Privacy Policy
Last updated: 29 April 2026
1. Who we are
This privacy policy applies to Content Engine, a Claude Cowork plugin and associated web service operated by:
Fifth Arc Ltd
52 Whirlow Grove, Sheffield, United Kingdom
Contact: leon@cmdcentre.com
Fifth Arc Ltd is the data controller for the personal data described in this policy. We are registered in England & Wales and operate under the UK GDPR and the Data Protection Act 2018.
2. What this policy covers
This policy describes how we collect, use, store, and share personal data when you purchase Content Engine, connect your Instagram Business or Creator account, install our Claude Cowork plugin, and use the product. It also explains your rights and how to exercise them.
3. What data we collect
We collect data in three categories:
3.1 Account data (you provide directly)
- Your email address (collected by Stripe at checkout and passed to us to deliver your license)
- Your Content Engine license key (generated by us and tied to your purchase)
3.2 Instagram data (you authorise via OAuth)
When you click Connect Instagram and grant permissions, Meta provides us with:
- An Instagram access token bound to your professional account
- Your Instagram profile information (username, name, profile picture, follower count, biography, account type) — under
instagram_business_basic - Your Instagram posts and their metadata (caption, media URL, permalink, timestamp, like count, comment count) — under
instagram_business_basic - Your Instagram account and post insights (reach, follower growth, views, saves, shares, demographic breakdowns) — under
instagram_business_manage_insights - Your Instagram direct message threads and their messages — under
instagram_business_manage_messages
This data is read on demand to power the Content Engine plugin’s features. We never request instagram_business_content_publish, instagram_business_manage_comments, pages_show_list, public_profile, or any Facebook Login permissions.
3.3 Brand context (you provide via the plugin)
When you run the /setup skill inside Claude Cowork, the plugin asks you a series of questions about your brand voice, audience, content pillars, no-go list, and visual identity. Your answers are saved to our database and used by other skills to draft content that matches your voice. This data is provided directly by you, not by Meta.
4. Why we use this data (lawful basis)
We process personal data on the following lawful bases under UK GDPR Article 6:
- Contract performance (Article 6(1)(b)): We need your email, license key, Instagram access token, and Instagram data to deliver the Content Engine product you purchased.
- Consent (Article 6(1)(a)): Meta’s OAuth flow requires your explicit consent before we can access any Instagram data. You can revoke this consent at any time via Instagram’s settings (see Section 9).
- Legitimate interest (Article 6(1)(f)): We process limited operational data (server logs, error reports) to maintain the security and reliability of the service. These interests are balanced against your privacy rights and we do not use such data for profiling or marketing.
5. Who we share data with
We share personal data only with the following data processors, who act on our behalf and under contractual obligations to protect it:
- Supabase Inc. (database hosting) — stores your license record, encrypted Instagram access token, brand context, and approval queue items. Data is hosted on AWS infrastructure in Ireland (eu-west-1); Supabase corporate is based in the United States.
- Vercel Inc. (application hosting and serverless compute) — hosts the Content Engine web application at
cmdcentre.com; every Meta API call passes through Vercel-hosted Next.js routes. Functions execute on Vercel’s United States infrastructure. - Anthropic PBC (AI inference) — when Claude drafts in-voice DM replies, weekly content plans, captions, or other content, the relevant context (your brand voice, the original DM text, post drafts) is sent to Anthropic’s Claude API for model inference. Anthropic operates from the United States.
- Stripe Inc. (payment processing) — processes your purchase and provides us with your email address and payment confirmation. Stripe handles your payment card details directly; we never receive or store them.
We do not sell, rent, or trade personal data with third parties for their own marketing purposes. We do not aggregate data across users for analytics or advertising.
6. International transfers
Some of our processors are based in the United States (Vercel, Anthropic, Stripe, and Supabase’s corporate operations). Where personal data is transferred outside the United Kingdom or European Economic Area, we rely on the UK’s recognised transfer mechanisms — the UK-US Data Bridge, Standard Contractual Clauses, or equivalent safeguards — to ensure your data receives an adequate level of protection.
7. How long we keep data
- License records and brand context: retained for as long as your Content Engine license is active. Deleted within 30 days of a verified deletion request.
- Instagram access tokens: stored encrypted and refreshed automatically via Meta’s long-lived token mechanism. Deleted immediately on revocation or deletion request.
- Cached Instagram content (posts, insights, DMs, conversations): retained as part of your private skill outputs and queue items. Cached items older than 90 days are auto-purged.
- Server logs: retained for up to 30 days for debugging and security purposes, then deleted or anonymised.
- Stripe billing records: retained for 7 years to comply with UK tax and accounting requirements.
8. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Erase your data (see Section 9 for how)
- Restrict or object to certain processing
- Data portability — request a copy in a machine-readable format
- Withdraw consent at any time
- Lodge a complaint with the UK Information Commissioner’s Office (ico.org.uk) if you believe we have mishandled your data
To exercise any of these rights, email leon@cmdcentre.com. We respond within 30 days.
9. How to delete your data
You have two options:
- Email request: send leon@cmdcentre.com with the subject line Data Deletion Request and the email address linked to your license. We acknowledge within 72 hours and complete deletion within 30 days.
- Revoke Instagram access: visit instagram.com/accounts/manage_access, find Content Engine, and click Remove. Meta will fire an automatic deauthorisation callback to our app and we will delete your access token immediately. Cached data is removed within 30 days.
For full details see our Data Deletion page.
10. Cookies and tracking
The Content Engine web application uses only essential cookies needed to complete the Instagram OAuth flow (a short-lived state cookie and a license-binding cookie that expire within 10 minutes of the OAuth start). We do not use third-party analytics, advertising trackers, or behavioural cookies.
11. Children
Content Engine is not intended for users under the age of 18. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with their data, please contact leon@cmdcentre.com and we will delete it promptly.
12. Security
Instagram access tokens are stored encrypted at rest. All traffic between your browser, Claude Cowork, and our servers is encrypted in transit (HTTPS/TLS). Database access is service-role-only with row-level security policies preventing cross-customer data access. We do not use shared admin credentials.
13. Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top of this page reflects the most recent revision. Material changes will be communicated to active customers by email at least 14 days before they take effect.
14. Contact
Questions about this policy or your personal data: leon@cmdcentre.com.
Postal address: Fifth Arc Ltd, 52 Whirlow Grove, Sheffield, United Kingdom.