deploy.social
Last updated: September 16, 2026

Privacy Policy

deploy.social is a tool for publishing short-form video to multiple platforms from one upload. This page explains what information we handle, why, and what control you have over it. No legalese — if anything here is unclear, email hello@deploy.social and a human will explain it.

The short version

We store your account, your videos, and encrypted credentials for the platform accounts you connect — because that’s literally what the product does. We don’t sell your data, we don’t run ads, we don’t mine your content, and we don’t use it to train AI. When you delete something, it’s deleted.

Who we are

deploy.social is operated by Deploy Social LLC, Bozeman, Montana, USA. Contact: hello@deploy.social.

What we collect and why

Google user data (YouTube)

deploy.social uses YouTube API Services to provide every YouTube feature in the app — connecting your channel, uploading your videos to it, and checking their processing status. This section explains exactly what that involves.

If you connect a YouTube channel, we request exactly two Google OAuth scopes: youtube.upload, which lets us upload videos to your channel and set their title, description, tags, and visibility; and youtube.readonly, which lets us read your channel identity (name, ID, avatar) so we can show you which channel you connected, and check a video’s processing status after we upload it. That is the whole list. We don’t request permission to edit, delete, or comment on anything.

How we use, process, and share YouTube data

Deleting stored YouTube data and revoking our access

Your Google tokens are encrypted at rest and are never shared with anyone except Google itself when we make API calls on your behalf. Google’s own handling of your data is governed by the Google Privacy Policy. deploy.social’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Other platforms (Meta, TikTok, Bluesky, X)

The same principle applies to every platform you connect: we access only what the publishing flow needs (your account identity, the ability to upload and publish, and post status), we use it only when you trigger it, and the credentials are encrypted at rest. Each platform also has its own privacy policy that governs what happens to your content once it’s published there — that part is between you and them.

Who else touches your data

We run on a small set of infrastructure providers (“subprocessors”):

That’s the whole list. Nobody else gets your data. We will update this list if it changes.

How long we keep things, and how to delete them

Security

Platform credentials are encrypted at rest (AES-256-GCM envelope encryption). Everything moves over TLS. Access to production systems is limited to the operator. No system is perfect; if we ever have a breach that affects you, we’ll tell you promptly and plainly.

If you connect a destination before signing up

You can authorize an Instagram or YouTube account before you create a deploy.social account. When you do, we hold that platform’s credential — encrypted at rest, the same way every other platform credential is — together with the account’s public identity (handle, display name, avatar) so we can show you what you authorized.

It stops being usable 30 minutes after you create it, whether or not you finish signing up — after that it can no longer be claimed by anyone, including you. The record itself is then erased by a cleanup job that runs hourly, so the deletion follows within about an hour of expiry rather than at the exact minute. If you want it gone straight away, discard it — that deletes it immediately.

It is not attached to any account or workspace until you sign in and explicitly confirm it, and it is tied to the browser you started in by a cookie we set for the same 30 minutes.

Deleting it destroys our copy of the credential. It does not remove deploy.social’s access at the platform itself — if you want that gone too, remove the app in your Instagram or Google account settings. Connecting a destination never signs you in or creates an account on its own: only a verified Google login or email link does that.

Cookies

We use session cookies to keep you signed in. If you start a connection before signing up, we also set one short-lived cookie that ties that connection to your browser; it expires after 30 minutes. That’s it — no third-party tracking cookies.

Kids

deploy.social isn’t intended for anyone under 13, and we don’t knowingly collect information from children.

Changes to this policy

If we change this policy in a way that matters, we’ll note the new date at the top and, for significant changes, email you. We won’t quietly weaken it.

Contact

hello@deploy.social — a human reads this.