Privacy Policy
Last updated: 27 September 2026
At a glance
- The site only ever reads your own posts at your request on the platforms you connect, and publish what you schedule. We never read notifications, mentions, or direct messages — and for most platforms it isn't even technically possible, because we don't request that permission.
- All our infrastructure — application servers, file storage, email delivery, and logging — runs on Scaleway in Paris, France. Nothing is hosted outside the EU.
- We use one strictly-necessary session cookie to keep you logged in, and a standard security cookie to protect forms from forgery. No advertising or analytics cookies, no third-party trackers.
- Your linked-account tokens are encrypted at rest (AES-256-GCM), not stored in plain text.
Who is responsible for your data
subPOSTMASTR is operated by Unique Code and Data Ltd. ("we", "us"), of Unique Code and Data Ltd., Grosvenor House, 3 Chapel Street, Congleton, Cheshire, CW12 4AB. For anything in this policy, or to exercise any of the rights below, contact us at info@uniquecodeanddata.co.uk.
What we collect
| Data | Why we have it |
|---|---|
| Account details — email address, display name, password (hashed, never stored in plain text) | To create and secure your account |
| Post content and media you create or upload | To schedule and publish it on your behalf |
| Linked-account credentials (OAuth access tokens, or an app password for Bluesky) and your platform username | To publish to the platforms you connect — see the next section for exactly what this does and doesn't allow us to see |
| Your own past public posts, imported from a platform you connect | Optional history feature, so you can browse or reuse past posts |
| Billing / usage data — credit balance, subscription plan, usage counts | To run the credit and subscription system |
| Application logs (requests, errors, and — via our reverse proxy — IP addresses) | To operate, secure, and debug the service. Kept briefly; see Retention below |
What we access on your linked accounts
When you connect a social account, the permission you approve is scoped as narrowly as each platform allows, and matches exactly what subPOSTMASTR's code does — nothing more:
| Platform | Permission requested | What we actually do with it |
|---|---|---|
| Mastodon | read:accounts read:statuses write:statuses write:media |
Read your profile and your own public posts; publish new posts and media |
| Bluesky | App password (you generate and control this in your Bluesky settings) | Read your own posts; publish new posts and images |
pages_show_list, pages_manage_posts, pages_read_engagement, business_management |
Post to a Page you manage. We never request the Messenger permission, so Page/Messenger DMs are not accessible to us | |
instagram_business_basic, instagram_business_content_publish |
Read basic profile info; publish posts | |
| Threads | threads_basic, threads_content_publish |
Read basic profile info; publish posts |
We never request permission to read direct messages, notifications, or anyone else's content, on any platform. Each platform is also its own data controller for the account you connect there — their own privacy policy governs how they handle your data on their service.
Cookies
| Cookie | Purpose | Type | Duration |
|---|---|---|---|
.subPOSTMASTR.Session |
Keeps you signed in and remembers your session state | Strictly necessary | Up to 24 hours of inactivity |
.AspNetCore.Antiforgery.* |
Protects forms (login, posting, settings) against cross-site request forgery | Strictly necessary | Session |
Both cookies are essential to the service working at all, so under UK/EU cookie law we don't need your consent to set them — this notice is enough. We don't use any advertising, analytics, or third-party tracking cookies. If that changes in future, this policy and our cookie practice will change with it, and we'll ask for consent where the law requires it.
Where your data lives — sovereign European hosting
Every part of subPOSTMASTR's infrastructure runs on Scaleway,
a French cloud provider, in their Paris (fr-par) region:
- Application servers and database — Scaleway, Paris
- Uploaded media (images/video) — Scaleway Object Storage, Paris
- Outbound email (password resets, notifications) — Scaleway Transactional Email, Paris
- Operational logs — Scaleway Cockpit (Grafana-based observability), Paris
We don't use any US hyperscaler (AWS, Google Cloud, Microsoft Azure) or route your data through one. Your data doesn't leave the EU as part of running this service, and we don't need to rely on cross-border transfer mechanisms (SCCs, adequacy decisions, etc.) for our own infrastructure. The one exception is inherent to the feature itself: if you choose to connect a social platform (e.g. a Mastodon instance, or Facebook/Instagram/Threads), publishing to it necessarily sends your post to that platform's own servers, wherever they are — that transfer is a result of your own choice to connect and post there, governed by that platform's terms.
How long we keep things
- Posts and media — kept for the retention period you choose in Settings (7 days to 12 months), then deleted automatically. You can also delete any post immediately yourself.
- Linked-account tokens — kept until you disconnect the account, at which point they're deleted.
- Operational logs — kept for a short period (around 7 days) purely for debugging and security monitoring, then aged out.
- API key audit logs — the record of requests made with your API keys (endpoint, timestamp, IP address), shown to you under API Keys, is kept for 90 days then purged automatically.
- Account data — kept for as long as your account is active. You can request deletion at any time from Settings; we permanently erase your account and all associated data (posts, media, connected-platform tokens) within 30 days of that request, and you can cancel it any time before then. You can also email info@uniquecodeanddata.co.uk if you'd rather ask us directly.
Your rights
Under UK GDPR and (where it applies to you) EU GDPR, you have the right to:
- Access the personal data we hold about you
- Have inaccurate data corrected
- Have your data deleted ("right to be forgotten")
- Object to or restrict certain processing
- Receive your data in a portable format
- Complain to your national data protection regulator (in the UK, the ICO) if you think we've got something wrong
You can request erasure of your account directly from Settings — see Account data above. For anything else on this list, email info@uniquecodeanddata.co.uk; we currently handle those requests manually rather than through self-service tooling, but we'll respond within the timeframes the law requires.
Security
- Linked-account tokens and platform app secrets are encrypted at rest using AES-256-GCM.
- All traffic to the site is encrypted in transit (HTTPS/TLS), enforced via HSTS.
- Passwords are hashed, never stored in plain text.
- Platform permissions are requested as narrowly as each platform allows — see the table above.
Changes to this policy
If we change what we collect or how we use it, we'll update this page and change the "last updated" date at the top. For material changes, we'll email you.
Contact
Questions about this policy or your data: info@uniquecodeanddata.co.uk.