1.Who we are
AutoPublishing.house is a business-to-business content automation platform that helps media organizations and publishers plan, generate, review, and publish editorial and social-media content to their own websites and their own connected social accounts (the "Service").
The data controller responsible for the processing described in this policy is:
V-Tech Services s.r.o.
Registered office: Janáčkova 455-27, 680 01 Boskovice, Czech Republic
Company ID (IČO): 24091995
E-mail: [email protected]
(the "Operator", "we"). We process personal data in accordance with Regulation (EU) 2016/679 (GDPR) and Czech Act No. 110/2019 Coll., on personal data processing.
2.Scope of this policy
This policy covers:
- personal data of the Service's users (our clients' authorized staff),
- data relating to third-party accounts (YouTube channels, Instagram and Facebook accounts, X accounts, Reddit accounts, TikTok accounts, WordPress sites) that a client connects to the Service, and
- visitors of the web pages on which this policy and our Terms of Service are published.
The Service is operated for business clients under individual contracts. Where such a contract contains a data processing agreement, that agreement prevails over this policy to the extent of any conflict.
3.What data we process
3.1 Platform user accounts
- Name, business e-mail address, and role/permissions within the client organization.
- Sign-in records for passwordless (magic link) authentication: one-time token identifiers, the requesting IP address, browser user-agent, and timestamps.
3.2 Connected third-party accounts
- OAuth access and refresh tokens for accounts the client connects. Tokens are stored encrypted at rest and are never displayed back to any user.
- Basic account identifiers needed to route publications correctly: for example a YouTube channel ID and channel title, an Instagram/Facebook account or page ID, an X account handle, a Reddit username, or a TikTok account identifier.
3.3 Content and publication records
- Content created, edited, or scheduled through the Service (articles, captions, images, audio, video) and its associated metadata.
- Publication records: what was published, where, when, the platform-assigned post/video identifier, and the public permalink.
3.4 Technical logs
- Operational logs of the platform (job processing, errors, API responses) which may incidentally contain account identifiers listed above. Logs are used solely for operating, securing, and debugging the Service.
We do not collect personal data of our clients' readers, viewers, followers, or other audience members, and the Service is not designed to do so.
4.Purposes and legal bases
- Providing the Service (content generation, scheduling, publication to connected accounts, publication history) — performance of a contract (Art. 6(1)(b) GDPR).
- Security and operations (authentication records, technical logs, abuse prevention, backups) — our legitimate interest in operating a secure and reliable service (Art. 6(1)(f) GDPR).
- Legal obligations (accounting and tax records relating to the contract) — Art. 6(1)(c) GDPR.
We do not use the data described in this policy for advertising, we do not build advertising profiles, and we do not sell personal data or platform API data to anyone.
5.Third-party platform API services
The Service publishes content to third-party platforms exclusively on the client's behalf, to accounts the client has connected through each platform's official authorization (OAuth) flow. The client always retains final authority over which accounts are connected and what is published to them; connecting an account and configuring a publication schedule constitutes the client's express instruction to publish. Access can be revoked at any time as described for each platform below and in Section 10.
5.1 YouTube API Services (Google)
The Service uses YouTube API Services to upload and schedule videos (including Shorts) to YouTube channels connected by the client. By using the YouTube-related features of the Service, you are also agreeing to be bound by the YouTube Terms of Service. Google's handling of your data is described in the Google Privacy Policy.
What we access, collect, and store. When a client connects a YouTube channel, the Service accesses and stores the following API data:
- OAuth tokens for the connected channel (Google API scopes
youtube.uploadandyoutube.readonly), stored encrypted at rest on our servers in the European Union; - the channel identifier and channel title, used to verify and display which channel a publication will go to;
- identifiers and permalinks of videos uploaded by the Service on the client's behalf, together with each video's upload and privacy status, which we read solely to confirm that a scheduled video was published as instructed.
How we use it. This data is used solely to upload videos, set the
metadata and visibility (including scheduled publication via YouTube's
publishAt mechanism, and the "Made for Kids" designation configured by
the client), and confirm publication outcomes. We do not access viewer or audience
personal data, comments, or third parties' analytics. We do not use YouTube API data
for advertising purposes and we do not serve advertisements based on it. We do not
share YouTube API data with third parties, except that requests are necessarily
transmitted to YouTube/Google itself in order to perform the actions the client
instructed.
Storage and deletion. Stored YouTube API data is kept only while the channel remains connected. The Service periodically reconfirms that its authorization tokens are still valid; where a token can no longer be refreshed, or where the client disconnects the channel, we delete the stored API data associated with that authorization. If you revoke the Service's access via Google (see below), we delete all stored API data related to your authorization within 30 calendar days of the revocation.
Revoking access. In addition to disconnecting the channel inside the Service or contacting us, you can revoke the Service's access to your Google/ YouTube data at any time via the Google security settings page at https://security.google.com/settings/security/permissions (also reachable as https://myaccount.google.com/permissions).
EU users. In connection with YouTube API Services we comply with the Google EU User Consent Policy.
5.2 Meta — Instagram Graph API and Facebook Pages API
The Service uses Meta's Instagram Graph API and Facebook Pages API to publish posts, Reels, and Stories to Instagram professional accounts and Facebook Pages connected by the client. We store the OAuth tokens and the account/page identifiers needed for publication, and the identifiers/permalinks of published posts. Use of these features is subject to the Meta Terms of Service and Meta Platform Terms; Meta's handling of your data is described in the Meta Privacy Policy. You can review and remove the Service's access in your Instagram settings under Website permissions / Apps and websites and in your Facebook settings under Apps and websites.
