Privacy Policy

Operated by Freddy Montes.

TODO before submission: replace the contact address, confirm the production domain, and name the hosting provider and its region once the deploy target is fixed.

yellit publishes video and images to social platforms on your behalf. You connect your accounts once; after that you can publish from a command-line tool or from this site. This policy describes exactly what that requires us to store.

What we collect

Only what publishing requires. There is no analytics SDK, no advertising pixel, and no third-party tracker on this site.

DataWhy we have itHow long we keep it
Your email address Identifies your account and is how we contact you about it. Until you delete your account.
Platform account IDs and display names (e.g. your Instagram user ID and @handle) So the app can show you which accounts are connected and address the right one when publishing. Until you disconnect that account or delete your account.
OAuth access and refresh tokens issued by Meta, Google, and X The credential that lets us post on your behalf. Nothing else. Until you disconnect that account or delete your account.
Media you choose to publish (video and image files) Instagram fetches media from a public URL rather than accepting an upload, so a file you publish from your own machine has to be reachable on the internet for the duration of the post. Deleted from our storage as soon as the platforms have taken it — typically seconds to a few minutes.
Publish history: caption text, which platforms you targeted, timestamps, per-platform success or failure, and the resulting post links So you can see what happened, and so a retry does not double-post. Until you delete your account.

What we do not collect

How your media is handled

This is the part most worth being precise about.

When you publish a local file, yellit uploads it to a Cloudflare R2 bucket under a key prefix scoped to your account, gives the platforms that URL, and deletes the object once the post has been created. The upload exists because Instagram's publishing API fetches media server-side from an HTTPS URL — it does not accept a direct file upload. Keeping the object after publishing would serve no purpose and would slowly accumulate a public archive of everything anyone ever posted, so we delete it.

If you publish media that is already at a public URL, we pass that URL through and store no copy at all.

How your tokens are protected

What we never do

Who else sees your data

We use a small number of service providers, and only for the function described:

We disclose data otherwise only where the law requires it.

Your choices and rights

Deleting your account is irreversible. Already-published posts remain on Instagram, YouTube, and X — we cannot remove them for you, and you should delete those on the platform itself.

Children

yellit is not directed at children and is not intended for anyone under 13, or under the minimum age required by Instagram, YouTube, and X in your country, whichever is higher.

Changes to this policy

If we change what we collect or how we use it, we update this page and its "last updated" date. Material changes will also be sent to the email address on your account.

Contact

Questions, or a request about your data: TODO: contact@yourdomain