Postdeck Sign in

Privacy Policy

Last updated 22 September 2026 · applies to Postdeck at postdeck.rgkn.dev

This policy explains what Postdeck at postdeck.rgkn.dev collects, why, and what you can do about it. The controller of your personal data is Artyom Mamonov, reachable at [email protected]. We follow the EU General Data Protection Regulation (GDPR).

What we collect

DataWhy
Your username, a salted scrypt hash of your password, your roleTo let you sign in and manage your account
A session cookie (pd_session), and hashes of the API keys you createTo keep you signed in and let your scripts and agents act for you. There are no analytics, advertising or tracking cookies.
The videos and photos you upload, titles, descriptions, schedules and per-platform settingsTo publish your posts when you ask
Access and refresh tokens of the accounts you connect, encrypted with AES-256-GCMTo post to those accounts on your behalf
Basic profile data from connected accounts: account ID, name, handle, avatar, and limits the platform reportsTo show which account a post goes to and what it allows
An activity log of publishing attempts and results, and standard server logs (IP address, time, request)To show you what happened, find errors and keep the service secure

Data from TikTok

When you connect TikTok, Postdeck asks for two scopes and uses them only as follows:

Postdeck does not read your existing videos, followers, likes, messages or analytics, does not use TikTok data for advertising or profiling, and does not share it with anyone. You can revoke access at any time by disconnecting the account in Postdeck, or in the TikTok app under Settings and privacy → Security → Manage app permissions.

Who receives your data

We do not sell or rent personal data, and we do not use it for advertising.

Legal basis

We process your data to provide the service you signed up for (Art. 6(1)(b) GDPR) and, for security logs, on our legitimate interest in keeping the service safe (Art. 6(1)(f)).

How long we keep it

Your rights

You can ask for access to, correction, deletion or a copy of your data, and object to or restrict its processing. Write to [email protected]; we answer within 30 days. You may also complain to your data protection authority; in Spain that is the Agencia Española de Protección de Datos.

Security

Connections are encrypted with HTTPS, platform tokens are encrypted at rest, passwords and API keys are stored only as hashes, and each person can see only their own data.

Children

Postdeck is not meant for anyone under 18 and we do not knowingly collect their data.

Changes

We will post any update here and change the date at the top. Material changes are announced in the app.