Privacy Policy
Effective Date: April 27, 2024
Last Updated: September 4, 2026 (version 2.4)
TONVI TECH SL ("we", "our", "us", "Upload-Post") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website https://www.upload-post.com and related services (collectively, the "Services").
This Privacy Policy is designed to comply with the General Data Protection Regulation (GDPR) (EU) 2016/679, the Spanish Organic Law 3/2018 on Personal Data Protection (LOPDGDD), and other applicable data protection laws.
Data Controller:
TONVI TECH SL
C.I.F.: B-19780394
Address: Calle Puerta del Mar, 18 5th Floor, 29005 Málaga, Spain
General email: [email protected]
Data protection requests: [email protected]
YouTube API Services: Our service uses YouTube API Services. Your use of our service is also subject to the Google Privacy Policy. You can revoke our access at any time through Google security settings.
1. Information We Collect
1.1 Information You Provide Directly
- Account Information: Name, email address, password, and profile information when you create an account
- Payment Information: Billing address, country, and VAT/tax identification number where you provide one. Card details are entered on Stripe's hosted checkout and never reach our servers.
- Communications: Messages, support requests, and feedback you send to us
- User Content: Videos, images, text, and other content you upload through our Services
1.2 Information from Third-Party Platforms
When you connect social media accounts, we may receive:
- Profile information (name, username, profile picture)
- Account identifiers and access tokens
- Platform-specific data required for posting (channel IDs, page IDs)
- Limited analytics data where permitted by the platform
1.3 Information Collected Automatically
- Device Information: IP address, browser type, operating system, device identifiers
- Usage Data: Pages visited, features used, time spent, click patterns
- Log Data: Server logs, error reports, API requests
- Cookies and Similar Technologies: See Section 8 for details
2. Legal Basis for Processing (GDPR)
We process your personal data based on the following legal grounds:
- Contract Performance (Art. 6(1)(b) GDPR): Processing necessary to provide our Services and fulfill our contractual obligations to you
- Legitimate Interests (Art. 6(1)(f) GDPR): Processing for our legitimate business interests, such as improving our Services, fraud prevention, and security
- Consent (Art. 6(1)(a) GDPR): Processing based on your explicit consent, such as marketing communications
- Legal Obligation (Art. 6(1)(c) GDPR): Processing required to comply with legal requirements
3. How We Use Your Information
We use your information for the following purposes:
3.1 Service Provision
- Creating and managing your account
- Processing and posting your content to connected social media platforms
- Processing payments and subscriptions
- Providing customer support
3.2 Service Improvement
- Analyzing usage patterns to improve our Services
- Developing new features and functionality
- Conducting research and analytics
3.3 Communication
- Sending service-related notifications (transactional emails)
- Responding to inquiries and support requests
- Sending marketing communications (with your consent)
3.4 Security and Compliance
- Detecting, preventing, and addressing fraud and abuse
- Enforcing our Terms of Use
- Complying with legal obligations
3.5 Automated Processing
Our Services rely on automated systems to process and deliver your content to connected social media platforms. This automated processing includes scheduling, formatting, and transmitting your content. While we implement safeguards to ensure accuracy, automated processing may occasionally result in errors, including content being delivered to incorrect accounts or platforms. We do not use automated decision-making that produces legal effects or similarly significantly affects you within the meaning of Article 22 GDPR.
You have the right not to be subject to a decision based solely on automated processing. If you believe an automated process has adversely affected you, please contact us at [email protected] to request human review.
Automated sign-up screening. For transparency we describe the only fully automated decisions we make at the point of registration, even though we consider that they do not produce legal or similarly significant effects and therefore fall outside Article 22 GDPR:
- Disposable email domains are refused: a registration using a throw-away mailbox provider is rejected automatically.
- Rate limit per IP address: a maximum of 10 registrations per day and 25 per week from the same IP address. Attempts beyond that are refused.
Both measures exist to prevent abuse of the free tier and fraud, on the basis of our legitimate interest (Article 6(1)(f) GDPR). They never rely on profiling and never assess you as a person. If your registration is refused and you believe it should not have been, write to [email protected] or [email protected]: a human reviews the case and can create the account manually.
Account suspension for breach of the Terms of Use is always decided by a person, never automatically, and you are told why and can reply.
3.6 AI-Powered Features
Several features of Upload-Post are powered by generative AI. So that you know exactly what leaves our servers, this is what is sent, to whom, and for what:
- Shorts analyser: the complete video file you submit — image and audio, including any faces and voices it contains — is uploaded to the Google Gemini API (Google LLC, United States) so the model can propose clips, titles and descriptions.
