Rutba Social Relay

Privacy policy

Last updated 23 August 2026

Rutba Social Relay publishes posts to social platforms on your behalf. It stores your account, the social accounts you connect, the posts you send and what each platform said in reply. Access tokens are encrypted at rest and used only to publish and to report the result. Nothing is sold, nothing is used for advertising or profiling, and disconnecting an account erases its credentials immediately.

1. Who we are and what this covers

Rutba Social Relay (“the service”) is operated by Rutba (“we”, “us”). Our postal address is Registered address available on request. Privacy enquiries: privacy@rutba.io.

This policy covers the relay API, the dashboard, this website, and the connections the service makes to third-party social platforms on your instruction. It applies to the organisations that subscribe to the service, the people who sign in on their behalf, and the social accounts they authorise.

It does not cover the social platforms themselves. Once a post is published to a platform, that platform handles it under its own privacy policy, and we have no control over what it does with it.

2. Controller and processor

For your account, billing and the operation of the service, we are the data controller.

For the content you publish and the platform accounts you connect, we act as a data processor on your instruction: you decide what is sent and where, and we transmit it. Where you use the service to publish on behalf of your own clients, you are the controller for that content and are responsible for having the authority to publish it. A data processing addendum is available from privacy@rutba.io for customers who need one.

3. What we collect

  • Account details. Your email address, your name if you give one, an argon2id hash of your password, and your organisation’s name, slug, timezone and billing address. Passwords are never stored in a readable form and cannot be recovered, only reset.
  • Connected social accounts. For each account you authorise: the platform, the account identifier and handle that platform reports, the granted scopes, token expiry, and the access and refresh credentials themselves. Credentials are encrypted at rest with AES-256-GCM and are decrypted only at the moment a request is made to that platform.
  • Posts and deliveries. The content you submit — text, links, scheduling and per-platform options — and one delivery record per destination holding its status, any error the platform returned, and the platform’s own identifier and URL for the published post.
  • Media. Images and video you upload, stored by content hash so identical files are stored once, together with their dimensions, duration and type.
  • Operational records. An audit trail of actions that changed something (who, what, when), request identifiers, the IP address and user agent recorded on authentication events, webhook delivery attempts, and per-month usage counts for billing.
  • Billing records. Plan, subscription state, invoices and the identifiers our payment processor issues. Card numbers never reach the service.
  • Support correspondence. What you write to us, and our replies.

Not stored in readable form: passwords (argon2id hashes), API keys and webhook signing secrets (SHA-256 hashes — the plaintext is displayed once at creation and cannot be recovered afterwards), and card details (held by Stripe, not by us).

4. Data obtained from connected platforms

When you connect a social account, the platform returns information about it. We keep the minimum needed to make the connection usable and to show you what you are publishing to:

  • the account, page, channel, board, subreddit or workspace identifier;
  • its display name, handle and avatar URL, so you can tell your connections apart;
  • the scopes granted and the token’s expiry, so the service can tell you when to reconnect;
  • the identifier and permalink of each post we publish, so a delivery can be linked back to its result.

We do not read your inbox or direct messages, we do not collect your followers or their profiles, we do not download your existing posts, and we do not collect analytics or audience data unless you explicitly enable a feature that reports on posts this service itself published — in which case we store only the aggregate counts that platform returns for those posts.

5. Permissions we request, and why

The service requests the narrowest set of scopes that lets it publish. In every case the purpose is the same: create a post on an account you own, and read back the result of that post.

PlatformWhat the permission is used for
Facebook PagesList the Pages you administer; publish posts to a Page you select; read the status of those posts.
InstagramIdentify the professional account linked to a Page; publish media containers; read publishing limits.
ThreadsIdentify the account and publish threads to it.
XIdentify the authorising account and create posts and media uploads on it.
LinkedInIdentify the member or organisation page and publish shares to it.
YouTubeIdentify the channel and upload videos to it, including title, description and privacy status.
TikTokIdentify the creator, query publishing limits, and upload and publish video.
PinterestList your boards and create pins on the board you select.
RedditIdentify the account and submit posts to the subreddits you choose.
Discord, Slack, TelegramPost messages to the channel or chat you nominate.
Mastodon, Bluesky, WordPressIdentify the account or site and create posts on it.

