Privacy Policy

Last updated: 2026-09-07

T.Social ("the Service") lets you connect a Facebook Page (and, through the same Facebook authorization, a linked Instagram Business account) and a Pinterest account, then schedule content to them. This policy explains what we store and why.

What we collect

DataSourceWhy
App-scoped user ID, name, emailFacebook Login or Google Sign-InTo identify your account and sign you in
Long-lived Facebook user access tokenFacebook LoginTo list the Pages you manage when you connect one
Page ID, Page name, Page access token, linked Instagram account ID/usernameFacebook Graph API, when you connect a PageTo publish the posts you schedule
Pinterest username, board ID/name, Pinterest access & refresh tokensPinterest API (OAuth), when you connect PinterestTo publish Pins to your board
Topic, timezone, posting schedule, captions, image prompts, generated images, post status/historyCreated by you in the appTo generate and publish your content
Timestamps, sanitized error messages, and your IP address (transiently)AutomaticOperations, troubleshooting, and rate limiting

How access tokens are handled

  • All access and refresh tokens (Facebook, Instagram, Pinterest) are encrypted at rest (Fernet/AES).
  • Tokens are sent only to the platform they belong to (Meta or Pinterest), only over HTTPS, only in the request body or Authorization header — never in a URL or a log.
  • We request the least permissions needed to publish:
    • Facebook / Instagram: pages_show_list, pages_read_engagement, pages_manage_posts, pages_manage_engagement (plus instagram_basic, instagram_content_publish where enabled).
    • Pinterest: user_accounts:read, boards:read, boards:write, pins:read, pins:write.

Who we share data with (sub-processors)

We do not sell your data or share it for advertising. We use these providers to run the Service:

  • Meta Platforms — publishing to your Page/Instagram (Graph API).
  • Pinterest — publishing Pins to your board (Pinterest API), only if you connect Pinterest.
  • Google — only if you choose Google Sign-In (name, email).
  • Render — application hosting.
  • Neon — PostgreSQL database hosting.
  • Upstash — Redis job queue.
  • Pollinations.ai — image generation; receives only the short text prompt derived from your chosen topic, no account data.

Retention

We keep your data until you delete it. When you disconnect an account (a Page, an Instagram account, or Pinterest) its access and refresh tokens are removed. When you remove the app from Facebook, Meta notifies us and we revoke all tokens and stop automation for your account. You can revoke Pinterest access at any time from your Pinterest account settings. When you delete your account (below), everything is erased.

Your choices

  • Access / export: your data is visible on your dashboard; contact us for a copy.
  • Delete everything: use Account → Delete my account. This permanently removes your login, connections, tokens, and all generated/scheduled posts.
  • Via Facebook: remove the app in your Facebook Settings → Business Integrations. Meta will send us a data-deletion request and we will erase your data and provide a confirmation page at https://www.social.tyagents.com/data-deletion.

Contact

Contact the operator of this deployment for privacy questions or requests.

Back · Terms of Service