Effective date: 11 September 2026
Wonder Publisher AI Privacy Policy
Last updated: 11 September 2026
1. Overview
This Privacy Policy explains how Rosanix, the operator of Wonder Publisher AI, handles personal information when you visit our website, contact us, connect supported social-platform accounts, or use publishing features.
2. Who is responsible for your information
Rosanix operates Wonder Publisher AI and is responsible for the website, support communications, and the Rosanix authentication service used to assist secure OAuth connections.
- Product: Wonder Publisher AI
- Operator: Rosanix
- Country of operation: Australia
- Privacy and support contact: support@rosanix.com
- Website: https://rosanix.com
3. Scope
This policy applies to the Rosanix website, Wonder Publisher AI desktop application, support channels, secure OAuth handoff service, diagnostic exports initiated by the user, and product-review demonstrations.
It does not replace the privacy policies of Meta, Facebook, Instagram, Google, YouTube, TikTok, LinkedIn, Cloudflare, or any AI provider chosen by the user.
4. Information we collect or process
Information you provide
- Name, email address, support messages, privacy requests, and data-deletion requests.
- Titles, captions, descriptions, hashtags, first comments, schedules, automation settings, and publishing preferences.
- User-selected media files and local file paths used for publishing.
- AI prompts or content supplied when the user explicitly requests AI assistance.
Technical information
- Application version, operating-system version, non-sensitive device information, workflow states, error codes, and sanitized diagnostic logs.
- Connection status, granted and declined permissions, token-expiry state, and last-sync timestamps.
5. Data received from connected platforms
When you authorize a platform, Wonder Publisher AI may receive only information needed for the enabled feature, including:
| Platform | Examples of data processed | Purpose |
|---|---|---|
| Meta / Facebook | Facebook user ID and name, Page IDs and names, Page profile images, permissions, Page access tokens, post IDs, processing status, and permalinks. | List Pages, select a destination, publish and manage authorized Page content. |
| Professional account ID, username, profile image, linked Facebook Page, media container IDs, publishing status, and permalink where available. | Discover linked professional accounts and publish authorized media. | |
| Google / YouTube | Google identity metadata, YouTube channel ID and name, profile image, channel statistics where authorized, upload IDs, publishing status, and comments and replies on the user’s own videos. | List channels, publish user-selected videos, display comments on the user’s own videos, and post a reply only after the user reviews and confirms it. |
| TikTok | Open ID, display name, profile image, granted scopes, creator-posting settings, privacy options, publish ID, upload status, and error information. | Connect accounts and perform Direct Post or Draft Upload when authorized. |
| Member or organization identifiers, profile metadata, granted permissions, post identifiers, and status where approved. | Select an authorized destination and publish supported content. |
Availability depends on platform API access, account type, app-review status, and permissions granted by the user.
6. OAuth credentials and secure authorization
Wonder Publisher AI does not ask for or store platform passwords. Authentication uses official OAuth authorization pages.
- The Rosanix authentication service may process authorization codes and tokens transiently to complete an encrypted handoff to the desktop application.
- Provider client secrets remain in controlled cloud configuration and are not included in the desktop application.
- On supported operating systems, access tokens, refresh tokens, Page tokens, and user-supplied AI API keys are stored locally using operating-system-provided secure storage.
- If secure storage is unavailable, the application is designed to fail closed rather than save sensitive credentials in plaintext.
- Tokens are used only for actions authorized by the user and can be revoked through the relevant provider.
Wonder Publisher AI’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
For information about how Google handles data in its services, see the Google Privacy Policy. Users can also revoke Wonder Publisher AI access from their Google Account at any time.
7. Local files, workspace data, queue, and history
Wonder Publisher AI is primarily a desktop application. The following data may be stored locally:
- Account metadata and selected destination identifiers.
- Encrypted credentials.
- Workspace folders such as Inbox, Processing, Queued, Scheduled, Published, Failed, Drafts, Thumbnails, and Metadata.
- Publishing queue entries, schedules, captions, status, retry count, provider content IDs, and sanitized errors.
- User-selected media files copied into a workspace only after the user chooses that action.
- If you start a free trial, we store a pseudonymous, hashed device identifier after the trial is claimed to prevent repeated trial abuse. The stored identifier is not used for advertising or cross-service tracking.
