Somera Privacy Policy

Last updated: 2026.07.07

1. Who we are

Somera Sosyal Medya Araştırma Ölçümleme ve Analiz Anonim Şirketi ("Somera", "we", "us") provides tools to connect, moderate, and manage your authorized third party online accounts and to monitor public digital media content in line with each platform's policies.

This Policy applies to the Services provided under this website's domain and under any other domain operated by Somera. This single Policy governs your use of the Services on any Somera domain.

Contact here. You can also contact us at this address with any inquiry or request regarding your information, including questions about what data we hold about you and requests to access, correct, or delete it.

2. How we connect to third party Platforms

When you connect a Platform account, you authorize our app via OAuth or an equivalent authorization flow. Somera requests only the permissions that are necessary to moderate accounts and content that you administer on each Platform. You can revoke Somera's access at any time from the relevant Platform's settings.

3. Categories of data we process

This section explains, clearly and comprehensively, what user information Somera accesses, collects, stores, and otherwise uses, including API Data relating to users that Somera obtains from connected Platforms such as YouTube.

"Account and profile": name, email address, organization details, account settings, and preferences that you provide when you register for or configure the Services.

"Connected accounts": OAuth identifiers, access and refresh tokens, the authorization scopes you grant, and the Platform account, page, and channel IDs you authorize. Somera does not collect or store your third party passwords.

"Service data": configuration settings, application and security logs, and usage events, including standard request metadata (such as IP address and browser type) recorded in server logs when you use the Services. Beyond the strictly necessary authentication cookies and local storage described in section 11, Somera does not collect information from your device through cookies or similar technologies.

"Platform": Third party service you connect to Somera.

"Platform Data": Content and metadata retrieved from or sent to a Platform through an authorized integration, including posts, comments, reviews, messages, usernames, ids, timestamps, reaction counts, and your moderation actions.

When you connect a Platform account, the Platform Data that Somera accesses, collects, and stores includes, depending on the Platform and the permissions you grant:

YouTube API Data specifically: where you connect a YouTube channel, Somera uses YouTube API Services to access and use the following API Data relating to you and your channel. Somera does not store this API Data in Somera systems: every time you open a channel, video, comment thread, or report in Somera, the data is queried fresh, in real time, from YouTube API Services, and historical data is likewise queried live at the moment you request it and is not retained. The only YouTube related item Somera stores is your authorization token, described below and in section 6.

Somera does not access, collect, or store YouTube data outside the scopes you grant, and does not collect your YouTube viewing or watch history.

"Services": Somera websites, applications, APIs, dashboards, and related services.

"Policy": applies to Somera websites, applications, and services. Somera's Privacy Policy forms part of its wider Terms of Service. Both the Terms of Service and Privacy Policy apply to your use of the Services.

Somera does not collect or store your Platform passwords.

4. Purposes and legal bases: how we use and process your information

We use and process personal data and Platform Data, including API Data obtained through YouTube API Services and other Platform APIs, only for the following purposes:

We do not use personal data or Platform Data for advertising, for sale to third parties, to determine credit-worthiness or for lending purposes, or to train general purpose artificial intelligence or machine learning models. Our legal bases include performance of contract, legitimate interests in providing and securing the Services, consent where required, and compliance with law.

5. OAuth and tokens

We use OAuth or the platform's equivalent to connect accounts. We request the minimum necessary scopes and document them. Tokens are encrypted at rest, rotated per platform rules, and deleted when you disconnect or after inactivity. You can revoke access through platform settings at any time.

6. Retention and deletion

A user becomes "inactive" when any of these occurs: 1) no use for more than 3 months; or 2) non payment for 30 days; or 3) Somera terminates for breach; or 4) the customer cancels. Inactive users enter a 30 day grace period. At the end of that period, the user account and associated Platform Data are deleted from Somera systems. Logs retained for security or legal reasons are minimized and are not used to provide the Services.

Platform specific retention, refresh, and deletion periods. In addition to the general rule above, Somera applies the following stricter rules required by the Platforms:

7. Data location and international transfers

Somera is a Turkish company with servers in Türkiye and in the European Union. When you authorize connections to third party Platforms, data may be transmitted to or from those Platforms' servers, many of which are in the United States or other countries outside Türkiye and the EU. Those transmissions are governed by the Platform's own terms and policies. Somera limits its own processing to what is necessary to provide the Services and uses contractual safeguards and technical measures appropriate to the transfer context. Nothing in this Policy expands Somera's responsibility for independent Platform processing.

8. AI assistance providers

To help analyze non personal content, we may use third party AI services from OpenAI, Google, or Anthropic. We do not share personal information with these providers and we take steps to avoid sending personal data in prompts. We do not use Platform Data, including YouTube API Data and X content, to train or fine-tune general purpose artificial intelligence or machine learning models, and we do not permit third parties to do so.

9. Apps and app store reviews

Somera provides web applications including progressive web apps. If you use Somera to draft or post responses to app store reviews, your use remains subject to the relevant store's rules for ratings, reviews, and responses.

