Privacy Policy
apublished
Version 1.0 Last updated: 8 August 2026 Effective: 8 August 2026
1. Summary
apublished is a publishing API. You connect your own social media accounts, you send us content, and we publish it for you at a scheduled time. To do that we hold access tokens for the accounts you connect, the content you send us, and a record of what was published.
The short version:
- We do not sell personal data, and we never will.
- We do not use your content, your media or your platform data to train machine learning models.
- We do not use platform data for advertising, profiling, lead generation or resale.
- We hold platform access tokens encrypted, and we delete them when you disconnect a channel.
- Some platforms impose their own deletion deadlines on us. Where they are shorter than ours, theirs win. Section 9 lists them.
This policy explains the detail. It applies to apublished.com, the apublished API, the MCP interface and our documentation endpoints.
2. Who is responsible for your data
The controller of the personal data described in this policy is:
Hippolyte Surer, sole proprietor Avenue du Delay 11 1110 Morges, Switzerland
Email: privacy@apublished.com
We are established in Switzerland. Because we offer the Service to people and organisations in the European Economic Area and the United Kingdom, we will appoint a representative under Article 27 of the EU GDPR and of the UK GDPR:
- EEA representative: [NAME AND ADDRESS, or "to be appointed"]
- UK representative: [NAME AND ADDRESS, or "to be appointed"]
We have not appointed a Data Protection Officer, as we are not required to. Privacy questions go to privacy@apublished.com.
3. Two different roles: controller and processor
This distinction matters, and it changes which rules apply.
We are the controller for the data we need in order to run our own business with you: your account, your billing relationship, your support messages, our security logs, and the analytics on our website. This policy governs that data.
We are a processor for the personal data that you push through the Service: the content you schedule, the audience and account data returned by the platforms you connect, and anything personal contained in your media. For that data you are the controller, you decide the purposes, and we act only on your instructions. Those instructions and our obligations are set out in the Data Processing Agreement, not in this policy.
If you are an end user whose personal data was published or processed by one of our customers, we are not the controller of that data. Contact the customer who runs the account. If you cannot identify them, write to privacy@apublished.com and we will pass your request on.
4. What we collect
4.1 Account data
Name, email address, password hash or identity provider identifier, tenant name, user role, account creation and login timestamps, preferred timezone and locale.
Source: you.
4.2 Billing data
Plan, subscription status, billing email, billing address, country, VAT identifier, invoices, and a Stripe customer and payment method identifier.
We never receive or store full card numbers. Card data goes directly to Stripe.
Source: you and Stripe.
4.3 Connected channel data
For each channel you connect through a platform's OAuth flow:
- OAuth access token and refresh token, and their expiry;
- the token scopes granted;
- the platform's account, page or channel identifier;
- the display name, handle and avatar URL of that account;
- sub-account or page selection, where the platform has that concept;
- channel health status, and the reason for any degraded or revoked state.
Tokens are encrypted at rest with envelope encryption. The master key is held in a key management service and never exists in plaintext in our application process. The PKCE verifier used during the connect flow is encrypted for the duration of that flow and then discarded.
Source: the platform, with your authorisation.
4.4 Content and media
Post text, captions, titles, descriptions, tags, link URLs, privacy and interaction settings, and the images, video and audio you upload or that we fetch from a URL you supply. Media derivatives we generate, such as resized images and probe metadata.
Content may contain personal data about third parties. Where it does, you are the controller of it and the Data Processing Agreement applies.
Source: you or your agent.
4.5 Scheduling and publication records
Target times, resolved posting slots, state transitions, attempt counts, lease and claim records, provider job identifiers, the platform's response, the resulting post URL, verification results, error codes and reasons for failure.
Source: generated by the Service, and returned by the platform.
4.6 API keys and webhooks
A keyed hash of each API key, its scopes, its label, its creation and last-used timestamps, and its revocation state. The key itself is shown once and is not stored. Webhook endpoint URLs you configure, delivery attempts, response codes and the signing secret.
Source: you.
4.7 Technical and security logs
IP address, user agent, request method, path, timing, response status, request identifier, rate limit decisions, authentication outcomes, and audit records of security-relevant mutations such as connecting a channel, revoking a key or changing a plan.
