Privacy Policy
- The video you upload is deleted from our servers no later than 72 hours after publishing.
- The permissions you grant (what lets the app post on your behalf) are stored encrypted, each under a key of its own, and are never written to any log.
- We do not sell your data, do not use it for ad targeting and do not pass it to data brokers.
- This website uses no cookies; there are no analytics or tracking scripts.
- You can delete your account from inside the app or from this site.
1. Data controller and contact
The data controller under the Turkish Personal Data Protection Law No. 6698 (KVKK) and under the EU General Data Protection Regulation (GDPR) is:
- Legal name
- [COMPANY NAME]
- Address
- [ADDRESS]
- destek@postinall.app
- Registered electronic mail (KEP)
- [KEP ADDRESS]
- VERBİS registration
- [VERBİS REGISTRATION STATUS / NUMBER]
Fields marked with square brackets are completed with the details of the organisation operating the service. Use the email address above for any privacy question, data request or complaint.
2. Scope of this policy
This policy covers the PostInAll mobile app, the servers behind it and this website. The platforms you publish to (Instagram, TikTok, YouTube, Threads, Facebook, Bluesky, Mastodon/NSosyal, Telegram, Discord and similar) are governed by their own privacy policies; once your content reaches them, the relevant platform is responsible for how it is processed.
While it is being published, your video sits briefly on our server. That is because some platforms will not take the video straight from your phone: they download it themselves from an address we provide. How long it stays and how it is deleted: section 10.
3. Data we process, purposes and legal bases
The table below lists every category of personal data we process, why we process it, the legal basis under the KVKK and the GDPR, and how long we keep it.
| Data category | Purpose | KVKK Art.5 basis | GDPR Art.6 basis | Retention |
|---|---|---|---|---|
| Account data email address, an irreversible encrypted stand-in for your password (we never store the password itself), language preference, account creation date |
Creating the account, authentication, access to the service | Art.5/2-c — necessary for the conclusion and performance of a contract | Art.6(1)(b) — performance of a contract | Until the account is deleted |
| Connected platform account data platform account/channel/page id, username, profile picture URL, account type, granted permission scopes |
Publishing to the right account, showing the account in the interface, monitoring connection health | Art.5/2-c | Art.6(1)(b) | Until you disconnect the account or delete your account |
| Platform permissions the permission keys the platform issues to us and their validity periods — stored encrypted |
Publishing on your behalf when you trigger it | Art.5/2-c | Art.6(1)(b) | Until you disconnect or delete your account (YouTube exception: at most 30 days, see section 7) |
| Media the video file you upload and its technical details (duration, resolution, frame rate, video recording format, size and the file's fingerprint — a number used to tell whether it is the same file) |
Delivering the video to the platforms, compatibility checks, retries | Art.5/2-c | Art.6(1)(b) | No later than 72 hours after publishing |
| Content text and settings title, description, platform-specific text, visibility choice, made-for-kids declaration, commercial content disclosure |
Composing the post, storing drafts and scheduled posts | Art.5/2-c | Art.6(1)(b) | Until you delete the post or your account |
| Publishing logs attempt timestamps, state transitions, error codes, platform post id and link |
Diagnostics, resolving support requests, abuse prevention, evidence in disputes | Art.5/2-ç (legal obligation) and Art.5/2-f (legitimate interests) | Art.6(1)(c) and Art.6(1)(f) | 12 months |
| Publishing metrics view, like, comment and share counts retrieved from the platforms |
Showing you how your published content performed | Art.5/2-c | Art.6(1)(b) | 12 months or until the account is deleted, whichever comes first |
| Device and notification data notification address (the id Apple or Google issues so notifications can reach your phone), app version, operating system version, device language |
Sending publishing result notifications, diagnosing compatibility problems | Art.5/2-c and Art.5/2-f | Art.6(1)(b) and Art.6(1)(f) | Until the notification address becomes invalid or the account is deleted |
| Support correspondence the content of emails you send us and your contact details |
Resolving and recording your request | Art.5/2-c and Art.5/2-f | Art.6(1)(b) and Art.6(1)(f) | 24 months |
| Subscription data store transaction id, plan name, subscription status and renewal date |
Unlocking subscription features, resolving billing disputes | Art.5/2-c and Art.5/2-ç | Art.6(1)(b) and Art.6(1)(c) | The period required by applicable tax and accounting law |
| Website form data the email address and optional note you enter in the account deletion form |
Verifying and carrying out the deletion request | Art.5/2-ç (legal obligation — fulfilling a deletion request) | Art.6(1)(c) | 12 months after the request is completed (as evidence), then deleted |
- We never see your payment card details. Subscription payments are taken by the App Store or Google Play; we only learn whether a subscription is active.
