or store your Platform passwords.
4. Purposes and legal bases: how we use and process your information
We use and process personal data and Platform Data, including API Data obtained through YouTube API Services and other Platform APIs, only for the following purposes:
- Providing the Services you request: displaying your connected accounts, content, comments, reviews, and messages in your Somera dashboard so that you can monitor and moderate them.
- Executing the actions you take in Somera on the relevant Platform, such as publishing posts, uploading videos, replying to or moderating comments, and responding to reviews.
- Producing analytics and reports about the accounts you authorize, for your own use.
- Operating, securing, and debugging the Services, including authentication, abuse prevention, audit trails, and incident response.
- Complying with each Platform's terms, developer policies, and data use rules, including data refresh and deletion obligations.
- Meeting our legal obligations and responding to lawful requests.
We do not use personal data or Platform Data for advertising, for sale to third parties, to determine credit-worthiness or for lending purposes, or to train general purpose artificial intelligence or machine learning models. Our legal bases include performance of contract, legitimate interests in providing and securing the Services, consent where required, and compliance with law.
5. OAuth and tokens
We use OAuth or the platform's equivalent to connect accounts. We request the minimum necessary scopes and document them. Tokens are encrypted at rest, rotated per platform rules, and deleted when you disconnect or after inactivity. You can revoke access through platform settings at any time.
6. Retention and deletion
A user becomes "inactive" when any of these occurs: 1) no use for more than 3 months; or 2) non payment for 30 days; or 3) Somera terminates for breach; or 4) the customer cancels. Inactive users enter a 30 day grace period. At the end of that period, the user account and associated Platform Data are deleted from Somera systems. Logs retained for security or legal reasons are minimized and are not used to provide the Services.
Platform specific retention, refresh, and deletion periods. In addition to the general rule above, Somera applies the following stricter rules required by the Platforms:
- Authorization tokens: stored only for as long as your connection remains active and used only for purposes consistent with the consent you granted. Tokens are deleted when you disconnect a Platform, when you revoke access in the Platform's settings, or when your account is deleted.
- YouTube API Data: Somera does not store YouTube API Data in Somera systems. All YouTube data shown in Somera, including historical and analytics data, is queried fresh from YouTube API Services in real time each time you request it and is not retained after it is displayed. As a result, Somera always displays the most updated API Data available through YouTube API Services, well within the 30 calendar day storage and refresh limits of the YouTube API Services Developer Policies, and historical data is presented accurately in the context of time. The only YouTube related item Somera stores is your authorization token, kept only while your connection is active and used only for purposes consistent with the consent you granted.
- YouTube deletion on revocation or request: if you revoke Somera's access through Google security settings, disconnect your YouTube account, or ask us to delete your data, Somera deletes your stored authorization tokens and any other data relating to your YouTube connection as soon as possible and in any event within 7 calendar days. Because YouTube API Data is not stored, no API Data remains in Somera systems to delete.
- X: if content is deleted, modified, or made private or protected on X, Somera deletes or modifies its stored copy as soon as reasonably possible, and within 24 hours after receiving a request to do so by X or the applicable X account owner.
- LinkedIn: Somera deletes content collected through LinkedIn APIs on behalf of a user immediately upon that user's request, when the user closes their account with Somera, or when LinkedIn requires deletion. LinkedIn profile data is refreshed only when the member is actually using the application and not on an automated schedule.
- Meta (Facebook and Instagram): Somera deletes Platform Data as soon as reasonably possible when it is no longer necessary for a legitimate business purpose consistent with the features you use, when you request deletion or no longer have an account, when Meta requests deletion for the protection of users, or when required by law.
7. Data location and international transfers
Somera is a Turkish company with servers in Türkiye and in the European Union. When you authorize connections to third party Platforms, data may be transmitted to or from those Platforms' servers, many of which are in the United States or other countries outside Türkiye and the EU. Those transmissions are governed by the Platform's own terms and policies. Somera limits its own processing to what is necessary to provide the Services and uses contractual safeguards and technical measures appropriate to the transfer context. Nothing in this Policy expands Somera's responsibility for independent Platform processing.
8. AI assistance providers
To help analyze non personal content, we may use third party AI services from OpenAI, Google, or Anthropic. We do not share personal information with these providers and we take steps to avoid sending personal data in prompts. We do not use Platform Data, including YouTube API Data and X content, to train or fine-tune general purpose artificial intelligence or machine learning models, and we do not permit third parties to do so.
9. Apps and app store reviews
Somera provides web applications including progressive web apps. If you use Somera to draft or post responses to app store reviews, your use remains subject to the relevant store's rules for ratings, reviews, and responses.
10. Sharing of information
This section explains how user information, including API Data obtained from connected Platforms, is shared with internal and external parties.
Internal sharing: within Somera, access to your information is limited to authorized Somera personnel who need it, on a need to know basis, to operate, support, secure, or improve the Services, and who are bound by confidentiality obligations. We do not share your information with contractors or affiliates.
External sharing: we share information with external parties only in the following cases:
- Service providers and subprocessors that host, secure, or support the Services (for example hosting and infrastructure providers in Türkiye and the European Union), under contracts that require confidentiality and appropriate security, and only to the extent needed to provide their services to us.