Source: automatic.
4.8 Support communications
Anything you send us by email or through a support channel, and our replies.
Source: you.
4.9 Website and analytics data
On our website we use analytics to understand how the site is used. Depending on the tool in use at the time, this may include pages viewed, referrer, approximate location derived from IP, device and browser type, and, where a session analytics tool is in use, a recording of pointer movement, clicks and scrolling on the pages you visit.
The analytics providers currently in use are listed at apublished.com/subprocessors. Where analytics are not strictly necessary, we ask for your consent first and you can withdraw it at any time. See Section 12.
Source: automatic, subject to consent where required.
5. Why we process it, and on what legal basis
| What we do | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Create and run your account, authenticate you | 4.1, 4.6 | Performance of the contract, Art. 6(1)(b) |
| Connect channels, hold and refresh tokens, publish on your instruction | 4.3, 4.4, 4.5 | Performance of the contract, Art. 6(1)(b) |
| Validate content against platform limits before sending | 4.4 | Performance of the contract, Art. 6(1)(b) |
| Deliver webhooks you have configured | 4.5, 4.6 | Performance of the contract, Art. 6(1)(b) |
| Charge you, issue invoices, handle tax | 4.2 | Contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c) |
| Provide support | 4.1, 4.8 | Contract, Art. 6(1)(b) |
| Keep the Service secure, detect and prevent abuse, rate limit, investigate incidents | 4.7, 4.5 | Legitimate interests, Art. 6(1)(f): running a secure service |
| Debug, monitor reliability, capacity planning | 4.5, 4.7 | Legitimate interests, Art. 6(1)(f) |
| Notify you about outages, token expiry, failed posts and required reconnections | 4.1, 4.3 | Contract, Art. 6(1)(b) |
| Send product and service announcements | 4.1 | Legitimate interests, Art. 6(1)(f), with an unsubscribe link |
| Send marketing email | 4.1 | Consent, Art. 6(1)(a), withdrawable at any time |
| Website analytics | 4.9 | Consent, Art. 6(1)(a), where required; otherwise legitimate interests |
| Comply with accounting, tax and legal obligations | 4.2, 4.7 | Legal obligation, Art. 6(1)(c) |
| Establish, exercise or defend legal claims | as needed | Legitimate interests, Art. 6(1)(f) |
Under the Swiss Federal Act on Data Protection, we process personal data in good faith, proportionately and for the purposes stated above. Swiss law does not require a legal basis in the same form as the GDPR, and the table is given for both.
Where we rely on legitimate interests, we have weighed those interests against your rights, and you can object as described in Section 11.
What we do not do
- We do not sell personal data, and we do not share it for cross-context behavioural advertising.
- We do not use your content, your media or platform data to train machine learning models, ours or anyone else's.
- We do not use platform data to build or enrich profiles, to generate leads, for ad targeting, for credit or eligibility decisions, or for any form of surveillance.
- We do not make decisions about you that produce legal or similarly significant effects by automated means alone.
6. Data received from the connected platforms
When you connect a channel, we receive data from that platform. We use it only to operate the Service for you.
What we take, from every platform
When you connect a social account, apublished stores the account identifier, the handle, the display name and the avatar of the connected account; the access and refresh tokens issued by that platform; and the record of what we published on your behalf, including the platform's own identifier for each published post.
Tokens are encrypted at rest. Each credential is sealed with its own data key, and that key is itself wrapped by our master key, which is held separately from the database; the sealed value is bound to the channel it belongs to, so a credential row is not readable outside its own account. No token is ever written to a log.
We obtain this data from Meta (Facebook, Instagram and Threads), TikTok, Google (YouTube) and LinkedIn, under the authorisation you grant at connection time and no more.
We use it for one purpose: to publish the content you or your authorised agent schedules, to the accounts you connected, and to report back what happened. We do not sell it. We do not use it for advertising. We do not use it to train machine-learning models, our own or anybody else's. We do not transfer it onward except as needed to publish what you asked us to publish.
