Privacy Policy
1. Who this covers
This policy applies to the private, self-hosted installation of Postiz
(an open-source social media scheduler) running at postiz.theredbutton.boo, operated by the
administrator of the theredbutton.boo domain.
This is not a public product. It is a private tool used by a small, named group of people to schedule posts to social media accounts that they themselves administer. Accounts are created by invitation only; public registration is disabled.
2. What we collect
Account information
- Your name and email address
- A cryptographic hash of your password — we never store the password itself
- Which workspace you belong to, and your role in it
Information from Meta (Facebook and Instagram)
If you connect a Facebook Page or Instagram Business account, we receive and store, via Facebook Login and the Meta Graph API:
- Your Facebook user ID and display name
- The list of Facebook Pages you administer, and each Page’s ID, name and profile picture
- Page access tokens, which allow the service to publish on behalf of the connected Page
- Instagram Business account IDs linked to those Pages, where connected
- Engagement and insight metrics for content published through this service
We request only the permissions needed to list your Pages and publish to them:
pages_show_list, pages_manage_posts, pages_read_engagement,
pages_manage_engagement, business_management and read_insights.
We do not read your personal timeline, your friends list, your messages, or any content you have not
asked us to publish.
Content you create
- Post text, scheduling times, and any images or video you upload for publication
- Comments, drafts and settings you save within the workspace
Technical information
- A session cookie used to keep you signed in. It is strictly necessary and is not used for tracking.
- Standard server logs (IP address, browser user agent, request time and path), kept short-term for security and troubleshooting
3. What we do with it
Your data is used for one purpose: to operate the scheduling service you asked for — showing you your connected accounts, publishing your scheduled content to them, and reporting back how that content performed.
We do not sell, rent, trade or licence your data. We do not use it for advertising, audience-building, profiling, or training machine learning models. We run no third-party analytics, no advertising pixels, and no cross-site trackers. We do not share Meta Platform data with anyone beyond the infrastructure providers listed below that are strictly necessary to run the service.
4. Where your data is stored
- In a PostgreSQL database on privately owned server hardware located in Australia. This is not a shared or public cloud host.
- Backups are encrypted with GPG (AES-256) and written to storage on the same private network. They are retained for 14 days and then destroyed.
- All traffic to the service is encrypted in transit with TLS.
- Access to the service is restricted at the network edge, and administrative access to the underlying server is limited to the operator.
5. Who else touches the data
Only these providers, and only to the extent required to deliver the service:
- Meta Platforms — the Graph API, which is the destination for content you publish and the source of the Page data described above.
- Cloudflare — DNS, TLS termination, and the authenticated tunnel through which the service is reached. Cloudflare processes traffic in transit.
- Resend — outbound transactional email only (account activation, invitations, password resets). No marketing email is sent.
Any other social network you choose to connect will receive the content you publish to it, under its own privacy policy.
6. How long we keep it
- Access tokens — for as long as the channel stays connected. Disconnecting a channel deletes its stored tokens immediately.
- Posts and media — until you delete them, or until your account is deleted.
- Account records — until you ask us to delete the account.
- Encrypted backups — deleted data can persist in backups for up to 14 days, after which those backups are destroyed on a rolling schedule.
- Server logs — short-term only, for security and diagnostics.
7. Your choices and rights
You can disconnect any social account at any time from within the application, which removes the stored tokens for it. You can also ask us to export or permanently delete everything we hold about you. Full instructions are on the data deletion page.
You may revoke this application’s access directly from Meta at any time, independently of us: Facebook → Settings & Privacy → Settings → Apps and Websites.
8. Security
We use TLS for all traffic, hash passwords rather than storing them, encrypt backups at rest, keep the service behind authenticated access at the network edge, and limit administrative access to the operator. No system is perfectly secure, but this instance is not publicly registerable and holds only the data described above.
9. Children
This service is not directed to children and is not intended for use by anyone under 18. We do not knowingly collect information from children.
10. Changes to this policy
If this policy changes, the updated version will be posted at this address with a new effective date. Material changes to how Meta Platform data is handled will also be communicated to workspace members directly.
11. Contact
Questions, access requests, or deletion requests: admin@theredbutton.boo