Privacy policy
Last updated 23 August 2026
Rutba Social Relay publishes posts to social platforms on your behalf. It stores your account, the social accounts you connect, the posts you send and what each platform said in reply. Access tokens are encrypted at rest and used only to publish and to report the result. Nothing is sold, nothing is used for advertising or profiling, and disconnecting an account erases its credentials immediately.
1. Who we are and what this covers
Rutba Social Relay (“the service”) is operated by Rutba (“we”, “us”). Our postal address is Registered address available on request. Privacy enquiries: privacy@rutba.io.
This policy covers the relay API, the dashboard, this website, and the connections the service makes to third-party social platforms on your instruction. It applies to the organisations that subscribe to the service, the people who sign in on their behalf, and the social accounts they authorise.
It does not cover the social platforms themselves. Once a post is published to a platform, that platform handles it under its own privacy policy, and we have no control over what it does with it.
2. Controller and processor
For your account, billing and the operation of the service, we are the data controller.
For the content you publish and the platform accounts you connect, we act as a data processor on your instruction: you decide what is sent and where, and we transmit it. Where you use the service to publish on behalf of your own clients, you are the controller for that content and are responsible for having the authority to publish it. A data processing addendum is available from privacy@rutba.io for customers who need one.
3. What we collect
- Account details. Your email address, your name if you give one, an argon2id hash of your password, and your organisation’s name, slug, timezone and billing address. Passwords are never stored in a readable form and cannot be recovered, only reset.
- Connected social accounts. For each account you authorise: the platform, the account identifier and handle that platform reports, the granted scopes, token expiry, and the access and refresh credentials themselves. Credentials are encrypted at rest with AES-256-GCM and are decrypted only at the moment a request is made to that platform.
- Posts and deliveries. The content you submit — text, links, scheduling and per-platform options — and one delivery record per destination holding its status, any error the platform returned, and the platform’s own identifier and URL for the published post.
- Media. Images and video you upload, stored by content hash so identical files are stored once, together with their dimensions, duration and type.
- Operational records. An audit trail of actions that changed something (who, what, when), request identifiers, the IP address and user agent recorded on authentication events, webhook delivery attempts, and per-month usage counts for billing.
- Billing records. Plan, subscription state, invoices and the identifiers our payment processor issues. Card numbers never reach the service.
- Support correspondence. What you write to us, and our replies.
Not stored in readable form: passwords (argon2id hashes), API keys and webhook signing secrets (SHA-256 hashes — the plaintext is displayed once at creation and cannot be recovered afterwards), and card details (held by Stripe, not by us).
4. Data obtained from connected platforms
When you connect a social account, the platform returns information about it. We keep the minimum needed to make the connection usable and to show you what you are publishing to:
- the account, page, channel, board, subreddit or workspace identifier;
- its display name, handle and avatar URL, so you can tell your connections apart;
- the scopes granted and the token’s expiry, so the service can tell you when to reconnect;
- the identifier and permalink of each post we publish, so a delivery can be linked back to its result.
We do not read your inbox or direct messages, we do not collect your followers or their profiles, we do not download your existing posts, and we do not collect analytics or audience data unless you explicitly enable a feature that reports on posts this service itself published — in which case we store only the aggregate counts that platform returns for those posts.
5. Permissions we request, and why
The service requests the narrowest set of scopes that lets it publish. In every case the purpose is the same: create a post on an account you own, and read back the result of that post.
| Platform | What the permission is used for |
|---|---|
| Facebook Pages | List the Pages you administer; publish posts to a Page you select; read the status of those posts. |
| Identify the professional account linked to a Page; publish media containers; read publishing limits. | |
| Threads | Identify the account and publish threads to it. |
| X | Identify the authorising account and create posts and media uploads on it. |
| Identify the member or organisation page and publish shares to it. | |
| YouTube | Identify the channel and upload videos to it, including title, description and privacy status. |
| TikTok | Identify the creator, query publishing limits, and upload and publish video. |
| List your boards and create pins on the board you select. | |
| Identify the account and submit posts to the subreddits you choose. | |
| Discord, Slack, Telegram | Post messages to the channel or chat you nominate. |
| Mastodon, Bluesky, WordPress | Identify the account or site and create posts on it. |
We do not request permissions the product does not use, and where a platform offers a narrower variant of a scope that is sufficient, we take it. The exact scopes requested for a given platform are shown before you authorise, and on the platforms page.
6. Meta platforms — Facebook, Instagram, Threads
Data received through Meta’s APIs is used solely to deliver the publishing feature you asked for. Consistent with Meta’s Platform Terms, we do not use Platform Data to build or augment user profiles, do not sell, licence or purchase it, do not use it for advertising or ad targeting, and do not transfer it to any data broker, ad network or monetisation service.
You may remove the app at any time from Facebook Settings → Apps and Websites, which revokes its access immediately. To have the data we hold about that connection erased, follow the data deletion instructions.
7. Google and YouTube API Services
The YouTube destination uses YouTube API Services. By connecting a YouTube channel you also agree to the YouTube Terms of Service, and Google’s handling of your information is described in the Google Privacy Policy.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Concretely: we use Google user data only to provide the publishing feature you requested, we do not use it for advertising, we do not sell it, we do not transfer it except as needed to provide the service or where required by law, and no human reads it except with your explicit consent, for security purposes, to comply with law, or where the data is aggregated and de-identified.
You can revoke this application’s access to your Google account at any time at Google security settings. Videos already uploaded to your channel remain on your channel and are managed in YouTube Studio.
8. TikTok
The TikTok destination uses TikTok’s Content Posting API. We store the creator identifier, nickname and avatar returned at authorisation, the granted scopes, and the identifier of each video we publish. TikTok data is used only to publish content you submit and to report the outcome; it is not used for advertising, profiling, resale, or training machine-learning models. Access can be revoked in the TikTok app under Settings → Security & permissions → Manage app permissions.
