Privacy Policy
Last updated: 14 September 2026
This policy explains what W AUTO POST collects, why, how connected social accounts are handled, and how to have data deleted. It covers the W AUTO POST application and this website.
Who we are
W AUTO POST is a social media management platform operated by [COMPANY LEGAL NAME NOT YET CONFIGURED], registered at [REGISTERED ADDRESS NOT YET CONFIGURED]. For any privacy question, or to exercise the rights described below, contact [CONTACT EMAIL NOT YET CONFIGURED].
W AUTO POST is a business tool used by social media agencies to manage publishing on behalf of their clients. Where an agency uses W AUTO POST to process information about its own clients, the agency is the controller of that information and W AUTO POST acts as a processor on its instructions.
Information we collect
We collect only what the service needs to function. Specifically:
- Account information. The email address and name used to create a W AUTO POST login, and the role that account holds (agency administrator or client). Authentication is handled by Supabase Auth; we store a password hash, never a plaintext password.
- Client records. The client name, company name, contact details, timezone and any notes an agency administrator chooses to enter.
- Connected social account data. When an account is connected, we store the platform, the account's public username and platform account identifier, the profile image URL where provided, and the access and refresh tokens issued by that platform.
- Content you upload. Videos, images, thumbnails, captions, titles, descriptions and hashtags, together with file metadata such as size, format, duration and dimensions.
- Scheduling and publishing records. Scheduled times, publishing status, the identifier and URL of the resulting post on the platform, and the details of any failure.
- Review activity. Approvals, rejections, change requests and comments made by client users.
- Performance data. Where a connected platform makes metrics available through its API, we store what it returns — for example views, likes, comments and shares. We do not estimate or generate metrics.
- Audit logs. A record of significant actions: who performed them, when, on which record, and whether they succeeded. Audit logs never contain access tokens, secrets or passwords.
- Contact form submissions. The name, email address, subject and message you send us, plus a one-way hash of the submitting IP address used solely to limit abuse. We do not store the raw IP address.
How social platform connections work
Connecting a social account uses the platform's own OAuth authorisation flow. The account holder signs in with the platform directly, on the platform's website, and chooses whether to grant access.
- We never ask for, receive or store social media passwords.
- We never ask anyone to disable two-factor authentication, and we do not attempt to bypass it, or CAPTCHA, or any other platform verification.
- We do not scrape platforms or automate logins. All access is through official, documented APIs.
- We request the narrowest set of permissions that the requested features require.
- An authorisation can be withdrawn at any time, either from within W AUTO POST by disconnecting the account, or from the platform’s own app settings.
Data obtained from a platform is used only to provide the features you asked for — publishing the content you scheduled, reporting whether it succeeded, showing account status, and displaying the metrics that platform reports. We do not sell it, use it for advertising, or use it to train machine learning models.
How access tokens are protected
Access and refresh tokens are the most sensitive data in the system and are treated accordingly:
- They are stored in a dedicated database table that has row level security enabled with no access policies, and no privileges granted to any application role. No signed-in user — client or administrator — can read it through the API.
- They are additionally encrypted with AES-256-GCM before being written, using a key held only in the server environment.
- They are decrypted only inside trusted server-side code at the moment a platform request is made.
- They are never sent to the browser, never written to logs, and never included in audit records.
- They are deleted when an account is disconnected or the client is deleted.
Platform data: what each platform gives us, and what we do with it
This section is written to satisfy the disclosure requirements of the platforms we integrate with. It applies in addition to everything above.
Scopes we request
- TikTok —
user.info.basicto read the account's username and avatar so several TikTok accounts can be told apart;video.uploadandvideo.publishto send and publish the video the agency scheduled. - Instagram —
instagram_basicto read the professional account's profile and media list;instagram_content_publishto create and publish a post or Reel;pages_show_listandbusiness_managementto find the linked Facebook Page and confirm the account belongs to the business that authorised us. - YouTube —
youtube.uploadto upload a video to the connected channel;youtube.readonlyto read the channel name and the public view, like and comment counts of videos we published.
What we do with it
- We use platform data only to provide the features you asked for: publishing the content you scheduled, reporting whether it succeeded, showing account status, and displaying the metrics the platform reports for content we published.
- We do not sell platform data, use it for advertising or ad targeting, or use it to train machine learning or AI models.