We do not request permissions the product does not use, and where a platform offers a narrower variant of a scope that is sufficient, we take it. The exact scopes requested for a given platform are shown before you authorise, and on the platforms page.

6. Meta platforms — Facebook, Instagram, Threads

Data received through Meta’s APIs is used solely to deliver the publishing feature you asked for. Consistent with Meta’s Platform Terms, we do not use Platform Data to build or augment user profiles, do not sell, licence or purchase it, do not use it for advertising or ad targeting, and do not transfer it to any data broker, ad network or monetisation service.

You may remove the app at any time from Facebook Settings → Apps and Websites, which revokes its access immediately. To have the data we hold about that connection erased, follow the data deletion instructions.

7. Google and YouTube API Services

The YouTube destination uses YouTube API Services. By connecting a YouTube channel you also agree to the YouTube Terms of Service, and Google’s handling of your information is described in the Google Privacy Policy.

Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Concretely: we use Google user data only to provide the publishing feature you requested, we do not use it for advertising, we do not sell it, we do not transfer it except as needed to provide the service or where required by law, and no human reads it except with your explicit consent, for security purposes, to comply with law, or where the data is aggregated and de-identified.

You can revoke this application’s access to your Google account at any time at Google security settings. Videos already uploaded to your channel remain on your channel and are managed in YouTube Studio.

8. TikTok

The TikTok destination uses TikTok’s Content Posting API. We store the creator identifier, nickname and avatar returned at authorisation, the granted scopes, and the identifier of each video we publish. TikTok data is used only to publish content you submit and to report the outcome; it is not used for advertising, profiling, resale, or training machine-learning models. Access can be revoked in the TikTok app under Settings → Security & permissions → Manage app permissions.

9. X, LinkedIn, Pinterest, Reddit and others

The same rules apply to every other destination: we store the account identity, the credentials and the record of what we published; we use them only to publish and report; and access can be revoked from that platform’s own connected-apps settings, which stops the service being able to publish there immediately.

Content you publish becomes subject to that platform’s terms and privacy policy at the moment it is delivered. Where a platform’s developer policy is stricter than this one about how its data may be handled, its policy governs.

10. Why we use it, and our legal basis

PurposeLegal basis (UK/EU GDPR)
Publishing your posts and reporting each deliveryPerformance of a contract
Authenticating you and keeping your account securePerformance of a contract; legitimate interests (security)
Metering usage and billingPerformance of a contract; legal obligation (tax records)
Preventing spam, abuse and platform-policy violationsLegitimate interests; compliance with platform terms
Service notices, incident and change notificationsPerformance of a contract
Diagnosing faults from logs and audit recordsLegitimate interests (operating a reliable service)
Marketing email, if you opt inConsent, withdrawable at any time

11. What we never do

  • We do not sell personal information, and we never have.
  • We do not share personal information for cross-context behavioural advertising.
  • We do not build advertising or interest profiles from anything the service holds.
  • We do not train machine-learning models on your content or on platform data.
  • We do not read the content of your posts except where you ask us to investigate a failure.
  • We do not post anything on your accounts other than what you send us.

12. Who else sees it

  • The platforms you connect. A post you publish to a platform is sent to that platform. That is the service.
  • Stripe — payment processing, subscriptions and invoices.
  • Our email provider — delivery of verification, invitation, password-reset and alert emails, which necessarily carry your address and the message.
  • Our hosting, database and object-storage providers — where the database, queue and uploaded media live.
  • Professional advisers and authorities — only where we are legally required, and we will tell you unless we are prohibited from doing so.
  • A successor — if the business is sold or merged, under the same commitments as this policy; you would be told before any transfer takes effect.

Every provider above is bound by a written contract limiting it to processing on our instructions. An up-to-date list of sub-processors is available on request from privacy@rutba.io, and customers under a data processing addendum are notified of changes to it in advance.

13. International transfers

The service is hosted in the region stated in your order or, absent one, in the European Union or United Kingdom. Some providers above, and every social platform you connect, operate globally, so publishing a post necessarily transfers it to wherever that platform runs. Where personal data leaves the UK or EEA, we rely on an adequacy decision where one exists, and otherwise on the UK Addendum or the European Commission’s Standard Contractual Clauses.

