Privacy Policy

Last updated: March 21, 2026

This Privacy Policy (the «Policy») describes how PublPost (publpost.ru) collects, uses, stores, and protects the personal data of users of the service.

1. General provisions

1.1. The data controller is ИП Попов Иван Петрович, ИНН 521600320843 (the «Controller»), which operates the PublPost internet service available at publpost.ru (the «Service»).

1.2. This Policy is based on Russian Federal Law No. 152-FZ of July 27, 2006 «On Personal Data», EU Regulation 2016/679 (GDPR) where applicable to processing of users from EU/EEA countries, and other Russian legal acts on the protection of personal data.

1.3. By registering with the Service and/or using its functionality, the User gives unconditional consent to this Policy and the personal data processing terms set out in it. If the User disagrees with the Policy, they must stop using the Service.

1.4. PublPost is a social media management platform providing tools for scheduling, creating, automatically publishing content, and analytics.

2. What data we collect

2.1. Data provided at registration

  • Email address
  • First name and last name (if provided)
  • Password hash — we do not store passwords in plain text, only a cryptographic hash (bcrypt)

2.2. Data received via OAuth authorisation

When you authorise via third-party services (Google, VKontakte, Telegram, Odnoklassniki, Pinterest) we receive only public profile information:

  • User identifier in the corresponding system
  • First name and last name (public)
  • Email address (if provided)
  • Avatar URL (if available)

2.3. Social network account data

To perform the core function of the Service — publishing content to social networks — we obtain and store:

  • Access tokens for social network APIs (VK, Telegram, OK, YouTube, Pinterest)
  • Identifiers of connected pages, groups, and channels
  • Account metadata (name, avatar, follower count)

Tokens are stored in encrypted form and used solely to perform actions requested by the User (publishing posts, retrieving statistics).

2.3a. Pinterest integration

When you connect a Pinterest account to PublPost, Pinterest issues us an OAuth access token that grants limited access to your boards and pins. The token is used exclusively for actions you initiate:

  • creating, scheduling, editing, and deleting pins;
  • reading engagement analytics (impressions, saves, pin clicks, outbound clicks) for pins published through PublPost;
  • reading the list of your boards so the composer can let you choose where to publish.

PublPost does not share Pinterest data with third parties, does not use it for advertising, and revokes our access immediately when you disconnect the account. Our use of Pinterest data complies with the Pinterest API Terms of Service and Developer Guidelines.

2.3b. TikTok integration

When you connect a TikTok account to PublPost, TikTok issues us an OAuth access token with the following scopes: user.info.basic, video.upload, video.publish, video.list. The token and related data are used exclusively for actions you initiate:

  • uploading and publishing videos to your TikTok account;
  • polling publish status (TikTok processes videos asynchronously — we poll until status transitions to «published»);
  • reading engagement metrics (views, likes, comments, shares) for videos you published through PublPost to display analytics in your dashboard;
  • reading basic profile information (display_name, avatar) to render the connected account in the UI.

PublPost does not share TikTok data with third parties, does not use it for advertising or retargeting, and does not aggregate data across users. When you disconnect the account, we revoke the access token via TikTok's OAuth revoke endpoint and delete stored tokens and metadata. Our use of TikTok data complies with the TikTok API Terms of Service and Developer Platform Guidelines.

TikTok API limitations: deleting or editing already- published videos via the API is not supported by TikTok — these actions are only available inside the TikTok app. PublPost does not simulate these actions and does not provide UI for them.

2.3c. YouTube (Google API) integration

When you connect a YouTube channel to PublPost, Google issues an OAuth access token with the scopes: youtube.upload, youtube.readonly, youtube.force-ssl. Data usage:

  • uploading videos and Shorts to your channel;
  • reading channel information (title, subscriber count, list of your own videos) for display in the dashboard;
  • deleting videos that were uploaded through PublPost (requires youtube.force-ssl scope);
  • retrieving published-video metrics (views, likes, comments) for analytics.

PublPost complies with the Google API Services User Data Policy, including the Limited Use requirements: Google user data is not transferred to third parties, is not used for personalised advertising, is not used to develop, improve, or train AI/ML models, and is not accessible to humans (except with the user's explicit consent or to resolve technical support issues).

