Privacy Policy

Effective October 2, 2026

Postcon lets you upload a short vertical video, write one caption and publish it to Instagram Reels, TikTok and YouTube Shorts, now or at a scheduled time. It is run by Relja Pavlovic, who you can reach at pavlovicrelja@gmail.com. This policy explains what Postcon stores, why, who processes it and how to delete it.

What we collect

Postcon uses only the cookies it needs to work: your sign-in session, the last workspace you opened, and a short-lived cookie that protects the connect-account flow. Your light or dark theme choice is kept in your browser. There are no advertising or tracking cookies. Page visits are counted with Vercel Web Analytics, which sets no cookies and records only aggregate data such as pages viewed, referrer, country and device type.

How we use it

Only to provide Postcon to you: to publish and schedule your videos on the accounts you choose, to show you each post's status and metrics, and to email you when a post fails. We do not sell your data, do not use it for advertising, do not share it with anyone except the service providers listed below, and do not use it for any other purpose.

Videos

Videos are uploaded from your browser to a private Supabase Storage bucket that only your account can access. At publish time Postcon sends the file to TikTok and YouTube, and gives Instagram a signed link, valid for one hour, to download it. A daily job deletes a video 7 days after it has published to every account you picked. Videos of drafts, and of posts that failed on any account, are kept so you can edit or retry them until you delete the post or the workspace. Deleting a post removes its video from storage right away.

Metrics

After a video is published, Postcon reads its view, like, comment and share counts from the platform every hour for the first 2 days, every 6 hours up to 30 days, then once a day up to 90 days. Each reading is saved so the analytics page can show growth over time.

Emails

If a post fails on one or more accounts, Postcon emails you once, through Brevo, listing the post's first caption line, the workspace, the accounts that failed and the error for each. Supabase also sends the email that invites you to Postcon.

YouTube

Postcon uses YouTube API Services. By connecting a YouTube account you agree to the YouTube Terms of Service, and Google's handling of your data is described in the Google Privacy Policy. Postcon requests these permissions:

Postcon's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can revoke Postcon's access to your Google account at any time from your Google security settings.

TikTok

Postcon requests these TikTok permissions:

You can revoke access in the TikTok app under Settings and privacy, Security and permissions, Apps and services permissions.

Instagram

Postcon connects Instagram professional accounts (Creator or Business) through Instagram Login and requests:

You can revoke access in Instagram under Settings, Website permissions, Apps and websites, or at instagram.com/accounts/manage_access.

Service providers

Postcon relies on these processors, each only for the part of the service it runs:

When you publish, your video and caption are sent to the platforms you picked, where their own terms and privacy policies apply.

Security and retention

All traffic uses HTTPS. Database rules limit every workspace, account, post and metric to its owner, OAuth tokens are encrypted at rest, and videos sit in a private bucket. Your data is kept while your account exists, except videos, which are deleted as described above.

Deleting your data

Videos already published to Instagram, TikTok or YouTube live on those platforms and are deleted there, not in Postcon.

Children

Postcon is not directed to children under 13 and does not knowingly collect their data.

Changes

If this policy changes, the new version will be posted on this page with a new effective date. Questions go to pavlovicrelja@gmail.com.