Privacy Policy

Last updated: September 9, 2026

SchdoSocial ("we", "our", or "us") operates a multi-platform scheduling and auto-publishing service for Facebook Pages and YouTube channels at schdosocial.tech. This Privacy Policy (version 1.2) explains what information we collect, how we use it, how long we keep it, and the choices available to you.

SchdoSocial uses YouTube API Services to connect channels, sync videos, publish content, and manage related features on your behalf. By using YouTube-related features, you also agree to be bound by the YouTube Terms of Service. Google's handling of personal data is described in the Google Privacy Policy.

Information We Collect

Account and profile data

  • Registration: name, email address, and password (stored as a bcrypt hash). If you sign in with Google or Facebook, we also store the provider user ID and profile picture URL when available.
  • Preferences: notification settings (email on publish success/failure, in-app notifications, weekly summary), onboarding status, and terms acceptance timestamp.
  • Sessions: active login sessions including device label, browser user agent, IP address, and last-used time.

Facebook data

When you connect Facebook or authorize Page access, we receive data from the Meta Graph API at your direction:

  • Facebook user ID, display name, and profile picture
  • Page IDs, Page names, Page pictures, follower counts, categories, and connection status
  • Encrypted user and Page access tokens required to publish and sync content on your behalf
  • Post content, media references, hashtags, scheduled times, publish status, Facebook post IDs, and engagement metrics (likes, comments, views) synced from or published to Facebook
  • Location tags (place ID and place name) when you add them to a post

YouTube / Google API data

When you connect a YouTube channel through Google OAuth, SchdoSocial accesses, collects, stores, and uses Authorized Data from YouTube API Services at your direction, including:

  • Google account user ID associated with the YouTube connection
  • Channel IDs, channel titles/names, channel thumbnails, custom URLs, and subscriber counts
  • Encrypted OAuth access and refresh tokens required to publish, update, sync, and manage content on your behalf
  • Video titles, descriptions, thumbnails, video IDs, privacy status, scheduled or published times, and related metadata for videos and Shorts you create, sync, or manage in SchdoSocial
  • Comment threads and related metadata when you enable features such as AI auto-replies or comment management
  • Engagement metrics synced from YouTube for videos you manage in the dashboard (for example views or other counts returned by the API)

Content you create

  • Post drafts and scheduled posts: text, image/video URLs, hashtags, post type (post, reel, image, story, video, Shorts), upload mode, and scheduling metadata
  • Scheduling models: recurring rules (daily/weekly/monthly), time windows, selected Pages or channels, default hashtags, and advanced campaign settings
  • Uploaded media: files stored on Cloudinary (or locally in development) with upload size, resource type, and pool assignment records

Usage and security data

  • Activity log entries (e.g. login, Page/channel connect, post publish, errors)
  • In-app notifications and their read status
  • IP address and user agent for authentication, rate limiting, and abuse prevention
  • Data deletion request records (confirmation code, Facebook user ID, status) when Meta initiates a deletion callback

How We Use Information

  • Authenticate you, manage sessions, and secure your account
  • Connect and manage Facebook Pages and YouTube channels at your request
  • Compose, schedule, publish, sync, update, and retry posts via the Meta Graph API and YouTube API Services
  • Store and deliver uploaded images and videos for post creation
  • Provide optional features such as AI replies on YouTube comments when you enable them
  • Send in-app and email notifications about publish results
  • Display activity history and dashboard analytics
  • Operate admin tools, enforce rate limits, and prevent abuse
  • Comply with Meta Platform requirements, YouTube API Services policies, and applicable law

We process and share API-related data with Meta and Google/YouTube only as needed to perform the actions you request (for example publishing a video or syncing comments). We do not sell your personal information. We do not use YouTube API data for advertising networks or unrelated profiling.

Legal Basis and Consent

We process your data to perform the service you request (scheduling and publishing), based on your account registration, Facebook and/or Google/YouTube authorization, and acceptance of our Terms of Service. You may withdraw Facebook or YouTube access at any time through the platform settings described below or through SchdoSocial.

Cookies and Device Information

SchdoSocial stores, accesses, or collects information on or from your device as needed to run the service, including:

  • HttpOnly authentication cookies and short-lived access tokens to keep you signed in securely
  • Browser user agent and IP address for session security, rate limiting, and abuse prevention
  • Local preferences such as locale or UI state when stored in your browser

We do not use third-party advertising cookies. If you clear cookies or revoke sessions, you may need to sign in again.

How We Store and Protect Information

  • Application data is stored in MongoDB
  • Facebook and YouTube/Google OAuth access tokens (and YouTube refresh tokens) are encrypted at rest using AES-256-GCM
  • Passwords are hashed with bcrypt and never stored in plain text
  • Authentication uses HttpOnly cookies and short-lived access tokens
  • API requests are protected with rate limiting, Helmet security headers, and CORS

Third-Party Services

  • Meta (Facebook):Page management and publishing via the Graph API. Meta's policies govern data on their platform.
  • Google / YouTube: Google OAuth sign-in (optional) and YouTube API Services for channel connection, publishing, syncing, and related features. See the Google Privacy Policy and YouTube Terms of Service.
  • Cloudinary: media hosting for images and videos used in posts.
  • SMTP email provider: transactional emails (password reset, publish notifications when enabled).
  • MongoDB Atlas: database hosting in production deployments.

SchdoSocial does not allow unrelated third parties to serve advertisements inside the product. Third parties listed above process data only to provide the infrastructure or platform features you use.

Data Retention

We retain your data while your account is active and as needed to provide the service. Session tokens expire automatically. When you disconnect Facebook Pages or YouTube channels, delete platform data, remove the app from Facebook or revoke Google access, or delete your account, we remove the associated records from our systems as described on our Data Deletion page.

Content already published on Facebook or YouTube remains on those platforms and is controlled by Meta or Google/YouTube. Some uploaded media metadata may persist in shared Cloudinary pools until released through post deletion or administrative maintenance.

Your Rights and Choices

  • Disconnect individual Facebook Pages or YouTube channels from Dashboard > Pages
  • Delete Facebook-related data from Dashboard > Settings > Privacy > Delete Facebook Data
  • Delete YouTube-related data from Dashboard > Settings > Privacy > Delete YouTube Data
  • Remove SchdoSocial from your Facebook account - Meta sends an automated deletion callback to our servers
  • In addition to SchdoSocial's deletion tools, revoke SchdoSocial's access to your Google/YouTube data at any time via the Google security settings page. After revocation, we delete stored YouTube/Google Authorized Data associated with that consent as soon as reasonably possible.
  • Check Meta deletion status on the Data Deletion page using your confirmation code
  • Permanently delete your entire SchdoSocial account from Dashboard > Settings > Privacy > Delete Account
  • Manage notification preferences in Settings > Notifications
  • Revoke active sessions in Settings > Security

Children

SchdoSocial is not intended for users under 18 (or the age of majority in your jurisdiction). We do not knowingly collect data from children.

International Users

Your data may be processed in countries where our hosting providers operate. By using SchdoSocial, you consent to this processing for service delivery.

Changes to This Policy

We may update this Privacy Policy. Material changes will be reflected by updating the version and date at the top of this page. Continued use after changes constitutes acceptance. If we begin accessing or using YouTube API Data in ways not covered by the policy you accepted, we will ask you to re-accept an updated policy.

Contact

For privacy questions, complaints about our privacy practices, or data requests (including YouTube/Google Authorized Data), email schdosocial@gmail.com or use the support channel listed in your SchdoSocial deployment.