Privacy Policy
Effective date: October 7, 2026
1. Introduction
SumUploader ("we", "us", or "our") provides a mobile application (iOS and Android) that lets a single user connect their own YouTube, TikTok, Instagram, Threads, and Facebook accounts and upload, schedule, and publish video and photo posts to those accounts. The app also offers caption and hashtag management, watermarks, sponsor campaign tracking, and post analytics ("insights").
This Privacy Policy explains what personal data we collect, why we collect it, how we use it, who we share it with, and the rights and controls you have over your data. By using SumUploader, you agree to the practices described here.
TODO for the app owner: Insert the legal entity name and registered business address of the operator of SumUploader here, and in the Terms of Service.
2. Data we collect
We collect only the data needed to provide and operate the service. The categories are:
(a) Account identifiers
- Your name and email address, provided when you sign in with Apple or Google.
(b) Platform OAuth tokens and granted permissions
- When you connect a YouTube, TikTok, Instagram, Threads, or Facebook account, the platform issues us an access token (and, where applicable, a refresh token) scoped to the permissions you approved during the OAuth consent flow.
- Tokens are stored encrypted server-side and are never exposed to other users.
- Tokens are used only to perform actions you requested, as described in Section 3.
(c) Content you provide
- Videos and photos you upload to the app.
- Captions, hashtags, and first-comment text you write.
- Watermark images you upload and your watermark settings (position, size, opacity).
- Scheduling choices (post now, scheduled date/time, recurring schedules).
- Campaign names, sponsor rates, and video links you add to the campaign tracker.
- Settings and preferences (theme, auto-reply keywords, per-platform options).
(d) Analytics and insights retrieved from platforms
- Performance data about your own posts, retrieved through the platforms' official APIs when you open the Insights screen or when scheduled refreshes run: views, likes, comments, shares, and related engagement metrics.
- This data describes your own content and accounts only; we do not pull analytics for any other person.
(e) Basic technical data
- Device type, operating system version, and app version, used solely for operation, debugging, and security (for example, identifying incompatible client versions or abuse).
We do not collect precise location data, contacts, advertising identifiers, or browsing history.
3. Platform permissions (scope) justification
The table below lists every permission SumUploader requests from each platform, why it is needed, and how you control it. Tokens are used only to perform actions you requested. We never post content without your action — publishing happens only for posts you create or schedule in the app. You can connect or disconnect any platform at any time from the app's settings; disconnecting deletes the stored token for that platform (see Section 7).
| Platform | Scope | Why it is needed | User control |
|---|---|---|---|
| YouTube | youtube.upload |
Upload videos and Shorts to your own YouTube channel when you choose to publish or schedule a post. | Connect/disconnect in app settings; uploads only happen for posts you create or schedule. |
| YouTube | youtube.readonly |
Read your channel and video metadata to confirm uploads completed and to display your post insights in the app. | |
| TikTok | user.info.basic |
Identify which TikTok account you connected (display name, avatar) so you know which account will receive your posts. | Connect/disconnect in app settings; uploads only happen for posts you create or schedule. |
| TikTok | video.upload |
Upload videos you choose to publish to your connected TikTok account. | |
instagram_basic |
Read your Instagram profile information and media so the app can show the connected account and list your published posts. | Connect/disconnect in app settings; publishing and replies only happen for content you create, schedule, or configure. | |
instagram_content_publish |
Publish Reels, photos, and carousels to your connected Instagram account for posts you create or schedule. | ||
instagram_manage_insights |
Read insights (views, likes, comments, reach) for your own posts to display them in the app's Insights screen. | ||
instagram_manage_comments |
Post public replies to comments on your posts, only when you enable and configure the keyword auto-reply feature in the app's settings. | ||
instagram_manage_messages |
Send direct-message replies to commenters, only when you enable and configure the keyword comment-to-DM auto-reply feature in the app's settings. | Connect/disconnect in app settings; used only if you enable auto-reply. | |
pages_show_list |
List the Facebook Pages you manage so you can choose which Page receives your posts. | Connect/disconnect in app settings; publishing only happens for posts you create or schedule. | |
pages_read_engagement |
Read engagement data (views, likes, comments) on your Page's posts to display insights in the app. | ||
pages_manage_posts |
Publish videos and photos to the Facebook Page you selected, for posts you create or schedule. | ||
pages_manage_metadata |
Read Page metadata needed to publish correctly and to confirm publish status (for example, verifying the Page's publishing capabilities). | ||
| Threads | threads_basic |
Read your Threads profile information to identify the connected account. | Connect/disconnect in app settings; publishing only happens for posts you create or schedule. |
| Threads | threads_content_publish |
Publish text and media posts to your Threads account for posts you create or schedule. | |
| Threads | threads_manage_insights |
Read insights for your own Threads posts to display them in the app. |
We do not request any permission beyond those listed above. If a platform changes its required scopes, we will update this policy before requesting new permissions.
