Privacy Policy

What this service stores, what it never stores, and how to delete all of it.


Last updated 25 August 2026.

Social Publisher schedules one upload to Facebook Pages, Instagram and YouTube at the same time. It is operated by НоушънТек ЕООД (NotionTech EOOD), ЕИК 206980517, registered in Bulgaria, and runs at https://publisher.notiontech.io.

НоушънТек ЕООД is the data controller. Contact: info@notiontech.io.

This policy describes what the software actually does.

Your media is never stored

Your photos and videos stay in your Google Drive. This service never keeps a copy of them.

When a scheduled post is due, the file is read from Drive and streamed straight through to Facebook, Instagram or YouTube in small chunks. It is never written to disk, never cached, and never held whole in memory. There is nothing to delete afterwards, because nothing was ever created.

One case works slightly differently, and still stores nothing. Instagram will not accept image bytes directly — it insists on fetching an image from a web address itself. So for still images going to Instagram, and only for those, the service creates a random, unguessable address that pipes the file through from Drive as Instagram reads it. That address:

  • points at your file in Drive; no copy is made
  • expires after one hour
  • is deleted as soon as the post finishes, whether it succeeded or failed
  • answers "not found" to anyone else

Facebook, YouTube and Instagram video never need this. Their bytes go out directly.

What is stored

In a Postgres database, on the server described further down.

Your account — your name, email address and profile picture address, as Google supplies them when you sign in; your time zone, which your browser reports so that scheduled times display correctly; and whether you are an administrator.

Your sign-in record — signing in with Google also writes a standard account record through the authentication library this service uses: the provider name, Google's identifier for you, the tokens Google issued for the sign-in itself, and the permissions they cover. Those are identity permissions — name, email address, profile — and carry no access to your Drive, your Pages or your channels. Unlike the publishing tokens below, they are stored as the library writes them, without the additional encryption layer.

Your connections — for each platform you authorise for publishing: which platform it is, that platform's own identifier for the account, a label, the permissions the platform reported granting, when the authorisation expires, and the access and refresh tokens. These publishing tokens are encrypted before they are written, using AES-256-GCM with a key kept outside the database. A copy of the database on its own is not enough to publish as you.

Your destinations — for each Page, Instagram account or YouTube channel you choose to publish to: its name, its username, its profile picture address, and the platform's identifier for it.

Your posts — the time you scheduled, and for each destination the caption you wrote, the format (photo, reel, carousel, short and so on), the Google Drive file identifiers of the media, and once it has run: the platform's post id, the link to the published post, the time it went out, how many attempts it took, and the platform's error message if it failed.

Note what that last list does not contain. Not the files. Not even their filenames. Only Drive's identifier for them.

Your user record also carries fields for a Stripe customer and subscription, inherited from the starter template this service is built on. Nothing is charged for the service today; see the Terms of Service.

What is not done

  • No advertising, no tracking pixels, and no analytics that profile you. The only thing ever sent to a third party is a technical error report when something breaks, described under Error monitoring below, and it carries none of your content
  • Nothing is sold, rented or shared with data brokers or advertising networks
  • Your Drive is read only to show you your own folders and files, and to read the files you scheduled, at the moment they publish
  • Your Facebook and Instagram messages, comments and audience statistics are never read. On Meta's API this service reads one thing — the list of Pages and Instagram accounts you administer — and writes one thing: the posts you scheduled

Error monitoring

To find and fix failures, this service sends technical error reports to Sentry (Functional Software, Inc.), an error-tracking processor. A report is created only when something goes wrong — in your browser, on the server, or in the background jobs that publish your posts and refresh your connections.

A report contains the error and its stack trace, the kind of browser or server it happened on, and a short trail of the technical steps that led up to it — enough to reproduce the fault.

It never contains your media, your captions, your access or refresh tokens or any other credential, or your Google Drive file identifiers. Those are stripped out before a report leaves the service. Your media in particular never reaches Sentry — consistent with the promise at the top of this page that your media never leaves your Google Drive. Reports are stored in Sentry's European Union region, in Germany.

Cookies

A sign-in cookie so that you stay signed in, its accompanying anti-forgery cookie, and a short-lived cookie during each platform authorisation that is deleted the moment the authorisation completes. There are no advertising or analytics cookies.

