Data Deletion & Account Removal
This page explains how to delete your data from SkedCast (operated by Alpha Exotic Tech LLC) and what happens to the stored access we hold for your connected social accounts. It is the data-deletion instructions URL we provide to the platforms we integrate with — and the URL configured as the Meta data-deletion callback.
1. Who can request deletion
Both our direct customers (agency account-holders) and the owners of a connected social account can request deletion of their data. The deletion right is available to anyone who can access the app. If you are an end user whose account was connected by one of our customers, you can contact us directly or ask that customer; we will route and assist with the request as needed.
2. How to request deletion
There are three ways to request deletion:
- Disconnect one account — disconnecting a connected social account inside SkedCast immediately erases the OAuth tokens we store for it, asks the platform to revoke them where the platform offers a revocation endpoint (see §3), and cancels anything still queued for it. Nothing else in your workspace is affected.
- Close your whole workspace — the owner can close a workspace at skedcast.com/legal/close-account. Closing is immediate and irreversible: it erases the stored tokens for every connected account, disconnects them all, cancels every scheduled and platform-scheduled post, marks your media for erasure, and signs out every member. You are shown a reference code and emailed a confirmation; the records that remain are taken out of service at the same moment and erased by hand within 30 days (see §4). Only the workspace owner can do this, and we ask you to type the workspace name to confirm.
- By email — send a deletion request to [email protected] from the email associated with your account, telling us what you want deleted (your whole workspace, only your own personal data, or a specific connected account and its data). This is the route to use if you cannot sign in, if you are not the workspace owner, or if you are the owner of a social account that one of our customers connected.
To protect your data, we verify the identity of the requester before we act on an emailed request. The two in-app routes are already authenticated, so they act at once.
3. Revoking access at the platform
Disconnecting an account here always erases the credentials we hold for it. Whether we can also revoke your authorization at the platform depends on the platform: TikTok, YouTube, X, Pinterest, and Bluesky expose a revocation endpoint and we call it; Meta (Facebook, Instagram, Threads), LinkedIn, and Telegram do not offer us one, so for those the authorization is withdrawn from the platform’s own settings rather than by us. For YouTube there is one further condition: a Google authorization is shared by every channel you connected under the same Google sign-in, so we do not revoke it while another of those channels is still connected — that would disconnect channels you never touched.
You can revoke SkedCast’s access yourself at any time from the platform’s own settings, and for the cases above that is the route that always works. For Google/YouTube, visit myaccount.google.com/permissions and remove SkedCast. Most other platforms offer a “connected apps” or “authorized apps” setting where you can revoke access. Revoking there stops us being able to act on that account at once.
Revoking at the platform does not by itself erase what we already stored: we learn about it only when our next call fails, and we then mark the connection as needing re-authorization. To have the stored data erased, use one of the three routes in §2 — disconnect the account, close your workspace, or email us — and the timelines in §4 then apply.
4. Deletion timelines
We acknowledge deletion requests promptly and complete verified requests within 30 days overall. Two things happen sooner than that, and the distinction matters:
- Immediately — when you disconnect an account or close a workspace in-app, the stored OAuth tokens are erased (and revoked with the platform where §3 says we can), the connections are severed, and everything still scheduled is canceled, in one step. We stop being able to act on your accounts at that moment.
- Within 30 days — the media bytes in our object storage are erased automatically: closing a workspace marks every asset, and the storage sweep purges the masters, renditions and thumbnails on that schedule. The records themselves — your workspace, client and connected-account records, and the posts and post variants attached to them — go out of service at once and are then erased in a second step that a person carries out, which we complete inside the same 30 days. Derived copies such as encrypted backups are purged on their normal rotation shortly afterwards.
That second step is deliberately ours to run rather than a job’s: a cascading delete of an entire workspace is the most destructive thing this system can do, and it is not something we let fire unattended. Keep the reference code your closure receipt shows you — quoting it to [email protected] is how you ask us to confirm the erasure is complete, or to have it done sooner.
Handling differs per platform. What that means for each platform you can connect, and what we commit to the platforms themselves:
- Meta — Facebook, Instagram & Threads — we delete the relevant Platform Data on request, on disconnection, and when your workspace closes, through the data-deletion callback and instructions URL registered with Meta.
- Google — YouTube Data API — disconnecting the channel erases our copy of the token immediately, and we ask Google to revoke it once we can confirm no other channel under the same Google sign-in is still connected — where we cannot confirm that, we skip the revoke rather than cut off channels you never touched, and you can withdraw the grant yourself in your Google security settings. 18 months after a channel is left disconnected we automatically purge the audience and per-video figures we recorded for it. That automatic purge covers the analytics and the stored credentials only: the channel identifiers, the uploads you published through SkedCast, and the day-by-day history behind their charts are kept as your publishing record until you close your workspace or make a verified deletion request; erasing them is then a manual step our team completes within 30 days, not one the purge above reaches. Revoking SkedCast in your Google security settings stops our access immediately, but it does not by itself erase what we already stored: disconnect the channel, close the workspace, or email us to have it removed.
