Privacy Policy
deploy.social is a tool for publishing short-form video to multiple platforms from one upload. This page explains what information we handle, why, and what control you have over it. No legalese — if anything here is unclear, email hello@deploy.social and a human will explain it.
The short version
We store your account, your videos, and encrypted credentials for the platform accounts you connect — because that’s literally what the product does. We don’t sell your data, we don’t run ads, we don’t mine your content, and we don’t use it to train AI. When you delete something, it’s deleted.
Who we are
deploy.social is operated by Deploy Social LLC, Bozeman, Montana, USA. Contact: hello@deploy.social.
What we collect and why
- Your account. Email address, display name, and — if you use password sign-in — a hashed password (we can’t read it). If you sign in with Google, we get your name, email, and avatar from Google. This is how you log in and how we reach you.
- Your content. The videos, thumbnails, captions, titles, tags, and schedules you create in the app. We store them so we can transcode your video into each platform’s required format and publish it where you tell us to.
- Connected platform credentials. When you connect a platform account (YouTube, Bluesky, and others as we add them), we store the credential that platform gives us — an OAuth token or app password. These are encrypted at rest with AES-256-GCM and are used for exactly one thing: doing what you asked (uploading and publishing your content, and checking its status).
- Notifications and preferences. Whether you want emails when a deployment finishes or fails, plus in-app notification history.
- Operational basics. Standard server logs (timestamps, requests, errors) so we can keep the service working and debug problems. No advertising trackers, no analytics profiles, no fingerprinting.
Google user data (YouTube)
deploy.social uses YouTube API Services to provide every YouTube feature in the app — connecting your channel, uploading your videos to it, and checking their processing status. This section explains exactly what that involves.
If you connect a YouTube channel, we request exactly two Google OAuth scopes: youtube.upload, which lets us upload videos to your channel and set their title, description, tags, and visibility; and youtube.readonly, which lets us read your channel identity (name, ID, avatar) so we can show you which channel you connected, and check a video’s processing status after we upload it. That is the whole list. We don’t request permission to edit, delete, or comment on anything.
How we use, process, and share YouTube data
- What we store: your encrypted OAuth token, your channel’s identity (name, ID, avatar), and the ID and processing status of each video you upload through us. We store no statistics, no watch history, no subscriber lists, and nothing about videos you didn’t publish through deploy.social.
- How we use and process it: only to provide the features you actively trigger — showing you which channel is connected, uploading the video you asked us to publish, and telling you whether it went live. We don’t read your subscriptions, watch history, or anything beyond what the publishing flow needs.
- Internal parties: deploy.social is operated by a single operator, and production access is limited to them. There is no other internal party, no analytics team, and no advertising use.
- External parties: your YouTube data is shared with nobody except Google itself (when we make the API calls you asked for, on your behalf) and the infrastructure providers that host the service, listed under Who else touches your data. We never sell it, never share it with advertisers or data brokers, and never use it to train AI.
Deleting stored YouTube data and revoking our access
- Disconnect in the app: remove the channel on the Destinations page at any time — the stored OAuth token is destroyed immediately.
- Delete the content records: delete videos and deployments in your Library whenever you like.
- Delete everything: email hello@deploy.social and we’ll erase your stored Google user data (tokens, channel identity, video records) within 7 days.
- Revoke from Google’s side: you can also cut off deploy.social’s access at any time from your Google security settings page, without touching the app at all.
Your Google tokens are encrypted at rest and are never shared with anyone except Google itself when we make API calls on your behalf. Google’s own handling of your data is governed by the Google Privacy Policy. deploy.social’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Other platforms (Meta, TikTok, Bluesky, X)
The same principle applies to every platform you connect: we access only what the publishing flow needs (your account identity, the ability to upload and publish, and post status), we use it only when you trigger it, and the credentials are encrypted at rest. Each platform also has its own privacy policy that governs what happens to your content once it’s published there — that part is between you and them.
Who else touches your data
We run on a small set of infrastructure providers (“subprocessors”):
- Railway — hosts the application and database (USA).
- Cloudflare — DNS, and object storage (R2) where your uploaded and transcoded videos live.
- Resend — sends our transactional email (sign-in links, deployment notifications).
- The platforms you connect — Google/YouTube, Meta, TikTok, Bluesky, X — receive your content when you publish to them, because that’s the point.
That’s the whole list. Nobody else gets your data. We will update this list if it changes.
How long we keep things, and how to delete them
- Media, drafts, and deployments: delete them yourself in the Library at any time. Deleting media removes the files from storage. Deployment history for posts you actually published is kept so your records stay accurate.
- Connected accounts: disconnect any destination at any time in your account settings — the stored credential is destroyed immediately. (Publishing history to that account is preserved, minus the credentials.)
- Your whole account: email hello@deploy.social and we’ll delete it — account, media, credentials, everything — normally within 30 days.
- Meta-initiated deletion: if you remove the app from your Meta settings, Meta pings our deletion endpoint automatically and we deactivate the connection and destroy its credentials, with a confirmation page you can check.
Security
Platform credentials are encrypted at rest (AES-256-GCM envelope encryption). Everything moves over TLS. Access to production systems is limited to the operator. No system is perfect; if we ever have a breach that affects you, we’ll tell you promptly and plainly.
If you connect a destination before signing up
You can authorize an Instagram or YouTube account before you create a deploy.social account. When you do, we hold that platform’s credential — encrypted at rest, the same way every other platform credential is — together with the account’s public identity (handle, display name, avatar) so we can show you what you authorized.
It stops being usable 30 minutes after you create it, whether or not you finish signing up — after that it can no longer be claimed by anyone, including you. The record itself is then erased by a cleanup job that runs hourly, so the deletion follows within about an hour of expiry rather than at the exact minute. If you want it gone straight away, discard it — that deletes it immediately.
It is not attached to any account or workspace until you sign in and explicitly confirm it, and it is tied to the browser you started in by a cookie we set for the same 30 minutes.
Deleting it destroys our copy of the credential. It does not remove deploy.social’s access at the platform itself — if you want that gone too, remove the app in your Instagram or Google account settings. Connecting a destination never signs you in or creates an account on its own: only a verified Google login or email link does that.
Cookies
We use session cookies to keep you signed in. If you start a connection before signing up, we also set one short-lived cookie that ties that connection to your browser; it expires after 30 minutes. That’s it — no third-party tracking cookies.
Kids
deploy.social isn’t intended for anyone under 13, and we don’t knowingly collect information from children.
Changes to this policy
If we change this policy in a way that matters, we’ll note the new date at the top and, for significant changes, email you. We won’t quietly weaken it.
Contact
hello@deploy.social — a human reads this.