Platform API Data Use & Compliance
SkedCast connects your social accounts and publishes to them on your behalf through each platform’s official API. This page consolidates, per platform, what we access, how we use it, how we comply with that platform’s developer policy, and the verbatim statements and disclosures the platforms require.
1. Our commitment across every platform
For every platform you connect, SkedCast follows the same core commitments: we act only with your authorization and through the platform’s official OAuth flow; we use the access we obtain solely to schedule and publish the content you compose, at your direction; we store OAuth tokens (never your passwords) encrypted in our token vault; we do not sell platform data, use it for advertising, or use it for surveillance; we retain it only as long as the feature needs it; and we erase it on disconnection or on a deletion request, revoking it with the platform as well wherever the platform gives us a way to (§6). See our Privacy Policy, Data Deletion page, and Security page for the full detail.
2. Google API Services — Limited Use & YouTube
SkedCast uses YouTube API Services. Where you connect a Google service (the YouTube Data API), SkedCast makes the affirmative commitment required by the Google API Services User Data Policy:
SkedCast’s use of information received from Google APIs (including the YouTube Data API) will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice, we limit our use of YouTube API data to the upload and scheduling features that are prominent in SkedCast; we do not transfer it to third parties except as that policy permits (to provide those features with your consent, for security, or to comply with law); we do not let humans read it except in the narrow cases the policy allows; we never use it to serve advertisements or to determine credit-worthiness; and we never use it to train generalized AI or ML models.
The Google Privacy Policy governs Google’s handling of your data. By using SkedCast with YouTube you also agree to the YouTube Terms of Service — By using SkedCast you agree to be bound by the YouTube Terms of Service. You can review or revokeSkedCast’s access at any time at myaccount.google.com/permissions. Disconnecting the channel erases our copy of the token immediately, and we ask Google to revoke it once we can confirm no other channel under the same Google sign-in is still connected — where we cannot confirm that, we skip the revoke rather than cut off channels you never touched, and you can withdraw the grant yourself in your Google security settings. 18 months after a channel is left disconnected we automatically purge the audience and per-video figures we recorded for it. That automatic purge covers the analytics and the stored credentials only: the channel identifiers, the uploads you published through SkedCast, and the day-by-day history behind their charts are kept as your publishing record until you close your workspace or make a verified deletion request; erasing them is then a manual step our team completes within 30 days, not one the purge above reaches. Revoking SkedCast in your Google security settings stops our access immediately, but it does not by itself erase what we already stored: disconnect the channel, close the workspace, or email us to have it removed.
3. TikTok posting disclosures
Our composer implements TikTok’s required posting experience: it calls TikTok before composing to determine eligibility, shows your creator nickname and avatar, presents a privacy selector with no default value, reflects the interaction (Comment/Duet/Stitch) settings, and surfaces the commercial-content and music-usage disclosures. We never add promotional watermarks to your content or strip attribution. The two consent statements presented in the composer before publishing are, verbatim:
By posting, you agree to TikTok’s Music Usage Confirmation.
By posting, you agree to TikTok’s Branded Content Policy and Music Usage Confirmation.
4. Per-platform compliance
For each platform we integrate with, the following sets out what we access, the purpose, how we comply with that platform’s developer policy, the retention and deletion behavior, and a link to the platform’s own developer terms.
Meta — Facebook, Instagram & Threads
- We access your Page/professional-account identifiers and the OAuth access and refresh tokens needed to publish to the Facebook Pages, Instagram, and Threads you connect.
- We use it solely to schedule and publish the content you compose to your connected Meta accounts, at your direction.
- SkedCast complies with Meta — Facebook, Instagram & Threads’s developer policy: We use Meta Platform Data only to provide the SkedCast scheduling features you authorize, we never sell it or use it for surveillance, we limit retention to what those features need, and we expose Meta’s required data-deletion mechanism.
- Tokens are held encrypted while the account is connected and are erased on disconnection or on a deletion request; you can also remove SkedCast from your Meta account settings at any time; we honor Meta’s data-deletion requirements through our data-deletion page and callback. On deletion: we delete the relevant Platform Data on request, on disconnection, and when your workspace closes, through the data-deletion callback and instructions URL registered with Meta.
Google — YouTube Data API
- We access your YouTube channel identifiers and the OAuth tokens needed to upload and schedule videos to the channel you connect.
- We use it solely to upload, schedule, and publish the videos you provide to your connected YouTube channel, at your direction.
- SkedCast complies with Google — YouTube Data API’s developer policy: SkedCast’s use of YouTube API data adheres to the Google API Services User Data Policy, including the Limited Use requirements; we only use the data for the upload/scheduling features visible in our product and never transfer or sell it for advertising or any unrelated purpose.
