Scheduler Privacy Policy
Last updated 27 July 2026
1. Scope
Social Scheduler is a private tool operated by one person for
managing their own social media accounts. It has no public users, no sign-up, and
collects no data from visitors. This policy describes what the operator's own
instance stores and why.
2. What is stored
- Account credentials for this tool — a username and a
scrypt hash of the password. The password itself is never stored.
- Connected platform tokens — OAuth access and refresh
tokens for social accounts you connect, encrypted at rest. These are
used solely to upload and schedule the content you submit.
- Scheduled post data — captions, hashtags, titles, target
accounts, and scheduled times.
- Uploaded media — video files you upload, stored in
S3-compatible object storage so a scheduled post can be delivered when the
operator's own computer is switched off.
- Operational logs — timestamps, request paths, and errors.
Failed sign-in attempts record the attempted username. Logs do not contain
passwords or tokens.
3. What is NOT collected
- No analytics, tracking pixels, advertising identifiers, or third-party
trackers of any kind.
- No cookies except a single session cookie required to stay signed in.
- No data about the audiences, followers, or viewers of connected accounts.
- No personal data of any third party.
4. Platform data
When a social account is connected, the service requests only the permissions it
needs to do its job: basic profile information (to display which account is
connected) and permission to upload or publish content. It does not read your
messages, followers, analytics, or other people's content. Data retrieved from a
platform is limited to the connected account's own identifier and display name.
5. Where data goes
- Railway — hosting, database, and object storage.
- The social platforms you connect — content you schedule is
transmitted to them at your instruction.
Data is not sold, shared, rented, or disclosed to anyone else. There are no
advertising or data-broker relationships.
6. Retention and deletion
Scheduled posts and uploaded media are retained until deleted by the operator.
Disconnecting a platform account deletes its stored tokens immediately. To request
deletion of all data held about a connected account, contact the address below;
tokens and associated posts will be removed.
7. Security
- All traffic is served over HTTPS with HSTS.
- Platform tokens are encrypted at rest.
- Passwords are hashed with scrypt and never stored in plaintext.
- Sessions use signed, HttpOnly cookies and are revoked when a password
changes.
- Sign-in is rate-limited to resist brute-force attempts.
No system is perfectly secure, and no guarantee of absolute security is made.
8. Children
This service is not directed at children and is not accessible to the public.
9. Changes
This policy is updated when the service changes. The date at the top reflects the
current version.
10. Contact
Privacy questions or deletion requests: clopez@obsdeckmedia.com