Privacy Policy
Last updated: 2026-09-07
T.Social ("the Service") lets you connect a Facebook Page (and, through the same Facebook authorization, a linked Instagram Business account) and a Pinterest account, then schedule content to them. This policy explains what we store and why.
What we collect
| Data | Source | Why |
|---|---|---|
| App-scoped user ID, name, email | Facebook Login or Google Sign-In | To identify your account and sign you in |
| Long-lived Facebook user access token | Facebook Login | To list the Pages you manage when you connect one |
| Page ID, Page name, Page access token, linked Instagram account ID/username | Facebook Graph API, when you connect a Page | To publish the posts you schedule |
| Pinterest username, board ID/name, Pinterest access & refresh tokens | Pinterest API (OAuth), when you connect Pinterest | To publish Pins to your board |
| Topic, timezone, posting schedule, captions, image prompts, generated images, post status/history | Created by you in the app | To generate and publish your content |
| Timestamps, sanitized error messages, and your IP address (transiently) | Automatic | Operations, troubleshooting, and rate limiting |
How access tokens are handled
- All access and refresh tokens (Facebook, Instagram, Pinterest) are encrypted at rest (Fernet/AES).
- Tokens are sent only to the platform they belong to (Meta or Pinterest), only over HTTPS, only in the request body or Authorization header — never in a URL or a log.
- We request the least permissions needed to publish:
- Facebook / Instagram:
pages_show_list,pages_read_engagement,pages_manage_posts,pages_manage_engagement(plusinstagram_basic,instagram_content_publishwhere enabled). - Pinterest:
user_accounts:read,boards:read,boards:write,pins:read,pins:write.
- Facebook / Instagram:
Who we share data with (sub-processors)
We do not sell your data or share it for advertising. We use these providers to run the Service:
- Meta Platforms — publishing to your Page/Instagram (Graph API).
- Pinterest — publishing Pins to your board (Pinterest API), only if you connect Pinterest.
- Google — only if you choose Google Sign-In (name, email).
- Render — application hosting.
- Neon — PostgreSQL database hosting.
- Upstash — Redis job queue.
- Pollinations.ai — image generation; receives only the short text prompt derived from your chosen topic, no account data.
Retention
We keep your data until you delete it. When you disconnect an account (a Page, an Instagram account, or Pinterest) its access and refresh tokens are removed. When you remove the app from Facebook, Meta notifies us and we revoke all tokens and stop automation for your account. You can revoke Pinterest access at any time from your Pinterest account settings. When you delete your account (below), everything is erased.
Your choices
- Access / export: your data is visible on your dashboard; contact us for a copy.
- Delete everything: use Account → Delete my account. This permanently removes your login, connections, tokens, and all generated/scheduled posts.
- Via Facebook: remove the app in your Facebook
Settings → Business Integrations. Meta will send us a data-deletion
request and we will erase your data and provide a confirmation page at
https://www.social.tyagents.com/data-deletion.
Contact
Contact the operator of this deployment for privacy questions or requests.