Disconnecting an account revokes our token at the platform. DELETE /v1/channels/{id}, and the Disconnect button in the console, call the platform's revocation endpoint before deleting our copy of the credential, so the authorisation ends at the platform and not only here. If the platform cannot be reached at that moment the disconnection still completes, and the failure is recorded in the audit log so it can be retried. Deleting your account revokes every connected token the same way and then removes all of the above; see Data deletion.
YouTube
The apublished Service uses YouTube API Services.
By using the parts of the Service that connect to YouTube, you also agree to the YouTube Terms of Service. Google's handling of your information is governed by the Google Privacy Policy.
We access the following through YouTube API Services: your channel identity and basic channel metadata, the ability to upload videos and set their title, description and privacy status, and the status of uploads we have made. We store the resulting video identifiers and publication records.
You can revoke our access to your Google account at any time, independently of anything you do in apublished, at the Google security settings page: https://security.google.com/settings/security/permissions. You can also disconnect the channel inside apublished, which revokes our token with Google directly.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Concretely: we use that data only to provide the features you asked for, we do not transfer it except as needed to provide those features or where you consent or the law requires, we do not allow humans to read it except with your affirmative consent, for security purposes, to comply with law, or where the data is aggregated and anonymised, and we never sell it or transfer it to advertising platforms, data brokers or information resellers.
We delete or refresh YouTube data on the schedule in Section 9, which is set by Google and is shorter than our normal retention.
Facebook and Instagram
We access page and professional-account identity, the permissions you grant, the ability to publish content to the pages and accounts you select, and the status and identifiers of content we have published. We do not read your inbox, your friends, your followers' personal data or your ad accounts unless a feature you have enabled requires it, and we will say so before enabling it.
Meta requires that content is published on a person's behalf only with their consent. You are responsible for obtaining that consent for every account you connect.
Data deletion. See Section 11.5 below, which is our data deletion instructions page for the purposes of Meta's Platform Terms.
We access your member identity, and the permission to post on your behalf or on behalf of an organisation page you administer. LinkedIn imposes strict caching limits on member data, which we honour. See Section 9.
LinkedIn access tokens expire after 60 days and cannot always be refreshed programmatically, so you will periodically be asked to reconnect.
TikTok
We access your creator identity, your posting capability and privacy options, and the status of content we have posted. TikTok requires that you select the privacy level and interaction settings for each post yourself, see a preview, and confirm before publication. The Service surfaces those options and does not choose them for you.
General
We do not combine platform data across platforms to build a profile of any person, and we do not export platform data out of the Service other than back to you, the customer whose channel it is.
Platform-specific notices, required declarations and revocation steps are collected in the Platform Disclosures.
7. Who we share data with
We share personal data only with:
Subprocessors, listed with their purpose and location at apublished.com/subprocessors. They act on our instructions under a written contract with confidentiality and security obligations at least as protective as ours. They include our hosting and database provider, our object storage provider, Stripe for payments, our transactional email provider, our error monitoring provider and our analytics provider.
The platforms you connect, to the extent needed to publish what you have instructed. That transfer is the point of the Service and is made on your instruction.
Professional advisers, such as our accountant and, if needed, our lawyer, under a duty of confidentiality.
Authorities and courts, where we are legally required. Where we may lawfully tell you first, we will.
A successor, if the business is incorporated, sold or merged. We will tell you before your data becomes subject to a different privacy policy.
We do not share personal data with anyone else, and we do not sell it.
8. Where your data is processed
Our primary processing takes place in the European Union, at Fly.io (Paris, France) for compute and the primary database, and Cloudflare R2 (European Union jurisdiction) for media.
Some subprocessors process data outside Switzerland and the EEA, including in the United States. Where that happens:
- Switzerland to EEA, and EEA to Switzerland: the two are mutually recognised as providing adequate protection, so no additional measure is needed.
- To the United States: we rely on the European Commission's adequacy decision for the EU-US Data Privacy Framework and on the Swiss-US Data Privacy Framework where the recipient is certified, and otherwise on the European Commission's Standard Contractual Clauses, with the Swiss amendments recognised by the Federal Data Protection and Information Commissioner and, for UK data, the UK International Data Transfer Addendum.
- To any other country without an adequacy decision: Standard Contractual Clauses plus, where our assessment shows it is needed, supplementary technical measures such as encryption in transit and at rest with keys held only by us.
