Skip to content

Privacy policy

Information under Articles 13 and 14 GDPR about how Selfpost processes personal data. Effective 1 September 2026.

1. Controller and contact

The controller is Tim Hausl-Kramper, trading as THK-Media, sole proprietorship, Sonnweg 17, 3463 Stetteldorf am Wagram, Austria.

Privacy enquiries and requests can be sent to [email protected] or made by telephone at +43 660 133 0906. No data protection officer has been appointed because Selfpost is not subject to the appointment duty in Article 37 GDPR at its current scale; the controller is the direct privacy contact.

DPIA assessment status: The controller reviews whether a data protection impact assessment is required whenever a new high-risk processing activity is introduced.

2. Scope and sources

This policy applies to the Selfpost website, web application, support, waitlist, billing, and publishing integrations. Most data comes directly from you. Connected platforms also provide account identity, permission, publication-status, and analytics data when you authorise a connection.

If a workspace customer invites another person or manages a client's social account, the customer is responsible for having authority to provide that person's data and for giving any additional information required by Article 14 GDPR.

3. Account, workspace, and content data

We process account identifiers, email address, display name, optional avatar, authentication identities, session and security records, team invitations, roles, workspace membership, notification and display preferences, and support correspondence.

For the publishing service we process connected social-account identifiers and profile information, encrypted access and refresh tokens, media and metadata, captions, titles, first comments, platform choices and confirmations, drafts, schedules, publishing attempts, provider identifiers, status, and available analytics.

The legal basis is performance of the Selfpost contract and steps requested before entering it (Article 6(1)(b) GDPR). Security, abuse prevention, service diagnostics, and reliable retry handling are based on our legitimate interests in operating a secure and dependable service (Article 6(1)(f)).

Instagram (Meta): when you connect an Instagram professional account we receive and store the Instagram user ID, username, account type, and profile picture, an encrypted access token valid for about 60 days that we refresh while the account stays connected, the IDs and permalinks of posts published through Selfpost, processing status, and comment IDs for first comments you request. Permissions used: instagram_business_basic, instagram_business_content_publish, instagram_business_manage_comments.

TikTok: when you connect a TikTok account we receive and store the TikTok open ID, display name, username, and temporary avatar URL, encrypted access and refresh tokens, the Creator Info options TikTok returns (available privacy options, interaction settings, maximum video length), publish IDs and processing status. Permission used: video.publish. If you sign in with TikTok, the user.info.basic permission provides your display name and avatar only.

YouTube (Google): Selfpost uses YouTube API Services. When you connect a YouTube channel we receive and store the channel ID, title, handle, and thumbnail, encrypted OAuth tokens, the IDs and URLs of videos uploaded through Selfpost, upload and privacy status, and the view, like, and comment counts you view in Selfpost. Permissions used: youtube.upload and youtube.force-ssl. Selfpost's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. Google's privacy policy: https://policies.google.com/privacy. YouTube Terms of Service: https://www.youtube.com/t/terms. If you sign in with Google, the openid, email, and profile scopes provide your name, email address, and avatar only.

We use platform data only to display the connected account, publish what you schedule, show processing status, refresh the statistics you view, and post a first comment you request. We do not sell it, use it for advertising, or share it with other apps.

4. Waitlist, support, and communications

Waitlist entries contain email address, locale, signup source, and timestamps. They are used for the requested launch update on the basis of consent (Article 6(1)(a) GDPR). Consent can be withdrawn at any time by contacting us; withdrawal does not affect earlier lawful processing.

Support requests contain account and optional workspace context, category, subject, message, status, and timestamps. We use them to perform the contract or take requested pre-contract steps and, where applicable, for our legitimate interest in resolving service issues.

Operational messages such as verification, security, publication, reconnection, billing, and invitation emails are necessary for the contract or service security. We do not use provider tokens, private media URLs, or payment-card data in support messages.

5. Billing data

Stripe processes checkout and payment-method details when billing is enabled. Current deployment status: used for checkout, subscriptions, and invoicing. Selfpost receives customer and subscription identifiers, plan, quantities, payment and subscription status, invoices or recovery links, and signed billing event metadata, but not complete card details.

Processing is necessary for the contract (Article 6(1)(b) GDPR) and for tax, accounting, and commercial record obligations (Article 6(1)(c)). Fraud prevention and billing reconciliation also serve our legitimate interests (Article 6(1)(f)).

6. Connected platforms and recipients

When you connect or publish to Instagram, TikTok, or YouTube, you instruct Selfpost to send the selected account identity, media, captions, settings, and publishing commands to that platform and to receive status and analytics. The platform then also processes data under the agreement and privacy terms for your platform account: Meta at https://privacycenter.instagram.com/policy, TikTok at https://www.tiktok.com/legal/page/eea/privacy-policy/en, and Google at https://policies.google.com/privacy.

Selfpost's infrastructure providers are OVHcloud (European Union data centres) for hosting, database, and object storage; Zoho/ZeptoMail for transactional email; and Stripe for billing. Their contracting entities and safeguards are listed on the Subprocessors page.