Signing in

The sign-in screen offers Google. The service is also built on a starter template that includes sign-in by emailed link; where that mechanism is used, the email address is passed to Resend, which delivers the message, and a one-time sign-in token is stored until it expires or is used.

Google user data

Signing in uses Google, which gives the service your name, email address and profile picture.

Connecting Google Drive requests one Drive permission, https://www.googleapis.com/auth/drive.readonly. It is read-only: the service cannot create, change, move or delete anything in your Drive. It is used to list your folders and files when you compose a post, and to read the files you scheduled when they publish.

Connecting a YouTube channel requests youtube.upload and youtube.readonly — enough to list your channels and to upload the videos you scheduled.

This application's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the features described on this page. It is not transferred to anyone other than the platform you asked the service to publish to, it is not used for advertising, and it is not read by a person except with your explicit permission or where the law requires it.

YouTube

This service uses YouTube API Services. By connecting a channel you also agree to the YouTube Terms of Service.

Google's privacy policy is at http://www.google.com/policies/privacy.

You can revoke this application's access to your Google and YouTube data at any time on the Google security settings page, https://security.google.com/settings/security/permissions.

Facebook and Instagram

There are two ways to connect. Facebook Login returns the Pages you administer and any Instagram account linked to one. Instagram Business Login authorises a single Instagram account directly, with no Facebook Page involved.

The Facebook consent screen asks for a broad set of Page and Instagram permissions, wider than the service uses. It uses two of the capabilities they cover: listing the Pages and Instagram accounts you administer, and publishing the posts you scheduled. The permissions covering messages, comments, audience insights and business management are requested but never exercised — no message is read or sent, no comment is read, no insight is read, and no Business Manager data is fetched.

You can review and remove this application's access at any time in Facebook settings under Business integrations, and for Instagram at https://www.instagram.com/accounts/manage_access/.

Deleting your data

Delete everything yourself, immediately. Sign in, open Settings, and use Delete Account. That deletes your user record and, with it, every connection, every stored token, every destination, every scheduled and past post with its captions, your sign-in record, and any media address still outstanding. It takes effect at once and cannot be undone.

Delete one connection. On the Accounts page, remove a platform. That deletes the stored token for it and every destination that was discovered through it. Remove a single destination to stop publishing to that one Page, account or channel while keeping the rest.

Two things deletion does not do.

Posts that already went out stay on Facebook, Instagram and YouTube. Delete those on the platform itself.

Removing a connection deletes this service's copy of your token, but it does not withdraw the application's authorisation at the platform. Do that at https://security.google.com/settings/security/permissions for Google and YouTube, at https://www.facebook.com/settings?tab=business_tools for Facebook, and at https://www.instagram.com/accounts/manage_access/ for Instagram.

If you cannot sign in, write to info@notiontech.io from the address on the account. Everything held about you will be deleted within thirty days, and in practice much sooner.

Where the data lives, and for how long

The application and its database run on one server rented from Hetzner Online GmbH in Nuremberg, Germany. Server logs rotate and are overwritten; they exist to diagnose failures and are used for nothing else.

Everything else is kept until you delete it, and goes when your account does. The temporary media addresses described above last at most one hour, and are usually gone within minutes. One-time sign-in tokens last until they are used or expire.

Who else sees your data

WhoWhat reaches themWhy
Hetzner Online GmbHhosting for the server and the databaseit runs the service
Googleyour sign-in, your Drive requests, your YouTube uploadsyou connected them
Metayour Page and Instagram requests, and what you publishyou connected them
Resendyour email address, when a sign-in link is sentto deliver that email
Sentry (Functional Software, Inc.)technical error reports, with your content and credentials removedto find and fix failures

That is the entire list. There is no analytics provider, no advertising network and no data broker. Nothing is charged for the service today, so no payment processor receives anything; if a paid plan is introduced, Stripe would take the payment and card details would go to it directly, never through this service.

Your rights

Under the GDPR you may ask for a copy of your data, ask for it to be corrected, ask for it to be deleted, object to how it is handled, or take it elsewhere. Deletion you can do yourself in Settings; for anything else write to info@notiontech.io.

If you believe your data has been mishandled you may complain to the Bulgarian Commission for Personal Data Protection (Комисия за защита на личните данни), https://www.cpdp.bg.

Children

This service is not intended for anyone under 16.

Changes

If this policy changes, the date at the top changes with it.