Privacy Policy

  • Version 1.0
  • Last updated: 6 August 2026
  • Effective: on the date of publication
In short
  • The video you upload is deleted from our servers no later than 72 hours after publishing.
  • The permissions you grant (what lets the app post on your behalf) are stored encrypted, each under a key of its own, and are never written to any log.
  • We do not sell your data, do not use it for ad targeting and do not pass it to data brokers.
  • This website uses no cookies; there are no analytics or tracking scripts.
  • You can delete your account from inside the app or from this site.

1. Data controller and contact

The data controller under the Turkish Personal Data Protection Law No. 6698 (KVKK) and under the EU General Data Protection Regulation (GDPR) is:

Legal name
[COMPANY NAME]
Address
[ADDRESS]
Email
destek@postinall.app
Registered electronic mail (KEP)
[KEP ADDRESS]
VERBİS registration
[VERBİS REGISTRATION STATUS / NUMBER]

Fields marked with square brackets are completed with the details of the organisation operating the service. Use the email address above for any privacy question, data request or complaint.

2. Scope of this policy

This policy covers the PostInAll mobile app, the servers behind it and this website. The platforms you publish to (Instagram, TikTok, YouTube, Threads, Facebook, Bluesky, Mastodon/NSosyal, Telegram, Discord and similar) are governed by their own privacy policies; once your content reaches them, the relevant platform is responsible for how it is processed.

While it is being published, your video sits briefly on our server. That is because some platforms will not take the video straight from your phone: they download it themselves from an address we provide. How long it stays and how it is deleted: section 10.

3. Data we process, purposes and legal bases

The table below lists every category of personal data we process, why we process it, the legal basis under the KVKK and the GDPR, and how long we keep it.

Data inventory
Data category Purpose KVKK Art.5 basis GDPR Art.6 basis Retention
Account data
email address, an irreversible encrypted stand-in for your password (we never store the password itself), language preference, account creation date
Creating the account, authentication, access to the service Art.5/2-c — necessary for the conclusion and performance of a contract Art.6(1)(b) — performance of a contract Until the account is deleted
Connected platform account data
platform account/channel/page id, username, profile picture URL, account type, granted permission scopes
Publishing to the right account, showing the account in the interface, monitoring connection health Art.5/2-c Art.6(1)(b) Until you disconnect the account or delete your account
Platform permissions
the permission keys the platform issues to us and their validity periods — stored encrypted
Publishing on your behalf when you trigger it Art.5/2-c Art.6(1)(b) Until you disconnect or delete your account (YouTube exception: at most 30 days, see section 7)
Media
the video file you upload and its technical details (duration, resolution, frame rate, video recording format, size and the file's fingerprint — a number used to tell whether it is the same file)
Delivering the video to the platforms, compatibility checks, retries Art.5/2-c Art.6(1)(b) No later than 72 hours after publishing
Content text and settings
title, description, platform-specific text, visibility choice, made-for-kids declaration, commercial content disclosure
Composing the post, storing drafts and scheduled posts Art.5/2-c Art.6(1)(b) Until you delete the post or your account
Publishing logs
attempt timestamps, state transitions, error codes, platform post id and link
Diagnostics, resolving support requests, abuse prevention, evidence in disputes Art.5/2-ç (legal obligation) and Art.5/2-f (legitimate interests) Art.6(1)(c) and Art.6(1)(f) 12 months
Publishing metrics
view, like, comment and share counts retrieved from the platforms
Showing you how your published content performed Art.5/2-c Art.6(1)(b) 12 months or until the account is deleted, whichever comes first
Device and notification data
notification address (the id Apple or Google issues so notifications can reach your phone), app version, operating system version, device language
Sending publishing result notifications, diagnosing compatibility problems Art.5/2-c and Art.5/2-f Art.6(1)(b) and Art.6(1)(f) Until the notification address becomes invalid or the account is deleted
Support correspondence
the content of emails you send us and your contact details
Resolving and recording your request Art.5/2-c and Art.5/2-f Art.6(1)(b) and Art.6(1)(f) 24 months
Subscription data
store transaction id, plan name, subscription status and renewal date
Unlocking subscription features, resolving billing disputes Art.5/2-c and Art.5/2-ç Art.6(1)(b) and Art.6(1)(c) The period required by applicable tax and accounting law
Website form data
the email address and optional note you enter in the account deletion form
Verifying and carrying out the deletion request Art.5/2-ç (legal obligation — fulfilling a deletion request) Art.6(1)(c) 12 months after the request is completed (as evidence), then deleted
Data we do not process
  • We never see your payment card details. Subscription payments are taken by the App Store or Google Play; we only learn whether a subscription is active.
  • We only receive the file you pick. The app declares no media permission; it uses the system gallery picker and cannot reach your other files.
  • We do not collect location data, contacts or advertising identifiers.
  • We do not collect special categories of personal data (health, biometrics, beliefs, political opinions and so on). The content of your video is not analysed, classified or used for profiling by us.