2.3d. X (Twitter) integration

When you connect an X account to PublPost, we receive an OAuth 2.0 access token with the scopes: tweet.read, tweet.write, users.read, offline.access. Data usage:

  • publishing tweets and threads on behalf of the user;
  • reading basic profile information (handle, display name, avatar);
  • deleting tweets published through PublPost;
  • retrieving published-tweet metrics (impressions, likes, retweets, replies) for analytics;
  • refreshing the token via refresh-token (offline.access) without re-prompting OAuth.

Our use of X data complies with the X Developer Agreement & Policy. PublPost does not pull data outside actions initiated by the user and does not aggregate third-party data.

2.3e. Instagram (Meta) integration

Instagram integration via the Meta Graph API requires an Instagram Business / Creator account linked to a Facebook Page. Requested scopes: instagram_basic, instagram_content_publish, instagram_manage_comments, instagram_manage_insights, pages_show_list, pages_read_engagement, pages_manage_posts. Data usage:

  • publishing posts, Reels, and Stories;
  • reading and replying to comments (moderation);
  • reading post metrics (impressions, reach, engagement, saves);
  • fetching the list of Facebook Pages so the user can pick the linked Instagram account.

Complies with the Meta Platform Terms and Developer Policies.

2.3f. Threads (Meta) integration

When you connect Threads to PublPost, we receive an OAuth token with the scopes: threads_basic, threads_content_publish, threads_manage_insights. Data usage:

  • reading basic profile info (username, avatar);
  • publishing posts and threads;
  • reading published-post metrics (views, likes, replies, reposts).

The Threads API is a Meta product; data use follows the same Meta Platform Terms and Developer Policies as Instagram/Facebook (see section 2.3e for links).

2.3g. Facebook (Meta Pages) integration

When you connect a Facebook Page to PublPost, we obtain a Page Access Token (derived from a User Access Token) with the scopes: pages_show_list, pages_manage_posts, pages_read_engagement, pages_manage_engagement, pages_manage_metadata, pages_read_user_content, read_insights. Data usage:

  • displaying the list of your Pages so you can pick the target;
  • publishing posts, photos, and videos to the selected Page;
  • reading comments and reactions for moderation;
  • deleting and editing posts published through PublPost;
  • reading Page Insights (impressions, reach, engagement) for analytics.

Complies with Meta Platform Terms and Developer Policies (links in section 2.3e). PublPost does not request access to Page direct messages and does not publish content without an explicit user action.

2.3h. Reddit integration

When you connect Reddit to PublPost, we receive an OAuth token with the scopes: identity, submit, edit, read, history. Data usage:

  • reading basic account info (username);
  • submitting posts to subreddits you select;
  • editing and deleting posts published through PublPost;
  • reading public subreddit posts for the preview that appears when choosing a target subreddit;
  • reading your own submission history so we can correlate Reddit posts with their entries in PublPost.

Complies with the Reddit Data API Terms. PublPost does not use Reddit data to train AI models and does not aggregate third-party content.

2.4. User content

  • Post text (posts, descriptions)
  • Uploaded images and video files
  • Publication schedules
  • Drafts and templates

2.5. Automatically collected data

  • IP address
  • Browser type and version (User-Agent)
  • Operating system
  • Date and time of access to the Service
  • Cookies (see section 8)
  • Analytics data (Yandex.Metrica)

2.6. Payment data

Service payments are processed by a certified payment provider. We do not store payment card data (card number, CVV, expiration date). The payment provider processes data in accordance with PCI DSS. We retain only: transaction ID, payment date and amount, subscription status.

3. Purposes of data processing

We process personal data for the following purposes:

  • Service provision — registration and authentication, content publishing to social networks, post scheduling, publication analytics
  • Communication — sending notifications about publication status, technical updates, terms of service changes
  • Service improvement — usage analysis to identify bugs, optimise performance, and develop new features
  • Security — preventing unauthorised access, detecting fraud and abuse
  • Legal obligations — payment processing, reporting, compliance with applicable law
  • AI content generation — passing text data (prompts, account context) to AI providers to generate content at the User's request

5. Data storage

5.1. User personal data is stored on servers located within the territory of the Russian Federation, in accordance with Article 18 part 5 of FZ-152.

5.2. Personal data retention periods:

Data typeRetention period
Account dataUntil the User deletes the account
Content (posts, media)Until deleted by the User or until account deletion
Social network access tokensUntil the social account is disconnected or until account deletion
Payment records5 years from transaction (RF Tax Code requirement)
Logs (IP, User-Agent)12 months
Analytics data26 months (Yandex.Metrica)

5.3. Data is transmitted over the secure HTTPS protocol (TLS 1.2+). Passwords are stored as cryptographic hashes (bcrypt). Social network access tokens are stored in encrypted form.

