Privacy Policy
Last Updated: March 25, 2026
1. Introduction
This Privacy Policy explains how WebSilk Lab (“we”, “us”, or “our”) handles data within this self-hosted instance of the Postiz application located at post.websilklab.com. We provide a tool for scheduling and managing social media content across TikTok, Instagram, YouTube, X (Twitter), and Pinterest.
2. Information We Collect via Social APIs
When you connect your social media accounts, we collect:
- Authentication Data: OAuth access tokens and refresh tokens provided by TikTok, Meta (Instagram), Google (YouTube), X, and Pinterest.
- Profile Data: Public handles, profile pictures, and account IDs to identify your channels within our dashboard.
- Content Metadata: Information about the videos, images, and captions you upload for the purpose of scheduling and publishing.
3. How We Use Your Information
We use the respective platforms’ APIs (including TikTok Content Posting API, YouTube API Services, Meta Graph API, X API, and Pinterest API) solely to:
- Authenticate your identity to the Postiz dashboard.
- Directly publish or schedule content (Reels, Videos, Pins, Tweets/Posts) to your profiles at your requested time.
- Display post-performance analytics (if enabled).
Data Storage: Because this is a self-hosted instance, all authentication tokens and media files are stored locally on our private server infrastructure. We do not sell, rent, or share your data with third parties.
4. YouTube API Services
By using this service to post to YouTube, you are also bound by the YouTube Terms of Service and the Google Privacy Policy. You can manage your Google security settings and revoke access at Google Security Settings.
5. Data Deletion & User Rights
How to Delete Your Data
- Self-Service: You can remove any connected social channel via the “Channels” settings in the Postiz dashboard. This immediately and permanently purges the associated OAuth tokens from our database.
- Manual Request: To request a full account wipe, email support@websilklab.com with the subject “Data Deletion Request.” We process all requests within 48 hours.
- Platform Revocation: You may also revoke access directly through the security settings of TikTok, Meta/Instagram, Google, and X.
6. Compliance
This service complies with the developer terms of all supported platforms. We do not use your data for profiling, data mining, or targeted advertising.