- The connected Platforms themselves, when we transmit content or actions back to a Platform at your direction, for example when you publish a post, upload a video, or reply to a comment through Somera.
- Legal and safety disclosures: to comply with law or legal process; to protect our rights, users, or the public; or to investigate abuse, fraud, or security incidents.
- Corporate transactions: in connection with a merger, acquisition, or sale of assets, subject to this Policy.
- At your direction: to execute your instructions or fulfill your requests, for example reports you choose to export or share.
We do not sell personal data or Platform Data. We do not transfer personal data or Platform Data to advertising platforms, data brokers, or information resellers, and we do not share it for serving advertisements, including retargeted, personalized, or interest based advertising. We do not share YouTube API Data with any internal or external party except as described in this section.
11. Cookies and related technologies
Somera uses only strictly necessary, first party cookies and similar technologies (such as browser local storage) for authentication and session purposes: keeping you signed in, securing your session, and remembering essential application state. These are required for the Services to function and are not used to track you. Somera does not use advertising, tracking, performance, or analytics cookies, does not run third party analytics services, and does not otherwise store, access, or collect information on or from your devices or allow third parties to do so. One exception applies: when you sign in to or connect a third party Platform (for example Facebook), that Platform's own login components and authorization pages run as part of the flow you request and may store their own cookies under that Platform's privacy policy, which Somera does not control. You can manage cookies in your browser settings; disabling strictly necessary cookies or local storage may prevent sign in.
12. Security
We apply administrative, technical, and organizational measures, including encryption at rest for tokens, TLS in transit, least privilege access, monitoring, and incident response procedures.
13. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, or portability of your personal data, and you may object to certain processing. You may revoke Platform permissions at any time from the relevant Platform. For Google and YouTube, you can revoke Somera's access via the Google security settings page at https://security.google.com/settings/security/permissions (also reachable at https://myaccount.google.com/permissions); after revocation, Somera deletes your stored authorization tokens and any other data relating to your YouTube connection within 7 calendar days. Somera does not otherwise store YouTube API Data. For any inquiry or request regarding your information, contact here or use the Deletion Request page.
14. Children
Somera is not directed to children. We do not knowingly process data of children under applicable age thresholds.
15. Changes to this Policy
We may update this Policy from time to time. We will post the updated version and change the "Last updated" date. Material changes may be notified through the Services or by email where required.
16. Platform specific disclosures and related links
By connecting a platform to Somera or using any Somera feature that accesses that platform's content or data, you acknowledge and agree that your use is governed by that platform's own terms, policies, and community rules; and you further acknowledge and agree that where Somera uses that platform's APIs or SDKs, your use of Somera in connection with that platform is subject to the platform's applicable API terms, developer policies, and data use rules.
YouTube: Somera uses YouTube API Services. By using Somera features that access YouTube content or data, you are agreeing to be bound by the YouTube Terms of Service at https://www.youtube.com/t/terms. The Google Privacy Policy at http://www.google.com/policies/privacy also applies to Google's handling of your data, and we encourage you to read it.
What YouTube data Somera accesses, collects, stores, and uses: Somera accesses and uses the YouTube API Data listed in section 3 (channel data; video data including privacy status; comments and comment threads; videos you upload through Somera; and analytics for the channels you authorize), and stores only your authorization tokens — all other YouTube API Data is queried fresh from YouTube API Services each time you request it and is not stored in Somera systems. How Somera uses, processes, and shares that data: only for the purposes listed in section 4 (displaying and moderating your channels, videos, and comments; executing your publishing and moderation actions on YouTube; reporting on your channels; and securing the Services), and it is shared only with the internal and external parties described in section 10. Somera does not sell YouTube API Data and does not use it for advertising or model training.
Somera's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Advertising and third party content: Somera does not allow third parties to serve content, including advertisements, within the Somera interfaces that display YouTube API Data.
Device storage: as described in section 11, Somera stores on your device only strictly necessary, first party authentication cookies and local storage used to keep you signed in, including on pages and features that use YouTube API Services. Somera does not use analytics, advertising, or tracking technologies on those pages and does not allow third parties to store, access, or collect information from your device, other than a Platform's own login components when you initiate a connection flow.
Video uploads and privacy status: when you upload a video to YouTube through Somera, Somera displays a privacy status selector and you choose the video's privacy status (Public, Unlisted, or Private) before the upload is submitted. Somera applies exactly the privacy status you select.
Storage, refresh, and deletion: Somera does not store YouTube API Data — every view in Somera is served by a fresh, real time query to YouTube API Services, including historical and analytics views, so dashboards always display the most updated API Data available. The only stored item is your authorization token, which is kept while your connection is active and is deleted, together with any other data relating to your YouTube connection, within 7 calendar days after you revoke access or request deletion. Somera operates its YouTube API Client under a single, dedicated Google API project.