5.4. After account deletion, personal data is erased within 30 days, except for data retained as required by law.

6. Sharing with third parties

6.1. We do not sell User personal data to third parties. Data is shared only in the cases described below, and only to the extent necessary for the stated purposes.

6.2. Social networks

To publish content, we share data via official social network APIs: VKontakte, Telegram, Odnoklassniki, YouTube. Data shared: post text, media files, publication parameters. Processing of data by social networks is governed by their own privacy policies.

6.3. Payment providers

For payment processing, data is shared with a PCI DSS certified payment provider. We share: User email, payment amount and description.

6.4. Analytics

We use Yandex.Metrica to analyse use of the Service. Yandex.Metrica automatically collects de-identified visit data. Yandex.Metrica's processing of data is governed by Yandex's Privacy Policy.

6.5. AI providers

To generate content at the User's request, we share text data (prompts, brand context) with OpenAI. Data is used solely to generate the response and is not retained by the provider for model training (when accessed via API). Media files and personal User data are not shared with AI providers.

6.6. Other cases

We may disclose personal data upon request by authorised state bodies in cases provided for by Russian Federation law.

7. User rights

Pursuant to Article 14 of FZ-152 and Chapter III of the GDPR, you have the following rights:

  • Right of access — you may request information about which of your personal data we process, for what purposes, and to whom it has been disclosed
  • Right of rectification — you may update or correct your personal data in your profile settings or by contacting us via email
  • Right to erasure — you may delete your account and all associated data in the Service settings. After deletion, the data will be permanently erased within 30 days
  • Right to withdraw consent — you may withdraw consent for personal data processing at any time by sending a request to support@publpost.ru. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal
  • Right to data portability — you may request a copy of your data in a machine-readable format
  • Right to restriction of processing — you may demand restriction of processing of your data in cases provided for in Article 18 GDPR
  • Right to lodge a complaint — you may lodge a complaint with Roskomnadzor (Federal Service for Supervision of Communications, Information Technology and Mass Media): rkn.gov.ru

To exercise any of these rights, send a request to support@publpost.ru. We will respond within 30 days.

8. Cookies and analytics

8.1. The Service uses cookies — small text files saved in the User's browser.

8.2. Types of cookies used:

TypePurposeLifetime
NecessaryAuthentication, session, CSRF protectionUntil session ends
FunctionalInterface settings, user preferences1 year
AnalyticsYandex.Metrica — visit statistics1 year

8.3. You can disable cookies in your browser settings. Note that disabling necessary cookies will prevent the Service from being used (no authentication).

8.4. To disable analytics cookies for Yandex.Metrica, you can use the Yandex.Metrica blocking extension.

9. Data security

9.1. We take all necessary organisational and technical measures to protect personal data from unauthorised access, destruction, modification, blocking, copying, distribution, or other unlawful actions by third parties.

9.2. Security measures applied:

  • Data transmission over the secure HTTPS protocol (TLS 1.2+)
  • Password hashing using bcrypt (with individual salts)
  • Encryption of social network access tokens
  • Access control within the Service
  • Regular data backups
  • Suspicious activity monitoring
  • CSRF, XSS, and SQL injection protection at the application level

9.3. Despite the measures taken, we cannot guarantee absolute security of data transmitted over the internet. In the event of a data breach, we will notify affected Users and the relevant authorities within the timelines established by law.

10. Age restrictions

10.1. The Service is not intended for persons under 16 years old. We knowingly do not collect personal data of minors.

10.2. If we become aware that we have received personal data of a person under 16 years old without parental or legal guardian consent, we will take steps to delete such data as soon as possible.

10.3. If you are a parent or legal guardian and believe that your child has provided us with personal data, please contact us at support@publpost.ru.

11. Changes to this policy

11.1. We reserve the right to make changes to this Policy. The current version is always available at publpost.ru/privacy.

11.2. In the event of material changes, we will notify Users by email at least 14 days before the changes take effect.

11.3. Continued use of the Service after the changes take effect constitutes the User's acceptance of the updated Policy.

12. Contact information

For all questions related to personal data processing, you can contact the Controller:

Response time: within 30 days of receiving the request.

Publication date: March 21, 2026

ИП Попов Иван Петрович, ИНН 521600320843 | PublPost | publpost.ru