- Captions, titles, descriptions and hashtags: the caption text and the metadata of the post you are composing are sent to the same Gemini API.
- Support assistant: your question plus a snapshot of your account context (plan, connected profiles and platforms, recent errors and upload titles) is sent to the Gemini API to draft an answer.
- Documentation assistant: the question you type into the documentation chat is sent to the Gemini API. It is stored for 90 days with no IP address attached.
We use the paid tier of the Gemini API. Under the Google APIs Terms of Service for paid services, Google does not use the content submitted through it to train or improve its own models, and does not use it for any purpose other than returning the response we requested. Google LLC is certified under the EU-U.S. Data Privacy Framework, and EU Standard Contractual Clauses apply in addition. The legal basis for providing an AI feature you request is the performance of our contract with you (Article 6(1)(b) GDPR).
Third parties in your videos. If the media you submit shows or records other people, you are responsible for having a lawful basis to process their data and for informing them, as set out in our Data Processing Agreement and in Section 4.5 below.
Our own model training, and how to opt out. We do not use your User Content in identifiable form to train shared AI models. We reserve the right to use User Content and associated analytics in aggregated and/or de-identified form to develop, train, evaluate and improve our own caption and title models, which power features offered to all users; where we do, the training corpus excludes the profile user name and any account identifier. We do not operate such a training pipeline at present — the AI features in the Services run on third-party models that are named on our Sub-processors page and that do not train on the content we submit. The legal basis is our legitimate interest in improving the Services (Article 6(1)(f) GDPR).
You can object at any time (Article 21 GDPR). Email [email protected] with the subject "AI Training Opt-Out" and we will record the objection against your account and honour it for all future training. Business customers can also have the exclusion written into their Data Processing Agreement.
All AI providers that process Personal Data on our behalf are named on our Sub-processors page.
3.7 AI Assistants and MCP Integrations
You can use Upload-Post through third-party AI assistants (for example Claude or ChatGPT) via our MCP server and API integrations. When you do, we receive only the specific tool inputs the assistant sends to Upload-Post (for example a caption, a media file, or a scheduling request) and we return the corresponding outputs. We never receive your full conversation with the assistant. Your conversation with the assistant itself is governed by the assistant provider's own terms and privacy policy, not by this Privacy Policy.
4. Information Sharing and Disclosure
We do NOT sell your personal data. We may share your information in the following circumstances:
4.1 Service Providers and Sub-processors
We engage the third parties named below to operate the Services. This table, the public Sub-processors page and Annex III of our Data Processing Agreement are generated from the same source and are therefore identical. Last updated: September 4, 2026.
| Recipient | What they do for us | Processing location | Transfer safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Cloud hosting and infrastructure: application servers, MongoDB and Redis databases, back-up staging, GPU/staging server (balrog) and every self-hosted service listed below. | Germany (EU) | Intra-EEA; no third-country transfer. |
| Cloudflare, Inc. | R2 object storage for media files uploaded for publication (media.upload-post.com and the scheduler bucket), plus CDN and DNS for our domains. | European Union (R2 EU jurisdictional restriction) / United States (corporate access) | EU-U.S. Data Privacy Framework (Cloudflare, Inc. is certified) and EU Standard Contractual Clauses (Decision (EU) 2021/914) for any transfer outside the EEA. |
| Google Cloud EMEA Limited / Google LLC (Google Cloud Storage) | Encrypted-at-rest object storage for database back-ups, compressed server logs, copied profile pictures and scheduler payloads (buckets mongodb-img2html, logs-back, pfp-social-pics-upload-post-eu3, upload-post-schedulers-eu3). | European Union (EU multi-region buckets) / United States (corporate access) | EU-U.S. Data Privacy Framework (Google LLC is certified) and EU Standard Contractual Clauses, under the Google Cloud Data Processing Addendum. |
| Google LLC (Gemini API, paid tier) | AI features: analysis of the full video you submit to the Shorts analyser (image and audio), generation of captions, titles, descriptions and hashtags, the support assistant and the documentation assistant. | United States | EU-U.S. Data Privacy Framework and EU Standard Contractual Clauses. On the paid tier Google does not use the submitted content to train its models (Google APIs Terms of Service — Paid Services). |
