Privacy Policy
Poster is a self-hosted publishing tool. It schedules videos and posts them to social media accounts that the operator of the installation owns and has connected themselves. There is no hosted service, no sign-up, and no user base: each installation is run by one person, on their own server, for their own accounts.
This policy describes the software and the reference installation run by its author. Anyone who deploys their own copy is the operator of that copy and responsible for it.
What the software stores
- Access tokens for the connected accounts (TikTok, YouTube, Instagram, VK), encrypted at rest in the operator's own database.
- Videos and captions the operator uploads for publishing, stored as files on the operator's own server.
- Publishing records: the time of a post, the platform, the resulting post id and URL, and any error the platform returned.
- Public performance data read back from the platforms: view, like, comment and share counts, follower counts, and the text of comments left on the operator's own posts.
What the software does not do
- It does not collect data about anyone other than the operator's own accounts and the public engagement on the operator's own posts.
- It does not sell, rent or share data with third parties, and contains no advertising or analytics trackers.
- It does not read private messages, friend lists, or any content belonging to other users.
- It does not transfer data anywhere except to the platform APIs required to publish a post and read its public statistics.
Where data goes
Data stays on the operator's own server and the platform APIs it talks to: TikTok, YouTube (Google), Instagram (Meta) and VK. Each of those platforms handles the data it receives under its own privacy policy. Uploaded video files are served to platforms that fetch media by URL (Instagram and TikTok) over links that expire after a few hours.
Retention and deletion
Publishing records and statistics are kept for as long as the operator finds them useful and can be deleted from the database at any time. Disconnecting an account deletes its stored tokens. Removing the installation removes all stored data. Revoking Poster's access from within a platform's own settings immediately stops all further access, regardless of what is stored locally.
Security
Access tokens are encrypted with a key held only by the operator; a copy of the database without that key does not grant access to any account. The management API requires a bearer token; only the media endpoint used by platforms to fetch a video is reachable without one, and its links are signed and short-lived.
Children
Poster is a tool for the operator of the installation and is not directed at children.
Changes
If this policy changes, the updated version is published at this address with a new date.
Contact
Questions about this policy or about data held by the reference installation: naigaod@gmail.com.