4. How we use data
We use the data described above only for the following purposes:
- Provide the service: authenticating you, connecting the platforms you choose, and storing your queued and scheduled posts.
- Publish on your instruction: uploading the media you selected to the platforms you selected, with the captions, hashtags, and watermarks you configured.
- Scheduling: holding scheduled posts and publishing them at the date and time you chose.
- Insights display: fetching analytics about your own posts from each platform and showing them to you in the app.
- Auto-reply (Instagram only, opt-in): if you enable it, responding to comments or messages according to the keyword rules you configured.
- Operation and security: diagnosing errors, preventing abuse, and keeping the service running reliably.
We do not use your data for advertising, profiling, or any purpose unrelated to operating SumUploader for you.
5. Sub-processors and data sharing
We do not sell your personal data. We do not share your data with third parties except as described below, strictly as needed to operate the service:
- Cloudinary — hosts and processes the videos and photos you upload (transcoding, overlays such as watermarks) so they can be published to the platforms.
- Supabase — provides authentication (Apple/Google sign-in) and the application database holding your account, settings, queue, and post history.
- Contabo — provides the virtual server that hosts the SumUploader backend.
- The platforms you connect (YouTube, TikTok, Instagram, Threads, Facebook) — we transmit only the content you choose to publish and make only the API calls you initiate (for example, publishing a post or reading your own post insights).
We may also disclose data when required by law, for example in response to a lawful request from a public authority.
6. Media retention
Videos and photos you upload are processed through Cloudinary and are automatically deleted after the post completes on all selected platforms. Items that fail to publish are kept only as long as needed for retry, and are then removed. We do not keep copies of your media beyond what is necessary to complete or retry your publishing requests.
7. Data retention and deletion
- Platform tokens: kept until you disconnect the platform in the app. Disconnecting deletes the stored token immediately.
- Queue and post history: kept until you delete individual items or your account.
- Media: handled as described in Section 6.
- Account data: kept while your account is active.
To request deletion of your data, disconnect the relevant platform in the app's settings, or email [email protected] and we will delete your account data. For Facebook/Instagram, we honor Meta's data-deletion callback: if you remove SumUploader from your Facebook or Instagram settings, we delete the associated tokens and account data on receipt of the callback.
8. Your rights
You have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data (for example, your name or email).
- Delete your data, as described in Section 7.
- Portability: receive a copy of your data in a commonly used format on request.
- Withdraw consent at any time, for example by disconnecting a platform or deleting your account — this does not affect processing that already happened.
To exercise any of these rights, email [email protected]. We will respond within a reasonable time and in any event within the time required by applicable law.
9. Children's privacy
SumUploader is not directed at children under 13, and we do not knowingly collect personal data from children under 13. If we learn that we have collected data from a child under 13, we will delete it promptly. If you believe a child under 13 has provided us with data, contact us at [email protected].
10. Security measures
We take reasonable steps to protect your data:
- All data in transit between the app, our backend, and the platforms is encrypted with TLS.
- Platform OAuth tokens are encrypted at rest on our servers and are never exposed to other users or to the mobile app directly.
- Access to production systems follows the principle of least privilege.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security, but we work to keep your data protected using industry-standard practices.
11. International transfers
Your data may be processed on servers located in the European Union or the United States, depending on where our hosting providers operate. By using SumUploader, you understand that your data may be transferred to and processed in these regions, and we take steps to ensure it is handled in accordance with this policy wherever it is processed.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will post the revised version here with an updated effective date. If a change is material, we will also notify you in the app or by email before it takes effect. Your continued use of SumUploader after the effective date constitutes acceptance of the updated policy.
13. Contact
If you have questions about this Privacy Policy, your data, or your rights, contact us at [email protected].
TODO for the app owner: The [email protected] inbox must actually be created and monitored before launch, so data requests and reviewer questions receive a reply.
