Privacy Policy
Effective date: 9 October 2026
This policy explains how Open Social at social.jengk.dev processes data when you use the dashboard, API, CLI, or MCP integration.
Data we process
- Account details: name, email address, password hash, organization membership, and authentication sessions.
- Connected account details: platform account or channel ID, display name, handle, avatar URL, permissions, and connection status.
- Credentials: access tokens, refresh tokens, and app passwords that you authorize us to use. Stored platform credentials are encrypted. API keys are stored as hashes.
- Publishing data: post text, uploaded media, filenames, media details, selected accounts, schedules, privacy settings, platform post IDs, and publication results.
- Operational data: API usage, configured limits, webhook destinations and delivery records, errors, and technical request or session details such as IP address and user agent.
Why we use data
We use this data to authenticate users, connect authorized accounts, validate and publish content, run schedules, refresh credentials, show publication status, deliver requested webhooks, and resolve service or security problems. We do not sell connected account data, use it for advertising, or use it to train AI models.
Platform permissions
TikTok access can include basic profile information and video publishing. Instagram access can include professional account details and content publishing. YouTube access can include channel details and video uploads. Permissions are shown during each platform's authorization flow. We use access only for the features that you request.
For YouTube API Services, see the Google Privacy Policy. You can revoke Open Social's access in your Google account permissions. Revocation stops future authorized access; see the deletion instructions below for stored data.
Who receives data
Selected social platforms receive the content and credentials required to complete your requests. Webhook destinations that you configure receive the subscribed event data. Vercel hosts the application, and Neon stores the production database. When media storage is configured, the storage provider processes uploaded files. These providers may process data outside your country.
If you use your own agent or MCP client, that client can access the data allowed by its API key. Its operator and privacy terms determine what it does with that data. Do not give API keys to an untrusted client.
Cookies and storage
We use authentication cookies to keep you signed in and browser storage to save interface preferences such as the theme. Hosting and security systems can record technical request logs. Open Social does not add advertising cookies.
Retention and your choices
We retain data while it is needed to provide the service, maintain requested publishing records, resolve errors, and meet applicable obligations. This development version does not have automatic account or media deletion. Deletion requests are handled by the service operator.
You can disconnect a social account in the dashboard. This removes its stored connection record and credentials. You can revoke platform permissions directly and revoke Open Social API keys. Disconnection does not delete content already published on a social platform, and backups or operational records may remain for a limited period.
To request access, correction, export, or deletion of your data, follow the data deletion and contact instructions. Do not include passwords, API keys, or access tokens in a request.
Contact and changes
Contact the Open Social operator through the support channel used to obtain access to this development service. Include the email address of your Open Social account so the operator can verify the request.
We will publish policy changes here with an updated effective date.