Privacy
Privacy Policy
Effective and last updated August 23, 2026
1. Who is responsible for your data?
The controller for AutoPostPlanner is Hakan Hasan Karakoyun, operating AutoPostPlanner in Germany ("AutoPostPlanner", "we", "us"). Privacy questions and data-rights requests can be sent to hakanhasankarakoyun@gmail.com. This policy applies to the AutoPostPlanner macOS application and this official website.
2. What the service does
AutoPostPlanner is a local-first tool for preparing, scheduling, and publishing creator-selected media through official social-platform APIs. The application does not request or store your TikTok, Google, YouTube, Meta, or Instagram password. Connections use the provider's OAuth screen, where you choose whether to grant access.
3. Data we process
Depending on the features you use, we process:
- local account and app settings, including locale and scheduling preferences;
- provider user ID, display name, avatar, account capabilities, and granted scopes;
- encrypted OAuth access and refresh tokens needed for actions you authorize;
- media, thumbnails, captions, hashtags, privacy settings, schedules, and destinations;
- provider responses, job IDs, timestamps, and attempts used for retries and duplicate prevention; and
- technical logs and information you send when requesting support.
4. TikTok permissions and use
AutoPostPlanner requests user.info.basic to show the TikTok account you connected. It requests video.uploadwhen you choose to send an editable draft to your TikTok inbox, and video.publish when you expressly authorize Direct Post. Before delivery, the app displays the selected creator, media, caption, privacy, and consent controls. Sandbox or unaudited Direct Posts may be restricted to Only you. TikTok data is used only for these user-requested features—not for advertising, profiling, sale, or unrelated sharing.
5. Purposes and legal bases
- Contract: connecting accounts, saving drafts, executing schedules, publishing approved content, and support (GDPR Article 6(1)(b)).
- Consent: optional OAuth permissions, withdrawable by disconnecting or revoking access (Article 6(1)(a)).
- Legitimate interests: security, failure diagnosis, duplicate prevention, and reliability (Article 6(1)(f)).
- Legal obligations: compliance with applicable law (Article 6(1)(c)).
6. Local storage and recipients
The desktop MVP stores its database, uploads, schedules, encrypted credentials, and audit records in the locally configured environment on your Mac. When you authorize an action, the minimum necessary media and metadata are sent to your selected destination, such as TikTok, Google/YouTube, or Meta/Instagram, and processed under that provider's terms and privacy policy. We may disclose data to infrastructure vendors acting on our instructions or when required by law. We do not sell personal data.
7. International transfers
Social-platform providers may process data outside Germany or the European Economic Area. Their privacy notices describe locations and safeguards, such as adequacy decisions or standard contractual clauses. You choose whether to connect and send content to each provider.
8. Retention
Locally stored connections and encrypted tokens remain until you disconnect, revoke authorization, reset app data, or delete the local database. Drafts, media, schedules, and attempt records remain until you delete them or reset local data. Temporary operational logs are kept only as long as reasonably necessary for security and troubleshooting. Provider-side data follows the provider's rules. Legal obligations may require limited records to be retained longer.
9. Security
Safeguards include OAuth rather than platform passwords, encryption of provider tokens at rest, least-privilege scopes, OAuth state validation, controlled retries, and idempotency records. No method of storage or transmission is completely secure.
10. Your rights and deletion
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or objection. You may withdraw consent without affecting earlier lawful processing and complain to a competent data-protection authority. Email the controller above; we may need to verify your identity. The Data Deletion guide explains how to remove local data and revoke provider access immediately.
11. Children, tracking, and automated decisions
AutoPostPlanner is not directed to children under 18. This information website does not use advertising trackers, and the local MVP does not enable separate cloud analytics. We do not make decisions producing legal or similarly significant effects solely by automated means.
12. Changes
We may update this policy when the service or legal requirements change. The date above identifies the current version. Material changes will be presented through the website or app where required.
