Privacy Policy
TODO before submission: replace the contact address, confirm the production domain, and name the hosting provider and its region once the deploy target is fixed.
yellit publishes video and images to social platforms on your behalf. You connect your accounts once; after that you can publish from a command-line tool or from this site. This policy describes exactly what that requires us to store.
What we collect
Only what publishing requires. There is no analytics SDK, no advertising pixel, and no third-party tracker on this site.
| Data | Why we have it | How long we keep it |
|---|---|---|
| Your email address | Identifies your account and is how we contact you about it. | Until you delete your account. |
| Platform account IDs and display names (e.g. your Instagram user ID and @handle) | So the app can show you which accounts are connected and address the right one when publishing. | Until you disconnect that account or delete your account. |
| OAuth access and refresh tokens issued by Meta, Google, and X | The credential that lets us post on your behalf. Nothing else. | Until you disconnect that account or delete your account. |
| Media you choose to publish (video and image files) | Instagram fetches media from a public URL rather than accepting an upload, so a file you publish from your own machine has to be reachable on the internet for the duration of the post. | Deleted from our storage as soon as the platforms have taken it — typically seconds to a few minutes. |
| Publish history: caption text, which platforms you targeted, timestamps, per-platform success or failure, and the resulting post links | So you can see what happened, and so a retry does not double-post. | Until you delete your account. |
What we do not collect
- We do not read your existing posts, your comments, your direct messages, your followers, or your audience insights. The permissions we request are publishing permissions, and the app never calls a read endpoint for that content.
- We do not collect your platform password. Authentication happens on Meta's, Google's, and X's own consent screens; we only ever receive a token.
- We do not use cookies for tracking or advertising. The only cookie set is the session cookie that keeps you logged in.
How your media is handled
This is the part most worth being precise about.
When you publish a local file, yellit uploads it to a Cloudflare R2 bucket under a key prefix scoped to your account, gives the platforms that URL, and deletes the object once the post has been created. The upload exists because Instagram's publishing API fetches media server-side from an HTTPS URL — it does not accept a direct file upload. Keeping the object after publishing would serve no purpose and would slowly accumulate a public archive of everything anyone ever posted, so we delete it.
If you publish media that is already at a public URL, we pass that URL through and store no copy at all.
How your tokens are protected
- Tokens are encrypted at rest with AES-256-GCM, with a distinct random IV per record and an authentication tag, using a key held in the deploy environment and never committed to source control.
- A decrypted token is never written to a log, an error message, or an analytics event — not even truncated.
- Tokens are used for exactly one thing: publishing the content you explicitly asked to publish, at the moment you ask for it. Nothing publishes on a schedule, and nothing publishes without an action you took.
What we never do
- We do not sell, rent, or trade your personal data.
- We do not share your data with advertisers or data brokers, and we run no advertising.
- We do not use your content, captions, or media to train machine learning models, and we do not provide them to anyone else for that purpose.
- We do not post anything you did not ask us to post.
Who else sees your data
We use a small number of service providers, and only for the function described:
- Meta Platforms (Instagram), Google (YouTube), and X Corp. — the destinations you chose. We send them the content you asked us to publish. Once published, that content lives on their platform under their own privacy policy and terms.
- Cloudflare R2 — temporary media staging, as described above.
- Our hosting provider — runs the application and the Postgres database.
We disclose data otherwise only where the law requires it.
Your choices and rights
- Disconnect one account at any time from your account page. Its tokens are deleted immediately, and yellit can no longer post to it.
- Delete your entire account at any time. This removes your email, every connected account and its tokens, and your entire publish history. See deleting your data.
- Revoke access at the source. You can also remove yellit's access from Instagram, Google, and X directly in each platform's own settings; this stops publishing immediately, independent of us.
- Depending on where you live, you may have rights to access, correct, export, or erase your personal data. Contact us and we will act on the request.
Deleting your account is irreversible. Already-published posts remain on Instagram, YouTube, and X — we cannot remove them for you, and you should delete those on the platform itself.
Children
yellit is not directed at children and is not intended for anyone under 13, or under the minimum age required by Instagram, YouTube, and X in your country, whichever is higher.
Changes to this policy
If we change what we collect or how we use it, we update this page and its "last updated" date. Material changes will also be sent to the email address on your account.
Contact
Questions, or a request about your data: TODO: contact@yourdomain