- Tokens are held encrypted while the channel is connected; disconnecting the channel in SkedCast erases the token immediately, and we ask Google to revoke it once we can confirm this is the last channel using that Google sign-in — for channels connected before we began recording that sign-in we cannot confirm it, so we skip the revoke rather than risk cutting off channels you never touched, and you can withdraw the grant yourself from your Google account permissions page; 18 months after a channel is left disconnected we automatically purge the audience and per-video figures we recorded for it, and a deletion request removes them sooner — apart from the day-by-day history behind their charts, which stays with the publish record and is erased with it; the channel identifiers stay attached to the record of what we published for you, and closing your workspace takes that record out of service at once — erasing it is a manual step our team completes within 30 days of the closure or of a verified deletion request, not one a job performs; if you instead revoke access from your Google account permissions page, publishing stops and we mark the channel as needing reconnection, but that alone deletes nothing here — disconnect it, or send us a deletion request, to have the stored data removed. On deletion: disconnecting the channel erases our copy of the token immediately, and we ask Google to revoke it once we can confirm no other channel under the same Google sign-in is still connected — where we cannot confirm that, we skip the revoke rather than cut off channels you never touched, and you can withdraw the grant yourself in your Google security settings. 18 months after a channel is left disconnected we automatically purge the audience and per-video figures we recorded for it. That automatic purge covers the analytics and the stored credentials only: the channel identifiers, the uploads you published through SkedCast, and the day-by-day history behind their charts are kept as your publishing record until you close your workspace or make a verified deletion request; erasing them is then a manual step our team completes within 30 days, not one the purge above reaches. Revoking SkedCast in your Google security settings stops our access immediately, but it does not by itself erase what we already stored: disconnect the channel, close the workspace, or email us to have it removed.
X (Twitter)
- We access your X account identifier and the OAuth tokens needed to post on your behalf.
- We use it solely to publish the posts you compose to your connected X account, at your direction.
- SkedCast complies with X (Twitter)’s developer policy: We act on your X account only with your express, informed consent; we store the posts you compose in SkedCast and the performance figures we record for them, and while we regularly read the public counters on your recent posts from X, it keeps only those figures — never the content of posts you did not publish through SkedCast. A daily sync stops retrieving X posts you have deleted, we erase stored X data by hand within 30 days of a verified deletion request or of your workspace closing, and we do not redistribute or sell X content or match it to off-X data.
- Tokens are held encrypted while the account is connected, and on disconnection we erase the token and ask X to invalidate it through its revocation endpoint; the only X content we hold is the posts you composed in SkedCast and the performance figures we recorded for them; a daily sync covering posts from the last 30 days marks any post you have deleted on X as removed and stops retrieving it, freezing rather than updating the figures we already hold; we keep our own record that the post was published, and delete it on request. On deletion: the token is erased when you disconnect the account or when your workspace closes, and because X offers a revocation endpoint we ask X to invalidate it as well; the posts you composed here go out of service the moment your workspace closes, and erasing the stored records themselves is a manual step our team completes within 30 days of that closure or of a verified deletion request — no job erases them for you. SkedCast has no per-post delete control: you can cancel a post before it goes out, and removing one we have already stored is a request you make to us. We do read X on a schedule — we read the public counters of your recent posts daily — so it does notice when a post you published through SkedCast is no longer there, but noticing is all it does: we stamp that post as gone and keep the figures we last recorded as its final ones. Taking a post down on X therefore does not by itself erase our copy; tell us and we will remove it.
TikTok
- We access your basic TikTok creator info and the OAuth tokens needed to post content on your behalf.
- We use it solely to publish the videos and photos you compose to your connected TikTok account, at your direction.
- SkedCast complies with TikTok’s developer policy: Our composer implements TikTok’s required posting disclosures — a non-default privacy selector, your creator nickname, the interaction toggles, and the commercial-content and Music Usage Confirmation statements — and we never strip attribution from your content or sell TikTok data.
- Tokens are held encrypted while the account is connected, and disconnecting the account erases the token immediately; the creator identifier we store stays attached to the record of what we published for you, and erasing that record is a manual step our team completes within 30 days of your workspace closing or of a verified deletion request. On deletion: disconnecting the account erases our copy of the token immediately, and closing your workspace erases the tokens for every connected account at once; the creator identifier stays attached to the record of what we published for you, and that record goes out of service the moment your workspace closes — erasing it, and the rest of the TikTok Platform Data we hold, is a manual step our team completes within 30 days of the closure or of a verified deletion request, not one a job performs.
