Social Publisher

Privacy Policy

Last updated: 16 August 2026

Social Publisher is a self-hosted tool that publishes posts to social media accounts. It is operated by Matt Miller for Eternal Morphs. This policy explains what it stores, why it stores it, and how to have it removed.

What is collected

DataWhyKept for
Access tokens and app passwords for connected social accounts These are the only way to publish on your behalf. Without them the tool cannot work. Until you disconnect the account or ask for deletion
Your account handle and platform user ID To show which account a post will go to, and to address the right account when publishing. Until you disconnect the account
Post content you create — text, images, video, scheduling times To publish it, and to show you what is queued. Until published, then removed from the queue
Publishing results — success or failure, error messages, the platform's post ID So you can see whether a post actually went out, and diagnose it if it did not. Until deleted on request

What is not collected

Where it is stored

Data is stored on a private server operated by Matt Miller, hosted in Germany. Access tokens are stored in files readable only by the account that runs the tool. Nothing is stored on a third-party analytics or marketing service.

Who it is shared with

Only the social platform you asked to publish to. When you publish to Instagram, the post goes to Instagram; that is the whole of the sharing. No data is passed to any other company.

YouTube API Services

Social Publisher uses YouTube API Services to upload videos to YouTube channels you have authorised.

Meta platforms (Facebook, Instagram, Threads)

Publishing to Facebook Pages and Instagram uses Meta's Graph API. You can review and remove this application's access at any time in your Facebook Business Integrations settings. Removing it stops all future publishing immediately.

TikTok

Publishing to TikTok uses the TikTok Content Posting API. You can disconnect the application from your TikTok account in TikTok's app under Settings → Security & permissions → Manage app permissions.

How to delete your data

Two ways, both of which work:

Revoking access at the platform (using the links above) stops the tool from publishing straight away, but you should still ask for deletion if you want the stored records removed as well.

Your rights

You can ask what data is held about you, ask for a copy of it, ask for it to be corrected, or ask for it to be deleted. Email the address above. There is no form and no account required — just ask.

Security

Access tokens are stored with filesystem permissions restricting them to the account running the tool, on a server with automatic security updates and a firewall limiting access to the ports required for publishing. No system is perfectly secure, and this policy does not claim otherwise.

Children

This tool is not directed at children and is not intended for use by anyone under 13.

Changes to this policy

If this policy changes, the date at the top of the page changes with it. If a change materially affects data already stored, anyone with a connected account will be told directly before it takes effect.

Contact

Matt Miller — matt@eternalmorphs.com