Privacy Policy
This policy explains how Yusuf Social Postiz handles information used by its private social media dashboard and this public information website.
Operator and scope
Yusuf Suhair operates this personal, self-hosted application. It is intended for the operator’s own social accounts and is not open for public registration. This policy applies to this installation, not to other Postiz installations or the social platforms themselves.
Information accessed and stored
Depending on the accounts connected and permissions granted, the dashboard processes account identifiers, display names, profile images, account email addresses, channel details, media and post metadata, comments and engagement or audience statistics. It also stores uploaded media, drafts, captions, schedules and publishing results.
OAuth access and refresh tokens allow the dashboard to communicate with connected platforms. Social account passwords are entered on the platform’s own login screen, not collected by this application. Dashboard login information and session cookies are used separately to secure the self-hosted account.
How information is used
Information is used to identify connected accounts, organize and schedule content, perform actions requested through the dashboard, display available analytics and diagnose service errors. Connecting an account grants API access; publishing or scheduling content is a separate action. Permissions may be broader than the features currently used.
Hosting and sharing
The dashboard, database and media storage run on Railway. This public policy website is hosted on Cloudflare Pages. These providers may process technical information such as IP addresses, request details and operational logs to deliver and protect their services. Data may be processed outside your country.
Content and related information are sent to the relevant social platform when an authorized action requires it. The operator does not sell personal information or use connected-account data for advertising. No third-party advertising or analytics scripts are added to this policy website. The dashboard uses cookies or similar browser storage for authentication and functionality. Optional AI integrations are not configured as part of this installation.
Retention, control and deletion
Tokens, drafts, media and account records are retained as needed for the connected-account workflow. You can stop future access by revoking the application in the platform’s account settings. Revocation does not itself erase all previously stored local records or posts already published on a social platform.
Contact the operator to request access to, correction of or deletion of data held by this installation, identifying the relevant account. The operator will verify ownership before acting. Deletion includes relevant local account records, tokens and stored content; any retained backup copies are subject to the hosting provider’s backup lifecycle. Data required to meet legal obligations or resolve a security incident may need to be retained. See data deletion instructions.
Connected platforms
This application uses YouTube API Services. Google’s handling of data is described in the Google Privacy Policy. You can revoke Google access through Google Account connections. Instagram access can be managed in Apps and websites. For TikTok, use the app’s security settings to manage connected app permissions.
Security and updates
Access to the dashboard is restricted, and public connections use HTTPS. No online service can guarantee absolute security. This policy may be updated as the installation changes; the date below identifies the current version.
Contact
For privacy questions or requests, contact Yusuf Suhair: yusufmohdsuhair@gmail.com.