- We only receive the file you pick. The app declares no media permission; it uses the system gallery picker and cannot reach your other files.
- We do not collect location data, contacts or advertising identifiers.
- We do not collect special categories of personal data (health, biometrics, beliefs, political opinions and so on). The content of your video is not analysed, classified or used for profiling by us.
4. How we obtain data
- Directly from you: when you create an account, enter a video and text, contact support, or fill in the form on this site.
- From the platforms you connect: only after you have granted permission on that platform's own screen, and limited to what that permission covers (account id, username, publishing result, remaining posting allowance, metrics).
- Automatically during use: publishing logs, error codes, app and operating system version.
We do not buy data about you from data brokers, ad networks or any other external source.
5. Meta platforms: Instagram, Threads, Facebook
Instagram Reels, Threads and Facebook Page Reels are published through Meta's own official route. When you set up those connections:
5.1 Data we receive from Meta
- Account/page id, username, display name, profile picture URL, account type (Business/Creator)
- Your remaining publishing allowance (asked live before each post)
- The id and permanent link of the published post
- Metrics for content published through the app only (views, reach, likes, comments, shares, saves)
5.2 Data we send to Meta
- The accessible address of your video, or the file itself
- Your title/description text and the platform-specific settings you chose
5.3 What we never do with Meta Platform Data
- We do not sell, license or transfer Meta Platform Data to data brokers or ad networks.
- We do not use it for ad targeting, profiling, or eligibility decisions such as credit or insurance.
- We do not combine data from different users into aggregated data sets.
5.4 Data Deletion Callback
When you remove our app's permission from your Instagram or Facebook account settings, Meta sends us a data deletion notification. On receiving it we delete the data belonging to that platform connection and return a confirmation code together with a status page address. You can check the state of the deletion at any time with that code on the data deletion status page.
5.5 How to revoke access yourself
- Instagram: Instagram app → Settings → Website permissions → Apps and websites → PostInAll → remove.
- Facebook: facebook.com/settings?tab=business_tools → Business integrations → PostInAll → remove.
- From inside the app: Accounts screen → the account → Disconnect. This revokes the permission on the platform side as well and deletes our copy.
6. TikTok
6.1 Data we receive from TikTok
Every time you open the "New post" screen we ask TikTok about your account. What comes back: your nickname, profile picture, the visibility options available for your account, the maximum permitted video duration, and whether comments, duets and stitches are enabled. It is used only to show that screen correctly and is kept until you close the app.
6.2 Data we send to TikTok
- The temporary address of your video on our server (TikTok downloads it from there), or the file itself
- The title text
- The visibility level you selected
- Your comment, duet and stitch preferences
- Your commercial content disclosure and your AI-generated content flag, if you set one
The TikTok card's "Who can view this?" is never preselected; publishing cannot start until you choose. The comment, duet and stitch boxes also arrive empty, and the music usage confirmation is visible on screen. This is a rule TikTok sets for apps.
6.3 How to revoke access yourself
TikTok app → Profile → Settings and privacy → Security and permissions → Manage app permissions → PostInAll → remove. Disconnecting from the Accounts screen in our app has the same effect.
7. Google and YouTube
PostInAll publishes to YouTube through YouTube API Services — that is the name YouTube gives to its own official route for apps, and YouTube requires us to name it here. By using PostInAll together with YouTube you agree to the YouTube Terms of Service. How Google processes personal data is explained in the Google Privacy Policy.
