Privacy Policy

  • Version 1.0
  • Last updated: 6 August 2026
  • Effective: on the date of publication
In short
  • The video you upload is deleted from our servers no later than 72 hours after publishing.
  • Your platform access tokens are stored with envelope encryption and are never written to any log.
  • We do not sell your data, do not use it for ad targeting and do not pass it to data brokers.
  • This website uses no cookies; there are no analytics or tracking scripts.
  • You can delete your account from inside the app or from this site.

1. Data controller and contact

The data controller under the Turkish Personal Data Protection Law No. 6698 (KVKK) and under the EU General Data Protection Regulation (GDPR) is:

Legal name
[COMPANY NAME]
Address
[ADDRESS]
Email
destek@postinall.app
Registered electronic mail (KEP)
[KEP ADDRESS]
VERBİS registration
[VERBİS REGISTRATION STATUS / NUMBER]

Fields marked with square brackets are completed with the details of the organisation operating the service. Use the email address above for any privacy question, data request or complaint.

2. Scope of this policy

This policy covers the PostInAll mobile app, its backend services and this website. The platforms you publish to (Instagram, TikTok, YouTube, Threads, Facebook, Bluesky, Mastodon/NSosyal, Telegram, Discord and similar) are governed by their own privacy policies; once your content reaches them, the relevant platform is responsible for how it is processed.

By design, PostInAll uses a server-side media pipeline: some platforms do not fetch the video from your device but from an address we make available. Your video therefore passes temporarily through our storage. See section 10 for durations and deletion rules.

3. Data we process, purposes and legal bases

The table below lists every category of personal data we process, why we process it, the legal basis under the KVKK and the GDPR, and how long we keep it.

Data inventory
Data category Purpose KVKK Art.5 basis GDPR Art.6 basis Retention
Account data
email address, cryptographic hash of your password, language preference, account creation date
Creating the account, authentication, access to the service Art.5/2-c — necessary for the conclusion and performance of a contract Art.6(1)(b) — performance of a contract Until the account is deleted
Connected platform account data
platform account/channel/page id, username, profile picture URL, account type, granted permission scopes
Publishing to the right account, showing the account in the interface, monitoring connection health Art.5/2-c Art.6(1)(b) Until you disconnect the account or delete your account
Platform access tokens
OAuth access and refresh tokens and their validity periods — stored encrypted
Publishing on your behalf when you trigger it Art.5/2-c Art.6(1)(b) Until you disconnect or delete your account (YouTube exception: at most 30 days, see section 7)
Media
the video file you upload and its technical metadata (duration, resolution, frame rate, codec, size, checksum)
Delivering the video to the platforms, compatibility checks, retries Art.5/2-c Art.6(1)(b) No later than 72 hours after publishing
Content text and settings
title, description, platform-specific text, visibility choice, made-for-kids declaration, commercial content disclosure
Composing the post, storing drafts and scheduled posts Art.5/2-c Art.6(1)(b) Until you delete the post or your account
Publishing logs
attempt timestamps, state transitions, error codes, platform post id and link
Diagnostics, resolving support requests, abuse prevention, evidence in disputes Art.5/2-ç (legal obligation) and Art.5/2-f (legitimate interests) Art.6(1)(c) and Art.6(1)(f) 12 months
Publishing metrics
view, like, comment and share counts retrieved from the platforms
Showing you how your published content performed Art.5/2-c Art.6(1)(b) 12 months or until the account is deleted, whichever comes first
Device and notification data
notification token (APNs/FCM), app version, operating system version, device language
Sending publishing result notifications, diagnosing compatibility problems Art.5/2-c and Art.5/2-f Art.6(1)(b) and Art.6(1)(f) Until the notification token becomes invalid or the account is deleted
Support correspondence
the content of emails you send us and your contact details
Resolving and recording your request Art.5/2-c and Art.5/2-f Art.6(1)(b) and Art.6(1)(f) 24 months
Subscription data
store transaction id, plan name, subscription status and renewal date
Unlocking subscription features, resolving billing disputes Art.5/2-c and Art.5/2-ç Art.6(1)(b) and Art.6(1)(c) The period required by applicable tax and accounting law
Website form data
the email address and optional note you enter in the account deletion form
Verifying and carrying out the deletion request Art.5/2-ç (legal obligation — fulfilling a deletion request) Art.6(1)(c) 12 months after the request is completed (as evidence), then deleted
Data we do not process
  • We never see your payment card details. Subscription payments are taken by the App Store or Google Play; we only learn whether a subscription is active.
  • We only receive the file you pick. The app declares no media permission; it uses the system gallery picker and cannot reach your other files.
  • We do not collect location data, contacts or advertising identifiers.
  • We do not collect special categories of personal data (health, biometrics, beliefs, political opinions and so on). The content of your video is not analysed, classified or used for profiling by us.