10. Sharing of information

This section explains how user information, including API Data obtained from connected Platforms, is shared with internal and external parties.

Internal sharing: within Somera, access to your information is limited to authorized Somera personnel who need it, on a need to know basis, to operate, support, secure, or improve the Services, and who are bound by confidentiality obligations. We do not share your information with contractors or affiliates.

External sharing: we share information with external parties only in the following cases:

We do not sell personal data or Platform Data. We do not transfer personal data or Platform Data to advertising platforms, data brokers, or information resellers, and we do not share it for serving advertisements, including retargeted, personalized, or interest based advertising. We do not share YouTube API Data with any internal or external party except as described in this section.

11. Cookies and related technologies

Somera uses only strictly necessary, first party cookies and similar technologies (such as browser local storage) for authentication and session purposes: keeping you signed in, securing your session, and remembering essential application state. These are required for the Services to function and are not used to track you. Somera does not use advertising, tracking, performance, or analytics cookies, does not run third party analytics services, and does not otherwise store, access, or collect information on or from your devices or allow third parties to do so. One exception applies: when you sign in to or connect a third party Platform (for example Facebook), that Platform's own login components and authorization pages run as part of the flow you request and may store their own cookies under that Platform's privacy policy, which Somera does not control. You can manage cookies in your browser settings; disabling strictly necessary cookies or local storage may prevent sign in.

12. Security

We apply administrative, technical, and organizational measures, including encryption at rest for tokens, TLS in transit, least privilege access, monitoring, and incident response procedures.

13. Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, or portability of your personal data, and you may object to certain processing. You may revoke Platform permissions at any time from the relevant Platform. For Google and YouTube, you can revoke Somera's access via the Google security settings page at https://security.google.com/settings/security/permissions (also reachable at https://myaccount.google.com/permissions); after revocation, Somera deletes your stored authorization tokens and any other data relating to your YouTube connection within 7 calendar days. Somera does not otherwise store YouTube API Data. For any inquiry or request regarding your information, contact here or use the Deletion Request page.

14. Children

Somera is not directed to children. We do not knowingly process data of children under applicable age thresholds.

15. Changes to this Policy

We may update this Policy from time to time. We will post the updated version and change the "Last updated" date. Material changes may be notified through the Services or by email where required.

16. Platform specific disclosures and related links

By connecting a platform to Somera or using any Somera feature that accesses that platform's content or data, you acknowledge and agree that your use is governed by that platform's own terms, policies, and community rules; and you further acknowledge and agree that where Somera uses that platform's APIs or SDKs, your use of Somera in connection with that platform is subject to the platform's applicable API terms, developer policies, and data use rules.

YouTube: Somera uses YouTube API Services. By using Somera features that access YouTube content or data, you are agreeing to be bound by the YouTube Terms of Service at https://www.youtube.com/t/terms. The Google Privacy Policy at http://www.google.com/policies/privacy also applies to Google's handling of your data, and we encourage you to read it.

What YouTube data Somera accesses, collects, stores, and uses: Somera accesses and uses the YouTube API Data listed in section 3 (channel data; video data including privacy status; comments and comment threads; videos you upload through Somera; and analytics for the channels you authorize), and stores only your authorization tokens — all other YouTube API Data is queried fresh from YouTube API Services each time you request it and is not stored in Somera systems. How Somera uses, processes, and shares that data: only for the purposes listed in section 4 (displaying and moderating your channels, videos, and comments; executing your publishing and moderation actions on YouTube; reporting on your channels; and securing the Services), and it is shared only with the internal and external parties described in section 10. Somera does not sell YouTube API Data and does not use it for advertising or model training.

Somera's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Advertising and third party content: Somera does not allow third parties to serve content, including advertisements, within the Somera interfaces that display YouTube API Data.

Device storage: as described in section 11, Somera stores on your device only strictly necessary, first party authentication cookies and local storage used to keep you signed in, including on pages and features that use YouTube API Services. Somera does not use analytics, advertising, or tracking technologies on those pages and does not allow third parties to store, access, or collect information from your device, other than a Platform's own login components when you initiate a connection flow.

Video uploads and privacy status: when you upload a video to YouTube through Somera, Somera displays a privacy status selector and you choose the video's privacy status (Public, Unlisted, or Private) before the upload is submitted. Somera applies exactly the privacy status you select.

Storage, refresh, and deletion: Somera does not store YouTube API Data — every view in Somera is served by a fresh, real time query to YouTube API Services, including historical and analytics views, so dashboards always display the most updated API Data available. The only stored item is your authorization token, which is kept while your connection is active and is deleted, together with any other data relating to your YouTube connection, within 7 calendar days after you revoke access or request deletion. Somera operates its YouTube API Client under a single, dedicated Google API project.