7.1 Data we receive from Google/YouTube
- Channel id and channel title
- The id, processing state and privacy status of the uploaded video
- Your remaining upload allowance
- Basic metrics (views, likes, comment count) for videos published through PostInAll only
7.2 Special rules for YouTube data
- The 30-day rule: authorized data obtained from YouTube is kept for at most 30 days. Within that period the data is either refreshed from YouTube or deleted.
- No blending: YouTube data is never combined with data from other platforms. In the app's statistics screens, YouTube data appears in a separate block attributed to YouTube.
- Every upload is user-initiated: nothing uploads by itself in the background. For scheduled posts too, it is you who start the post and approve its time and destinations.
- No advertising: we do not use YouTube data for advertising purposes and do not sell it to third parties.
7.3 How to revoke access yourself
You can remove our app's access from your Google account security settings at any time: https://security.google.com/settings/security/permissions. Once you revoke it, our stored copy of the permission becomes unusable and is deleted on the first attempted use; if you want it deleted immediately, disconnect the account from the Accounts screen in the app.
8. Other platforms
- Bluesky: your sign-in details (your handle and app password, or the permission you granted) are stored encrypted and used only for publishing.
- Mastodon / NSosyal: the address of the server your account lives on and the permission you granted it are stored. These servers are run by people and organisations independent of us; once your content arrives there, that server's operator is responsible for it.
- Telegram: the bot key you provide and the channel id are stored encrypted. Because a bot key carries the authority to post in your channel, it is treated like a password and never written to any log.
- Discord: the channel address (webhook) you provide is stored encrypted; because it carries the authority to post in your channel, it is treated like a password.
9. Recipients, processors and international transfers
9.1 Who receives data
| Provider | Function | Data transferred |
|---|---|---|
| Cloudflare (R2 object storage, Pages) | Temporary storage of video files and hosting of this website | Video file and its technical details; website access logs |
| [HOSTING PROVIDER] | Application servers, database and queue infrastructure | All data categories listed in section 3 |
| Apple (APNs) and Google (FCM) | Push notification delivery | Notification address and notification text |
| [EMAIL PROVIDER] | Transactional email (verification, deletion confirmation, publishing alerts) | Email address and message content |
| Apple App Store and Google Play | Subscription sales and billing | Subscription status (payment details never reach us) |
| The platforms you publish to | Publishing your video and text | Only the content you chose, only to the destinations you chose |
These providers act as processors, only on our instructions and within the limits of a contract. The list is kept up to date with the services actually used in production.
9.2 International transfers
The cloud infrastructure we use and the platforms you publish to also operate servers outside Türkiye. Your personal data may therefore be transferred abroad.
- KVKK: transfers are made on the basis of a standard contract under Article 9 of the KVKK. The standard contract is notified to the Turkish Personal Data Protection Authority within five business days of signature.
- GDPR: for transfers outside the EU, Standard Contractual Clauses (SCCs) under GDPR Art.46(2)(c) apply.
- Transfers to the platforms you select happen by the nature of the service and on your instruction; you decide what goes to which platform for every post.
10. Retention periods and deletion
| Data | Period | Reason |
|---|---|---|
| Uploaded video file | No later than 72 hours after publishing | The retry window; the file is then removed by an automatic cleanup job |
| Unpublished (draft) video | At most 7 days from upload | Clearing incomplete uploads |
| Authorized data obtained from YouTube | At most 30 days | Required by the YouTube API Services Terms of Service |
| Platform permissions | Until you disconnect or delete your account | Necessary to provide the service |
| Account and post data | Until the account is deleted | Necessary to provide the service |
| Publishing logs and metrics | 12 months | Support, abuse prevention, evidence in disputes |
| Subscription and billing records | The period required by applicable tax and accounting law | Legal obligation |
When you delete your account it all goes together: your account record, your platform connections, your videos, your drafts and your scheduled posts are deleted, and the permissions you gave the platforms are revoked.
Only two things fall outside that: records we are required by law to keep (for example financial records), and statistics that no longer point back to you. Details and the request form are on the account and data deletion page.