4. How we obtain data

  • Directly from you: when you create an account, enter a video and text, contact support, or fill in the form on this site.
  • From the platforms you connect: only after you have granted permission on that platform's own screen, and limited to what that permission covers (account id, username, publishing result, remaining posting allowance, metrics).
  • Automatically during use: publishing logs, error codes, app and operating system version.

We do not buy data about you from data brokers, ad networks or any other external source.

5. Meta platforms: Instagram, Threads, Facebook

Instagram Reels, Threads and Facebook Page Reels are published through Meta's own official route. When you set up those connections:

5.1 Data we receive from Meta

  • Account/page id, username, display name, profile picture URL, account type (Business/Creator)
  • Your remaining publishing allowance (asked live before each post)
  • The id and permanent link of the published post
  • Metrics for content published through the app only (views, reach, likes, comments, shares, saves)

5.2 Data we send to Meta

  • The accessible address of your video, or the file itself
  • Your title/description text and the platform-specific settings you chose

5.3 What we never do with Meta Platform Data

  • We do not sell, license or transfer Meta Platform Data to data brokers or ad networks.
  • We do not use it for ad targeting, profiling, or eligibility decisions such as credit or insurance.
  • We do not combine data from different users into aggregated data sets.

5.4 Data Deletion Callback

When you remove our app's permission from your Instagram or Facebook account settings, Meta sends us a data deletion notification. On receiving it we delete the data belonging to that platform connection and return a confirmation code together with a status page address. You can check the state of the deletion at any time with that code on the data deletion status page.

5.5 How to revoke access yourself

  • Instagram: Instagram app → Settings → Website permissions → Apps and websites → PostInAll → remove.
  • Facebook: facebook.com/settings?tab=business_tools → Business integrations → PostInAll → remove.
  • From inside the app: Accounts screen → the account → Disconnect. This revokes the permission on the platform side as well and deletes our copy.

6. TikTok

6.1 Data we receive from TikTok

Every time you open the "New post" screen we ask TikTok about your account. What comes back: your nickname, profile picture, the visibility options available for your account, the maximum permitted video duration, and whether comments, duets and stitches are enabled. It is used only to show that screen correctly and is kept until you close the app.

6.2 Data we send to TikTok

  • The temporary address of your video on our server (TikTok downloads it from there), or the file itself
  • The title text
  • The visibility level you selected
  • Your comment, duet and stitch preferences
  • Your commercial content disclosure and your AI-generated content flag, if you set one
Visibility is never chosen by us

The TikTok card's "Who can view this?" is never preselected; publishing cannot start until you choose. The comment, duet and stitch boxes also arrive empty, and the music usage confirmation is visible on screen. This is a rule TikTok sets for apps.

6.3 How to revoke access yourself

TikTok app → Profile → Settings and privacy → Security and permissions → Manage app permissions → PostInAll → remove. Disconnecting from the Accounts screen in our app has the same effect.

7. Google and YouTube

YouTube API Services notice

PostInAll publishes to YouTube through YouTube API Services — that is the name YouTube gives to its own official route for apps, and YouTube requires us to name it here. By using PostInAll together with YouTube you agree to the YouTube Terms of Service. How Google processes personal data is explained in the Google Privacy Policy.