Revoking access: you can revoke Somera's access to your YouTube and Google data at any time via the Google security settings page at https://security.google.com/settings/security/permissions or https://myaccount.google.com/permissions.

https://www.google.com/policies/privacy

https://www.youtube.com/t/terms

https://developers.google.com/youtube/terms/api-services-terms-of-service

https://developers.google.com/youtube/terms/developer-policies

https://developers.google.com/terms/api-services-user-data-policy

Meta (Facebook and Instagram): We host a public Data Deletion Instructions page and honor deletion requests. We request and use only the data necessary for the features you enable. We delete Meta Platform Data as soon as reasonably possible when it is no longer necessary for a legitimate business purpose, when you request deletion or no longer have an account, when Meta requests deletion for the protection of users, or when required by law. We do not sell, license, or purchase Platform Data; we do not use Platform Data for surveillance, including for law enforcement or national security purposes; we do not use Platform Data to discriminate or to build user profiles without valid consent.

https://www.facebook.com/privacy/policy/

https://developers.facebook.com/terms

https://developers.facebook.com/policy

X: We follow X developer and platform policies and do not use X content to train general purpose AI models. The X content we collect, how we use and share it (including with X when you post or reply through Somera), and how you can contact us with inquiries and requests regarding your information are described in sections 3, 4, 10, and 1 of this Policy. If content is deleted, modified, or made protected on X, we delete or modify our stored copy as soon as reasonably possible and within 24 hours after receiving a request from X or the applicable account owner, and we only show content from protected accounts to people with permission to view it. We do not associate X content with off-X identifiers except with the person's express opt in consent or based on information they provided directly or that is publicly available on X. We do not use X data for surveillance purposes.

https://x.com/en/privacy

https://x.com/en/tos

https://developer.x.com/en/developer-terms/agreement-and-policy

LinkedIn: Our LinkedIn integrations, if enabled, are limited to approved use cases and are subject to access tier restrictions. We delete content collected through LinkedIn APIs on your behalf immediately upon your request or when you close your Somera account, and we refresh LinkedIn profile data only while you are actually using the application, not on an automated schedule. We do not sell, share, or transfer LinkedIn content to third parties and we do not use it in or for targeting advertisements. You may withdraw your consent at any time by disconnecting LinkedIn in Somera or in your LinkedIn settings, and you may request deletion via the Deletion Request page.

https://www.linkedin.com/legal/privacy-policy

https://www.linkedin.com/legal/l/api-terms-of-use

TikTok: We use OAuth 2.0, request the minimum scopes, and follow TikTok Developer Guidelines and rate limits.

https://www.tiktok.com/legal/page/us/privacy-policy/en

https://developers.tiktok.com/doc/our-guidelines-developer-guidelines

https://developers.tiktok.com/doc/app-review-guidelines

Google and Google Business Profile: We follow the Google API Services User Data Policy and request minimum scopes. Somera's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

https://www.google.com/policies/privacy

https://developers.google.com/terms/api-services-user-data-policy

https://developers.google.com/my-business/content/terms

https://developers.google.com/my-business/content/policies

WhatsApp Business Platform: We process phone numbers and message content to deliver messages on your behalf only with documented opt in. We honor opt out messages and deletion requests and require customers to maintain proof of opt in.

https://www.whatsapp.com/legal/privacy-policy

https://www.whatsapp.com/legal/business-app-privacy-policy

https://www.whatsapp.com/legal/business-terms

https://www.whatsapp.com/legal/business-solution-terms

Telegram: We follow Telegram API and Bot Platform terms.

https://telegram.org/privacy

https://core.telegram.org/api/terms

https://telegram.org/tos/bot-developers

Bluesky: We register per instance as required, follow instance policies, and process only permitted data.

https://bsky.social/about/support/privacy-policy

https://docs.bsky.app/docs/support/developer-guidelines

Mastodon: We register per instance as required, follow instance policies, and process only permitted data.

https://mastodon.social/privacy-policy

https://docs.joinmastodon.org/entities/PrivacyPolicy

https://docs.joinmastodon.org/api

VKontakte: Integrations are via official APIs and subject to VK rules.

https://vk.com/privacy

https://vk.com/dev/rules

Apple App Store: If you respond to reviews using Somera, your use may remain subject to the Apple App Store policies for ratings, reviews, and responses.

https://www.apple.com/legal/privacy/data/en/app-store

https://developer.apple.com/app-store/app-privacy-details

https://developer.apple.com/app-store/review/guidelines

Google Play: If you respond to reviews using Somera, your use may remain subject to the Google Play policies for ratings, reviews, and responses.

https://policies.google.com/privacy

https://support.google.com/googleplay/android-developer/answer/16543315

Huawei App Gallery: If you respond to reviews using Somera, your use may remain subject to the Huawei AppGallery policies for ratings, reviews, and responses.

https://developer.huawei.com/consumer/en/doc/app/AGCPrivacyStatement

https://developer.huawei.com/consumer/en/doc/AppGallery-connect-Guides/agcapi-overview

17. Deletion requests

For data deletion or account removal, check this page. Somera deletes the account and Platform Data at the end of the 30 day grace period after an account becomes inactive as described in section 6. Independently of that grace period, if you revoke a Platform authorization or request deletion, Somera deletes the related stored Platform Data within the platform specific windows in section 6, including within 7 calendar days for your YouTube connection — for YouTube, only authorization tokens are stored; YouTube API Data itself is never stored in Somera systems.