- We access your member or organization identifier and the OAuth tokens needed to publish to your personal profile or to a Company Page you administer.
- We use it solely to publish the content you compose to your connected LinkedIn profile or Page, for your benefit and at your direction.
- SkedCast complies with LinkedIn’s developer policy: We use LinkedIn member data only to manage the profile or Page you connect — never for any other use case — we keep storage to what the feature needs, and we delete member data on request.
- We store only the member data needed to provide the posting feature, within LinkedIn’s storage limits; disconnecting erases the stored credential immediately and the cached LinkedIn figures are deleted 18 months later at the latest, apart from the day-by-day history behind their charts, which stays with the publish record and is erased with it; the member or organization identifier stays attached to the record of what we published for you, and erasing that record is a manual step our team completes within 30 days of your workspace closing or of a verified deletion request. On deletion: the stored credential is erased immediately when you disconnect the account or close your workspace, and the member or organization identifier stays attached to the record of what we published for you — erasing that record is a manual step our team completes within 30 days of your workspace closing or of a verified deletion request.
- We access your Pinterest business-account identifier and the OAuth tokens needed to create Pins and boards on your behalf.
- We use it solely to publish the Pins you compose to the boards you choose on your connected Pinterest account, at your direction.
- SkedCast complies with Pinterest’s developer policy: We follow the Pinterest Developer Guidelines: we publish only with your authorization, we do not share or sell Pinterest API data with third parties, and we delete stored access on request.
- Tokens are held encrypted while the account is connected, and disconnecting the account erases the token immediately; the business-account identifier and the board references we store stay attached to the record of what we published for you, and erasing that record is a manual step our team completes within 30 days of your workspace closing or of a verified deletion request; the only other Pinterest data we hold is the audience and per-Pin figures our analytics job records, and 18 months after the account is left disconnected we automatically purge the current figures — the day-by-day history behind their charts stays with the publish record and is erased by the same manual step. On deletion: disconnecting the account erases our copy of the token immediately, and closing your workspace erases the tokens for every connected account at once; the business-account identifier and the boards you pinned to stay attached to the record of what we published for you, and erasing that record is a manual step our team completes within 30 days of the closure or of a verified deletion request; the audience and per-Pin figures our analytics job recorded are the only other Pinterest data we hold, and 18 months after the account is left disconnected we automatically purge the current figures — the day-by-day history behind their charts stays with the publish record and is erased by the same manual step.
Bluesky (AT Protocol)
- We access your handle/DID and the per-account credential or session needed to post on your behalf.
- We use it solely to publish the posts you compose to your connected Bluesky account, at your direction.
- SkedCast complies with Bluesky (AT Protocol)’s developer policy: We follow the Bluesky Developer Guidelines: SkedCast posts only at your direction, we provide a way to delete content and data on request, and we publish monitored contact information.
- Credentials are held encrypted while the account is connected, and disconnecting the account erases the stored credential immediately; the account identifiers we store — your handle and DID — stay attached to the record of what we published for you, and erasing that record is a manual step our team completes within 30 days of your workspace closing or of a verified deletion request. On deletion: disconnecting the account erases our copy of the credential immediately, and closing your workspace erases the credentials for every connected account at once; the account identifiers — your handle and DID — stay attached to the record of what we published for you, and erasing that record is a manual step our team completes within 30 days of the closure or of a verified deletion request, not one a job performs.
Telegram (Bot API)
- We access the bot token you configure and the channel/chat identifiers needed to post where your bot is an administrator.
- We use it solely to publish the messages you compose to the Telegram channels you choose, at your direction.
- SkedCast complies with Telegram (Bot API)’s developer policy: We follow the Telegram Bot Developer Terms: we store only the data needed to operate the integration, comply with applicable privacy law, and do not misuse Telegram branding.
- The bot token is held encrypted while the integration is configured, and disconnecting it — or closing your workspace — erases the token immediately; what neither erases is the identifiers around it — the bot identifier on the connection, and the channel identifiers stored with each post you sent — which stay attached to the record of what we published for you, and erasing that record is a manual step our team completes within 30 days of your workspace closing or of a verified deletion request. On deletion: disconnecting the integration erases the stored bot token immediately, and closing your workspace erases it as well; what neither erases is the bot identifier on the connection or the channel identifiers stored with each post you sent — they stay attached to the record of what we published for you, and erasing that record is a manual step our team completes within 30 days of the closure or of a verified deletion request, not one a job performs.
