Privacy Policy
This Privacy Policy explains how Nguyễn Viết Dân ("we", "us", "our") collects, uses, stores and shares information when you use PostHub (the "Service"), available at https://dtool.bar and https://app.dtool.bar.
PostHub is a social media publishing tool. It lets you connect social media accounts (TikTok, Facebook, Instagram, Threads, YouTube, LinkedIn, X, Pinterest, Telegram, Bluesky, Discord, Tumblr, Mastodon and Google Business Profile) and create, schedule and publish content to those accounts. By using the Service you agree to this Privacy Policy.
1. Information we collect
1.1 Information you provide directly
- Account information: name, email address and password (stored hashed) when you register.
- Content: videos, images, captions, hashtags, titles and scheduling settings that you upload or create in the Service in order to publish them.
- Billing information: if you purchase a paid plan, payment is processed by our payment provider. We store only the plan, invoice history and the last four digits of the payment method, never the full card number.
- Support communications: messages you send to us.
1.2 Information from connected social media platforms
When you connect a social media account, you authorize the platform to share certain data with us through its official API (OAuth). We only request the permissions (scopes) required for the features of the Service: publishing and scheduling posts (text, images and videos), posting comments on your own posts, and showing you the performance of your posts. Depending on the platform, this includes:
| Platform | Data we access | Why |
|---|---|---|
| TikTok | Open ID, display name, avatar (user.info.basic); profile statistics such as follower, likes and video counts (user.info.stats); list of your public videos with their view, like, comment and share counts (video.list); ability to upload and publish videos and photos (video.upload, video.publish). |
Identify the connected account, publish the content you create, and show you the performance of your videos. |
| Facebook (Meta) | Public profile; list of Pages you manage and Page access tokens (pages_show_list); ability to publish posts, photos and videos to those Pages (pages_manage_posts); ability to post comments on the Page's own posts (pages_manage_engagement); post and Page engagement data such as reactions, comments, shares and reach (pages_read_engagement, read_insights). |
Identify the connected Pages, publish content and comments on your behalf, and show you post performance. |
| Instagram (Meta) | Instagram professional account ID, username, profile picture and media list (instagram_basic); ability to publish photos, videos, Reels and carousels (instagram_content_publish); ability to post comments on your own media (instagram_manage_comments); media insights such as views, reach, likes, comments and saves (instagram_manage_insights). |
Identify the connected account, publish content and comments on your behalf, and show you post performance. |
| YouTube (Google) | Channel ID, channel name, thumbnail and list of your videos with their view, like and comment counts (youtube.readonly); ability to upload videos (youtube.upload); ability to post comments on your own videos (youtube.force-ssl). |
Identify the connected channel, upload videos and comments you create, and show you video performance. |
Name, profile picture and member ID (openid, profile); organization Pages you administer; ability to create posts and comments on your own posts (w_member_social, w_organization_social); engagement statistics of those posts (r_organization_social). |
Identify the connected profile/Page, publish content and comments, and show you post performance. | |
| X (Twitter) | User ID, username, profile image (users.read, tweet.read); ability to create posts and replies and upload media (tweet.write, media.write); continued access without re-login (offline.access). |
Identify the connected account and publish posts and replies you create. |
| Threads (Meta) | Threads user ID, username and profile picture (threads_basic); ability to publish text, image, video and carousel posts (threads_content_publish); ability to reply to your own posts (threads_manage_replies); post insights such as views, likes, replies and reposts (threads_manage_insights). |
Identify the connected account, publish content and replies on your behalf, and show you post performance. |
Username and profile image (user_accounts:read); list of your boards (boards:read); ability to create Pins with images or videos (pins:write); your Pins and their metrics such as impressions, saves and clicks (pins:read). |
Let you choose a board, publish Pins you create, and show you Pin performance. | |
| Telegram | You add our Telegram bot as an administrator of your channel or group. We store the channel/group ID, title and the bot's posting permission. The bot only sends the messages, photos and videos you schedule; we do not store messages posted by other members. | Publish content you create to the channels and groups you choose. |
| Bluesky | Account DID, handle, display name and avatar; ability to create posts and replies with images or videos (atproto, transition:generic). |
Identify the connected account and publish posts and replies you create. |
| Discord | Your Discord user ID and username (identify); a webhook for the server channel you select (webhook.incoming). |
Publish messages, images and videos you create to the channel you selected. |
| Tumblr | Blog names and avatars (basic); ability to create posts with text, images and videos (write); continued access without re-login (offline_access). |
Let you choose a blog and publish posts you create. |
| Mastodon | Account ID, username and avatar on your server (read:accounts); ability to publish posts and upload media (write:statuses, write:media). |
Identify the connected account and publish posts you create. |
| Google Business Profile | List of business locations you manage and ability to publish updates, offers and event posts with photos to them (business.manage). |
Let you choose a location and publish posts you create. |
We store the OAuth access tokens and refresh tokens issued by each platform, encrypted at rest, so that we can publish scheduled posts without asking you to log in again. We store post metrics (views, likes, comments, shares and similar counts) only to display them to you in your dashboard. We do not access your private messages or your friends/followers lists, and we do not read the content of other people's posts or comments.