7.1 Data we receive from Google/YouTube

  • Channel id and channel title
  • The id, processing state and privacy status of the uploaded video
  • Your remaining upload allowance
  • Basic metrics (views, likes, comment count) for videos published through PostInAll only

7.2 Special rules for YouTube data

  • The 30-day rule: authorized data obtained from YouTube is kept for at most 30 days. Within that period the data is either refreshed from YouTube or deleted.
  • No blending: YouTube data is never combined with data from other platforms. In the app's statistics screens, YouTube data appears in a separate block attributed to YouTube.
  • Every upload is user-initiated: nothing uploads by itself in the background. For scheduled posts too, it is you who start the post and approve its time and destinations.
  • No advertising: we do not use YouTube data for advertising purposes and do not sell it to third parties.

7.3 How to revoke access yourself

You can remove our app's access from your Google account security settings at any time: https://security.google.com/settings/security/permissions. Once you revoke it, our stored copy of the permission becomes unusable and is deleted on the first attempted use; if you want it deleted immediately, disconnect the account from the Accounts screen in the app.

8. Other platforms

  • Bluesky: your sign-in details (your handle and app password, or the permission you granted) are stored encrypted and used only for publishing.
  • Mastodon / NSosyal: the address of the server your account lives on and the permission you granted it are stored. These servers are run by people and organisations independent of us; once your content arrives there, that server's operator is responsible for it.
  • Telegram: the bot key you provide and the channel id are stored encrypted. Because a bot key carries the authority to post in your channel, it is treated like a password and never written to any log.
  • Discord: the channel address (webhook) you provide is stored encrypted; because it carries the authority to post in your channel, it is treated like a password.

9. Recipients, processors and international transfers

9.1 Who receives data

Service providers acting as processors
Provider Function Data transferred
Cloudflare (R2 object storage, Pages) Temporary storage of video files and hosting of this website Video file and its technical details; website access logs
[HOSTING PROVIDER] Application servers, database and queue infrastructure All data categories listed in section 3
Apple (APNs) and Google (FCM) Push notification delivery Notification address and notification text
[EMAIL PROVIDER] Transactional email (verification, deletion confirmation, publishing alerts) Email address and message content
Apple App Store and Google Play Subscription sales and billing Subscription status (payment details never reach us)
The platforms you publish to Publishing your video and text Only the content you chose, only to the destinations you chose

These providers act as processors, only on our instructions and within the limits of a contract. The list is kept up to date with the services actually used in production.

9.2 International transfers

The cloud infrastructure we use and the platforms you publish to also operate servers outside Türkiye. Your personal data may therefore be transferred abroad.

  • KVKK: transfers are made on the basis of a standard contract under Article 9 of the KVKK. The standard contract is notified to the Turkish Personal Data Protection Authority within five business days of signature.
  • GDPR: for transfers outside the EU, Standard Contractual Clauses (SCCs) under GDPR Art.46(2)(c) apply.
  • Transfers to the platforms you select happen by the nature of the service and on your instruction; you decide what goes to which platform for every post.

10. Retention periods and deletion

Retention periods
Data Period Reason
Uploaded video file No later than 72 hours after publishing The retry window; the file is then removed by an automatic cleanup job
Unpublished (draft) video At most 7 days from upload Clearing incomplete uploads
Authorized data obtained from YouTube At most 30 days Required by the YouTube API Services Terms of Service
Platform permissions Until you disconnect or delete your account Necessary to provide the service
Account and post data Until the account is deleted Necessary to provide the service
Publishing logs and metrics 12 months Support, abuse prevention, evidence in disputes
Subscription and billing records The period required by applicable tax and accounting law Legal obligation

When you delete your account it all goes together: your account record, your platform connections, your videos, your drafts and your scheduled posts are deleted, and the permissions you gave the platforms are revoked.

Only two things fall outside that: records we are required by law to keep (for example financial records), and statistics that no longer point back to you. Details and the request form are on the account and data deletion page.

11. Security measures

  • Encrypted in transit: everything travelling between your phone and our servers, and between our servers and the platforms, goes over an encrypted connection (TLS); nobody in between can read it.
  • Permissions in a vault: each permission you grant a platform is encrypted under a key of its own, and that key is itself locked with a separate master key (AES-256-GCM). They are never written to logs, error reports or developer output.
  • We do not even have your password: we derive an irreversible stand-in from it and store that (argon2). The password itself is kept nowhere — which is why we cannot look it up for you, though you can reset it.
  • We ask only for what is needed: we request only the permissions required to publish and to read the result.
  • Video access is short-lived: the address of your video file is valid only briefly and stops working when it expires.
  • Data not collected cannot leak: the app asks for no gallery permission and collects no location data or advertising identifier.
  • Everyone sees only their own data: every database query is scoped to a single user.

