Privacy Policy
RostrumPost handles prepared social content, provider account connections, media, approvals, and audit logs for teams that publish through the product.
Information We Process
We process account profile information, workspace settings, prepared post text, attached media, schedules, approvals, audit logs, and operational metadata needed to run the service. When you connect a social provider, we process the OAuth tokens, provider account identifiers, handles, and permission scopes needed to connect that account and publish only as authorized by the user.
How We Use Information
We use information to authenticate users, run preflight checks, prepare native social variants, schedule or publish approved posts, maintain audit logs, provide support, secure the service, and comply with provider platform rules. RostrumPost does not sell social provider data or use connected account data for advertising.
Provider Connections
RostrumPost requests only the scopes needed for the connected workflow. Provider tokens are stored in a credential vault or deployment secret store, and are used only to refresh access, read the connected account identity, upload approved media, or publish content the user has prepared and authorized.
Google and YouTube API Data
When a user connects YouTube, RostrumPost accesses the authorized YouTube channel's
identifier and public profile details, including its title and thumbnail, through the
youtube.readonly scope. RostrumPost uses this data only to identify and
display the connected channel, confirm that the authorization belongs to the intended
channel, and show connection status inside the product.
With the youtube.upload scope, RostrumPost uploads only videos and
associated metadata that the user has explicitly selected, reviewed, and authorized
for publication. New YouTube uploads default to private visibility unless the user
deliberately chooses another available visibility setting. RostrumPost does not read,
edit, or delete unrelated YouTube videos.
RostrumPost stores the YouTube channel identifier, display name, granted scopes, OAuth access token, refresh token, and token expiry information needed to maintain the connection and perform authorized uploads. Google and YouTube user data is not sold, used for advertising, or shared with third parties except service providers that are necessary to operate and secure RostrumPost. Users can disconnect YouTube in RostrumPost or revoke access in their Google Account. They can also request deletion of stored Google and YouTube OAuth data by contacting [email protected].
TikTok OAuth and API Data
When a user connects TikTok, RostrumPost uses TikTok Login Kit and TikTok APIs to
connect the creator account, confirm the account identity, and support the assisted
TikTok publishing workflow shown in the product. The basic connection requests
account identity access such as user.info.basic and may store TikTok
identifiers such as the account open_id, display name, avatar metadata,
granted scopes, OAuth access tokens, refresh tokens, and token expiry timestamps.
RostrumPost uses TikTok data only to show connection status, prepare TikTok-specific variants, run preflight checks, and, if TikTok approves additional Content Posting scopes for the app, upload or publish user-selected video content and metadata after explicit user review. RostrumPost does not sell TikTok data, use it for advertising, or access TikTok content outside the permissions granted by the connected user.
Users can disconnect TikTok in RostrumPost or revoke RostrumPost access from their TikTok account settings. After disconnect, RostrumPost stops using TikTok tokens for that account. Customers can request deletion of stored TikTok OAuth data, workspace content, media, and audit records by contacting [email protected], subject to security, legal, and abuse-prevention retention requirements.
Sharing
We share data with infrastructure, email, storage, billing, analytics, and social platform providers only as needed to operate RostrumPost. We may disclose information when required by law, to protect the service, or with the customer's direction.
Retention and Deletion
Workspace content and logs are retained while an account is active or as needed for operational, security, legal, and audit purposes. Customers can disconnect provider accounts, revoke provider OAuth access, and request deletion by contacting us.
Security
RostrumPost uses scoped access, server-side session controls, credential encryption, audit logging, and deployment secret management. No Internet service can guarantee absolute security, but we design the workflow to minimize unnecessary provider access.
Contact
For privacy questions, provider review, or deletion requests, contact [email protected].