4. How we obtain data

  • Directly from you: when you create an account, enter a video and text, contact support, or fill in the form on this site.
  • From the platforms you connect: only after you have granted permission through OAuth, and limited to the scopes you granted (account id, username, publishing result, quota information, metrics).
  • Automatically during use: publishing logs, error codes, app and operating system version.

We do not buy data about you from data brokers, ad networks or any other external source.

5. Meta platforms: Instagram, Threads, Facebook

Instagram Reels, Threads and Facebook Page Reels are published through Meta's official developer APIs. When you set up those connections:

5.1 Data we receive from Meta

  • Account/page id, username, display name, profile picture URL, account type (Business/Creator)
  • Publishing quota usage (we query your remaining publishing allowance live before each post)
  • The id and permanent link of the published post
  • Metrics for content published through the app only (views, reach, likes, comments, shares, saves)

5.2 Data we send to Meta

  • The accessible address of your video, or the file itself
  • Your title/description text and the platform-specific settings you chose

5.3 What we never do with Meta Platform Data

  • We do not sell, license or transfer Meta Platform Data to data brokers or ad networks.
  • We do not use it for ad targeting, profiling, or eligibility decisions such as credit or insurance.
  • We do not combine data from different users into aggregated data sets.

5.4 Data Deletion Callback

When you remove our app's permission from your Instagram or Facebook account settings, Meta sends us a data deletion notification. On receiving it we delete the data belonging to that platform connection and return a confirmation code together with a status page address. You can check the state of the deletion at any time with that code on the data deletion status page.

5.5 How to revoke access yourself

  • Instagram: Instagram app → Settings → Website permissions → Apps and websites → PostInAll → remove.
  • Facebook: facebook.com/settings?tab=business_tools → Business integrations → PostInAll → remove.
  • From inside the app: Accounts screen → the account → Disconnect. This revokes the token on the platform side as well and deletes our copy.

6. TikTok

6.1 Data we receive from TikTok

Every time you open the composer we call TikTok's creator info endpoint. It returns your nickname, profile picture, the visibility options available for your account, the maximum permitted video duration, and whether comments, duets and stitches are enabled. This data is used only to render the composer correctly and is cached for the session.

6.2 Data we send to TikTok

  • The address on our verified domain from which the video is pulled, or the chunk-uploaded file itself
  • The title text
  • The visibility level you selected
  • Your comment, duet and stitch preferences
  • Your commercial content disclosure and your AI-generated content flag, if you set one
Visibility is never chosen by us

The visibility selector on the TikTok card has no default value; publishing cannot start until you choose one. The comment, duet and stitch checkboxes are unchecked by default, and the music usage confirmation statement is visible in the interface.

6.3 How to revoke access yourself

TikTok app → Profile → Settings and privacy → Security and permissions → Manage app permissions → PostInAll → remove. Disconnecting from the Accounts screen in our app has the same effect.

7. Google and YouTube

YouTube API Services notice

PostInAll uses YouTube API Services. By using PostInAll together with YouTube you agree to the YouTube Terms of Service. How Google processes personal data is explained in the Google Privacy Policy.