| Google Ireland Limited / Google LLC (Google Ads) | Advertising measurement: the gtag conversion tag on the website (marketing cookies only, and only with your consent) and the Offline Conversions API, to which a SHA-256 hash of the buyer email address is sent when a subscription is paid. | Ireland (EU) / United States | EU-U.S. Data Privacy Framework and EU Standard Contractual Clauses, under the Google Ads Data Processing Terms. |
| Reddit, Inc. | Advertising measurement for our Reddit campaigns: the Reddit advertising pixel (marketing cookies only, and only with your consent) and the Reddit Conversions API, to which a SHA-256 hash of the buyer email address is sent when a subscription is paid. | United States | EU Standard Contractual Clauses (Decision (EU) 2021/914) and supplementary measures. |
| Stripe Payments Europe, Ltd. / Stripe, Inc. | Hosted checkout, subscription billing, invoicing, automatic VAT calculation and VAT-number collection. Card data is entered on Stripe pages and never reaches our servers. | Ireland (EU) / United States | EU-U.S. Data Privacy Framework and EU Standard Contractual Clauses. |
| Amazon Web Services EMEA SARL (Amazon SES) | Transactional email delivery: magic sign-in links, account and billing notifications. | France (eu-west-3) | Intra-EEA primary processing; EU Standard Contractual Clauses for incidental support access. |
| Namecheap, Inc. (PrivateEmail / Titan) | Hosted mailbox for [email protected] — receipt of customer correspondence and support requests — and fallback SMTP relay when Amazon SES is unavailable. | United States | EU Standard Contractual Clauses. |
| Listmonk (self-hosted by TONVI TECH SL) Self-hosted | Newsletter and product-marketing email list (churnkiller.upload-post.com). Only subscribers who opted in receive marketing email; every message carries a one-click unsubscribe link. | Germany (EU) — our own server at Hetzner | Intra-EEA; no third-party processor involved. |
| OpenPanel (self-hosted by TONVI TECH SL) Self-hosted | Product and website analytics (api.openpanel.fotoexamen.com). The browser SDK is served from www.upload-post.com itself, so no third-party host sees your IP address. Analytics only runs with your consent. | Germany (EU) — our own server at Hetzner | Intra-EEA; no third-party processor involved. |
| Upload-Post media processing service "balrog" (self-hosted by TONVI TECH SL) Self-hosted | Server-side video processing with ffmpeg (trimming, re-encoding, subtitles, format conversion) for the media you submit. Processed results are deleted after 24 hours. | Germany (EU) — our own server at Hetzner | Intra-EEA; no third-party processor involved. |
| Upload-Post affiliate platform (self-hosted by TONVI TECH SL) Self-hosted | affiliates.upload-post.com — attribution of affiliate clicks and commissions. Receives the affiliate code, landing page, referrer and any advertising click identifiers, and later the conversion, plus the payout details of affiliates who join the programme. | Germany (EU) — our own server at Hetzner | Intra-EEA; no third-party processor involved. |
| Aikount — TONVI TECH SL Self-hosted | Statutory invoicing and accounting for the invoices we are legally required to issue and keep (api.aikount.com). Receives the billing identifiers of the transaction (Stripe customer id, amounts, tax data). | Spain (EU) — operated by the controller itself | Intra-EEA; same corporate group as the controller. |
| Telegram Messenger Inc. | Internal operational and security alerts to the engineering channel (failed payments, sign-up abuse, platform restrictions). Being phased out; the alerts currently sent contain only pseudonymised identifiers (an 8-character hash plus the email domain) and a truncated IP address, never a full email address. | Outside the EEA (United Arab Emirates / United Kingdom) | EU Standard Contractual Clauses are not available for this channel; the transfer is minimised to pseudonymised identifiers and the channel is being replaced by an internal alerting system. |
Two corrections to earlier versions of this policy, made in version 2.4:
- Paddle is not, and has never been, a payment processor for Upload-Post. The only payment processor is Stripe. Earlier versions listed Paddle in error and the reference has been removed.
- OpenPanel: our analytics server has always been self-hosted at api.openpanel.fotoexamen.com on our own infrastructure, but until 4 September 2026 the browser script was downloaded from openpanel.dev, which meant that host could see your IP address. The script is now served from www.upload-post.com itself, so the statement "no third party is involved" is now accurate for the whole chain. PostHog appeared in earlier versions and is not used at all.
4.2 Social Media Platforms
When you use our Services to post content, your content and associated metadata are transmitted to the social media platforms you have connected. This transmission is necessary to provide our core service functionality. You acknowledge that once content is transmitted to a third-party platform, it is subject to that platform's terms and privacy policies, and we cannot guarantee its retrieval, modification, or deletion from those platforms.
These platforms may process data in countries outside the European Economic Area, including the United States and other jurisdictions, under their own roles as independent controllers and their own transfer mechanisms. You should review the privacy policy and platform terms of each connected social media service.
