AUTOSOCPOST
Legal

Privacy Policy

Effective August 15, 2026

1. Data we process

We process your account email and password hash, connected social account identifiers, encrypted OAuth access and refresh tokens, channel settings, scheduled content and media, publication results, and security logs.

2. Why we process data

We use this data to authenticate you, connect accounts at your request, schedule and publish content, refresh OAuth authorization, diagnose failures, prevent abuse, and comply with legal obligations.

3. Social platforms

When you connect a platform, its OAuth screen describes the permissions requested. Autosocpost uses official APIs and sends only the data needed for the action you request. Platform providers process data under their own privacy policies.

4. Storage and security

OAuth tokens and application secrets are encrypted at rest. Passwords are stored as one-way hashes. Access is tenant-scoped, browser forms use CSRF protection, and internal publishing endpoints require separate authentication.

5. Sharing

We do not sell personal data. Data is shared only with connected platforms, infrastructure providers needed to operate the service, or authorities when legally required.

6. Retention

We retain account and publication data while your account or connection is active and as needed for security and legal records. Disconnecting a social account removes its stored tokens and channels. Media and logs may remain briefly in backups or operational retention.

7. Your choices and deletion

You may revoke platform access, disconnect accounts, or request deletion of your Autosocpost data. Platform deauthorization and data-deletion callbacks are authenticated before account data is removed.

8. Children

Autosocpost is intended for business users and is not directed to children under 13 or the minimum digital-consent age in their jurisdiction.

9. Changes

We may update this policy as integrations, infrastructure, or legal requirements change. The effective date above identifies the current version.

10. Cookies

The site uses only strictly necessary cookies (session, "remember me", chosen language). See the Cookie Policy.

11. Data storage location

In accordance with Part 5, Article 18 of Federal Law No. 152-FZ "On Personal Data", the recording, systematization, accumulation, storage, updating, and retrieval of personal data of Russian Federation citizens are carried out using databases physically located within the territory of the Russian Federation.

12. Cross-border data transfer

When you connect a third-party social network (e.g. YouTube, Instagram, Facebook, Threads, X, TikTok, Pinterest, VKontakte) to publish your content, data is sent directly to that platform's official API — an unavoidable consequence of the auto-posting function, which happens only on your initiative and with your explicit consent when you connect the account.

13. Use of certain foreign services

Meta Platforms Inc. (owner of Facebook, Instagram, and Threads) has been designated an extremist organization in the Russian Federation, and its activity is prohibited there. Autosocpost does not provide access to blocked resources and does not circumvent Roskomnadzor restrictions — the integrations use official APIs and require that you already have lawful access to the relevant account. By connecting such services, you are solely responsible for complying with applicable Russian law.

14. Connection encryption

All site pages and the API are served exclusively over HTTPS (TLS encryption). Unencrypted HTTP requests are automatically redirected to a secure connection.

15. Google and YouTube data

When you connect YouTube, the service requests exactly two scopes from Google. The youtube.readonly scope is needed to list your channels so you can choose where to publish. The youtube.upload scope is needed to upload the video you scheduled. Autosocpost requests no other scopes.

Of the data received from Google we store only the channel id and name, plus the access and refresh tokens, all encrypted. Autosocpost does not read your email, contacts, Google Drive files or channel analytics. Google data is never sold, never shared with advertising networks, data brokers or third parties, and never used to train artificial intelligence models.

You can revoke access at any time: on the Connections page in your account, or in your Google Account settings at myaccount.google.com/permissions. Once revoked, the stored tokens and channels are deleted from the database. Deleting your Autosocpost account removes all Google data immediately and irreversibly — the procedure is described on the page about data deletion.

Autosocpost uses YouTube API Services. By connecting a channel you accept the YouTube Terms of Service and Google Privacy Policy.

16. Limited use of Google data

Autosocpost's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Autosocpost's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

17. Contacts

Privacy and deletion requests: misterdeni02@gmail.com. A contact form is also available.