Privacy Policy
Last updated: 2026-07-23
PostsBridge ("we", "our", or "the Service") lets you compose a post once and publish it to multiple social media platforms. This policy explains what data we collect, why we collect it, and the choices you have.
Information We Collect
We collect only the information needed to operate the Service:
- Account details you provide: email address, username, and password (stored only as a secure hash).
- Social account connections: OAuth access and refresh tokens plus basic profile, page, or channel identifiers for the platforms you connect, such as Facebook Pages, Instagram Professional accounts, LinkedIn profiles, and YouTube channels.
- YouTube channel data returned by the YouTube Data API when you connect a channel: the channel ID, channel name, channel avatar image URL, and the public subscriber count of that channel.
- Content you create: the text, images, and videos you upload to publish, together with their scheduling details and, for YouTube, the title, tags, category, and the required "made for kids" and "synthetic or altered media" declarations you provide. There is no separate YouTube description field: the video description is taken from the text of the post you wrote (its first 5,000 characters).
- Publishing results: the identifier and link of the item created on the platform (for example the YouTube video ID), its publishing status, and error codes returned by the platform.
- Technical data: limited log data such as timestamps and error records used to keep the Service secure and reliable.
- Security data: the IP address, browser user agent, and timestamps of your sign-ins and of security-relevant actions, used for session management, rate limiting, and abuse prevention. Some of these security records may remain after your account is deleted, no longer linked to your account, where that is needed to prevent abuse.
How We Use Your Information
We use your information solely to provide the Service:
- To authenticate you and keep your account secure.
- To publish or schedule the content you create to the platforms you have connected, at your explicit instruction.
- To show you your connected accounts, your posts, and their publishing status.
- To maintain, protect, and improve the Service.
Third-Party Platforms
When you connect a social account and publish content, we send that content and the necessary tokens to the relevant platform (for example Meta's Facebook and Instagram, LinkedIn, or YouTube, which is a Google service) to complete publishing on your behalf. We only access the permissions you explicitly grant when connecting. Your use of those platforms is also governed by their own terms and privacy policies.
YouTube and Google Data
PostsBridge uses YouTube API Services. When you connect a YouTube channel, you authorize PostsBridge through Google's OAuth consent screen, and we act on your channel only when you explicitly ask us to publish, or at the time you scheduled yourself.
We request exactly two permissions (scopes) and no others. The scope youtube.upload is used to upload the video you created in PostsBridge to your channel. The scope youtube.readonly is used to identify the channel you connected and to check the processing and visibility status of a video that PostsBridge uploaded.
We do not read or store your comments, your subscriber list, your watch or search history, your private messages, or any video that was not uploaded through PostsBridge. We never delete or edit videos on your channel, never manage playlists, and never post comments, ratings, or subscriptions on your behalf.
PostsBridge currently collects no engagement, statistics, or analytics data from YouTube: there is no analytics feature in the product and no such data is gathered. If we ever add one, we will update this policy first and ask for your consent before any such data is collected.
By connecting a YouTube channel and using the YouTube features of PostsBridge, you also agree to be bound by the YouTube Terms of Service, available at https://www.youtube.com/t/terms. Google's handling of your data is described in the Google Privacy Policy, available at https://policies.google.com/privacy.
- What we store for a connected channel: the channel ID, channel name, channel avatar image URL, public subscriber count, and the encrypted OAuth access and refresh tokens.
- What we store for a video you publish through PostsBridge: the video ID, the title, tags, and category you entered, the description taken from your post text, the visibility (privacy status) applied — today always private — the upload and processing status returned by YouTube, and the resulting video link.
- What we do not collect today: comments, subscriber identities, watch history, search history, analytics, engagement or revenue data, and any content on your channel that you did not publish through PostsBridge.
Data Sharing and Restrictions
We do not sell your data. We do not share YouTube or Google data with any third party, do not use it for advertising or ad targeting, do not build advertising profiles, and do not use it to train machine-learning or artificial-intelligence models. YouTube data is used only to show you the channel you connected and to publish the content you created.
The only processors involved are the infrastructure providers required to run the Service: our hosting provider, our database, and Cloudflare R2 object storage for the media files you upload. We may also disclose information where we are legally required to do so.
PostsBridge's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. That policy is available at https://developers.google.com/terms/api-services-user-data-policy.
Data Storage and Security
OAuth access and refresh tokens for your connected accounts are encrypted at rest using AES-256-GCM authenticated encryption. The encryption keys are held in the server environment, outside the database, and are never written to the database or to log files.
Passwords are kept only as salted hashes. Media files are stored using Cloudflare R2 object storage. All connections use HTTPS. Raw responses from platform APIs are not written to our logs, and access to your data is limited to what is required to run the Service.
Data Retention
We keep your data for as long as your account is active. When you disconnect a social account, the stored tokens and the connection details of that account are deleted immediately. When your account is deleted, the associated data is removed as described in our Data Deletion instructions.
We store the YouTube channel data returned at the moment you connect a channel (the channel ID, name, avatar image URL, and subscriber count) and keep it only while that channel stays connected. It is deleted the moment you disconnect the channel, and it is refreshed only when you reconnect: PostsBridge does not re-fetch it in the background, so it shows your channel as it was at the time of connection. For a video published through PostsBridge we keep the video identifier and its link so we can show you the history of what you published.
Revoking Access
You can disconnect any connected account at any time from the Accounts page in PostsBridge. Disconnecting deletes the tokens and the connection details we store for that account.
For Google and YouTube you can additionally, and at any time, revoke PostsBridge's access from your Google Account security settings at https://myaccount.google.com/permissions. Removing PostsBridge on that page withdraws the authorization on Google's side, independently of the data we delete on ours. We recommend doing both.
Revoking access stops any future publishing to that channel. Videos that were already uploaded remain on your channel and can be managed or deleted from YouTube Studio.
Your Rights and Choices
You can review and update your profile and disconnect any social account at any time from within PostsBridge. You may also contact us to request access to, correction of, or deletion of your data; the exact steps are described on our Data Deletion page.
Children's Privacy
The Service is not directed to individuals below the age required by their local law to consent to online services, and we do not knowingly collect their data.
Changes to This Policy
We may update this policy from time to time. Material changes are reflected by the "Last updated" date shown above.
Contact
For any questions about this page or a request regarding your data, contact us at: [email protected]