Revoking access: you can revoke Somera's access to your YouTube and Google data at any time via the Google security settings page at https://security.google.com/settings/security/permissions or https://myaccount.google.com/permissions.
https://www.google.com/policies/privacy
https://www.youtube.com/t/terms
https://developers.google.com/youtube/terms/api-services-terms-of-service
https://developers.google.com/youtube/terms/developer-policies
https://developers.google.com/terms/api-services-user-data-policy
Meta (Facebook and Instagram): We host a public Data Deletion Instructions page and honor deletion requests. We request and use only the data necessary for the features you enable. We delete Meta Platform Data as soon as reasonably possible when it is no longer necessary for a legitimate business purpose, when you request deletion or no longer have an account, when Meta requests deletion for the protection of users, or when required by law. We do not sell, license, or purchase Platform Data; we do not use Platform Data for surveillance, including for law enforcement or national security purposes; we do not use Platform Data to discriminate or to build user profiles without valid consent.
https://www.facebook.com/privacy/policy/
https://developers.facebook.com/terms
https://developers.facebook.com/policy
X: We follow X developer and platform policies and do not use X content to train general purpose AI models. The X content we collect, how we use and share it (including with X when you post or reply through Somera), and how you can contact us with inquiries and requests regarding your information are described in sections 3, 4, 10, and 1 of this Policy. If content is deleted, modified, or made protected on X, we delete or modify our stored copy as soon as reasonably possible and within 24 hours after receiving a request from X or the applicable account owner, and we only show content from protected accounts to people with permission to view it. We do not associate X content with off-X identifiers except with the person's express opt in consent or based on information they provided directly or that is publicly available on X. We do not use X data for surveillance purposes.
https://developer.x.com/en/developer-terms/agreement-and-policy
LinkedIn: Our LinkedIn integrations, if enabled, are limited to approved use cases and are subject to access tier restrictions. We delete content collected through LinkedIn APIs on your behalf immediately upon your request or when you close your Somera account, and we refresh LinkedIn profile data only while you are actually using the application, not on an automated schedule. We do not sell, share, or transfer LinkedIn content to third parties and we do not use it in or for targeting advertisements. You may withdraw your consent at any time by disconnecting LinkedIn in Somera or in your LinkedIn settings, and you may request deletion via the Deletion Request page.
https://www.linkedin.com/legal/privacy-policy
https://www.linkedin.com/legal/l/api-terms-of-use
TikTok: We use OAuth 2.0, request the minimum scopes, and follow TikTok Developer Guidelines and rate limits.
https://www.tiktok.com/legal/page/us/privacy-policy/en
https://developers.tiktok.com/doc/our-guidelines-developer-guidelines
https://developers.tiktok.com/doc/app-review-guidelines
Google and Google Business Profile: We follow the Google API Services User Data Policy and request minimum scopes. Somera's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
https://www.google.com/policies/privacy
https://developers.google.com/terms/api-services-user-data-policy
https://developers.google.com/my-business/content/terms
https://developers.google.com/my-business/content/policies
WhatsApp Business Platform: We process phone numbers and message content to deliver messages on your behalf only with documented opt in. We honor opt out messages and deletion requests and require customers to maintain proof of opt in.
https://www.whatsapp.com/legal/privacy-policy
https://www.whatsapp.com/legal/business-app-privacy-policy
https://www.whatsapp.com/legal/business-terms
https://www.whatsapp.com/legal/business-solution-terms
Telegram: We follow Telegram API and Bot Platform terms.
https://core.telegram.org/api/terms
https://telegram.org/tos/bot-developers
Bluesky: We register per instance as required, follow instance policies, and process only permitted data.
https://bsky.social/about/support/privacy-policy
https://docs.bsky.app/docs/support/developer-guidelines
Mastodon: We register per instance as required, follow instance policies, and process only permitted data.
https://mastodon.social/privacy-policy
https://docs.joinmastodon.org/entities/PrivacyPolicy
https://docs.joinmastodon.org/api
VKontakte: Integrations are via official APIs and subject to VK rules.
Apple App Store: If you respond to reviews using Somera, your use may remain subject to the Apple App Store policies for ratings, reviews, and responses.
https://www.apple.com/legal/privacy/data/en/app-store
https://developer.apple.com/app-store/app-privacy-details
https://developer.apple.com/app-store/review/guidelines
Google Play: If you respond to reviews using Somera, your use may remain subject to the Google Play policies for ratings, reviews, and responses.
https://policies.google.com/privacy
https://support.google.com/googleplay/android-developer/answer/16543315
Huawei App Gallery: If you respond to reviews using Somera, your use may remain subject to the Huawei AppGallery policies for ratings, reviews, and responses.
https://developer.huawei.com/consumer/en/doc/app/AGCPrivacyStatement
https://developer.huawei.com/consumer/en/doc/AppGallery-connect-Guides/agcapi-overview
17. Deletion requests
For data deletion or account removal, check this page. Somera deletes the account and Platform Data at the end of the 30 day grace period after an account becomes inactive as described in section 6. Independently of that grace period, if you revoke a Platform authorization or request deletion, Somera deletes the related stored Platform Data within the platform specific windows in section 6, including within 7 calendar days for your YouTube connection — for YouTube, only authorization tokens are stored; YouTube API Data itself is never stored in Somera systems.