Privacy Policy
Last updated 4 September 2026
What Post Once does
Post Once watches one social account you own for new short videos, then republishes each new video to the other accounts you have connected. To do that it needs permission to read your videos on the account you choose as the source, and permission to publish on the accounts you choose as destinations.
This policy explains what we collect, why, who we share it with, and how to get it deleted.
What we collect
- Account details: your email address, and a hashed password if you signed up with one. If you sign in with Google or Apple we store the identifier they give us, your email, and nothing else from those accounts.
- Platform connections: for each account you connect (YouTube, Instagram, TikTok) we store the platform account id, the handle, the permissions you granted, and the access and refresh tokens. Tokens are encrypted with AES-256-GCM before they are written to our database.
- Video metadata: the title, description, duration, thumbnail, publish time and platform id of each video we detect and republish, plus the result of each publish attempt.
- Video files: a temporary copy of each video, needed to move it from one platform to another.
- Operational logs: request and job logs that record errors and timing, used to keep the service running.
- Billing: if you subscribe, our payment processor handles your card details. We never see or store them. We keep your customer identifier and subscription status.
How we use it
We use your data only to run the service you signed up for: detecting new videos on your source account, republishing them to your destinations, showing you the results, keeping your connections authorised, emailing you when something needs your attention, and billing you if you are on a paid plan.
We do not sell your data. We do not use it for advertising. We do not use your videos or your account data to train machine learning models, and we do not share it with anyone who does.
Data from connected platforms
Data we obtain from YouTube, Instagram and TikTok is used only to perform the cross-posting you asked for. We read the list of recent videos on your source account and, for each new video, its file and its caption. We write new posts to your destination accounts. We do not read your direct messages, comments, followers or analytics, and we do not request permission to.
Post Once's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Post Once uses the YouTube API Services. By connecting a YouTube account you agree to the YouTube Terms of Service. You can revoke our access to your Google account at any time at https://myaccount.google.com/permissions.
How long we keep it
- Video files: deleted from our storage roughly 24 hours after the video has been republished. We do not keep an archive of your videos.
- Video metadata and publish history: kept while your account is open, so you can see what was posted where.
- Platform tokens: kept until you disconnect the account or delete your account, whichever comes first.
- Account details: kept while your account is open.
- Operational logs: kept for up to 30 days.
Deleting your data
You can disconnect any platform at any time from the Accounts page in Post Once. Disconnecting revokes our stored tokens for that account and stops all reading and publishing on it. You can also revoke access from the platform itself: Google at myaccount.google.com/permissions, Instagram under Settings, Website Permissions, Apps and Websites, and TikTok under Settings, Security and permissions, Manage app permissions.
To delete your account and everything we hold about you, email [email protected] from the address you signed up with, with the subject "Delete my account". We delete your account, your platform connections and tokens, your video metadata and publish history within 30 days, and confirm by email when it is done. Any temporary video copies are already deleted on the 24 hour schedule described above.
Backups are rotated out within 30 days, so deleted data disappears from backups within that window. We may keep the minimum records we are legally required to keep, such as invoices for paid subscriptions.
Your rights
You can ask us for a copy of the data we hold about you, ask us to correct it, ask us to delete it, or object to how we use it. Email us and we will respond within 30 days. If you are in the EEA or the UK, the legal basis for our processing is the contract between us, which is the service you signed up for, and our legitimate interest in keeping that service secure and working.
Our servers are in Germany. If you use Post Once from outside the EEA, your data is transferred to and processed there.
Security
Platform tokens are encrypted at rest. Passwords are hashed with bcrypt and are never stored in readable form. Traffic to Post Once is served over HTTPS. Access to production systems is restricted to the people who operate the service.
No service can promise perfect security. If we ever discover a breach affecting your data, we will tell you.
Children
Post Once is not intended for anyone under 13, and we do not knowingly collect data from children. If you believe a child has given us data, email us and we will delete it.
Changes to this policy
If we change this policy in a way that affects how we handle your data, we will update the date at the top of this page and, for significant changes, email you before the change takes effect.
Contact
Questions about this policy, or requests about your data, go to [email protected].
Post Once