apublished

Platform Disclosures

apublished

Version 1.0 Last updated: 8 August 2026


Why this page exists

apublished publishes on your behalf through the developer APIs of Facebook, Instagram, LinkedIn, Threads, TikTok and YouTube. Each of those programmes requires us to disclose certain things publicly, to link to certain documents, and to give you a clear way to revoke our access. This page collects those disclosures in one place.

It forms part of the Terms of Service and supplements the Privacy Policy. Where a platform's requirement conflicts with anything we say elsewhere, the platform's requirement wins, because our access to it depends on that.

The platforms change these rules. This page is dated, and we update it when they do.


Non-affiliation

apublished is an independent product. apublished is not affiliated with, endorsed, sponsored by or otherwise connected to Meta Platforms, Inc., LinkedIn Corporation, TikTok Ltd. and its affiliates, or Google LLC and YouTube.

Facebook, Instagram and Meta are trademarks of Meta Platforms, Inc. LinkedIn is a trademark of LinkedIn Corporation. TikTok is a trademark of TikTok Ltd. YouTube and Google are trademarks of Google LLC. We use these names only to identify the services we connect to, as permitted by each platform's brand guidelines.


What is true of every platform

You must own or be authorised to manage every account you connect. Connecting an account you are not authorised to manage breaches our Acceptable Use Policy and, in most cases, that platform's terms.

Consent before publishing on someone's behalf. Every platform here requires the account holder's consent before content is published for them. Section 6 of the Acceptable Use Policy explains what this means for automated and agent-driven workflows, and why a fully unattended agent pipeline is not compliant on several of these platforms.

We do not use platform data for anything other than running the Service for you. Not for training models, not for advertising, not for building profiles, not for lead generation, and never for sale.

You can disconnect at any time, from inside apublished or from the platform's own settings. Both revoke our access. Instructions per platform are below, and the consolidated deletion instructions are at apublished.com/privacy#data-deletion.

Platform limits are real limits. Where a platform caps publication volume, restricts what may be posted, or requires an audit before content can be public, apublished enforces or surfaces that cap. We cannot lift it.


YouTube

Required notices

The apublished Service uses YouTube API Services.

By using apublished to publish to YouTube, you agree to be bound by the YouTube Terms of Service, in addition to our own Terms of Service.

Google's handling of information it receives is governed by the Google Privacy Policy.

What we access

Your channel identity and basic channel metadata, the ability to upload a video and set its title, description and privacy status, and the status of uploads we have made. We store the resulting video identifiers and the publication record.

Revoking access

In addition to disconnecting the channel inside apublished, you can revoke our access to your Google account at any time from the Google security settings page: https://security.google.com/settings/security/permissions.

Disconnecting inside apublished revokes the token with Google directly, so you do not need to do both.

Deletion deadlines

These are set by Google and are shorter than our default retention:

Limited use

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular we do not sell that data, do not transfer it to advertising platforms, data brokers or information resellers, do not use it for advertising, credit or lending decisions, and do not allow humans to read it except with your affirmative consent, for a security investigation, to comply with law, or where it has been aggregated and anonymised.

Upload certification

Before any video is uploaded through apublished, you must see and accept the following:

By clicking "upload," you certify that the content you are uploading complies with the YouTube Terms of Service (including the YouTube Community Guidelines) at https://www.youtube.com/t/terms. Please be sure not to violate others' copyright or privacy rights.

This wording is required by the YouTube API Services Terms of Service and must appear on the screen from which the upload is triggered. If you are building your own interface on top of the apublished API, you must display it in your interface. It is not sufficient that it appears in ours or in this document.

Setting title, description and privacy

YouTube requires that the person uploading can set the video's title, description and privacy status. apublished exposes all three. Any interface you build on top of the API must expose them too, and must not silently default the privacy status.

Automation

YouTube prohibits automating or triggering uploads and other actions without the user's prior specific and express consent. Scheduled publication is permitted where the account holder specifically and expressly approved that schedule and what would go out under it. Fully unattended generation and publication is not.

Quota

YouTube grants a default daily quota that permits roughly 100 uploads per day across a project before an audit. Higher volume requires passing Google's compliance audit, and audits recur. Publication may be refused or deferred where quota is exhausted.

Naming

Google prohibits the use of "YouTube", "YT" or any variant of the name in a product's name. If you build a product on apublished, name it accordingly.


Facebook and Instagram (Meta)

What we access

Page and professional-account identity, the permissions you grant during the connect flow, the ability to publish to the pages and accounts you select, and the identifiers and status of content we have published. We request the narrowest permissions the features you use require.

We do not read your inbox, your friend list, your followers' personal data or your ad accounts.

Meta requires that you obtain consent from a person before publishing content or taking any other action on their behalf. If you manage accounts for clients, you must hold that consent and be able to evidence it.

Meta also restricts pre-filled content: content published through an app must be created by the person using the app, or by a business whose employees use the app to administer that business's own presence. Scheduling a business's own content is squarely permitted. Pushing machine-generated content into a consumer's personal account is not.

