Legal
Privacy Policy
PostEmAll holds the posts you schedule, the access tokens for the accounts you connected, and the public performance figures of what it published. It holds nothing else, and it sells none of it.
In effect from 20 August 2026. See also the Terms & Conditions.
01Who is responsible
Songtive operates PostEmAll at https://postemall.songtive.com and is the controller of the data described here. Write to support@songtive.com about anything on this page.
02What we collect
| Category | What it is | Why we have it |
|---|---|---|
| Content you create | Captions, titles, custom fields, and the video, image or carousel files you upload. | It is the post. Without it there is nothing to publish. |
| Schedule | The account, the format and the date and time you chose. | The worker reads it to know what is due. |
| Connection data | The access and refresh tokens a platform issues, its expiry, the granted permissions, and the account's public handle, display name and avatar. | To publish on your behalf and to show you which account is which. Tokens are stored encrypted. |
| Publication results | The post id the platform returned, the resulting URL, and any error text if it failed. | To link you to the live post and to explain a failure. |
| Performance figures | Views, impressions, reach, likes, comments, shares and saves for posts PostEmAll published. | The performance charts. Fourteen days of daily history are kept per post. |
| Operational logs | Timestamped records of publish attempts, authentication failures and API errors, including the calling IP address. | To debug a failed post and to stop somebody guessing the access token. |
There is no analytics tracker, no advertising pixel and no third-party session cookie on this site or in the console. The only cookie the Service sets is a short-lived, signed one during a platform connect flow, which exists to prove that the login that comes back is the one you started.
03What each platform connection gives us
Every permission the Service requests is listed below, exactly as it is sent to the provider, with what it is used for. The Service does not request any permission that is not on this list.
TikTok
user.info.basicvideo.uploadvideo.listRead the connected account's display name and avatar so you can tell two accounts apart; upload the video or photo you scheduled; read back the view, like, comment and share counts of the posts PostEmAll published.
YouTube
https://www.googleapis.com/auth/youtube.uploadhttps://www.googleapis.com/auth/youtube.readonlyhttps://www.googleapis.com/auth/youtube.force-sslUpload a video or short to the connected channel, read that channel's own video statistics, and read the comments people leave on those videos. YouTube grants comment access only through youtube.force-ssl, which is broader than reading — PostEmAll never writes, moderates or deletes anything on the channel.
instagram_basicinstagram_content_publishinstagram_manage_insightspages_show_listbusiness_managementList the professional accounts you administer, publish a reel, image or carousel to the one you chose, and read its insights.
pages_manage_postspages_read_engagementpages_show_listread_insightsbusiness_managementList the Pages you administer, publish to the Page you chose, and read that Page's post insights.
X
tweet.readtweet.writeusers.readmedia.writeoffline.accessRead the connected handle, upload media and post on its behalf. Offline access keeps the connection alive without a fresh login every two hours.
Data received from TikTok is handled in accordance with the TikTok Developer Terms of Service. It is used only for the purposes stated above, it is not combined with data from other sources to build a profile of any TikTok user, and it is deleted when you disconnect the account.
04What we never do
- Read your direct messages, your private inbox or anyone else's content.
- Follow, unfollow, like or comment on your behalf.
- Sell, rent or share your data with advertisers or data brokers.
- Train a machine-learning model on your content or your audience data.
- Publish anything you did not schedule — every post starts as a row you created.
05Who else sees it
Your content is sent to exactly one kind of recipient: the social platform you scheduled it for. Beyond that, the Service relies on a small number of processors:
| Processor | What it handles |
|---|---|
| The social platforms you connect | Receive the post you scheduled, and return its id and its statistics. Each is an independent controller of what you publish to it. |
| Object storage (S3-compatible) | Holds a private, non-public copy of your uploaded media so publishing does not depend on one machine. |
| Server hosting | Runs the application and the database on a dedicated virtual server in the EU. |
We do not sell personal data, we do not share it for advertising, and we do not disclose it to anyone else except where the law requires it.
06Where it is stored, and how it is protected
Posts, schedules and connection records live in a single database file on a server we operate in the EU. Media files live beside it and in private object storage. In transit everything travels over HTTPS.
- Platform access tokens are encrypted at rest, not stored in plain text.
- Every HTTP surface — the console, the read-only routes and the MCP endpoint — is behind a single admin token, and a production deployment refuses every request until that token is set.
- Repeated wrong tokens are rate-limited and logged.
- There are no user accounts and no password database, because there is nothing multi-tenant to separate.
07How long we keep it
| Data | Retention |
|---|---|
| Posts and their media | Until you delete the post, or ask us to delete your data. |
| Access and refresh tokens | Until you disconnect the account or revoke access at the platform. Deleted immediately at that point. |
| Daily performance figures | Rolling 14 days per post, then overwritten. |
| Operational logs | Up to 30 days, then rotated out. |
08Your choices and your rights
You can, at any time and without asking us:
- Disconnect a platform in the console. The stored token is deleted at once and the Service can no longer act for that account.
- Revoke access from the platform’s own settings — for TikTok, under Settings → Security & permissions → Manage app permissions. This has the same effect and does not depend on us.
- Delete a post, which removes its caption, its schedule and its media from the Service.
Where the GDPR applies you also have the right to access, correct, export, restrict or erase your personal data, and to complain to your supervisory authority. Write to support@songtive.com; we answer within 30 days. A deletion request removes your posts, media, tokens and statistics — everything except log entries we are required to keep, which expire on their own schedule.
Deleting content from PostEmAll does not delete a post that has already been published. Remove that on the platform itself.
09Children
The Service is not intended for anyone under 18 and we do not knowingly collect data from children. If you believe a child’s data has reached us, write to support@songtive.com and it will be deleted.
10Changes to this policy
The date at the top of this page says when the current text took effect. A change that materially affects how your data is handled will be announced here before it applies. Past versions are in the project’s public git history.
11Contact
Privacy questions, access requests and deletion requests all go to support@songtive.com. The rules of use are in the Terms & Conditions.