Privacy Policy
Last Updated: September 2026
Welcome to Pushlyr ("we," "our," or "us"). We are committed to protecting your privacy and ensuring that your personal data and social media accounts are handled with the utmost security. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our automated publishing SaaS platform.
1. Information We Collect
To provide our automated publishing services, we collect specific types of information from our users:
- Account Information: When an agency registers, we collect basic administrative information, including organization names and master PIN configurations.
- OAuth & Authentication Tokens: When you link third-party social media accounts (TikTok, YouTube, Instagram, Google Drive), we collect and securely store OAuth access tokens and refresh tokens. These tokens are strictly used to authenticate API requests on your behalf.
- Media & Content: We temporarily process video files, metadata (titles, descriptions, captions), and scheduling times required to execute the publishing workflows.
- Usage Logs: We maintain internal activity logs (such as timestamps, actions performed by team members, and success/error rates of API publishing) for security, auditing, and platform improvement.
2. How We Use Your Information
We use the collected information exclusively for the operation and improvement of our platform:
- Automated Publishing: To programmatically upload and publish your video content to your connected social media platforms via official APIs.
- Multi-Tenant Isolation: To ensure that data, media, and credentials belonging to one organization are strictly isolated from others through unique organization IDs.
- System Functionality: To trigger backend workflows via GitHub Actions and QStash for video processing and scheduled delivery.
3. Third-Party API Services (Google, TikTok, Meta)
Pushly’s core functionality relies on integrating with third-party platforms. By using Pushly, you are also subject to the privacy policies of these services:
- Google & YouTube: Our application utilizes YouTube API Services. By connecting your YouTube account, you agree to the YouTube Terms of Service and the Google Privacy Policy. We only request scopes necessary to upload videos and read basic profile data.
- TikTok: By connecting your TikTok account, you authorize us to use the TikTok API for video uploading and publishing, subject to the TikTok Privacy Policy.
- Meta (Instagram): Publishing to Instagram Reels utilizes the Meta Graph API, subject to Meta’s Privacy Policy.
Note on Google Data: Pushly’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. Data Storage and Security
We implement stringent technical and organizational security measures to protect your data:
- Encrypted Databases: All OAuth tokens and sensitive agency data are stored in secure databases (Supabase/PostgreSQL) with Row Level Security (RLS) enabled.
- Master PIN Protection: Access to sensitive connection management panels requires a physical/digital Master PIN, ensuring unauthorized team members cannot modify your social media bindings.
- Temporary Processing: Video files routed through our ingestion servers (Cloudflare R2) are processed temporarily for the sole purpose of delivery to target platforms.
5. Data Sharing & Disclosure
We do not sell, rent, trade, or share your personal information, media, or authentication tokens with any external third parties for marketing or advertising purposes. Your data is only shared with the specific social media platforms (e.g., sending a video payload to the TikTok API) that you explicitly authorize during the publishing process.
6. Data Retention and Deletion
We retain your authentication tokens and activity logs only as long as you maintain an active account with us. You have the right to request the deletion of your data.
Revoking Access: You can revoke Pushly's access to your data at any time via the security settings of your Google, TikTok, or Meta accounts. Once access is revoked, our system immediately loses all capability to interact with your accounts, and we will purge your obsolete tokens from our database.
7. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please contact the Pushly administration team directly.