9. X, LinkedIn, Pinterest, Reddit and others
The same rules apply to every other destination: we store the account identity, the credentials and the record of what we published; we use them only to publish and report; and access can be revoked from that platform’s own connected-apps settings, which stops the service being able to publish there immediately.
Content you publish becomes subject to that platform’s terms and privacy policy at the moment it is delivered. Where a platform’s developer policy is stricter than this one about how its data may be handled, its policy governs.
10. Why we use it, and our legal basis
| Purpose | Legal basis (UK/EU GDPR) |
|---|---|
| Publishing your posts and reporting each delivery | Performance of a contract |
| Authenticating you and keeping your account secure | Performance of a contract; legitimate interests (security) |
| Metering usage and billing | Performance of a contract; legal obligation (tax records) |
| Preventing spam, abuse and platform-policy violations | Legitimate interests; compliance with platform terms |
| Service notices, incident and change notifications | Performance of a contract |
| Diagnosing faults from logs and audit records | Legitimate interests (operating a reliable service) |
| Marketing email, if you opt in | Consent, withdrawable at any time |
11. What we never do
- We do not sell personal information, and we never have.
- We do not share personal information for cross-context behavioural advertising.
- We do not build advertising or interest profiles from anything the service holds.
- We do not train machine-learning models on your content or on platform data.
- We do not read the content of your posts except where you ask us to investigate a failure.
- We do not post anything on your accounts other than what you send us.
13. International transfers
The service is hosted in the region stated in your order or, absent one, in the European Union or United Kingdom. Some providers above, and every social platform you connect, operate globally, so publishing a post necessarily transfers it to wherever that platform runs. Where personal data leaves the UK or EEA, we rely on an adequacy decision where one exists, and otherwise on the UK Addendum or the European Commission’s Standard Contractual Clauses.
14. How long we keep it
| Record | Retention |
|---|---|
| Account, organisation, connection and post records | For as long as the account exists |
| Connection credentials | Until disconnected or revoked — erased immediately on either |
| Session records | Until they expire or are revoked, whichever is first |
| Email verification tokens | 24 hours, single use |
| Password-reset tokens | One hour, single use |
| Idempotency records | 24 hours |
| Uploaded media | Until the owning organisation is deleted, or you delete the asset |
| Audit trail and webhook delivery logs | For as long as the account exists |
| Usage counters | Per month, retained for billing history |
| Invoices and tax records | Six years, as required by law, after which they are destroyed |
| Backups | Rolling, overwritten within 35 days |
Closing an account deletes its organisation and everything owned by it — connections, credentials, posts, deliveries, media, audit entries — by cascade, and the deletion propagates to backups as those backups age out. Posts already published to a platform are unaffected, because they live on that platform and this service cannot un-publish them.
15. Deleting your data and revoking access
There are three levers, and they are independent:
- Disconnect an account in the dashboard. The stored credentials for it are erased immediately and anything still queued for it is cancelled.
- Revoke from the platform — Facebook, Google, TikTok, X and the rest all have a connected-apps screen. Revoking there stops the service being able to publish, from that platform’s side.
- Delete everything — closing the organisation removes all of the above plus your account.
Step-by-step instructions, including the route required by Meta’s app review, are on the data deletion page. Requests sent to privacy@rutba.io are completed within 30 days and confirmed in writing.
16. Security
- Connection credentials are encrypted at rest with AES-256-GCM under a key held outside the database.
- Passwords use argon2id; API keys and webhook secrets are stored only as SHA-256 hashes.
- Sessions are HttpOnly, Secure, SameSite cookies with the
__Host-prefix; cross-origin state-changing requests are refused. - All traffic to the API and dashboard is encrypted in transit with TLS.
- Outbound fetches of media URLs you supply are validated against private and link-local address ranges on every redirect hop, so the service cannot be steered into an internal network.
- Every tenant’s data is scoped by organisation at the query layer, and administrative access is limited to named staff, logged, and used only for support and incident response.
No system is perfect. If you believe you have found a vulnerability, write to support@rutba.io and we will acknowledge it within two working days.
17. Your rights
Subject to local law, you may ask us to give you a copy of your data, correct it, delete it, restrict or object to a particular use, or provide it in a portable format; and you may withdraw consent where consent is what we relied on. The dashboard already exposes your posts, deliveries and audit trail directly, and the same records are readable through the API with a key, so most requests can be answered without asking us.
For anything the dashboard does not cover, write to privacy@rutba.io. We respond within 30 days and do not charge for it. There is no automated decision-making with legal or similarly significant effects in this service.
If you are in the UK or EEA you may complain to your supervisory authority — in the UK, the Information Commissioner’s Office. If you are a California resident, the rights above are the CCPA/CPRA rights to know, delete, correct and opt out; we do not sell or share personal information, so there is nothing to opt out of, and we will not discriminate against you for exercising a right.
19. Children
The service is a business tool and is not directed at children. You must be at least 16, and old enough under the rules of every platform you connect, to use it. We do not knowingly collect data from children; if we learn that we have, we delete it.
20. Incident notification
If a breach affects your personal data, we will notify the affected account holders without undue delay and, where required, the relevant supervisory authority within 72 hours of becoming aware of it. The notice will say what happened, what data was involved, and what to do about it.
21. Changes to this policy
The date at the top changes whenever this page does. If a change is material — a new category of data, a new purpose, a new sub-processor with access to content — account holders are emailed before it takes effect.
22. Contact
Rutba, Registered address available on request.
Privacy: privacy@rutba.io
Everything else: support@rutba.io
See also the terms of service and the data deletion instructions.