No system is perfectly secure. If we determine that personal data has been obtained unlawfully by others, we notify the affected individuals and the Turkish Personal Data Protection Authority as soon as possible under KVKK Art.12/5, and the competent supervisory authority and, where required, you, under GDPR Art.33-34.

12. Cookies and this website

This website uses no cookies. There are no analytics, advertising, heatmap or social media tracking scripts, and no fonts, scripts or images are loaded from third-party servers.

Your browser's own memory holds exactly one thing: the appearance theme you chose (light/dark/system). It is never sent to a server, does not identify you, and is removed when you clear your browser data. This is why we show no cookie consent banner.

The provider hosting this site may keep technical access logs (IP address, browser information, requested address, time) for security and abuse prevention. Those logs are never used for marketing.

When you submit the account deletion form, the email address and any note you entered are sent to our servers; there is no other data-collecting form on this site.

13. Children's data

PostInAll is not directed at people under 18 and we do not knowingly collect personal data from anyone under 18. If we become aware that we hold such data, we delete it without delay. If you believe we hold a child's data, write to destek@postinall.app.

14. Your rights and how to exercise them

The short route: from the email address registered on your account, write to destek@postinall.app and say what you want — a copy of your data, a correction, or deletion. We reply within 30 days at the latest, free of charge. If you only want deletion, the form on the deletion page is faster. The two lists below are the full set of rights the law gives you.

14.1 Your rights under KVKK Art.11

  • To learn whether your personal data is processed
  • To request information if it has been processed
  • To learn the purpose of processing and whether the data is used in line with that purpose
  • To know the third parties in Türkiye or abroad to whom the data has been transferred
  • To request correction if the data is incomplete or inaccurate
  • To request erasure or destruction under the conditions of KVKK Art.7
  • To request that correction, erasure and destruction be notified to third parties to whom the data was transferred
  • To object to an adverse outcome arising from analysis carried out solely by automated systems
  • To claim compensation for damage suffered because of unlawful processing

14.2 Your rights under GDPR Art.15-22

  • Art.15 — Right of access: to obtain a copy of the data we hold about you
  • Art.16 — Right to rectification
  • Art.17 — Right to erasure ("right to be forgotten")
  • Art.18 — Right to restriction of processing
  • Art.19 — Notification of rectification or erasure to recipients
  • Art.20 — Right to data portability: to receive your data in a structured, commonly used, machine-readable format
  • Art.21 — Right to object to processing based on legitimate interests
  • Art.22 — Right not to be subject to decisions based solely on automated processing (we operate no such decision mechanism)

14.3 How to make a request

You can contact us in any of the following ways:

  • By writing to destek@postinall.app from the email address registered in our system
  • By sending or delivering a signed written request to [ADDRESS]
  • By sending a message from a registered electronic mail (KEP) address to [KEP ADDRESS]
  • By sending a message signed with a secure electronic signature or mobile signature

We respond to requests within 30 days (KVKK Art.13). For GDPR requests the response period is one month; depending on the complexity of the request this may be extended by up to two further months under GDPR Art.12(3), and we will tell you the reason for the extension. Requests are free of charge as a rule; a cost may be charged in the cases foreseen by the Turkish Communiqué on the Procedures and Principles of Application to the Data Controller.

If you ask for a copy of your data, we may request additional information to verify your identity — this is to avoid disclosing someone's data to the wrong person.

14.4 Right to complain

  • Türkiye: if your request is refused, answered insufficiently, or not answered in time, you may complain to the Personal Data Protection Board (KVKK Art.14).
  • European Union: you may lodge a complaint with the supervisory authority of the member state of your residence, place of work, or the place of the alleged infringement (GDPR Art.77).

15. Changes to this policy

We update this policy when the service or the applicable law changes. Each version's number and update date appear at the top of the page. For material changes (for example a new data category, a new recipient of a transfer, or a longer retention period) we notify you inside the app and at your registered email address before the change takes effect.

Questions: destek@postinall.app