11. Security measures
- Encrypted in transit: everything travelling between your phone and our servers, and between our servers and the platforms, goes over an encrypted connection (TLS); nobody in between can read it.
- Permissions in a vault: each permission you grant a platform is encrypted under a key of its own, and that key is itself locked with a separate master key (AES-256-GCM). They are never written to logs, error reports or developer output.
- We do not even have your password: we derive an irreversible stand-in from it and store that (argon2). The password itself is kept nowhere — which is why we cannot look it up for you, though you can reset it.
- We ask only for what is needed: we request only the permissions required to publish and to read the result.
- Video access is short-lived: the address of your video file is valid only briefly and stops working when it expires.
- Data not collected cannot leak: the app asks for no gallery permission and collects no location data or advertising identifier.
- Everyone sees only their own data: every database query is scoped to a single user.
No system is perfectly secure. If we determine that personal data has been obtained unlawfully by others, we notify the affected individuals and the Turkish Personal Data Protection Authority as soon as possible under KVKK Art.12/5, and the competent supervisory authority and, where required, you, under GDPR Art.33-34.
13. Children's data
PostInAll is not directed at people under 18 and we do not knowingly collect personal data from anyone under 18. If we become aware that we hold such data, we delete it without delay. If you believe we hold a child's data, write to destek@postinall.app.
14. Your rights and how to exercise them
The short route: from the email address registered on your account, write to destek@postinall.app and say what you want — a copy of your data, a correction, or deletion. We reply within 30 days at the latest, free of charge. If you only want deletion, the form on the deletion page is faster. The two lists below are the full set of rights the law gives you.
14.1 Your rights under KVKK Art.11
- To learn whether your personal data is processed
- To request information if it has been processed
- To learn the purpose of processing and whether the data is used in line with that purpose
- To know the third parties in Türkiye or abroad to whom the data has been transferred
- To request correction if the data is incomplete or inaccurate
- To request erasure or destruction under the conditions of KVKK Art.7
- To request that correction, erasure and destruction be notified to third parties to whom the data was transferred
- To object to an adverse outcome arising from analysis carried out solely by automated systems
- To claim compensation for damage suffered because of unlawful processing
14.2 Your rights under GDPR Art.15-22
- Art.15 — Right of access: to obtain a copy of the data we hold about you
- Art.16 — Right to rectification
- Art.17 — Right to erasure ("right to be forgotten")
- Art.18 — Right to restriction of processing
- Art.19 — Notification of rectification or erasure to recipients
- Art.20 — Right to data portability: to receive your data in a structured, commonly used, machine-readable format
- Art.21 — Right to object to processing based on legitimate interests
- Art.22 — Right not to be subject to decisions based solely on automated processing (we operate no such decision mechanism)
14.3 How to make a request
You can contact us in any of the following ways:
- By writing to destek@postinall.app from the email address registered in our system
- By sending or delivering a signed written request to [ADDRESS]
- By sending a message from a registered electronic mail (KEP) address to [KEP ADDRESS]
- By sending a message signed with a secure electronic signature or mobile signature
We respond to requests within 30 days (KVKK Art.13). For GDPR requests the response period is one month; depending on the complexity of the request this may be extended by up to two further months under GDPR Art.12(3), and we will tell you the reason for the extension. Requests are free of charge as a rule; a cost may be charged in the cases foreseen by the Turkish Communiqué on the Procedures and Principles of Application to the Data Controller.
If you ask for a copy of your data, we may request additional information to verify your identity — this is to avoid disclosing someone's data to the wrong person.
14.4 Right to complain
- Türkiye: if your request is refused, answered insufficiently, or not answered in time, you may complain to the Personal Data Protection Board (KVKK Art.14).
- European Union: you may lodge a complaint with the supervisory authority of the member state of your residence, place of work, or the place of the alleged infringement (GDPR Art.77).
15. Changes to this policy
We update this policy when the service or the applicable law changes. Each version's number and update date appear at the top of the page. For material changes (for example a new data category, a new recipient of a transfer, or a longer retention period) we notify you inside the app and at your registered email address before the change takes effect.
Questions: destek@postinall.app