PostHub

Privacy Policy

Last updated: September 15, 2026

This Privacy Policy explains how Nguyễn Viết Dân ("we", "us", "our") collects, uses, stores and shares information when you use PostHub (the "Service"), available at https://dtool.bar and https://app.dtool.bar.

PostHub is a social media publishing tool. It lets you connect social media accounts (TikTok, Facebook, Instagram, Threads, YouTube, LinkedIn, X, Pinterest, Telegram, Bluesky, Discord, Tumblr, Mastodon and Google Business Profile) and create, schedule and publish content to those accounts. By using the Service you agree to this Privacy Policy.

1. Information we collect

1.1 Information you provide directly

1.2 Information from connected social media platforms

When you connect a social media account, you authorize the platform to share certain data with us through its official API (OAuth). We only request the permissions (scopes) required for the features of the Service: publishing and scheduling posts (text, images and videos), posting comments on your own posts, and showing you the performance of your posts. Depending on the platform, this includes:

PlatformData we accessWhy
TikTok Open ID, display name, avatar (user.info.basic); profile statistics such as follower, likes and video counts (user.info.stats); list of your public videos with their view, like, comment and share counts (video.list); ability to upload and publish videos and photos (video.upload, video.publish). Identify the connected account, publish the content you create, and show you the performance of your videos.
Facebook (Meta) Public profile; list of Pages you manage and Page access tokens (pages_show_list); ability to publish posts, photos and videos to those Pages (pages_manage_posts); ability to post comments on the Page's own posts (pages_manage_engagement); post and Page engagement data such as reactions, comments, shares and reach (pages_read_engagement, read_insights). Identify the connected Pages, publish content and comments on your behalf, and show you post performance.
Instagram (Meta) Instagram professional account ID, username, profile picture and media list (instagram_basic); ability to publish photos, videos, Reels and carousels (instagram_content_publish); ability to post comments on your own media (instagram_manage_comments); media insights such as views, reach, likes, comments and saves (instagram_manage_insights). Identify the connected account, publish content and comments on your behalf, and show you post performance.
YouTube (Google) Channel ID, channel name, thumbnail and list of your videos with their view, like and comment counts (youtube.readonly); ability to upload videos (youtube.upload); ability to post comments on your own videos (youtube.force-ssl). Identify the connected channel, upload videos and comments you create, and show you video performance.
LinkedIn Name, profile picture and member ID (openid, profile); organization Pages you administer; ability to create posts and comments on your own posts (w_member_social, w_organization_social); engagement statistics of those posts (r_organization_social). Identify the connected profile/Page, publish content and comments, and show you post performance.
X (Twitter) User ID, username, profile image (users.read, tweet.read); ability to create posts and replies and upload media (tweet.write, media.write); continued access without re-login (offline.access). Identify the connected account and publish posts and replies you create.
Threads (Meta) Threads user ID, username and profile picture (threads_basic); ability to publish text, image, video and carousel posts (threads_content_publish); ability to reply to your own posts (threads_manage_replies); post insights such as views, likes, replies and reposts (threads_manage_insights). Identify the connected account, publish content and replies on your behalf, and show you post performance.
Pinterest Username and profile image (user_accounts:read); list of your boards (boards:read); ability to create Pins with images or videos (pins:write); your Pins and their metrics such as impressions, saves and clicks (pins:read). Let you choose a board, publish Pins you create, and show you Pin performance.
Telegram You add our Telegram bot as an administrator of your channel or group. We store the channel/group ID, title and the bot's posting permission. The bot only sends the messages, photos and videos you schedule; we do not store messages posted by other members. Publish content you create to the channels and groups you choose.
Bluesky Account DID, handle, display name and avatar; ability to create posts and replies with images or videos (atproto, transition:generic). Identify the connected account and publish posts and replies you create.
Discord Your Discord user ID and username (identify); a webhook for the server channel you select (webhook.incoming). Publish messages, images and videos you create to the channel you selected.
Tumblr Blog names and avatars (basic); ability to create posts with text, images and videos (write); continued access without re-login (offline_access). Let you choose a blog and publish posts you create.
Mastodon Account ID, username and avatar on your server (read:accounts); ability to publish posts and upload media (write:statuses, write:media). Identify the connected account and publish posts you create.
Google Business Profile List of business locations you manage and ability to publish updates, offers and event posts with photos to them (business.manage). Let you choose a location and publish posts you create.

We store the OAuth access tokens and refresh tokens issued by each platform, encrypted at rest, so that we can publish scheduled posts without asking you to log in again. We store post metrics (views, likes, comments, shares and similar counts) only to display them to you in your dashboard. We do not access your private messages or your friends/followers lists, and we do not read the content of other people's posts or comments.

1.3 Information collected automatically

2. How we use information

We do not sell your personal data. We do not use data obtained from social media platforms for advertising, profiling, or to train machine-learning models. We do not use it for any purpose other than operating the Service on your behalf.

3. How we share information

4. Data retention

5. Your rights and choices

6. Security

We use industry-standard measures to protect your data, including HTTPS for all traffic, encryption of access tokens at rest, hashed passwords, and access controls limiting which staff can access production systems. No method of transmission or storage is 100% secure; if we become aware of a breach affecting your data we will notify you as required by law.

7. International transfers

Our servers are located in Singapore. If you access the Service from another region, your data may be transferred to and processed in that location. We take steps to ensure appropriate safeguards are in place.

8. Children

The Service is not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will delete it.

9. Third-party platform terms

Your use of each connected platform is also governed by that platform's own terms and privacy policy, including:

10. Changes to this policy

We may update this Privacy Policy from time to time. We will post the new version on this page and update the "Last updated" date. For material changes we will notify you by email or in the Service.

11. Contact us

Nguyễn Viết Dân
Hanoi, Vietnam
Email: dannguyen22993@gmail.com
Phone: +84 333 697 665