- We do not transfer platform data to third parties except the infrastructure providers listed above that are necessary to run the service, and only for that purpose.
- We do not request access to private messages, follower lists, or any data unrelated to publishing and reporting.
Storage and retention
- Access and refresh tokens are encrypted and stored only for as long as the connection exists. Disconnecting an account deletes them immediately.
- Profile data we cache (username, display name, avatar URL) is refreshed from the platform and deleted when the account is disconnected.
- Metrics we retrieve are stored as dated snapshots so performance can be shown over time, and are deleted with the post they belong to.
- Where a platform requires that its data be deleted or refreshed within a set period, we honour that period.
Revoking access
You can withdraw our access at any time, and it takes effect immediately:
- Any platform — ask your agency to disconnect the account in W AUTO POST, which deletes the stored authorisation.
- Google / YouTube — revoke at Google security settings.
- TikTok — Settings and privacy, then Security and permissions, then Manage app permissions.
- Instagram / Meta — Settings, then Apps and websites, then remove the application.
You can also request deletion of everything we hold through our Data Deletion page.
YouTube API Services: required disclosures
W AUTO POST uses YouTube API Services. By connecting a YouTube channel you are also agreeing to the YouTube Terms of Service, and Google's handling of any data it receives is governed by the Google Privacy Policy. We store YouTube user data only as described above, and you can revoke our access to it at any time through Google security settings.
TikTok and Meta platform terms
Our use of TikTok data is governed by the TikTok Developer Terms, and our use of Instagram and Facebook data by the Meta Platform Terms. Where those terms are stricter than this policy, those terms apply.
Why we process this information
We process the information above in order to:
- Provide the service — storing content, scheduling it, and publishing it to the accounts you connected.
- Authenticate users and keep each client’s data separated from every other client’s.
- Show the status of accounts, posts and publishing attempts, including failures.
- Maintain an audit trail for security and accountability.
- Respond to support and contact enquiries.
- Prevent abuse of the service, including rate-limiting the public contact form.
- Meet legal obligations that apply to us.
Where the law requires a lawful basis, we rely on performance of a contract for providing the service, our legitimate interests in keeping the service secure and functioning, and consent where consent is what a platform or a regulation requires.
Third-party services we use
We keep third-party processors to a minimum. The services below are integral to running W AUTO POST:
- Supabase — database, authentication and file storage. Content, account records and encrypted tokens are stored here.
- Vercel — application hosting and delivery. Vercel processes request metadata such as IP address as part of serving the site.
- Connected social platforms — TikTok, Instagram/Meta and YouTube/Google, for accounts you choose to connect. Their own privacy policies govern what they do with data on their side.
We do not use third-party advertising networks, and we do not embed third-party tracking or analytics scripts.
How long we keep information
- Account and client records are kept while the account is active.
- Uploaded media, posts and their publishing history are kept while the client exists, so that the record of what was published remains accurate.
- Access tokens are deleted as soon as an account is disconnected.
- Audit logs are retained so that the security record stays meaningful, and are not deleted when an individual record is edited.
- Contact form submissions are kept while the enquiry is open and for a reasonable period afterwards.
- On deletion of an account, data is removed as described in the Data Deletion policy.
Your rights
Depending on where you live, you may have the right to access the information we hold about you, correct it, delete it, restrict or object to how we use it, and receive a copy in a portable format. You may also have the right to complain to your local data protection authority.
To exercise any of these, contact [CONTACT EMAIL NOT YET CONFIGURED] or use the Data Deletion page. If you are a client of an agency that uses W AUTO POST, we may need to direct your request to that agency, since they control the records concerning you.
Children
W AUTO POST is a business tool and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child has provided us with information, contact us and we will delete it.
International transfers
Our infrastructure providers operate globally, so information may be processed outside the country where you are located. Where required, transfers rely on appropriate safeguards such as standard contractual clauses.
Changes to this policy
We may update this policy as the product changes. The “last updated” date at the top always reflects the current version, and material changes will be communicated to account holders.
Contact
Questions about this policy: [CONTACT EMAIL NOT YET CONFIGURED], or write to [COMPANY LEGAL NAME NOT YET CONFIGURED] at [REGISTERED ADDRESS NOT YET CONFIGURED].