The current location of each subprocessor is shown in the subprocessor list. You may request a copy of the transfer safeguards we rely on by writing to privacy@apublished.com.
9. How long we keep it
| Data | Retention |
|---|---|
| Account data | For the life of the account. Deleted immediately if you close the account yourself; 30 days if we terminate it |
| Billing records and invoices | 10 years from the end of the financial year, as required by Swiss accounting law |
| Content and media | For the life of the account. Deleted immediately if you close the account yourself; 30 days if we terminate it; deleted sooner at any time on your instruction |
| Publication records and audit logs | 24 months, then deleted or aggregated beyond identification |
| OAuth access and refresh tokens | Until the channel is disconnected, the token is revoked, or the account is closed, then deleted promptly and in any event within 7 days; see the platform-imposed limits below |
| API key hashes | Until revoked, then 90 days for audit, then deleted |
| Technical and security logs | 90 days, longer only where needed to investigate a specific incident |
| Webhook delivery records | 30 days |
| Support email | 24 months from the last message in the thread |
| Website analytics | As stated by the provider in the subprocessor list, and no longer than 14 months |
| Backups | Copies may persist until they age out of the backup cycle. We do not yet publish a retention period — see the security page |
Platform-imposed limits, which override the table above where they are shorter:
- YouTube. Authorised data other than analytics is deleted or refreshed within 30 calendar days. If you ask us to delete YouTube data, or you revoke access through apublished, we delete it within 7 calendar days. If you revoke access through Google's security settings, we delete it within 30 calendar days.
- LinkedIn. LinkedIn's Marketing API Program sets data-storage limits: profile data of members other than the authenticated member may be kept for no more than 24 hours, social activity data for no more than 48 hours, and organisation data within the limits for its category, the shortest applicable limit governing where two overlap. We comply with those limits, and we comply with them by not collecting the data in the first place.
Concretely, the only LinkedIn resources apublished reads are: the authenticated member's own profile (/v2/userinfo, to identify the account you just connected), the list of organisation pages that member administers (organizationAcls, so you can choose which page to post as), and our own posts — the ones we published for you, read back to confirm they are live. We do not read any other member's profile, and we do not read social activity data of any kind: no feeds, no comments, no likes, no follower lists. The only comment we ever touch is one we posted ourselves on your behalf.
For an organisation page you connect, we hold what any connected channel holds: its identifier, name, handle and avatar, for as long as the channel is connected. If we ever begin caching member or activity data, the limits above apply to it and this policy is updated first.
- Facebook and Instagram. Platform data is deleted when it is no longer necessary for the purpose it was obtained for, when you ask us to delete it, when you no longer have an account with us, or when Meta requires it.
Where the law requires us to keep something longer, we keep only what the law requires and restrict its use to that purpose.
10. How we protect it
Security is a design property of this Service, not a bolt-on. The measures include:
- Tenant isolation enforced in the database. Every HTTP request runs under a database role with row-level security enforced and no bypass. The isolation is tested under concurrency, with interleaved requests from different tenants, as part of our test suite.
- Envelope encryption for secrets. OAuth tokens and other credentials are encrypted with per-record data keys wrapped by a master key held in a key management service. The master key does not exist in plaintext in the application process.
- API keys stored as keyed hashes with a pepper held outside the database, so that a database dump alone does not allow offline verification of guessed keys. Revocation propagates across the fleet in under a second.
- Encryption in transit with TLS for all external connections.
- Signed webhooks with HMAC, with automatic disabling of persistently failing endpoints, and an outbound request guard that refuses private and link-local network targets.
- Media validated by content, not by file extension, with format sniffing and sandboxed inspection isolated from the publishing path.
- Least privilege: three separate database roles for migrations, request handling and the cross-tenant scheduler, with the privileged role confined to a single audited module.
- Audit logging of security-relevant mutations.
- Access to production is limited to those who need it, protected by multi-factor authentication.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to people's rights and freedoms, we will notify the competent supervisory authority within 72 hours where required, and notify affected customers without undue delay.