4.3 Legal Requirements
We may disclose your information if required by law, court order, or governmental authority, or when we believe disclosure is necessary to:
- Comply with legal obligations
- Protect our rights, privacy, safety, or property
- Prevent fraud or illegal activities
- Respond to lawful requests from public authorities
4.4 Business Transfers
In the event of a merger, acquisition, reorganization, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you of any such change and your choices regarding your data.
4.5 Data About People Who Are Not Our Customers (Article 14 GDPR)
When a customer uses Upload-Post, the Services necessarily handle data about people who have no relationship with TONVI TECH SL. We set this out expressly, as Article 14 GDPR requires when personal data is not obtained from the data subject:
- Authors of comments and direct messages on the customer's connected accounts: platform user id, user name, the full text of the message or comment, and the timestamp. Source: the API of the social platform concerned.
- Followers and audience of the customer's accounts: aggregated demographic data (age brackets, gender, city or country) as computed and supplied by the platform. This is an inference produced by the platform, not data we collect ourselves.
- People who appear or are heard in the media a customer uploads, including material sent to the AI features described in Section 3.6.
- Owners of third-party channels a customer connects (for example the email address associated with a YouTube channel that is not the customer's own).
- End users of white-label customers, who connect their own social accounts inside the customer's product.
- Team members invited by a customer into their workspace: name and email address.
Roles. For all of the above, the customer is the data controller and Upload-Post acts solely as a processor on their documented instructions, under our Data Processing Agreement. We do not use this data for our own purposes, we do not sell it, we do not send comments or direct messages of third parties to any AI provider, and we do not build advertising profiles from it.
What this means for our customers. If you use Upload-Post you are responsible for having a lawful basis for processing the data of these people and for informing them, in your own privacy notice, that you use a publishing and engagement tool that stores their messages and audience data on your behalf. If you publish media featuring identifiable people, you are responsible for the consent or other lawful basis required.
If you are one of those people and you wish to exercise your rights, address your request to the customer who operates the account — they are the controller. You may also write to [email protected]: we will forward the request to the relevant customer without undue delay and assist them in answering it, as Article 28(3)(e) GDPR requires.
5. International Data Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA). When we transfer data outside the EEA, we ensure appropriate safeguards are in place:
- Adequacy decisions by the European Commission
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Binding Corporate Rules where applicable
- For US transfers: EU-US Data Privacy Framework certification where applicable
6. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption of data in transit (TLS/SSL) and at rest
- Regular security assessments and penetration testing
- Access controls and authentication mechanisms
- Employee training on data protection
- Incident response procedures
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
7. Data Retention
We retain your personal data for as long as necessary to:
- Provide our Services and maintain your account
- Comply with legal obligations (e.g., tax records for 6 years)
- Resolve disputes and enforce our agreements
- Prevent fraud and abuse
Specific retention periods, aligned with the deletion jobs that actually run on our systems:
| Data | Retention |
|---|---|
| Account data (profile, connected accounts, tokens) | Until you delete the account, plus a 30-day grace period during which you can restore it |
| Invoices and transaction records | 6 years, as required by Article 30 of the Spanish Commercial Code and the General Tax Act. These are kept even after account deletion; that obligation overrides erasure. |
| User Content (media uploaded for publication) | Until you delete it or the account is deleted; temporary media handled through the API is removed after 24 hours |
Server logs (gs://logs-back archive included) | 90 days |
| Database back-ups | 30 days. A deletion request is applied to live systems immediately; back-ups age out within 30 days and are never used to repopulate deleted accounts. |
Record of emails sent to you (sent_emails_log, contains sign-in links) | 30 days |
| Support chat transcripts and tickets | 12 months |
| Documentation chat questions | 90 days, with no IP address stored |
| Shorts analyser records | 30 days |
| AI usage records (which feature, when, how many tokens) | 12 months |
| Direct messages and comment logs (including third-party authors) | 90 days |
| Analytics and audience snapshots | 26 months |
| Video processing jobs and their results | 24 hours for the output file, 30 days for the job record |
| Free accounts with no sign-in activity | 24 months, after which we send a warning email and then delete the account |
| Marketing cookies and attribution identifiers | 60 to 90 days — see the Cookie Policy |
When a retention period expires, the data is deleted or irreversibly anonymised. Where a legal obligation requires us to keep a record (invoicing, accounting, defence of legal claims), we keep only that record and restrict all other processing of it.
8. Cookies, Tracking Technologies and Marketing Consent
The complete inventory — every cookie and storage key, its provider, purpose, category and duration — is published in our Cookie Policy. This section summarises it.