Rosanix does not automatically receive the contents of local workspace media unless the user publishes it to a selected third-party platform, submits it for support, or explicitly uses a cloud/AI feature that requires transfer.
8. AI-assisted features
AI features may generate titles, captions, hashtags, descriptions, first comments, translations, or reply drafts. Depending on the selected provider, relevant text and limited contextual information may be sent to that provider.
- Platform tokens and provider secrets are not intentionally included in AI prompts.
- Users should not submit confidential, sensitive, or unlawful information.
- AI output may be inaccurate and must be reviewed before publishing.
- YouTube comment replies are never sent until the user reviews and confirms them. Other supported automation rules remain under the user’s control.
9. How we use information
- Authenticate and connect authorized accounts.
- Display Pages, channels, profiles, and organizations available to the user.
- Prepare, schedule, publish, and monitor content at the user’s direction.
- Generate optional AI-assisted metadata.
- Maintain local queues, workspaces, history, and account preferences.
- Provide support, investigate errors, protect security, prevent abuse, and comply with lawful obligations.
- Prepare evidence required for platform review when the user or reviewer performs a test.
10. When information is shared
Information may be shared only as required to provide a requested feature:
- With the selected social platform when the user connects an account or publishes content.
- With Cloudflare or similar infrastructure used to operate the Rosanix authentication and website services.
- With the AI provider selected by the user for an AI-assisted feature.
- With professional advisers, service providers, or authorities when legally required or reasonably necessary to protect rights and security.
Rosanix does not sell personal information.
11. Security
Rosanix uses reasonable administrative and technical safeguards, including encrypted OAuth handoff, operating-system-backed secret storage, restricted Electron renderer privileges, typed IPC boundaries, URL allowlisting, log redaction, bounded retries, and destination-specific token resolution.
No system is completely secure. Users remain responsible for device security, platform-account security, correct destination selection, and reviewing content before publishing. More information is available on our Security page.
12. Data retention
- Local application data: retained on the user’s device until removed by the user, cleared in the application, or deleted during uninstall/manual cleanup.
- OAuth handoff data: processed only as needed to complete authorization and security validation; transient infrastructure logs may be retained for a limited period for security and troubleshooting.
- Support communications: normally retained for up to 24 months, or longer where required for legal, security, or dispute-resolution purposes.
- Deletion requests: retained only as needed to verify and document completion.
- Trial-abuse prevention identifier: retained while the service operates or as necessary to prevent repeated trial abuse, subject to applicable legal requirements.
13. Your choices and rights
Depending on applicable law, you may request access, correction, deletion, restriction, objection, or a copy of eligible personal information. You may also:
- Disconnect a provider inside Wonder Publisher AI.
- Revoke access through Meta Business Integrations, Google Account third-party access, TikTok settings, LinkedIn settings, or the relevant provider.
- Clear local credentials, queue/history, settings, or workspace media separately.
- Contact support@rosanix.com.
14. Data deletion
Detailed deletion instructions are available at https://rosanix.com/data-deletion.
Email requests should use the subject Data Deletion Request. We may request limited information to verify account ownership. Eligible Rosanix-controlled data will normally be addressed within 30 days. Platform-hosted posts and provider-account data must also be managed through the relevant platform.
15. International processing
Connected platforms and service providers may process data in countries outside Australia. Their handling is governed by their own terms and privacy policies. Rosanix uses providers only as reasonably necessary to operate requested features and applies safeguards appropriate to the service.
16. Children
Wonder Publisher AI is intended for users who are legally able to manage the connected platform accounts and enter into an agreement. It is not directed to children under 13. Platform-specific minimum ages may be higher.
17. Changes to this policy
We may update this policy when the product, legal requirements, or third-party platform APIs change. The revised effective date will be shown at the top of this page.
18. Contact
Privacy, security, support, and deletion enquiries:
Rosanix — Australia
https://rosanix.com
Website advertising and cookies
Rosanix may use Google AdSense on public website pages. Google and its advertising partners may use cookies, local storage, device information, IP addresses, and similar technologies to provide, measure, secure, and personalize or limit advertising according to the visitor's consent choices and applicable law.
Visitors can learn more or manage advertising choices through Google's advertising information.