14. How long we keep it

RecordRetention
Account, organisation, connection and post recordsFor as long as the account exists
Connection credentialsUntil disconnected or revoked — erased immediately on either
Session recordsUntil they expire or are revoked, whichever is first
Email verification tokens24 hours, single use
Password-reset tokensOne hour, single use
Idempotency records24 hours
Uploaded mediaUntil the owning organisation is deleted, or you delete the asset
Audit trail and webhook delivery logsFor as long as the account exists
Usage countersPer month, retained for billing history
Invoices and tax recordsSix years, as required by law, after which they are destroyed
BackupsRolling, overwritten within 35 days

Closing an account deletes its organisation and everything owned by it — connections, credentials, posts, deliveries, media, audit entries — by cascade, and the deletion propagates to backups as those backups age out. Posts already published to a platform are unaffected, because they live on that platform and this service cannot un-publish them.

15. Deleting your data and revoking access

There are three levers, and they are independent:

  1. Disconnect an account in the dashboard. The stored credentials for it are erased immediately and anything still queued for it is cancelled.
  2. Revoke from the platform — Facebook, Google, TikTok, X and the rest all have a connected-apps screen. Revoking there stops the service being able to publish, from that platform’s side.
  3. Delete everything — closing the organisation removes all of the above plus your account.

Step-by-step instructions, including the route required by Meta’s app review, are on the data deletion page. Requests sent to privacy@rutba.io are completed within 30 days and confirmed in writing.

16. Security

  • Connection credentials are encrypted at rest with AES-256-GCM under a key held outside the database.
  • Passwords use argon2id; API keys and webhook secrets are stored only as SHA-256 hashes.
  • Sessions are HttpOnly, Secure, SameSite cookies with the __Host- prefix; cross-origin state-changing requests are refused.
  • All traffic to the API and dashboard is encrypted in transit with TLS.
  • Outbound fetches of media URLs you supply are validated against private and link-local address ranges on every redirect hop, so the service cannot be steered into an internal network.
  • Every tenant’s data is scoped by organisation at the query layer, and administrative access is limited to named staff, logged, and used only for support and incident response.

No system is perfect. If you believe you have found a vulnerability, write to support@rutba.io and we will acknowledge it within two working days.

17. Your rights

Subject to local law, you may ask us to give you a copy of your data, correct it, delete it, restrict or object to a particular use, or provide it in a portable format; and you may withdraw consent where consent is what we relied on. The dashboard already exposes your posts, deliveries and audit trail directly, and the same records are readable through the API with a key, so most requests can be answered without asking us.

For anything the dashboard does not cover, write to privacy@rutba.io. We respond within 30 days and do not charge for it. There is no automated decision-making with legal or similarly significant effects in this service.

If you are in the UK or EEA you may complain to your supervisory authority — in the UK, the Information Commissioner’s Office. If you are a California resident, the rights above are the CCPA/CPRA rights to know, delete, correct and opt out; we do not sell or share personal information, so there is nothing to opt out of, and we will not discriminate against you for exercising a right.

18. Cookies and tracking

This marketing site sets no cookies and runs no third-party analytics, advertising or tracking scripts. The dashboard sets exactly one cookie, the session cookie described above, which is strictly necessary to keep you signed in and is not used for analytics. There is no consent banner because there is nothing to consent to.

19. Children

The service is a business tool and is not directed at children. You must be at least 16, and old enough under the rules of every platform you connect, to use it. We do not knowingly collect data from children; if we learn that we have, we delete it.

20. Incident notification

If a breach affects your personal data, we will notify the affected account holders without undue delay and, where required, the relevant supervisory authority within 72 hours of becoming aware of it. The notice will say what happened, what data was involved, and what to do about it.

21. Changes to this policy

The date at the top changes whenever this page does. If a change is material — a new category of data, a new purpose, a new sub-processor with access to content — account holders are emailed before it takes effect.

22. Contact

Rutba, Registered address available on request.
Privacy: privacy@rutba.io
Everything else: support@rutba.io

See also the terms of service and the data deletion instructions.