Product: Posting API Operator: Asra (GitHub: Asrasarker) Effective date: 31 August 2026 Last updated: 31 August 2026
This policy applies to the Posting API service (the “Service”): a multi-tenant publishing API that other applications (“Customers”) call so their end users (“End Users”) can connect social accounts and publish content. We are not a consumer social network. We act as a processor for Customer apps: we store OAuth tokens and post metadata so we can publish on the End User’s behalf at the Customer’s request.
Replace api.variantpost.com with the production hostname before this page goes live. Contact: privacy@api.variantpost.com (and the operator email on file).
This page must be served at https://api.variantpost.com/legal/privacy with HTTP 200, no authentication, no cookies required.
Posting API is operated by Asra. Until a registered legal entity is designated, the operator is the individual associated with GitHub account Asrasarker.
We provide infrastructure. The Customer’s product is the controller of End User relationships for that Customer’s app. We process End User data to perform the publish job the Customer (and the End User, via OAuth consent) asked us to perform.
If you are an End User of a Customer app, that Customer’s privacy policy also applies. This policy covers our processing as the posting pipe.
Customers send API requests (create media, create posts, connect accounts). End Users complete a white-label OAuth Connect flow for a network. We vault tokens, transcode media when needed, and deliver posts to the network the End User authorized.
We do not sell a public social feed. We do not return tokens to Customers.
v1 networks we may process tokens and content for:
We only access a network after the End User grants OAuth (or equivalent) permission on that network’s consent screen.
end_user_id (opaque to us; we do not ask for the End User’s name or email unless a network returns it as profile data)remote_account_id, app-scoped IDs)We do not scrape social graphs. We do not use End User content to train general-purpose AI models.
Authorization: Bearer sk_live_… / sk_test_…)active / needs_reconnect / revoked / expired statedelivery.succeeded, connection.disconnected, etc.)We use network APIs only to provide or improve the publishing functionality the End User consented to.
When an End User connects YouTube, we request only:
https://www.googleapis.com/auth/youtube.upload — upload videos to the authorized channelhttps://www.googleapis.com/auth/youtube.readonly — read channel/video status needed to confirm uploadsWe access, store, and use YouTube / Google user data solely to upload on the End User’s behalf, poll publish status, and display connection state to the Customer. We do not use Google user data for advertising, credit decisions, or unrelated profiling. We do not sell Google user data. We do not allow independent use of Google user data by other parties except (a) the Customer that initiated the Connect, as needed to show delivery status, and (b) Google/YouTube as the platform.
End Users can revoke Google access at any time at https://security.google.com/settings/security/permissions When Google reports the token as revoked or refresh fails, we delete stored YouTube tokens and associated Google/YouTube profile identifiers for that Connection and mark the Connection needs_reconnect or revoked.
This use is intended to comply with the Google API Services User Data Policy, including Limited Use, and the YouTube API Services Developer Policies.
We use Instagram API with Instagram Login, Facebook Pages APIs, and the Threads API as a Tech Provider: we process business/creator assets owned by other businesses because Customers ask us to publish for their End Users.
Meta permissions we request (v1) are limited to publishing and the listing of destinations:
instagram_business_basic, instagram_business_content_publishpages_show_list, pages_read_engagement, pages_manage_posts, publish_videothreads_basic, threads_content_publishWe do not request messaging or Human Agent for v1.
We share data with:
We do not sell personal information. We do not share End User content with data brokers.
Default targets (we may shorten; we will not silently extend without an update to this policy):
| Data | After disconnect / deletion request |
|---|---|
| OAuth tokens, refresh tokens | Deleted immediately (async job; typically minutes) |
| Connection row + profile ids | Deleted or irreversibly anonymized |
| Media uploaded for that End User in that tenant | Deleted (original + renditions) |
| Delivery logs | Retained up to 90 days for abuse/billing, then PII stripped; residual logs without identifiers may remain |
Sandbox (sk_test_) data is isolated from live network APIs and may be wiped on a shorter cycle.
You can have us delete tokens and stored profile/media data in any of these ways. Say this out loud in the App Review screencast.
The Customer calls DELETE /v1/connections/:id (revokes remote token where the network supports it, wipes our tokens) or POST /v1/end-users/{end_user_id}/delete (all connections, tokens, and media for that End User in that tenant).
Email privacy@api.variantpost.com from a contact we can reasonably match to the tenant or to a network user id. Include the network, the account handle if known, and the Customer app name. We will complete deletion or explain a lawful delay.
Facebook / Instagram / Threads users can request deletion without emailing us:
Meta then POSTs a signed request to https://api.variantpost.com/legal/meta/data-deletion. We verify the signature (Meta app secret and Instagram App Secret), enqueue deletion of tokens, connections, and media we hold for that user across tenants, and immediately return JSON:
{"url":"https://api.variantpost.com/legal/meta/data-deletion/status/<code>","confirmation_code":"<code>"}
The status page (pending | complete | failed) is public, human-readable, and requires no login.
If a user only deauthorizes (removes the app without Send Request), Meta POSTs https://api.variantpost.com/legal/meta/deauthorize. We mark matching connections revoked, wipe tokens, and emit connection.disconnected with reason=remote_deauthorize. We do not wait for the user.
Revoke the app in that network’s account settings (Google permissions page in §6; equivalent X / LinkedIn / TikTok / etc. authorized-apps screens). We drop tokens when refresh fails or when the Customer disconnects.
The Customer may call GET /v1/end-users/{end_user_id}/export for a machine-readable copy of connection and post metadata we hold for that End User in that tenant (tokens are never exported).
The Service is for Customer businesses and creators. We do not knowingly collect data from children under 16 (or a higher age required in the End User’s country). If we learn we have, we delete it.
Infrastructure may process data in the United States and other countries where our processors operate. Where required, we use appropriate transfer mechanisms (for example Standard Contractual Clauses) with processors.
Depending on where you live, you may have rights to access, correct, delete, restrict, object, port, or withdraw consent. End Users should usually start with the Customer app; we will assist the Customer and will also honour §11 requests made to us directly. You may complain to a supervisory authority.
California / similar: we do not sell or share personal information as those statutes define “sell” / “share.” We do not use sensitive personal information to infer characteristics.
Material changes will be posted here with a new “Last updated” date. Continued use of the Service after the effective date constitutes notice to Customers; Customers are responsible for notifying their End Users when their own policies require it.
privacy@api.variantpost.comhttps://api.variantpost.com/legal/meta/data-deletion/status/<confirmation_code>https://api.variantpost.com/legal/termsIf a Data Protection Officer is required (for example EU establishment), that contact will be added here before we offer the Service to EU Customers as a documented establishment. Until then, use privacy@api.variantpost.com.