Privacy Policy
This policy explains what Postdeck at postdeck.rgkn.dev collects, why, and what you can do about it. The controller of your personal data is Artyom Mamonov, reachable at [email protected]. We follow the EU General Data Protection Regulation (GDPR).
What we collect
| Data | Why |
|---|---|
| Your username, a salted scrypt hash of your password, your role | To let you sign in and manage your account |
A session cookie (pd_session), and hashes of the API keys you create | To keep you signed in and let your scripts and agents act for you. There are no analytics, advertising or tracking cookies. |
| The videos and photos you upload, titles, descriptions, schedules and per-platform settings | To publish your posts when you ask |
| Access and refresh tokens of the accounts you connect, encrypted with AES-256-GCM | To post to those accounts on your behalf |
| Basic profile data from connected accounts: account ID, name, handle, avatar, and limits the platform reports | To show which account a post goes to and what it allows |
| An activity log of publishing attempts and results, and standard server logs (IP address, time, request) | To show you what happened, find errors and keep the service secure |
Data from TikTok
When you connect TikTok, Postdeck asks for two scopes and uses them only as follows:
user.info.basic: your open ID, display name and avatar, to identify the connected account in Postdeck.video.publish: to upload the videos and photos you scheduled, with the caption, privacy level, interaction settings and commercial content disclosure you chose, and to read your creator info and the status of those uploads.
Postdeck does not read your existing videos, followers, likes, messages or analytics, does not use TikTok data for advertising or profiling, and does not share it with anyone. You can revoke access at any time by disconnecting the account in Postdeck, or in the TikTok app under Settings and privacy → Security → Manage app permissions.
Who receives your data
- The platforms you choose. Your media and captions go to YouTube (Google), TikTok, Instagram (Meta) or Telegram only when you schedule a post to them, under their own privacy policies.
- Infrastructure. Postdeck runs on a server we operate in Spain. Traffic passes through Cloudflare, which acts as a proxy and processes connection data under its own terms.
We do not sell or rent personal data, and we do not use it for advertising.
Legal basis
We process your data to provide the service you signed up for (Art. 6(1)(b) GDPR) and, for security logs, on our legitimate interest in keeping the service safe (Art. 6(1)(f)).
How long we keep it
- Media, posts and settings: until you delete them or your account.
- Tokens of a connected account: until you disconnect it, which deletes them.
- Activity and server logs: up to 90 days.
- Deleting your account removes your media, posts, connected accounts, keys and activity. Posts already published stay on the platforms until you delete them there.
Your rights
You can ask for access to, correction, deletion or a copy of your data, and object to or restrict its processing. Write to [email protected]; we answer within 30 days. You may also complain to your data protection authority; in Spain that is the Agencia Española de Protección de Datos.
Security
Connections are encrypted with HTTPS, platform tokens are encrypted at rest, passwords and API keys are stored only as hashes, and each person can see only their own data.
Children
Postdeck is not meant for anyone under 18 and we do not knowingly collect their data.
Changes
We will post any update here and change the date at the top. Material changes are announced in the app.