Personal data deletion
Last updated: March 31, 2026
This document describes the procedure and timelines for the deletion of personal data of PublPost (publpost.ru) users in accordance with Russian Federal Law No. 152-FZ of July 27, 2006 «On Personal Data», the EU General Data Protection Regulation (GDPR), and the requirements of Meta Platforms, Inc.
1. Legal grounds
This document is based on:
- Russian Federal Law No. 152-FZ of July 27, 2006 «On Personal Data» (Articles 9, 14, 17, 21)
- Russian Federal Law No. 149-FZ of July 27, 2006 «On Information, Information Technologies and Information Protection»
- EU General Data Protection Regulation (GDPR), Article 17 «Right to be forgotten»
- Meta Platforms, Inc. policy on user data deletion (Meta Platform Terms, Section 3.2)
Pursuant to Article 9 of FZ-152, a personal data subject has the right to withdraw their consent to processing at any time. Upon receipt of such withdrawal, the operator is obligated to cease processing and ensure deletion within the timeframes set out in Article 21 of FZ-152.
2. Data controller
| Controller | ИП Попов Иван Петрович, ИНН 521600320843 |
| Service | PublPost (publpost.ru) |
| support@publpost.ru | |
| Jurisdiction | Russian Federation |
3. What data is processed
PublPost processes the following categories of personal data:
- Account data: name, email, hashed password, avatar, biography
- OAuth tokens: access tokens for connected platforms (Facebook, Instagram, Telegram, VK, etc.)
- Content: post text, uploaded images and videos, drafts
- Settings: workspace parameters, schedules, publication templates
- Analytics: publication statistics, account metrics
- Communications: incoming messages and comments from connected platforms
- Payment data: subscription and transaction information (processed by a payment provider)
4. How to request data deletion
Method 1. Self-service account deletion (recommended)
- Sign in to PublPost with your account
- Open Settings → Security
- In the «Delete account» section, click «Delete account»
- Enter your current password and confirm your email to authorise the action
Once confirmed, the account is moved into a deletion state. All active sessions are terminated immediately. We send a recovery link to your email — you have 30 days to restore the account. After that the data is permanently destroyed according to the timelines in section 5.
Method 2. Written request to the controller
Send a request to support@publpost.ru including:
- Full name (if listed in the account)
- Email associated with the account
- Statement: «I request to cease processing and delete my personal data pursuant to Articles 9 and 21 of FZ-152» (or equivalent in English: «I withdraw my consent to processing of my personal data and request its deletion»)
The controller will acknowledge the request within 3 business days and notify you by email when deletion is complete.
Method 3. Through Facebook settings
You can revoke PublPost's access to your Facebook/Instagram data directly: Facebook → Settings & Privacy → Settings → Apps and Websites → PublPost → Remove. Alternatively, open facebook.com/settings?tab=applications and remove the app from the list.
5. Deletion timeline
Pursuant to Article 21 of FZ-152, the controller must delete personal data within no more than 30 days of receiving the consent withdrawal. If technically impossible — data is blocked within 30 days and deleted within no more than 6 months thereafter.
| Data category | Deletion timeline | Legal basis |
|---|---|---|
| Sessions, refresh tokens | Immediately | — |
| Platform OAuth tokens | Immediately | Meta Platform Terms 3.2 |
| Profile, settings | Up to 3 business days | Article 21 FZ-152 |
| Posts, media files, drafts | Up to 30 days | Article 21 FZ-152 |
| Analytics, statistics | Up to 30 days | Article 21 FZ-152 |
| Backups | Up to 90 days | Article 21 part 3 FZ-152 |
| Payment records | 5 years (retained) | Article 29 FZ-402, Article 23 RF Tax Code |
6. Data that gets deleted
When you delete your account, the following data is destroyed:
- User account record (name, email, password hash, avatar, biography)
- All connected social accounts and their access tokens
- All created posts (scheduled, drafted, and published)
- Uploaded media files (images, videos)
- Drafts and templates
- Workspace settings, schedules, publication queues
- Incoming messages and comments
- Analytics and statistics data
- Mention monitoring results (Social Listening)
- Approval Workflow data
7. Data retained by law
Pursuant to Article 6, part 1, point 2 of FZ-152, the operator may continue processing personal data without the subject's consent if necessary to fulfil obligations imposed on the operator by law:
| Data type | Retention period | Legal basis |
|---|---|---|
| Primary accounting documents and receipts | 5 years | Article 29 of Federal Law No. 402-FZ «On Accounting» |
| Tax records | 5 years | Article 23, part 1, sub-paragraph 8 of the RF Tax Code |
| Data necessary for performance of an active contract | Contract term + 3 years | Article 6 part 1 point 5 of FZ-152, Article 196 of the RF Civil Code |
The retained data is kept in anonymised form and used solely for accounting and tax purposes.
8. Facebook, Instagram and Threads data
PublPost uses Meta Platforms APIs (Facebook Graph API, Instagram API, Threads API) to publish content and retrieve analytics on behalf of the user. In accordance with Meta Platform Terms:
- When the user disconnects their account or removes the app from Facebook/Instagram, all access tokens are revoked immediately
- PublPost ceases access to the user's pages, profiles, and publications on Meta platforms
- Locally stored data (post text, analytics) is deleted within 30 days
- PublPost does not store Meta account passwords and has no access to private messages
To revoke access yourself: Facebook → Settings & Privacy → Settings → Apps and Websites → PublPost → Remove. Direct link: facebook.com/settings?tab=applications.
9. Data subject rights
Pursuant to Article 14 of FZ-152, the data subject has the right to:
- Receive information about the processing of their personal data
- Request clarification, blocking, or deletion of personal data
- Withdraw consent for personal data processing (Article 9 FZ-152)
- Appeal actions or inaction of the operator (Article 17 FZ-152)
In accordance with the GDPR (where applicable), you also have the right to data portability (Article 20 GDPR) and the right to restriction of processing (Article 18 GDPR).
10. Complaint procedure
If you believe that the operator is violating your personal data rights, you may contact:
- The operator: support@publpost.ru — response within 10 business days
- Roskomnadzor (Russian Federal Service for Supervision of Communications, Information Technology, and Mass Media): rkn.gov.ru
- Court at the data subject's place of residence (Article 17 FZ-152)
11. Contact information
| Controller | ИП Попов Иван Петрович, ИНН 521600320843 |
| Email for requests | support@publpost.ru |
| Website | publpost.ru |
| Response time | Up to 10 business days |
When contacting us regarding data deletion, please include the email associated with your PublPost account so we can verify your identity.