5.3 X API (X Corp.)
The Service uses the X API v2 to publish posts (text, images, video) to X accounts connected by the client. We store the account's OAuth tokens (including refresh tokens, which X rotates) and identifiers/permalinks of published posts. Use of these features is subject to the X Terms of Service; X's handling of your data is described in the X Privacy Policy. You can revoke the Service's access at any time in X under Settings → Security and account access → Apps and sessions → Connected apps.
5.4 Reddit API
The Service uses the Reddit API to prepare and, where the client so instructs, submit posts to Reddit from accounts connected by the client. We store the account's OAuth tokens and identifiers/permalinks of submitted posts. Use of these features is subject to the Reddit User Agreement; Reddit's handling of your data is described in the Reddit Privacy Policy. You can revoke the Service's access at any time at https://www.reddit.com/prefs/apps.
5.5 TikTok (Login Kit and Content Posting API)
Where the client connects a TikTok account, the Service uses TikTok's Login Kit to authorize the account and TikTok's Content Posting API to publish video and photo posts to that account on the client's behalf. We store the account's OAuth tokens, the creator identifier and nickname (displayed so the client always knows which account a post will be published to), and identifiers of published posts. The client controls each post's metadata and privacy level. Use of these features is subject to the TikTok Terms of Service; TikTok's handling of your data is described in the TikTok Privacy Policy. You can revoke the Service's access at any time in the TikTok app under Settings and privacy → Security & permissions → Manage app permissions. If a client has not connected a TikTok account, no TikTok data is processed.
5.6 Client websites (WordPress and other destinations)
The Service publishes articles to websites operated by the client (typically via the WordPress REST API or a client-designated interface) using credentials supplied by the client, which we store encrypted at rest. Content published there is governed by the client's own policies.
6.Other service providers
To provide the Service we use a small number of vendors as processors or independent services. Content passed to them is editorial material being produced for the client; we do not pass them platform OAuth tokens:
- Anthropic, PBC — large-language-model API used for drafting and reviewing editorial content.
- ElevenLabs — text-to-speech synthesis of narration for video content.
- Hosting — the Service runs on dedicated servers operated by the Operator and located in the European Union; media files being published may be temporarily exposed at non-indexed URLs solely so that a destination platform can retrieve them during publication.
7.International data transfers
Platform data is stored in the European Union. When the Service communicates with the platforms and providers listed above (Google/YouTube, Meta, X Corp., Reddit, TikTok, Anthropic, ElevenLabs), data is transmitted to those companies, which may process it in the United States or other third countries. Such transfers rely on the safeguards those providers offer, in particular the EU–US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses.
8.Data retention
- OAuth tokens and connected-account identifiers — for as long as the account remains connected; deleted when the client disconnects the account, when the contract ends, or when authorization can no longer be refreshed. For YouTube, stored API data is deleted within 30 calendar days of consent revocation (see Section 5.1).
- Content and publication records — for the duration of the contract with the client and any statutory retention periods.
- Authentication records and technical logs — up to 90 days.
- Backups — deleted data leaves backup cycles within 30 days.
9.Security
We maintain administrative, organizational, technical, and physical safeguards appropriate to the data we process, including: encryption of stored OAuth tokens and credentials, encrypted transport (TLS) for all platform communication, role-based access scoped per client project, server access restricted to authorized administrators, and segregated per-client data isolation at the database layer. We never request, collect, or store users' platform login credentials (usernames or passwords for YouTube, Meta, X, Reddit, or TikTok accounts); connections are made exclusively through each platform's OAuth flow.
10.Your rights and revoking access
Subject to the conditions of the GDPR, you have the right to access your personal data, to rectification, to erasure, to restriction of processing, to data portability, and to object to processing based on legitimate interest. You also have the right to lodge a complaint with a supervisory authority — in the Czech Republic the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.gov.cz).
To exercise any of these rights, or to request deletion of data we hold, contact us using the details in Section 13; we respond within 30 days. Independently of us, you can revoke the Service's access to a connected platform account at any time directly with the platform:
- Google/YouTube — Google security settings,
- Instagram/Facebook — account settings, Apps and websites,
- X — Settings → Security and account access → Connected apps,
- Reddit — reddit.com/prefs/apps,
- TikTok — Settings and privacy → Security & permissions → Manage app permissions.
After a revocation we delete the stored data associated with that authorization as described in Sections 5 and 8.
11.Cookies
The pages on which this policy and the Terms of Service are published do not set cookies and do not use analytics or tracking technologies.
12.Children
The Service is a business tool intended for adult professional users (18+). It is not directed to children and we do not knowingly process children's personal data. Obligations relating to "Made for Kids" designation of YouTube content are described in the Terms of Service.
13.Contact and changes
Questions about this policy or our privacy practices, and any privacy requests, can be sent to [email protected] or by post to the address in Section 1. The same address serves as the contact point for all data protection matters.
We may update this policy from time to time, for example when the Service adds support for a new platform. The current version is always published at this address with the "Last updated" date above. If a change materially expands how we access, collect, or use data from a connected platform, we will notify affected clients and, where a platform's rules so require, ask for renewed consent before the change takes effect.