Privacy Policy
Last updated: October 2, 2026
Postyra ("we", "the application") helps you manage and publish your own social media content using official platform APIs. This policy describes what we collect and how it is used. It reflects the current architecture; it is not legal advice.
Data we collect
- Account registration: email address and authentication credentials (via Supabase Auth).
- Profile preferences such as timezone.
- Brand names you create and platform connection metadata (account IDs, usernames).
- OAuth access and refresh tokens for connected platforms — stored encrypted at rest and used only server-side to publish on your behalf.
- Media files you upload (video/image), captions, titles, tags, and scheduling metadata.
- Publication history (platform post IDs/URLs when available) and operational logs/errors.
How we use data
We use this data solely to operate the publishing product: authenticate you, store media, schedule posts, call official Instagram/TikTok/YouTube APIs you authorized, show status, and secure the service. We do not sell personal data.
Storage & processors
Application data is stored in Supabase (PostgreSQL + Auth). Media is stored in Cloudflare R2. The app may be hosted on Cloudflare Workers. Platform APIs (Meta, TikTok, Google) process content you choose to publish under their respective terms.
Security
Tokens are encrypted with AES-256-GCM using a server-side key. Tokens are never sent to the browser. Access is protected with authentication and database row-level security.
Retention & deletion
You may disconnect platforms (tokens cleared) and delete your account from Settings. Account deletion removes brands, posts, connections, and media records and deletes the auth user. Object storage cleanup is performed best-effort. Publication records on Instagram/TikTok/YouTube remain under those platforms' controls.
Revoking access
Disconnect a platform in Accounts, or revoke Postyra from the platform's security settings. You can also request deletion via Delete account.
Contact
For privacy requests, use the Support page.