Privacy Policy
Last updated 28 July 2026
Uploader lets you connect your own social media accounts and publish your own posts to them from one place. This page describes exactly what we store to make that work, and what we do not.
What we store
- Your account: your email address, an optional display name, and — if
you set one — your password as an
argon2hash. We never store the password itself. - Your sessions: a random token is placed in a cookie in your browser. We store only its SHA-256 hash, so our database cannot be used to sign in as you.
- Your connected accounts: the access and refresh tokens each platform issues when you authorize us, plus the account name and id we show you in the dashboard. Tokens are encrypted at rest with AES-256-GCM.
- Media you publish: if you upload a file rather than give us a URL, we host a copy so the platform can fetch it, because several publishing APIs only accept a public URL.
- Operational records: server logs and error reports, which may include your account id and the request that failed.
What we do not do
- We do not read your feed, your messages, your followers or anyone else's posts. We request only the permissions needed to publish.
- We do not sell, rent or share your data with advertisers or data brokers.
- We do not build advertising profiles and we run no advertising.
- We do not post anything you did not ask us to post.
Who else sees it
- The platforms you connect — Facebook, Instagram, Threads, YouTube, LinkedIn, X, TikTok — receive the posts you tell us to publish, under their own privacy policies.
- Postmark delivers the sign-in codes we email you.
- Sentry receives error reports when something breaks.
- Our servers are hosted in the European Union.
Deleting your data
- Disconnect one account at any time from the dashboard. Its stored tokens are deleted immediately.
- Revoke our access from the platform's own settings. It stops working here at once.
- Delete everything by emailing hello@stapilo.com. We remove your account, your sessions, your connected accounts and their tokens.
- Remove Uploader from Facebook, Instagram or Threads and Meta tells us you did. We delete that connection and its stored tokens straight away, without you having to ask us as well.
- A data deletion request made through Meta reaches us at /data-deletion. We delete the connection and its tokens when the request arrives, and hand back a confirmation code you can open to check the result yourself.
YouTube
Uploader uses YouTube API Services to publish to the channel you connect. By connecting a YouTube channel here you also accept the YouTube Terms of Service, and Google's handling of your data is described in the Google Privacy Policy.
- What we read: once, at the moment you connect, the id, name and picture of the channel that authorised us. The name and picture are shown in your dashboard so you can see which channel is linked; the id is what we address when uploading. We read nothing else — no video lists, no analytics, no subscriptions, no comments.
- What we write: the video you attached in the composer, with the title, description and visibility you chose. Only when you press Publish, never on a schedule and never in the background.
- What we keep: that channel id, name and picture, and the OAuth tokens, encrypted at rest. Disconnecting the channel deletes all of it.
- Revoking access: you can withdraw our access at any time at Google's security settings page, whether or not you disconnect it here. Doing so stops any further upload immediately.
How it is protected
All traffic runs over HTTPS. Platform tokens are encrypted at rest; passwords are hashed with argon2; session tokens are stored only as hashes. Sign-in has rate limits and lockouts to make guessing impractical.
Changes
If this policy changes we update this page and the date above.