Instagram publication limit

Instagram permits a maximum of 100 API-published posts per Instagram account in any rolling 24 hours. A carousel counts as one post. apublished counts against this limit and will refuse or defer targets that would exceed it. Meta expects scheduling tools to enforce this themselves, so this is not a limit we can raise.

Instagram publishing also requires a professional account, and media must be reachable at a publicly accessible URL for the duration of the upload.

Data deletion

Our data deletion instructions, as required by the Meta Platform Terms, are at:

apublished.com/privacy#data-deletion

In summary, you can remove the data associated with a connected Meta account by disconnecting the channel in apublished, by removing apublished from Settings and privacy → Settings → Apps and websites on Facebook or Settings → Apps and websites on Instagram, or by emailing privacy@apublished.com.

When you remove apublished from your Meta settings, Meta notifies us and we delete the associated platform data.

Retention

Meta does not set a fixed number of days. It requires deletion when retention is no longer necessary for a legitimate business purpose, on your request, on Meta's request, when you no longer have an account with us, or where the law requires it. Our retention periods are in Section 9 of the Privacy Policy.

Prohibited uses

We do not, and you must not use apublished to: sell, license or purchase platform data; use it to discriminate; use it for eligibility decisions about housing, employment, insurance, education or credit; build surveillance tooling; build or augment profiles without valid consent; or attempt to re-identify or de-anonymise data.


LinkedIn

What we access

Your member identity, and permission to post on your behalf or on behalf of an organisation page you administer.

Caching and retention limits

LinkedIn imposes storage limits that are much shorter than ordinary retention, and we honour them:

Restricted uses

LinkedIn prohibits the use of member data for advertising, sales or recruiting purposes, for identifying prospects or talent, for lead creation or enrichment, for enhancing CRM or marketing automation records, for audience building, for ad targeting, for account-based marketing or for mass messaging.

LinkedIn also treats bulk posting or automation for advertising, sales or recruiting as an unapproved use case, along with rendering LinkedIn feeds on external sites and mass messaging.

What this means for you: apublished may be used to publish a member's or a page's own content on their own behalf. It may not be used as an outbound sales, recruiting or lead-generation channel on LinkedIn. Using it that way breaches our Acceptable Use Policy and puts our LinkedIn access at risk.

Member data obtained for managing a specific page or profile may only be displayed to people associated with that page or profile.

Reconnection

LinkedIn access tokens are valid for 60 days, and programmatic refresh is not available to all developers. You may therefore be asked to reconnect a LinkedIn channel periodically. apublished warns you in advance, and holds the queue rather than dropping it while a channel awaits reconnection.

Revoking access

Disconnect the channel in apublished, or remove apublished from LinkedIn → Settings → Data privacy → Other applications → Permitted services.


TikTok

What we access

Your creator identity, your current posting capability and the privacy options available to your account, and the status of content we have posted.

Required pre-post declaration

Before any post is published to TikTok, you must see and accept the following statement:

By posting, you agree to TikTok's Music Usage Confirmation.

Where the content is commercial and "Branded content" is selected, the statement instead reads:

By posting, you agree to TikTok's Branded Content Policy and Music Usage Confirmation.

Both links must be live and clickable. If you build your own interface on the apublished API, you must display this in your interface.

Commercial content disclosure

TikTok requires a commercial content toggle that defaults to off. When it is on, the user must choose "Your brand", "Branded content" or both, and must be shown the resulting label:

Branded content cannot be posted with private visibility.

No silent defaults

TikTok requires that, for every post, the user manually selects the title, the privacy status from the options TikTok returns for that account, and the interaction settings for comments, Duet and Stitch. The user must see a content preview and give express consent before upload. The creator's nickname must be shown on the publishing screen.

This is the strictest consent requirement of any platform we support, and it rules out unattended publication to TikTok. apublished surfaces every one of these options and does not choose them for you. Your interface must present them.

Audit and public posting

Until a developer application passes TikTok's audit, all content posted through the API is forced to private visibility. If your posts are appearing as visible only to you, that is why. Photo posts additionally require media served from a domain whose ownership has been verified with TikTok.

AI-generated content

TikTok provides a flag that labels a post as AI-generated. apublished exposes it. If your content is generated or materially altered by machine, you must set it.

Rate and volume

TikTok limits requests per user token and enforces a daily posting cap per account. Exceeding it returns a spam-risk error and the post is refused.

Revoking access

Disconnect the channel in apublished, or remove apublished from TikTok → Settings and privacy → Security and permissions → Manage app permissions. Disconnecting in apublished revokes the token with TikTok, after which apublished no longer appears in that list.


If a platform withdraws our access

Developer access to these platforms is conditional and reviewable. Meta requires an annual data use checkup and business verification. Google requires periodic compliance audits for quota above the default. TikTok requires an audit before public posting. Any of them can restrict or withdraw access.

If that happens, we will tell you promptly, say what we know, and say what we are doing about it. Section 12 of the Terms of Service sets out where liability sits when a platform acts.


Contact

Questions about this page: legal@apublished.com Privacy and data deletion: privacy@apublished.com Abuse and copyright: abuse@apublished.com