Privacy Policy

Product: Posting API Operator: Asra (GitHub: Asrasarker) Effective date: 31 August 2026 Last updated: 31 August 2026

This policy applies to the Posting API service (the “Service”): a multi-tenant publishing API that other applications (“Customers”) call so their end users (“End Users”) can connect social accounts and publish content. We are not a consumer social network. We act as a processor for Customer apps: we store OAuth tokens and post metadata so we can publish on the End User’s behalf at the Customer’s request.

Replace api.variantpost.com with the production hostname before this page goes live. Contact: privacy@api.variantpost.com (and the operator email on file).

This page must be served at https://api.variantpost.com/legal/privacy with HTTP 200, no authentication, no cookies required.


1. Who we are

Posting API is operated by Asra. Until a registered legal entity is designated, the operator is the individual associated with GitHub account Asrasarker.

We provide infrastructure. The Customer’s product is the controller of End User relationships for that Customer’s app. We process End User data to perform the publish job the Customer (and the End User, via OAuth consent) asked us to perform.

If you are an End User of a Customer app, that Customer’s privacy policy also applies. This policy covers our processing as the posting pipe.

2. What the Service does

Customers send API requests (create media, create posts, connect accounts). End Users complete a white-label OAuth Connect flow for a network. We vault tokens, transcode media when needed, and deliver posts to the network the End User authorized.

We do not sell a public social feed. We do not return tokens to Customers.

3. Networks we connect to

v1 networks we may process tokens and content for:

We only access a network after the End User grants OAuth (or equivalent) permission on that network’s consent screen.

4. Information we collect

4.1 From Customers (tenants)

4.2 From End Users, via Customer apps and OAuth

4.3 Automatically

We do not scrape social graphs. We do not use End User content to train general-purpose AI models.

5. How we use information

We use network APIs only to provide or improve the publishing functionality the End User consented to.

6. Google / YouTube user data

When an End User connects YouTube, we request only:

We access, store, and use YouTube / Google user data solely to upload on the End User’s behalf, poll publish status, and display connection state to the Customer. We do not use Google user data for advertising, credit decisions, or unrelated profiling. We do not sell Google user data. We do not allow independent use of Google user data by other parties except (a) the Customer that initiated the Connect, as needed to show delivery status, and (b) Google/YouTube as the platform.

End Users can revoke Google access at any time at https://security.google.com/settings/security/permissions When Google reports the token as revoked or refresh fails, we delete stored YouTube tokens and associated Google/YouTube profile identifiers for that Connection and mark the Connection needs_reconnect or revoked.

This use is intended to comply with the Google API Services User Data Policy, including Limited Use, and the YouTube API Services Developer Policies.

7. Meta (Instagram, Facebook Pages, Threads)

We use Instagram API with Instagram Login, Facebook Pages APIs, and the Threads API as a Tech Provider: we process business/creator assets owned by other businesses because Customers ask us to publish for their End Users.

Meta permissions we request (v1) are limited to publishing and the listing of destinations:

We do not request messaging or Human Agent for v1.

8. Legal bases (where GDPR / UK GDPR / similar apply)

9. Sharing

We share data with:

We do not sell personal information. We do not share End User content with data brokers.

10. Storage, security, retention

Default targets (we may shorten; we will not silently extend without an update to this policy):

DataAfter disconnect / deletion request
OAuth tokens, refresh tokensDeleted immediately (async job; typically minutes)
Connection row + profile idsDeleted or irreversibly anonymized
Media uploaded for that End User in that tenantDeleted (original + renditions)
Delivery logsRetained up to 90 days for abuse/billing, then PII stripped; residual logs without identifiers may remain

Sandbox (sk_test_) data is isolated from live network APIs and may be wiped on a shorter cycle.

11. How to request deletion

You can have us delete tokens and stored profile/media data in any of these ways. Say this out loud in the App Review screencast.

A. In-product (End User via Customer)

The Customer calls DELETE /v1/connections/:id (revokes remote token where the network supports it, wipes our tokens) or POST /v1/end-users/{end_user_id}/delete (all connections, tokens, and media for that End User in that tenant).

B. Email

Email privacy@api.variantpost.com from a contact we can reasonably match to the tenant or to a network user id. Include the network, the account handle if known, and the Customer app name. We will complete deletion or explain a lawful delay.

C. Meta — Apps and Websites → Send Request

Facebook / Instagram / Threads users can request deletion without emailing us:

  1. Open https://www.facebook.com/settings?tab=applications (Settings & Privacy → Settings → Apps and Websites)
  2. Remove our app
  3. Open View Removed Apps and Websites
  4. Click View next to the app
  5. Click Send Request

Meta then POSTs a signed request to https://api.variantpost.com/legal/meta/data-deletion. We verify the signature (Meta app secret and Instagram App Secret), enqueue deletion of tokens, connections, and media we hold for that user across tenants, and immediately return JSON:

{"url":"https://api.variantpost.com/legal/meta/data-deletion/status/<code>","confirmation_code":"<code>"}

The status page (pending | complete | failed) is public, human-readable, and requires no login.

If a user only deauthorizes (removes the app without Send Request), Meta POSTs https://api.variantpost.com/legal/meta/deauthorize. We mark matching connections revoked, wipe tokens, and emit connection.disconnected with reason=remote_deauthorize. We do not wait for the user.

D. Other networks

Revoke the app in that network’s account settings (Google permissions page in §6; equivalent X / LinkedIn / TikTok / etc. authorized-apps screens). We drop tokens when refresh fails or when the Customer disconnects.

E. Export

The Customer may call GET /v1/end-users/{end_user_id}/export for a machine-readable copy of connection and post metadata we hold for that End User in that tenant (tokens are never exported).

12. Children

The Service is for Customer businesses and creators. We do not knowingly collect data from children under 16 (or a higher age required in the End User’s country). If we learn we have, we delete it.

13. International transfers

Infrastructure may process data in the United States and other countries where our processors operate. Where required, we use appropriate transfer mechanisms (for example Standard Contractual Clauses) with processors.

14. Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object, port, or withdraw consent. End Users should usually start with the Customer app; we will assist the Customer and will also honour §11 requests made to us directly. You may complain to a supervisory authority.

California / similar: we do not sell or share personal information as those statutes define “sell” / “share.” We do not use sensitive personal information to infer characteristics.

15. Changes

Material changes will be posted here with a new “Last updated” date. Continued use of the Service after the effective date constitutes notice to Customers; Customers are responsible for notifying their End Users when their own policies require it.

16. Contact

If a Data Protection Officer is required (for example EU establishment), that contact will be added here before we offer the Service to EU Customers as a documented establishment. Until then, use privacy@api.variantpost.com.