5. Platform-specific retention & deletion commitments
Each platform imposes its own storage and deletion rules. What we do — and therefore what we commit to — for each is below:
- Meta — Facebook, Instagram & Threads — we delete the relevant Platform Data on request, on disconnection, and when your workspace closes, through the data-deletion callback and instructions URL registered with Meta.
- Google — YouTube Data API — disconnecting the channel erases our copy of the token immediately, and we ask Google to revoke it once we can confirm no other channel under the same Google sign-in is still connected — where we cannot confirm that, we skip the revoke rather than cut off channels you never touched, and you can withdraw the grant yourself in your Google security settings. 18 months after a channel is left disconnected we automatically purge the audience and per-video figures we recorded for it. That automatic purge covers the analytics and the stored credentials only: the channel identifiers, the uploads you published through SkedCast, and the day-by-day history behind their charts are kept as your publishing record until you close your workspace or make a verified deletion request; erasing them is then a manual step our team completes within 30 days, not one the purge above reaches. Revoking SkedCast in your Google security settings stops our access immediately, but it does not by itself erase what we already stored: disconnect the channel, close the workspace, or email us to have it removed.
- X (Twitter) — the token is erased when you disconnect the account or when your workspace closes, and because X offers a revocation endpoint we ask X to invalidate it as well; the posts you composed here go out of service the moment your workspace closes, and erasing the stored records themselves is a manual step our team completes within 30 days of that closure or of a verified deletion request — no job erases them for you. SkedCast has no per-post delete control: you can cancel a post before it goes out, and removing one we have already stored is a request you make to us. We do read X on a schedule — we read the public counters of your recent posts daily — so it does notice when a post you published through SkedCast is no longer there, but noticing is all it does: we stamp that post as gone and keep the figures we last recorded as its final ones. Taking a post down on X therefore does not by itself erase our copy; tell us and we will remove it.
- TikTok — disconnecting the account erases our copy of the token immediately, and closing your workspace erases the tokens for every connected account at once; the creator identifier stays attached to the record of what we published for you, and that record goes out of service the moment your workspace closes — erasing it, and the rest of the TikTok Platform Data we hold, is a manual step our team completes within 30 days of the closure or of a verified deletion request, not one a job performs.
- LinkedIn — the stored credential is erased immediately when you disconnect the account or close your workspace, and the member or organization identifier stays attached to the record of what we published for you — erasing that record is a manual step our team completes within 30 days of your workspace closing or of a verified deletion request.
- Pinterest — disconnecting the account erases our copy of the token immediately, and closing your workspace erases the tokens for every connected account at once; the business-account identifier and the boards you pinned to stay attached to the record of what we published for you, and erasing that record is a manual step our team completes within 30 days of the closure or of a verified deletion request; the audience and per-Pin figures our analytics job recorded are the only other Pinterest data we hold, and 18 months after the account is left disconnected we automatically purge the current figures — the day-by-day history behind their charts stays with the publish record and is erased by the same manual step.
- Bluesky (AT Protocol) — disconnecting the account erases our copy of the credential immediately, and closing your workspace erases the credentials for every connected account at once; the account identifiers — your handle and DID — stay attached to the record of what we published for you, and erasing that record is a manual step our team completes within 30 days of the closure or of a verified deletion request, not one a job performs.
- Telegram (Bot API) — disconnecting the integration erases the stored bot token immediately, and closing your workspace erases it as well; what neither erases is the bot identifier on the connection or the channel identifiers stored with each post you sent — they stay attached to the record of what we published for you, and erasing that record is a manual step our team completes within 30 days of the closure or of a verified deletion request, not one a job performs.
6. Revocation & deletion mechanism
You can disconnect any account at any time, which erases the stored tokens for that account and, where the platform offers a revocation endpoint (TikTok, YouTube, X, Pinterest, Bluesky), asks the platform to revoke them as well. The Meta family and LinkedIn expose no revocation endpoint to us; for those, remove SkedCast from the platform’s own connected-apps settings if you want the authorization itself withdrawn. You can also request deletion of your account and all platform-derived data. We complete verified deletion requests within 30 days, as described on our Data Deletion & Account Removal page — the same page we provide to the platforms as our data-deletion instructions and as the Meta data-deletion callback URL.
7. Related policies & contact
This page works together with:
- Our Privacy Policy (including “Data from the platforms you connect”).
- Our Terms of Service (the “Connected third-party platforms” section, including the YouTube binding statement).
- Our Acceptable Use Policy (per-platform compliance, rate limits, and AI-content disclosure).
- Our Data Deletion page and Security page.
For any question about how SkedCast uses platform data, contact [email protected].