Last updated: August 23, 2026
This is a starting draft, not a finished legal document.
It accurately describes what Rosalinda's software actually does with data as of this writing, but it is not legal advice, and every place marked [BRACKETED] needs a real decision from Limitless (and, ideally, a licensed attorney's review) before this is published or relied on - particularly around data retention periods and any jurisdiction-specific rights (GDPR, CCPA, and similar) that may apply to your clients.
This Privacy Policy explains how Limitless Enterprises (“Limitless,” “we”) handles data through Rosalinda, the dashboard we use to deliver social media management services to our clients. It covers the business account holders who log into Rosalinda (“you,” “Client”) and, where relevant, the third-party platform data we process on your behalf.
We collect the following, directly through your use of Rosalinda:
When you connect a Facebook Page or Instagram Business account, Rosalinda receives and stores, via Meta's Graph API:
We use this data solely to provide the services you've engaged Limitless for: publishing the posts you've approved, showing you your own account's analytics, and surfacing comments/messages for you to review and respond to. We do not sell, license, or share this data with any third party for their own purposes, do not use it to build advertising profiles, and do not use it to make eligibility determinations about anyone (employment, credit, housing, or similar).
Requesting deletion: you can disconnect any platform account at any time from the Accounts tab, which immediately deletes the stored access token and revokes Rosalinda's access to that account. To request deletion of any other data described in this section, contact us using the information in Section 9 - we will delete it as soon as reasonably possible once it is no longer needed to provide the service, and no later than [BRACKETED: a specific number of days Limitless commits to].
We use the information above to: operate your Rosalinda dashboard and account; publish posts you've approved to your connected platforms and read/respond to activity on them; calculate and display the analytics shown to you; communicate with you about your account and respond to feedback you send us; maintain the security of the service (rate-limiting login attempts, detecting misuse); and diagnose and fix technical problems.
We share data only as necessary to provide the service:
We do not sell your data or your clients' data to anyone.
Passwords are never stored in plain text - they're hashed with scrypt, a memory-hard algorithm designed to resist password-cracking. Platform access tokens are encrypted at rest (AES-256-GCM) before being stored, and are only decrypted in memory at the moment they're used to make a request to Facebook/Instagram. Session cookies are signed so they cannot be forged or edited, and are marked HttpOnly (unreadable by page scripts) and Secure (sent only over HTTPS) in production. Login attempts are rate-limited to slow down password-guessing. No method of storage or transmission is perfectly secure, but this is what Rosalinda does today to protect your data.
We retain your account and content data for as long as your engagement with Limitless is active. Platform access tokens are deleted immediately when you disconnect an account. [BRACKETED: decide and state how long data is retained after the overall Limitless engagement ends, and make sure it matches the Terms of Service's termination section.]
Rosalinda is a business tool for companies engaging Limitless's services and is not directed at, or knowingly used by, children. We do not knowingly collect information from anyone under 16.
You can review and update most of your account information directly in Settings. To request access to, correction of, or deletion of data we hold about you or your business, or with any other question about this policy, contact [BRACKETED: a real, monitored contact email - the codebase currently references raoul@limitlessenterprisespro.com internally; confirm this is the right address before publishing it here]. [BRACKETED: if any clients are located in the EU/UK, California, or another jurisdiction with its own privacy law (GDPR, CCPA, etc.), this section needs the specific rights those laws grant - this draft only covers general good-practice disclosure, not a specific statute's requirements.]
We may update this policy as Rosalinda's features change. Material changes will be reflected by updating the “Last updated” date above, and, where required, by notifying Clients directly.
© 2026 Limitless Enterprises. All rights reserved.