Privacy Policy
Last updated 11 October 2026.
Isharo is a social media service: we make posts for businesses, each business approves them in its own Isharo console, and Isharo publishes the approved posts to the business's own social media accounts and shows how they did. This policy explains what data Isharo handles, why, who it's shared with, how long it's kept, and how to have it deleted.
Who we are
Isharo is provided by Elden Studios Company, Commercial Registration No. 7051824170, King Abdulaziz ibn Abdulaziz Saud Branch Street, Riyadh, Kingdom of Saudi Arabia ("Elden Studios", "we", "us"). Website: elden-studios.com. Contact for anything in this policy: bazerbashi@elden-studios.com.
What we collect
When you sign in:
- Your email address, which you sign in with. If you choose Continue with Google, Google also shares your name, your Google account ID and the address of your profile photo, with your permission.
- If you sign in with your email, we send you a 6-digit code. We store it only as a one-way hash, so nobody can read it back. It works once and expires after 10 minutes.
- A session cookie keeps you signed in for 30 days. It's a secure cookie on our own domain that only Isharo's servers can read. We don't use cookies for advertising or tracking.
- The time of each sign-in, and a hashed form of your IP address, to keep accounts secure.
When you set up your business: its name, what you sell, who you want to reach, your time zone and the language you post in.
If you buy a plan: your card is handled by Moyasar, our payment provider. We never receive or store your card number. We keep your plan, whether it's active, and your invoices.
When you use the Isharo console:
- What you do in the console: approvals, posts sent back with notes, schedule changes, notes to the studio and requests, each recorded with who did it and when, so the history of every post is clear.
- The content you give us or approve: photos, videos, captions, brand details (words, colours, faces you choose, your plan) and the posts we make from them.
If you connect a social media account (Instagram, Facebook, Threads, TikTok, and when available X or YouTube), we receive from that platform, with your permission:
- The account's name and ID, and for Facebook the Page you choose.
- An access token that lets Isharo publish for you. We store it encrypted, and use it only for your account.
- For the posts Isharo publishes: their IDs, and their results (reach, views, likes, comment counts, saves, shares, profile visits and, for videos, watch time).
If you joined our waitlist before sign-up opened: your email address, your business or brand name, and the platforms you ticked. The waitlist is now closed.
We don't collect your social media password, your followers' personal details, or anything from accounts you haven't connected.
How we use it
- To make your posts, show them to you for approval, and publish only the ones you approve, at the time you chose.
- To show you how your posts did, and to plan better posts with you.
- To let the people you invite use your brand's console, and nobody else.
- To take payment for your plan, and keep the invoices the law requires.
- To write to you about your account and your plan, or, if you joined the waitlist, to tell you Isharo is open.
- To keep Isharo secure and working: preventing abuse, fixing problems.
We don't sell your data, use it for advertising, or share one business's data with another. Data we receive from Instagram, Facebook or any other platform is used only to provide Isharo to the business it belongs to.
Who we share it with
Only the services Isharo runs on, each for its part of the service:
- Cloudflare: hosting, the database, file storage, sending our emails (such as sign-in codes), and protection against abuse.
- Google: only if you choose Continue with Google, to confirm who you are.
- Moyasar: to take payments for your plan. Your card details go to Moyasar, not to us.
- The platforms you connect (Meta for Instagram, Facebook and Threads, TikTok, and X or Google for YouTube when you connect them): to publish your approved posts and read their results.
- AI services we use to help make posts: currently Anthropic (Claude) to help plan, write and check posts, and fal.ai to generate video only when a post uses generated video. They receive only what's needed to make your posts.
We may also disclose data if the law requires it. If any of these services change, we'll update this page.
How long we keep it
- While you're a client: your posts, their history and results, and your brand's details, so the console can show them.
- When you disconnect an account: its access token is deleted at once. You can disconnect any account on the Accounts page.
- When you stop using Isharo, or ask us to: we delete your account, your brand and everything in it (posts, files, results, notes, connected accounts and the people invited) within 30 days.
- Sign-in codes: they expire after 10 minutes and can't be used again.
- Sign-in records (sign-in times and hashed IP addresses): kept for security, and deleted with your account.
- Invoices and payment records: as long as Saudi tax and accounting law requires, even after you leave.
- Waitlist details: until you ask us to remove them, or until you start using Isharo.
- Backups: copies kept to protect against mistakes are deleted within 90 days.
How we protect it
Isharo runs over encrypted connections only. Access tokens for your social accounts are encrypted before they're stored. Each business sees only its own brand: this is enforced by Isharo's servers, not just its screens. Signing in needs your Google account or a one-time code sent to your email, and codes are stored only as a one-way hash. Card numbers never reach Isharo.
Your choices
You can ask us for a copy of your data, to correct it, or to delete it, by writing to bazerbashi@elden-studios.com. You can disconnect any social account at any time on the Accounts page, or from the platform itself.
How to delete your data
To have Isharo delete your data, including everything we received from Facebook or Instagram:
- Email bazerbashi@elden-studios.com with the subject "Delete my Isharo data", from the email you use with Isharo, and the name of your business.
- We confirm, then delete your brand and everything in it within 30 days, apart from invoices the law requires us to keep, and reply when it's done.
You can also remove Isharo's access from Facebook yourself: in Facebook, go to Settings & privacy → Settings → Business integrations, choose Isharo, then Remove. Isharo then stops publishing to your accounts, and you can ask us to delete the rest as above.
Children
Isharo is a service for businesses. It isn't meant for anyone under 18, and we don't knowingly collect children's data.
Changes to this policy
If we change this policy, we'll update this page and its date. If a change matters for how we use your data, we'll tell clients by email before it applies.