11. Your rights
11.1 What you can ask for
Under the Swiss FADP and, where it applies to you, the GDPR, you can ask us to:
- confirm whether we process personal data about you, and give you access to it;
- give you a copy in a portable, machine-readable format, or transmit it to another provider where technically feasible;
- correct data that is inaccurate or incomplete;
- delete data, where there is no overriding reason for us to keep it;
- restrict processing while a dispute about accuracy or legitimate interests is resolved;
- object to processing based on legitimate interests, including profiling, and to direct marketing at any time and without reason;
- withdraw consent where processing is based on consent, without affecting what was lawful before withdrawal.
11.2 How to exercise them
Write to privacy@apublished.com. We respond within 30 days. If a request is complex we may extend that once, and will tell you why. We may ask for information to verify your identity, and we will not use it for anything else.
Exercising these rights is free. We may charge a reasonable fee, or refuse, only where a request is manifestly unfounded or excessive, and we will explain why.
11.3 Complaints
If you think we have handled your data wrongly, tell us first at privacy@apublished.com. You can also complain to a supervisory authority:
- Switzerland: the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, edoeb.admin.ch.
- EEA: the data protection authority of your country of residence, work, or of the alleged infringement.
- United Kingdom: the Information Commissioner's Office, ico.org.uk.
11.4 Requests about data we hold as a processor
If your data reached us because one of our customers published or scheduled it, we cannot decide the request. Contact that customer. If you write to us, we will forward the request and tell you we have done so, unless the customer's instructions or the law say otherwise.
11.5 Data deletion instructions
This section is our data deletion instructions page for the purposes of Meta's Platform Terms and the equivalent requirements of the other platforms. It is stable at apublished.com/privacy#data-deletion.
To have the data associated with a connected social account deleted:
- Disconnect the channel inside apublished. Open the channel in your account, choose Disconnect, and confirm. This revokes the token with the platform and deletes the token, the platform account identifiers and the cached account metadata. Publication records for that channel are retained for the period in Section 9 unless you also ask us to delete them.
- Or revoke our access from the platform's own settings. Facebook: Settings and privacy, Settings, Apps and websites. Instagram: Settings, Apps and websites. LinkedIn: Settings, Data privacy, Permitted services. TikTok: Settings, Security and permissions, Manage app permissions. YouTube and Google: https://security.google.com/settings/security/permissions.
- Or email us at privacy@apublished.com from the email address on the account, saying which platform account you want removed. We will confirm when it is done.
To delete your entire apublished account and everything in it, use Delete account in your account settings, or email privacy@apublished.com. Deletion is final after the 30-day recovery window described in Section 9.
We honour deletion requests within the deadlines in Section 9, including the shorter deadlines the platforms impose on us.
12. Cookies and website analytics
The apublished landing page ships no JavaScript and sets no cookies by itself.
We use cookies and similar technologies only as follows:
- Strictly necessary: session and authentication cookies in the application, and a CSRF token. These are required for the Service to work, and no consent is required for them.
- Preference: your timezone and display preferences, stored locally.
- Analytics: where we run analytics on the marketing site or in the application, and the tool is not strictly necessary, we ask for your consent before it loads and record your choice. Some analytics tools we may use record session activity, including pointer movement, clicks and scrolling on the pages you visit. Where such a tool is in use it is named in the subprocessor list and disclosed in the consent banner.
You can withdraw analytics consent at any time from the cookie settings link in the site footer, and you can block or delete cookies in your browser. Blocking strictly necessary cookies will break the application.
We do not use advertising cookies and we do not run retargeting pixels.
13. Children
The Service is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, write to privacy@apublished.com and we will delete it.
14. Automated decision-making and profiling
We do not carry out automated decision-making that produces legal or similarly significant effects on you, and we do not profile you. Automated systems in the Service decide when to publish a post, whether content passes platform validation, and whether a request exceeds a rate limit. Those decisions concern content and requests, not people.
15. Changes to this policy
We may update this policy. For material changes we will give notice by email to your account address and by a notice in the Service at least 30 days before they take effect, unless a shorter period is required by law. The version and date are at the top. Previous versions are available on request.
16. Contact
Hippolyte Surer Avenue du Delay 11 1110 Morges, Switzerland
Privacy: privacy@apublished.com Security: security@apublished.com General: support@apublished.com