7.1 Data we receive from Google/YouTube

  • Channel id and channel title
  • The id, processing state and privacy status of the uploaded video
  • Upload quota usage information
  • Basic metrics (views, likes, comment count) for videos published through PostInAll only

7.2 Special rules for YouTube data

  • The 30-day rule: authorized data obtained from YouTube is kept for at most 30 days. Within that period the data is either refreshed from YouTube or deleted.
  • No blending: YouTube data is never combined with data from other platforms. In the app's statistics screens, YouTube data appears in a separate block attributed to YouTube.
  • Every upload is user-initiated: nothing uploads by itself in the background. For scheduled posts too, it is you who start the post and approve its time and destinations.
  • No advertising: we do not use YouTube data for advertising purposes and do not sell it to third parties.

7.3 How to revoke access yourself

You can remove our app's access from your Google account security settings at any time: https://security.google.com/settings/security/permissions. Once you revoke it, our stored token copy becomes unusable and is deleted on the first attempted use; if you want it deleted immediately, disconnect the account from the Accounts screen in the app.

8. Other platforms

  • Bluesky: your session credentials (handle and app password, or OAuth session) are stored encrypted and used only for publishing.
  • Mastodon / NSosyal: the address of the instance you connect to and the access token are stored. These servers are operated by independent third parties; once your content arrives there, the instance operator is responsible for how it is processed.
  • Telegram: the bot token you provide and the target channel id are stored encrypted. Because a bot token carries the authority to post in your channel, it is treated as a secret and never written to any log.
  • Discord: the webhook address you provide is stored encrypted; because it carries the authority to post in your channel, it is treated as a secret.

9. Recipients, processors and international transfers

9.1 Who receives data

Service providers acting as processors
Provider Function Data transferred
Cloudflare (R2 object storage, Pages) Temporary storage of video files and hosting of this website Video file and its technical metadata; website access logs
[HOSTING PROVIDER] Application servers, database and queue infrastructure All data categories listed in section 3
Apple (APNs) and Google (FCM) Push notification delivery Notification token and notification text
[EMAIL PROVIDER] Transactional email (verification, deletion confirmation, publishing alerts) Email address and message content
Apple App Store and Google Play Subscription sales and billing Subscription status (payment details never reach us)
The platforms you publish to Publishing your video and text Only the content you chose, only to the destinations you chose

These providers act as processors, only on our instructions and within the limits of a contract. The list is kept up to date with the services actually used in production.

9.2 International transfers

The cloud infrastructure we use and the platforms you publish to also operate servers outside Türkiye. Your personal data may therefore be transferred abroad.

  • KVKK: transfers are made on the basis of a standard contract under Article 9 of the KVKK. The standard contract is notified to the Turkish Personal Data Protection Authority within five business days of signature.
  • GDPR: for transfers outside the EU, Standard Contractual Clauses (SCCs) under GDPR Art.46(2)(c) apply.
  • Transfers to the platforms you select happen by the nature of the service and on your instruction; you decide what goes to which platform for every post.

10. Retention periods and deletion

Retention periods
Data Period Reason
Uploaded video file No later than 72 hours after publishing The retry window; the file is then removed by an automatic cleanup job
Unpublished (draft) video At most 7 days from upload Clearing incomplete uploads
Authorized data obtained from YouTube At most 30 days Required by the YouTube API Services Terms of Service
Platform access tokens Until you disconnect or delete your account Necessary to provide the service
Account and post data Until the account is deleted Necessary to provide the service
Publishing logs and metrics 12 months Support, abuse prevention, evidence in disputes
Subscription and billing records The period required by applicable tax and accounting law Legal obligation

When you delete your account, your account record, connected platform permissions, media, drafts and scheduled posts are deleted and platform tokens are revoked. Only records subject to a statutory retention obligation (for example financial records) and statistics that no longer identify you fall outside this deletion. Details and the request form are on the account and data deletion page.

11. Security measures

  • Transport security: all traffic between the app and our servers, and between our servers and the platforms, is encrypted with TLS.
  • Token vault: platform access tokens are protected with envelope encryption: a separate data key is generated for each token and that key is itself encrypted with a master key (AES-256-GCM). Tokens are never written to logs, error reports or debug output.
  • Passwords: your password is stored irreversibly using a current password hashing algorithm (argon2); the plain value is never kept anywhere.
  • Least privilege: we request only the permission scopes required to publish and read the result.
  • Media access: access to video files is limited to short-lived signed addresses that expire.
  • Data minimisation: the app declares no media permission and collects no location data or advertising identifier.
  • Access control: every database query is user-scoped; one user's data is never visible to another.