Platform recipients you select are Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland; Meta Platforms, Inc. (United States) under the EU-US Data Privacy Framework, TikTok Technology Limited, Dublin, Ireland and TikTok Information Technologies UK Limited, London; group companies outside the EEA may access data under TikTok's transfer safeguards, and Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Google LLC (United States) under the EU-US Data Privacy Framework. Revoke Selfpost's access at any time: Instagram at https://www.instagram.com/accounts/manage_access/ (Settings → Website permissions → Apps and websites); TikTok in the TikTok app under Settings and privacy → Security & permissions → Manage app permissions. You can also revoke Selfpost's access from the Google security settings page at https://security.google.com/settings/security/permissions. Disconnecting in Selfpost also revokes TikTok and Google tokens and deletes cached platform data.

7. International transfers

Selfpost's own hosting, database, and media storage run in European Union data centres. Publishing to a platform transfers the selected content, settings, and account identity to that platform: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland; Meta Platforms, Inc. (United States) under the EU-US Data Privacy Framework (EU-US Data Privacy Framework and Meta's Standard Contractual Clauses); TikTok Technology Limited, Dublin, Ireland and TikTok Information Technologies UK Limited, London; group companies outside the EEA may access data under TikTok's transfer safeguards (European Commission Standard Contractual Clauses in TikTok's data processing terms plus TikTok's documented supplementary measures); Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Google LLC (United States) under the EU-US Data Privacy Framework (EU-US Data Privacy Framework and Google's Standard Contractual Clauses). Selfpost relies on the Standard Contractual Clauses and supplementary measures above; information about the transfer assessment is available from the privacy contact. Copies of the applicable safeguards can be requested at [email protected].

8. Retention

Normal sessions expire after 7 days and remembered sessions after 30 days. Authentication and OAuth states expire after 10 minutes, action tokens after 30 minutes, invitations after 7 days, abandoned upload reservations after approximately 1 hour, and idempotency records after approximately 24 hours.

Media, drafts, posts, connected accounts, and workspace data are retained while the relevant account or workspace exists and until the user deletes them; deleting a workspace or account removes them immediately, subject to backup rotation. Platform tokens are deleted immediately when you disconnect an account or delete the workspace or your account. Platform analytics and capability data: provider analytics and capability snapshots are refreshed by the scheduled synchronisation and deleted 30 days after their last refresh or immediately when the account is disconnected; audit records are deleted after 12 months. Support and email records: support requests are deleted 24 months after they are closed; delivered email records are deleted after 30 days.

Waitlist data is retained until consent is withdrawn or the requested launch communication no longer requires the entry. Billing records are retained for the applicable Austrian tax and accounting retention period, generally seven years, and longer where a pending proceeding requires it. Account deletion removes or anonymises operational personal data subject to mandatory retention. Disconnecting revokes Google and TikTok access at the provider and deletes the local tokens; for Instagram, Selfpost deletes its token immediately and you can additionally remove Selfpost under Apps and websites in Instagram.

Backups: database backups are rotated automatically; the deployment process retains the latest 14 pre-migration database dumps and older copies are overwritten.

9. Cookies, browser storage, and measurement

Selfpost uses a secure HttpOnly session cookie and first-party locale, theme, and animation-preference storage. These are necessary to sign you in, remember choices, and provide requested application functions; they are not advertising cookies.

The application also stores local interface preferences, navigation history, and recent searches in local or session storage on your device. You can clear these using browser controls.

Optional site measurement is configured only as cookieless, non-advertising measurement and must not create cross-site profiles. If the deployed measurement setup changes to store or access non-essential device information, it will remain disabled until valid consent controls and this policy are updated.

10. Your GDPR rights

Depending on the circumstances, you have rights of access, rectification, erasure, restriction, data portability, and objection. Where processing relies on consent, you may withdraw it at any time. Where processing relies on legitimate interests, you may object on grounds relating to your situation; you may object to direct marketing at any time.

You can delete many records in the application, including your whole account from Account settings → “Your data”, and can request the remaining rights at [email protected]. We may need proportionate information to verify identity. Rights can be limited where a statutory exception applies, including mandatory retention or another person's rights.

Data export: Signed-in users can download a machine-readable JSON export of their account, workspaces, posts, media metadata, and analytics from Account settings; requests for other formats are handled through the privacy contact.

11. Required data and automated decisions

Account, authentication, workspace, and destination-specific publishing data are required to provide the requested service. Without them, the relevant account, connection, or publication cannot operate. Waitlist participation is optional.

Selfpost does not make decisions based solely on automated processing that produce legal or similarly significant effects within Article 22 GDPR. Preflight, capability, analytics, and any assistance features provide operational results or suggestions; the user chooses content, destinations, settings, and publication actions.

12. Security and children

Measures include role-based workspace authorisation, encrypted provider tokens, hashed session and action tokens, private media storage with short-lived signed URLs, request validation, rate limiting, audit records, log redaction, and restricted production configuration. No internet service can promise absolute security.

Selfpost is intended for adults and business use and is not directed to children. Do not submit another person's sensitive data or content unless it is necessary and you have a lawful basis.

13. Complaints and changes

You may complain to the Austrian Data Protection Authority, Barichgasse 40-42, 1030 Vienna, Austria, [email protected], or to another competent supervisory authority, without prejudice to other remedies.

We will update this policy when processing materially changes. The current version and effective date are published at this stable URL; material changes affecting registered users will also be communicated through an appropriate account or email notice.