Privacy Policy

Last updated: June 26, 2026

SchdoSocial ("we", "our", or "us") operates a Facebook post scheduling and auto-publishing platform at schdosocial.tech. This Privacy Policy (version 1.1) explains what information we collect, how we use it, how long we keep it, and the choices available to you.

Information We Collect

Account and profile data

  • Registration: name, email address, and password (stored as a bcrypt hash). If you sign in with Google or Facebook, we also store the provider user ID and profile picture URL when available.
  • Preferences: notification settings (email on publish success/failure, in-app notifications, weekly summary), onboarding status, and terms acceptance timestamp.
  • Sessions: active login sessions including device label, browser user agent, IP address, and last-used time.

Facebook data

When you connect Facebook or authorize Page access, we receive data from the Meta Graph API at your direction:

  • Facebook user ID, display name, and profile picture
  • Page IDs, Page names, Page pictures, follower counts, categories, and connection status
  • Encrypted user and Page access tokens required to publish and sync content on your behalf
  • Post content, media references, hashtags, scheduled times, publish status, Facebook post IDs, and engagement metrics (likes, comments, views) synced from or published to Facebook
  • Location tags (place ID and place name) when you add them to a post

Content you create

  • Post drafts and scheduled posts: text, image/video URLs, hashtags, post type (post, reel, image, story), upload mode, and scheduling metadata
  • Scheduling models: recurring rules (daily/weekly/monthly), time windows, selected Pages, default hashtags, and advanced campaign settings
  • Uploaded media: files stored on Cloudinary (or locally in development) with upload size, resource type, and pool assignment records

Usage and security data

  • Activity log entries (e.g. login, Page connect, post publish, errors)
  • In-app notifications and their read status
  • IP address and user agent for authentication, rate limiting, and abuse prevention
  • Data deletion request records (confirmation code, Facebook user ID, status) when Meta initiates a deletion callback

How We Use Information

  • Authenticate you, manage sessions, and secure your account
  • Connect and manage Facebook Pages at your request
  • Compose, schedule, publish, sync, and retry posts via the Meta Graph API
  • Store and deliver uploaded images and videos for post creation
  • Send in-app and email notifications about publish results
  • Display activity history and dashboard analytics
  • Operate admin tools, enforce rate limits, and prevent abuse
  • Comply with Meta Platform requirements and applicable law

Legal Basis and Consent

We process your data to perform the service you request (scheduling and publishing), based on your account registration, Facebook authorization, and acceptance of our Terms of Service. You may withdraw Facebook access at any time through Facebook settings or SchdoSocial.

How We Store and Protect Information

  • Application data is stored in MongoDB
  • Facebook access tokens are encrypted at rest using AES-256-GCM
  • Passwords are hashed with bcrypt and never stored in plain text
  • Authentication uses HttpOnly cookies and short-lived access tokens
  • API requests are protected with rate limiting, Helmet security headers, and CORS

We do not sell your personal information.

Third-Party Services

  • Meta (Facebook):Page management and publishing via the Graph API. Meta's policies govern data on their platform.
  • Google: optional OAuth sign-in if you choose that method.
  • Cloudinary: media hosting for images and videos used in posts.
  • SMTP email provider: transactional emails (password reset, publish notifications when enabled).
  • MongoDB Atlas: database hosting in production deployments.

Data Retention

We retain your data while your account is active and as needed to provide the service. Session tokens expire automatically. When you disconnect Facebook Pages, delete Facebook data, remove the app from Facebook, or delete your account, we remove the associated records from our systems as described on our Data Deletion page.

Content already published on Facebook remains on Facebook and is controlled by Meta. Some uploaded media metadata may persist in shared Cloudinary pools until released through post deletion or administrative maintenance.

Your Rights and Choices

  • Disconnect individual Facebook Pages from Dashboard > Pages
  • Delete Facebook-related data from Dashboard > Settings > Privacy > Delete Facebook Data
  • Remove SchdoSocial from your Facebook account — Meta sends an automated deletion callback to our servers
  • Check Meta deletion status on the Data Deletion page using your confirmation code
  • Permanently delete your entire SchdoSocial account from Dashboard > Settings > Privacy > Delete Account
  • Manage notification preferences in Settings > Notifications
  • Revoke active sessions in Settings > Security

Children

SchdoSocial is not intended for users under 18 (or the age of majority in your jurisdiction). We do not knowingly collect data from children.

International Users

Your data may be processed in countries where our hosting providers operate. By using SchdoSocial, you consent to this processing for service delivery.

Changes to This Policy

We may update this Privacy Policy. Material changes will be reflected by updating the version and date at the top of this page. Continued use after changes constitutes acceptance.

Contact

For privacy questions or data requests, email schdosocial@gmail.com or use the support channel listed in your SchdoSocial deployment.