No analytics or advertising script is loaded until you have given consent through our consent banner. Rejecting is as easy and as visible as accepting, and Google Consent Mode v2 is initialised in a denied state as the first instruction of every page. You can change or withdraw your choice at any time with the "Cookie settings" button in the footer of every page.
8.1 Strictly Necessary
Your consent record (up_consent) and your light/dark theme preference. Exempt from consent under Article 22.2 LSSI-CE; they cannot be disabled without breaking the site.
8.2 Analytics
OpenPanel, self-hosted on our own server at api.openpanel.fotoexamen.com (Hetzner, Germany). The browser script is served from www.upload-post.com itself, so no third-party host receives your IP address. OpenPanel sets no cookie, but it does write one sessionStorage key, which is why it still requires your consent under Article 22.2 LSSI-CE. It only runs if you accept the analytics category. We do not use Google Analytics, Google Tag Manager, Meta Pixel, TikTok Pixel, LinkedIn Insight, Hotjar, Clarity or PostHog.
8.3 Marketing and Attribution
Only with your consent: the Google Ads conversion tag, the Reddit advertising pixel, and our own first-party affiliate and attribution cookies (aff_ref, 60 days; up_attribution, 90 days; __td_conversion_id__, 90 days). We also send a SHA-256 hash of the buyer's email address to Google Ads and Reddit through their server-side conversion APIs when a subscription is paid, so that a purchase can be matched to the campaign that produced it.
8.4 Marketing Emails — a Separate Consent
Consent to marketing cookies is not consent to marketing emails, and earlier versions of this policy wrongly suggested the cookie banner covered both. There are three independent controls:
- The cookie banner governs trackers on the website only.
- A separate, unticked marketing checkbox at sign-up governs commercial emails. You are never added to a marketing list by the mere act of creating an account, and you can also switch the preference on or off at any time in the application under notification settings.
- Every marketing email carries an unsubscribe link and a
List-Unsubscribeheader; one click removes you. Transactional messages (sign-in links, billing and service notices) are not marketing and are sent on the basis of our contract with you, so they cannot be unsubscribed from while the account exists.
9. Your Rights (GDPR)
Under GDPR, you have the following rights regarding your personal data:
- Right of Access (Art. 15): Request a copy of your personal data
- Right to Rectification (Art. 16): Request correction of inaccurate data
- Right to Erasure (Art. 17): Request deletion of your data ("right to be forgotten")
- Right to Restriction (Art. 18): Request limitation of processing
- Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format
- Right to Object (Art. 21): Object to processing based on legitimate interests
- Right to Withdraw Consent (Art. 7): Withdraw consent at any time where processing is based on consent
- Right to Lodge a Complaint (Art. 77): File a complaint with a supervisory authority
9.1 Exercising Your Rights
To exercise any of these rights, please contact us at:
- Data protection mailbox: [email protected]
- General email: [email protected]
- Address: Calle Puerta del Mar, 18 5th Floor, 29005 Málaga, Spain
We will respond to your request within one month. Where permitted by GDPR, this period may be extended by up to two additional months if the request is complex or numerous, and we will inform you of any extension within the first month. We may need to verify your identity before processing your request.
9.2 YouTube API Data
If you have authorized our application to access your YouTube data:
- You can revoke access at any time through Google security settings
- Upon account deletion request, we will delete all stored YouTube API data within 30 days
- To request deletion, contact us at the email address above
10. Children's Privacy
Our Services are intended exclusively for users who are at least 18 years old and have the legal capacity to enter into a binding agreement. Our Services are not directed at minors, and we do not knowingly collect personal data from anyone under 18. If we become aware that we have collected personal data from a minor, we will delete that information promptly. If you believe we have inadvertently collected data from a minor, please contact us at [email protected].
11. Third-Party Links
Our Services may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to read the privacy policies of any third-party services you access.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a prominent notice on our website at least 30 days before the changes take effect. Your continued use of our Services after the effective date constitutes acceptance of the updated Privacy Policy.
13. Supervisory Authority
If you are located in the European Union and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection authority. In Spain, this is the Agencia Española de Protección de Datos (AEPD): www.aepd.es
14. Contact Us
For any questions or concerns about this Privacy Policy or our data practices, please contact us:
- Company: TONVI TECH SL
- C.I.F.: B-19780394
- Address: Calle Puerta del Mar, 18 5th Floor, 29005 Málaga, Spain
- General email: [email protected]
- Data protection mailbox: [email protected]
Document Version: 2.4
Last Updated: September 4, 2026
Effective Date: April 27, 2024