Posttyy

Privacy Policy

What Posttyy collects, why we collect it, who else sees it, and how to have it deleted.

Effective 12 September 2026

1. Who is responsible for your data

Cavelights LTD is the data controller for Posttyy. For any question or request about your data, or to exercise the rights in section 9, write to cavelightstore@gmail.com.

2. The short version

We collect what the service needs to schedule your posts, and nothing else. We do not sell your data, we do not use it for advertising, we do not build profiles from it, and we run no third-party analytics or tracking of any kind. Your social media credentials are encrypted before they are stored, and your uploaded media sits in a private bucket that is not publicly readable.

3. What we collect

Your account. Your email address and a securely hashed password, handled by our authentication provider. We never see your password in readable form.

Connected social accounts. When you connect an account we store: the platform, your username or page name on it, the platform’s own identifier for the account, the permissions you granted, the access credential and its expiry, and — where the platform issues one — a refresh credential. Access and refresh credentials are encrypted at rest using AES-256-GCM and are only decrypted on our server at the moment a post is published or a credential renewed.

Your content. The text of your posts and drafts, the times you schedule them for, any photos or videos you attach and their descriptions, and the outcome of each publish — whether it succeeded, the link to the published post, and the error if it failed.

Your subscription.Which plan you are on, whether it is being paid for, and the dates it renews or ends. We also store the identifiers Stripe gives us for your customer record and your subscription, so we can open your billing portal and match Stripe’s messages to your account. We never receive or store your card details.You enter those on Stripe’s own checkout page, and Stripe tells us only whether a payment succeeded.

Operational records. Our hosting and database providers keep standard server logs, which include IP addresses and request details, for security and troubleshooting.

Your accounts’ numbers. When you open Analytics, we ask the platform for the connected account’s public totals, such as its follower count, and for its recent posts with their likes, comments, shares and views. For Instagram, Facebook Pages, Pinterest and YouTube we keep that answer for up to 15 minutes, so that opening the page again does not ask the platform again, and we do not save it in our database.

For X we do save it, so that the page can show how the numbers change over time. Once you have opened Analytics for an X account, we record once a day the account’s totals (followers, following, posts and lists), and for each of its posts from the last 90 days the post’s text, when it was posted, and its impressions, likes, replies, reposts, quotes, bookmarks, profile clicks and link clicks. These are totals only: they do not say who liked, replied or clicked.

We do not collect your contacts, the list of who follows you, your direct messages, your location, or anything about who is in your audience.

4. Cookies

Posttyy sets no advertising or analytics cookies. The only cookies are the ones required to make it work:

5. Why we use it, and our legal basis

We do not use your data for marketing, and we do not make automated decisions that produce legal effects for you.

6. Data from connected platforms

The permissions you grant are the minimum each platform offers for publishing. We use platform data solely to operate features you have asked for, and we do not use it to build advertising profiles, sell it, or share it with data brokers.

Posttyy uses YouTube API Services. By connecting a YouTube channel you also accept the YouTube Terms of Service, and Google’s handling of your data is governed by the Google Privacy Policy. You can withdraw Posttyy’s access to your Google account at any time at myaccount.google.com/permissions, which is separate from disconnecting the channel in Posttyy.

Once a post is published it lives on that platform and is governed by that platform’s own privacy policy, not this one.

7. Who else sees your data

We do not sell or rent personal data. We share it only with the providers that run the service on our behalf, each bound to protect it and to use it only for that purpose:

We may also disclose data where the law requires it, or to establish or defend legal claims. If the business is ever sold or transferred, data may pass to the buyer under the protections of this policy.

8. Where your data is held, and for how long

Our providers operate internationally, so your data may be processed outside the UK and EEA. Where it is, the transfer is covered by appropriate safeguards such as the UK International Data Transfer Agreement or the EU Standard Contractual Clauses.

We keep data for as long as you keep using the service:

9. Your rights

Under UK and EU data protection law you have the right to access a copy of your data, to have inaccurate data corrected, to have your data deleted, to restrict or object to how we use it, and to receive it in a portable form. You can also withdraw consent where we rely on it.

Write to cavelightstore@gmail.com and we will respond within one month. There is no charge.

If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office (ICO), or to your local supervisory authority.

10. Deleting your data

You can remove your data yourself at any time:

Posts already published to a platform are not deleted by any of this. They are on your account, on that platform, and you remove them there.

11. Security

Social media credentials are encrypted with AES-256-GCM before being stored, and the encryption key is held separately from the database. Uploaded media is stored in a private bucket and is only reachable through short-lived links generated for someone already entitled to see it. Database access is restricted per account, so one account cannot read another’s data. Traffic is encrypted in transit.

No system is perfectly secure. If a breach affects your data and is likely to put your rights at risk, we will tell you and the regulator as the law requires.

12. Children

Posttyy is not intended for children. You must be at least 13, and old enough to hold accounts on the platforms you connect. We do not knowingly collect data from children; if you believe a child has given us data, contact us and we will delete it.

13. Changes to this policy

We may update this policy. The effective date at the top of the page shows when the current version took effect, and for material changes we will make a reasonable effort to notify you.

14. Contact

Cavelights LTD, operator of Posttyy cavelightstore@gmail.com.