Privacy Policy
Effective October 2, 2026
Postcon lets you upload a short vertical video, write one caption and publish it to Instagram Reels, TikTok and YouTube Shorts, now or at a scheduled time. It is run by Relja Pavlovic, who you can reach at pavlovicrelja@gmail.com. This policy explains what Postcon stores, why, who processes it and how to delete it.
What we collect
- Your Postcon account: your email address and password, handled by Supabase Auth (the password is stored only as a hash).
- Workspaces: the name and timezone you give each workspace.
- Connected accounts: for each Instagram, TikTok or YouTube account you connect, its platform account ID, username or channel name, profile picture URL, the permissions you granted, and the OAuth access and refresh tokens. Tokens are encrypted with AES-256-GCM before they are stored and are never sent to your browser.
- Posts: the video you upload, its caption, length and scheduled time, its status on each account, the ID and link of the published post, and any error message a platform returned.
- Post metrics: view, like, comment and share counts of the videos you published through Postcon.
- Waitlist: if you join the waitlist on the home page, your email address and the time you joined, used only to invite you.
Postcon uses only the cookies it needs to work: your sign-in session, the last workspace you opened, and a short-lived cookie that protects the connect-account flow. Your light or dark theme choice is kept in your browser. There are no advertising or tracking cookies. Page visits are counted with Vercel Web Analytics, which sets no cookies and records only aggregate data such as pages viewed, referrer, country and device type.
How we use it
Only to provide Postcon to you: to publish and schedule your videos on the accounts you choose, to show you each post's status and metrics, and to email you when a post fails. We do not sell your data, do not use it for advertising, do not share it with anyone except the service providers listed below, and do not use it for any other purpose.
Videos
Videos are uploaded from your browser to a private Supabase Storage bucket that only your account can access. At publish time Postcon sends the file to TikTok and YouTube, and gives Instagram a signed link, valid for one hour, to download it. A daily job deletes a video 7 days after it has published to every account you picked. Videos of drafts, and of posts that failed on any account, are kept so you can edit or retry them until you delete the post or the workspace. Deleting a post removes its video from storage right away.
Metrics
After a video is published, Postcon reads its view, like, comment and share counts from the platform every hour for the first 2 days, every 6 hours up to 30 days, then once a day up to 90 days. Each reading is saved so the analytics page can show growth over time.
Emails
If a post fails on one or more accounts, Postcon emails you once, through Brevo, listing the post's first caption line, the workspace, the accounts that failed and the error for each. Supabase also sends the email that invites you to Postcon.
YouTube
Postcon uses YouTube API Services. By connecting a YouTube account you agree to the YouTube Terms of Service, and Google's handling of your data is described in the Google Privacy Policy. Postcon requests these permissions:
youtube.upload: to upload the videos you publish to your channel, with the title and description taken from your caption.youtube.readonly: to read your channel's ID, name, handle and thumbnail so you can see which channel is connected, and the view, like and comment counts of the videos you published through Postcon.
Postcon's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can revoke Postcon's access to your Google account at any time from your Google security settings.
TikTok
Postcon requests these TikTok permissions:
user.info.basic: your account's open ID, display name and avatar, to show which account is connected.video.publish: to post the videos you publish directly to your TikTok account.video.list: to read the view, like, comment and share counts of the videos you published through Postcon.
You can revoke access in the TikTok app under Settings and privacy, Security and permissions, Apps and services permissions.
Postcon connects Instagram professional accounts (Creator or Business) through Instagram Login and requests:
instagram_business_basic: your account ID, username and profile picture, to show which account is connected.instagram_business_content_publish: to publish the videos you publish as Reels.instagram_business_manage_insights: to read the view, like, comment and share counts of the Reels you published through Postcon.
You can revoke access in Instagram under Settings, Website permissions, Apps and websites, or at instagram.com/accounts/manage_access.
Service providers
Postcon relies on these processors, each only for the part of the service it runs:
- Supabase: database, authentication and video storage.
- Vercel: hosting of the website and its server functions, and cookieless visit statistics.
- Inngest: runs the background jobs that publish, schedule, sync metrics and clean up videos; it sees job details such as post IDs.
- Brevo: sends failure emails; it receives your email address and the email's content.
When you publish, your video and caption are sent to the platforms you picked, where their own terms and privacy policies apply.
Security and retention
All traffic uses HTTPS. Database rules limit every workspace, account, post and metric to its owner, OAuth tokens are encrypted at rest, and videos sit in a private bucket. Your data is kept while your account exists, except videos, which are deleted as described above.
Deleting your data
- Delete a post: open the post and click Delete draft or Delete post. This works for drafts, scheduled posts (which cancels them), and published or failed posts, but not while a post is publishing. It immediately deletes the post, its status on each account and its metrics, and removes its video from storage.
- Disconnect an account: in a workspace, open Accounts and click Disconnect. This deletes the account's stored tokens and details, along with its post history and metrics in that workspace. For YouTube and TikTok, Postcon first asks Google or TikTok to revoke its access, unless the same account is still connected in another Postcon workspace. Instagram offers apps no way to revoke their own access, so remove Postcon in Instagram's settings as described in the Instagram section above. If a revoke request fails, the account is still disconnected and you can revoke access yourself as described above.
- Delete a workspace: in Settings, delete the workspace. This immediately deletes its connected accounts and their tokens, its posts and its metrics. Its video files are removed from storage by the daily cleanup job within two days.
- Delete your whole account: email pavlovicrelja@gmail.com from the address you signed up with. Your account and all of its data will be deleted within 30 days. The same address handles removal from the waitlist and any other privacy request, such as a copy or correction of your data.
Videos already published to Instagram, TikTok or YouTube live on those platforms and are deleted there, not in Postcon.
Children
Postcon is not directed to children under 13 and does not knowingly collect their data.
Changes
If this policy changes, the new version will be posted on this page with a new effective date. Questions go to pavlovicrelja@gmail.com.