- X (Twitter) — the token is erased when you disconnect the account or when your workspace closes, and because X offers a revocation endpoint we ask X to invalidate it as well; the posts you composed here go out of service the moment your workspace closes, and erasing the stored records themselves is a manual step our team completes within 30 days of that closure or of a verified deletion request — no job erases them for you. SkedCast has no per-post delete control: you can cancel a post before it goes out, and removing one we have already stored is a request you make to us. We do read X on a schedule — we read the public counters of your recent posts daily — so it does notice when a post you published through SkedCast is no longer there, but noticing is all it does: we stamp that post as gone and keep the figures we last recorded as its final ones. Taking a post down on X therefore does not by itself erase our copy; tell us and we will remove it.
- TikTok — disconnecting the account erases our copy of the token immediately, and closing your workspace erases the tokens for every connected account at once; the creator identifier stays attached to the record of what we published for you, and that record goes out of service the moment your workspace closes — erasing it, and the rest of the TikTok Platform Data we hold, is a manual step our team completes within 30 days of the closure or of a verified deletion request, not one a job performs.
- LinkedIn — the stored credential is erased immediately when you disconnect the account or close your workspace, and the member or organization identifier stays attached to the record of what we published for you — erasing that record is a manual step our team completes within 30 days of your workspace closing or of a verified deletion request.
- Pinterest — disconnecting the account erases our copy of the token immediately, and closing your workspace erases the tokens for every connected account at once; the business-account identifier and the boards you pinned to stay attached to the record of what we published for you, and erasing that record is a manual step our team completes within 30 days of the closure or of a verified deletion request; the audience and per-Pin figures our analytics job recorded are the only other Pinterest data we hold, and 18 months after the account is left disconnected we automatically purge the current figures — the day-by-day history behind their charts stays with the publish record and is erased by the same manual step.
- Bluesky (AT Protocol) — disconnecting the account erases our copy of the credential immediately, and closing your workspace erases the credentials for every connected account at once; the account identifiers — your handle and DID — stay attached to the record of what we published for you, and erasing that record is a manual step our team completes within 30 days of the closure or of a verified deletion request, not one a job performs.
- Telegram (Bot API) — disconnecting the integration erases the stored bot token immediately, and closing your workspace erases it as well; what neither erases is the bot identifier on the connection or the channel identifiers stored with each post you sent — they stay attached to the record of what we published for you, and erasing that record is a manual step our team completes within 30 days of the closure or of a verified deletion request, not one a job performs.
Some derived copies (such as encrypted backups) are purged on their normal rotation shortly after the request is fulfilled.
5. What is deleted
On a verified deletion request, we remove:
- Your account profile and the records of your workspace, clients, and connected accounts.
- Stored OAuth access and refresh tokens for the affected connected accounts (erased from our encrypted token vault, and revoked with the platform where §3 says we can).
- Platform-derived data we hold for the affected accounts — the account/channel identifiers, creator info, and any cached platform content tied to those connections.
- Your posts, post variants, scheduled targets, and the associated media stored in our object storage.
- Queued jobs and cached data tied to the deleted records.
Only the second line happens the instant you disconnect or close: the credentials are destroyed in the same transaction, and everything still queued is canceled with them. The rest — your profile, the workspace, client and connection records, the identifiers and figures attached to them, and your posts and post variants — are what §4’s second step covers: out of service immediately, erased by us within 30 days. Nothing in that step runs on its own, which is why the reference code is worth keeping.
Content that was already published to a social platform is not removed from that platform. Once access is revoked we can no longer act on your accounts, so posts that already went out must be deleted on the platform itself. Our own copies of them are erased on the timeline above.
This page is the deletion mechanism the platforms we integrate with require us to publish and to keep reachable — Meta’s requirement to give users a way to request deletion (this URL is also the Meta data-deletion callback), Google’s YouTube API data-deletion instructions, LinkedIn’s delete-on-request/closure rule, TikTok’s deletion requirements, and the route by which we delete stored X content when you ask us to. The exact commitment for each platform is in §4 above: that is what we actually do, and where a platform’s own policy asks for something faster or broader, §4 states our behaviour rather than the policy’s wording.
6. What we may retain
We may retain a limited set of data where the law requires it or to protect legitimate interests, for example:
- Billing, transaction, and tax records required by law (your billing identifiers may be anonymized where retention is not required).
- Limited security and audit logs needed to detect and investigate abuse, retained for a bounded period.
- Records we must keep to comply with a legal obligation or to establish, exercise, or defend legal claims.
- Where a referral reward was refused because it was fraudulent, the one-way fingerprints used to detect it are kept on a fraud-prevention list after the account is deleted. A list that is erased on request would let the same person start again, which is the whole reason it exists. It holds no names, no addresses and no readable email addresses.
Retained data is minimized, access-controlled, and deleted once it is no longer required.
7. Related policies & contact
Deletion is part of the broader rights described in our Privacy Policy, how we handle each platform’s data is summarized on our Platform API Data Use & Compliance page, and processing on a customer’s behalf is governed by our Data Processing Addendum. For any deletion question or to follow up on a request, contact [email protected].