1.3 Information collected automatically
- Log data: IP address, browser type, device type, pages visited, timestamps and error reports.
- Cookies: session cookies required to keep you signed in and, if you consent, analytics cookies to understand how the Service is used.
2. How we use information
- To provide the Service: connect your accounts, store your content and publish it to the platforms you choose, at the time you choose.
- To show you the status of your posts (scheduled, published, failed) and their performance (views, likes, comments, shares and similar metrics).
- To post comments on your own posts when you ask us to (for example a first comment scheduled together with a post).
- To maintain, secure and improve the Service, and to prevent abuse.
- To communicate with you about your account, billing and important changes.
- To comply with legal obligations.
We do not sell your personal data. We do not use data obtained from social media platforms for advertising, profiling, or to train machine-learning models. We do not use it for any purpose other than operating the Service on your behalf.
3. How we share information
- Social media platforms: we send the content you create (media, captions, comments, settings) to the platforms you selected, using their official APIs, solely to publish it.
- Service providers: hosting, storage, email and payment providers that process data on our behalf under contractual confidentiality obligations.
- Legal: when required by law, regulation, legal process or to protect the rights, property or safety of our users or the public.
- Business transfers: if we are involved in a merger, acquisition or sale of assets, your data may be transferred; we will notify you before your data becomes subject to a different privacy policy.
4. Data retention
- Uploaded media: deleted from our servers automatically within 7 days after a post has been published or failed, or immediately when you delete the post.
- OAuth tokens: deleted immediately when you disconnect the social account or delete your PostHub account.
- Account data, post history and post metrics: retained while your account is active and deleted within 30 days after you delete your account.
- Log data: retained for up to 90 days.
5. Your rights and choices
- Disconnect a platform: in the Service, open Settings → Connected accounts → Disconnect. We delete the stored tokens immediately. You can also revoke access from the platform itself (for example TikTok: Settings and privacy → Security → Manage app permissions).
- Delete your account and data: follow the steps on our Data Deletion page.
- Access, correct or export your data: contact us at dannguyen22993@gmail.com.
- Depending on where you live (for example the EU/EEA, UK, California), you may have additional rights such as the right to object to or restrict processing and the right to lodge a complaint with a supervisory authority.
6. Security
We use industry-standard measures to protect your data, including HTTPS for all traffic, encryption of access tokens at rest, hashed passwords, and access controls limiting which staff can access production systems. No method of transmission or storage is 100% secure; if we become aware of a breach affecting your data we will notify you as required by law.
7. International transfers
Our servers are located in Singapore. If you access the Service from another region, your data may be transferred to and processed in that location. We take steps to ensure appropriate safeguards are in place.
8. Children
The Service is not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will delete it.
9. Third-party platform terms
Your use of each connected platform is also governed by that platform's own terms and privacy policy, including:
- TikTok: Privacy Policy
- Meta (Facebook / Instagram): Privacy Policy
- Google (YouTube, Google Business Profile): Privacy Policy. PostHub's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- LinkedIn: Privacy Policy
- X: Privacy Policy
- Threads: Threads Supplemental Privacy Policy
- Pinterest: Privacy Policy
- Telegram: Privacy Policy
- Bluesky: Privacy Policy
- Discord: Privacy Policy
- Tumblr: Privacy Policy
- Mastodon: the privacy policy of the Mastodon server your account is hosted on.
10. Changes to this policy
We may update this Privacy Policy from time to time. We will post the new version on this page and update the "Last updated" date. For material changes we will notify you by email or in the Service.
11. Contact us
Nguyễn Viết Dân
Hanoi, Vietnam
Email: dannguyen22993@gmail.com
Phone: +84 333 697 665