Privacy Policy
Last updated: September 1, 2026
1.In short
- We never ask for or store your social media passwords.
- We do not sell your data, use it for advertising, or share it with third parties for marketing.
- We use your connected accounts only to publish posts that you created.
- When you disconnect an account, its access token is deleted immediately.
- When you delete your account, your data is deleted with it.
2.What data we collect
We collect only what the service needs in order to work. By category:
Your account information
- Your email address — so you can sign in and we can send you a sign-in link.
- Your time zone — so scheduled posts go out at the right local time.
- When your account was created and last updated.
The social accounts you connect
- The platform name and your account identifier on that platform.
- Your display name and profile picture URL — so we can show you which account is connected.
- The access token the platform issues to you. It is stored encrypted and used only to publish your own posts.
Your content
- The post text you write.
- The images you upload.
- Which accounts a post goes to, and when it should be published.
Publishing records
- Whether a post was published, when, and its address on the platform.
- The error message returned by the platform when an attempt fails. We keep this so we can show you what went wrong and fix it.
We do not use advertising networks, tracking pixels, or third-party analytics tools.
3.When you connect your TikTok account
To connect TikTok you are sent to TikTok’s own login screen. Your TikTok password stays there; it never reaches us.
What we receive from TikTok
- Your account identifier (open ID) — so posts go to the correct account.
- Your display name, username, and profile picture URL — so we can show you which account is connected.
- Permission to publish — used only to publish posts that you created.
What we do not do with your TikTok data
- We do not read your follower list, your messages, or your view statistics.
- We never publish content you did not create, and we do not follow, like, or comment on your behalf.
- We do not sell, advertise with, or share any information received from TikTok with third parties.
- We do not process your TikTok data for any purpose outside providing this service.
Deleting your TikTok data
4.Why we process your data
- Performance of a contract: to create your account, store your posts, and publish them to the platforms you choose.
- Legitimate interests: to keep the service secure, prevent abuse, and diagnose faults.
- Legal obligation: where the law requires us to retain information.
5.Who we share it with
We do not sell your data. We share only what is necessary, and only with:
- The social platforms you publish to — only the posts and images you asked to publish, and only when you choose to publish them.
- Our infrastructure providers — the companies providing our database, file storage, and hosting. They host your data on our behalf and may not use it for their own purposes.
- Competent authorities — where we are legally required to do so.
6.Where your data is stored
We run the service on infrastructure located outside Türkiye, which means your data is transferred abroad. You have a right to know where it sits, so we state it plainly:
- Database and files — your account details, connected channels, posts and uploaded images are hosted on Supabase, on servers located in India (Mumbai).
- Application server — runs on Cloudflare’s global network. No data is stored there permanently; your information is only held in memory for as long as it takes to serve your request.
- Remote access — both providers are based in the United States, so the data may also be accessed from there for operational and technical support purposes.
Connections are encrypted in transit, and your social account access tokens are separately encrypted before they are ever written to the server. Our providers host your data solely on our behalf and may not use it for their own purposes.
7.Requests from public authorities
Courts, prosecutors and administrative authorities may from time to time request user data. When such a request reaches us, this is what we do:
- We review its legality. Before acting on a request we check whether it actually binds us and whether it was issued through proper process.
- We challenge unlawful requests. We do not simply comply with a request that lacks a legal basis, overreaches, or is procedurally defective.
- We disclose the minimum. We stay within the scope of the request; we do not respond to “send us whatever you have”.
- We keep records. We document the request, our response, and the reasoning behind it.
Where we are not legally prohibited from doing so, we try to notify the user whose data has been requested.
8.How long we keep it
- Your account information and content: until you delete it or close your account.
- A channel's access token: until you disconnect it. Disconnecting deletes the token immediately.
- Publishing records: until the related post is deleted.
9.How we protect it
- Access tokens for your social accounts are stored encrypted and are never sent to your browser.
- Each user can access only their own data; this is enforced at the database level, not merely in application code.
- Signing in uses a one-time link sent to your email rather than a password — there is no password to steal.
- All connections are encrypted in transit (HTTPS).
No system is perfectly secure. If a security incident affects your data, we will notify you and, where required, the relevant authorities.
10.Your rights
You have the right to know whether we process your data, to request a copy, to have it corrected or deleted, to object to processing, and to receive a portable copy.
To exercise these rights, write to destek@postju.com. We respond within 30 days at the latest. You can also do most of this yourself right away — see the next section.
11.Deleting your data
You can do all of this yourself, right now
Disconnect a single account: use the disconnect button next to the account on the Channels page. Its access token is deleted immediately.
Delete a post: delete it from the Posts page. Already-published posts remain on the platform; you need to remove those from the platform’s own app.
Delete your account entirely: use the account deletion section on the Settings page. Your profile, connected channels, posts, and uploaded images are permanently deleted. This cannot be undone.
12.Cookies
We use only the cookies needed to keep you signed in and to remember your language preference. We do not use advertising or tracking cookies. If you block session cookies, you will not be able to sign in.
13.Children
The service is not intended for anyone under 18, and we do not knowingly collect data from children. If we learn that we have, we delete it.
14.Changes
We may update this policy from time to time. If a change is significant, we will tell you in the app or by email. The date at the top of this page shows the most recent update.
15.Contact
Data controller: Postju. For anything related to privacy, reach us at destek@postju.com.
You may also want to read our Terms of Service.