No system is perfectly secure. If we determine that personal data has been obtained unlawfully by others, we notify the affected individuals and the Turkish Personal Data Protection Authority as soon as possible under KVKK Art.12/5, and the competent supervisory authority and, where required, you, under GDPR Art.33-34.

12. Cookies and this website

This website uses no cookies. There are no analytics, advertising, heatmap or social media tracking scripts, and no fonts, scripts or images are loaded from third-party servers.

The site stores a single technical value in your browser's own localStorage to remember the appearance theme you chose (light/dark/system). That value is never sent to a server, does not identify you, and is removed when you clear your browser data. This is why we show no cookie consent banner.

The provider hosting this site may keep technical access logs (IP address, browser information, requested address, time) for security and abuse prevention. Those logs are never used for marketing.

When you submit the account deletion form, the email address and any note you entered are sent to our servers; there is no other data-collecting form on this site.

13. Children's data

PostInAll is not directed at people under 18 and we do not knowingly collect personal data from anyone under 18. If we become aware that we hold such data, we delete it without delay. If you believe we hold a child's data, write to destek@postinall.app.

14. Your rights and how to exercise them

14.1 Your rights under KVKK Art.11

  • To learn whether your personal data is processed
  • To request information if it has been processed
  • To learn the purpose of processing and whether the data is used in line with that purpose
  • To know the third parties in Türkiye or abroad to whom the data has been transferred
  • To request correction if the data is incomplete or inaccurate
  • To request erasure or destruction under the conditions of KVKK Art.7
  • To request that correction, erasure and destruction be notified to third parties to whom the data was transferred
  • To object to an adverse outcome arising from analysis carried out solely by automated systems
  • To claim compensation for damage suffered because of unlawful processing

14.2 Your rights under GDPR Art.15-22

  • Art.15 — Right of access: to obtain a copy of the data we hold about you
  • Art.16 — Right to rectification
  • Art.17 — Right to erasure ("right to be forgotten")
  • Art.18 — Right to restriction of processing
  • Art.19 — Notification of rectification or erasure to recipients
  • Art.20 — Right to data portability: to receive your data in a structured, commonly used, machine-readable format
  • Art.21 — Right to object to processing based on legitimate interests
  • Art.22 — Right not to be subject to decisions based solely on automated processing (we operate no such decision mechanism)

14.3 How to make a request

You can contact us in any of the following ways:

  • By writing to destek@postinall.app from the email address registered in our system
  • By sending or delivering a signed written request to [ADDRESS]
  • By sending a message from a registered electronic mail (KEP) address to [KEP ADDRESS]
  • By sending a message signed with a secure electronic signature or mobile signature

We respond to requests within 30 days (KVKK Art.13). For GDPR requests the response period is one month; depending on the complexity of the request this may be extended by up to two further months under GDPR Art.12(3), and we will tell you the reason for the extension. Requests are free of charge as a rule; a cost may be charged in the cases foreseen by the Turkish Communiqué on the Procedures and Principles of Application to the Data Controller.

If you ask for a copy of your data, we may request additional information to verify your identity — this is to avoid disclosing someone's data to the wrong person.

14.4 Right to complain

  • Türkiye: if your request is refused, answered insufficiently, or not answered in time, you may complain to the Personal Data Protection Board (KVKK Art.14).
  • European Union: you may lodge a complaint with the supervisory authority of the member state of your residence, place of work, or the place of the alleged infringement (GDPR Art.77).

15. Changes to this policy

We update this policy when the service or the applicable law changes. Each version's number and update date appear at the top of the page. For material changes (for example a new data category, a new recipient of a transfer, or a longer retention period) we notify you inside the app and at your registered email address before the change takes effect.

Questions: destek@postinall.app