Privacy Policy

Last updated: 27 September 2026

At a glance

  • The site only ever reads your own posts at your request on the platforms you connect, and publish what you schedule. We never read notifications, mentions, or direct messages — and for most platforms it isn't even technically possible, because we don't request that permission.
  • All our infrastructure — application servers, file storage, email delivery, and logging — runs on Scaleway in Paris, France. Nothing is hosted outside the EU.
  • We use one strictly-necessary session cookie to keep you logged in, and a standard security cookie to protect forms from forgery. No advertising or analytics cookies, no third-party trackers.
  • Your linked-account tokens are encrypted at rest (AES-256-GCM), not stored in plain text.

Who is responsible for your data

subPOSTMASTR is operated by Unique Code and Data Ltd. ("we", "us"), of Unique Code and Data Ltd., Grosvenor House, 3 Chapel Street, Congleton, Cheshire, CW12 4AB. For anything in this policy, or to exercise any of the rights below, contact us at info@uniquecodeanddata.co.uk.

What we collect

Data Why we have it
Account details — email address, display name, password (hashed, never stored in plain text) To create and secure your account
Post content and media you create or upload To schedule and publish it on your behalf
Linked-account credentials (OAuth access tokens, or an app password for Bluesky) and your platform username To publish to the platforms you connect — see the next section for exactly what this does and doesn't allow us to see
Your own past public posts, imported from a platform you connect Optional history feature, so you can browse or reuse past posts
Billing / usage data — credit balance, subscription plan, usage counts To run the credit and subscription system
Application logs (requests, errors, and — via our reverse proxy — IP addresses) To operate, secure, and debug the service. Kept briefly; see Retention below

What we access on your linked accounts

When you connect a social account, the permission you approve is scoped as narrowly as each platform allows, and matches exactly what subPOSTMASTR's code does — nothing more:

Platform Permission requested What we actually do with it
Mastodon read:accounts read:statuses write:statuses write:media Read your profile and your own public posts; publish new posts and media
Bluesky App password (you generate and control this in your Bluesky settings) Read your own posts; publish new posts and images
Facebook pages_show_list, pages_manage_posts, pages_read_engagement, business_management Post to a Page you manage. We never request the Messenger permission, so Page/Messenger DMs are not accessible to us
Instagram instagram_business_basic, instagram_business_content_publish Read basic profile info; publish posts
Threads threads_basic, threads_content_publish Read basic profile info; publish posts

We never request permission to read direct messages, notifications, or anyone else's content, on any platform. Each platform is also its own data controller for the account you connect there — their own privacy policy governs how they handle your data on their service.

Cookies

Cookie Purpose Type Duration
.subPOSTMASTR.Session Keeps you signed in and remembers your session state Strictly necessary Up to 24 hours of inactivity
.AspNetCore.Antiforgery.* Protects forms (login, posting, settings) against cross-site request forgery Strictly necessary Session

Both cookies are essential to the service working at all, so under UK/EU cookie law we don't need your consent to set them — this notice is enough. We don't use any advertising, analytics, or third-party tracking cookies. If that changes in future, this policy and our cookie practice will change with it, and we'll ask for consent where the law requires it.

Where your data lives — sovereign European hosting

Every part of subPOSTMASTR's infrastructure runs on Scaleway, a French cloud provider, in their Paris (fr-par) region:

We don't use any US hyperscaler (AWS, Google Cloud, Microsoft Azure) or route your data through one. Your data doesn't leave the EU as part of running this service, and we don't need to rely on cross-border transfer mechanisms (SCCs, adequacy decisions, etc.) for our own infrastructure. The one exception is inherent to the feature itself: if you choose to connect a social platform (e.g. a Mastodon instance, or Facebook/Instagram/Threads), publishing to it necessarily sends your post to that platform's own servers, wherever they are — that transfer is a result of your own choice to connect and post there, governed by that platform's terms.

How long we keep things

Your rights

Under UK GDPR and (where it applies to you) EU GDPR, you have the right to:

You can request erasure of your account directly from Settings — see Account data above. For anything else on this list, email info@uniquecodeanddata.co.uk; we currently handle those requests manually rather than through self-service tooling, but we'll respond within the timeframes the law requires.

Security

Changes to this policy

If we change what we collect or how we use it, we'll update this page and change the "last updated" date at the top. For material changes, we'll email you.

Contact

Questions about this policy or your data: info@uniquecodeanddata.co.uk.