Privacy Policy

Effective Date: April 27, 2024

Last Updated: September 4, 2026 (version 2.4)

TONVI TECH SL ("we", "our", "us", "Upload-Post") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website https://www.upload-post.com and related services (collectively, the "Services").

This Privacy Policy is designed to comply with the General Data Protection Regulation (GDPR) (EU) 2016/679, the Spanish Organic Law 3/2018 on Personal Data Protection (LOPDGDD), and other applicable data protection laws.

Data Controller:
TONVI TECH SL
C.I.F.: B-19780394
Address: Calle Puerta del Mar, 18 5th Floor, 29005 Málaga, Spain
General email: [email protected]
Data protection requests: [email protected]

YouTube API Services: Our service uses YouTube API Services. Your use of our service is also subject to the Google Privacy Policy. You can revoke our access at any time through Google security settings.

1. Information We Collect

1.1 Information You Provide Directly

1.2 Information from Third-Party Platforms

When you connect social media accounts, we may receive:

1.3 Information Collected Automatically

2. Legal Basis for Processing (GDPR)

We process your personal data based on the following legal grounds:

3. How We Use Your Information

We use your information for the following purposes:

3.1 Service Provision

3.2 Service Improvement

3.3 Communication

3.4 Security and Compliance

3.5 Automated Processing

Our Services rely on automated systems to process and deliver your content to connected social media platforms. This automated processing includes scheduling, formatting, and transmitting your content. While we implement safeguards to ensure accuracy, automated processing may occasionally result in errors, including content being delivered to incorrect accounts or platforms. We do not use automated decision-making that produces legal effects or similarly significantly affects you within the meaning of Article 22 GDPR.

You have the right not to be subject to a decision based solely on automated processing. If you believe an automated process has adversely affected you, please contact us at [email protected] to request human review.

Automated sign-up screening. For transparency we describe the only fully automated decisions we make at the point of registration, even though we consider that they do not produce legal or similarly significant effects and therefore fall outside Article 22 GDPR:

Both measures exist to prevent abuse of the free tier and fraud, on the basis of our legitimate interest (Article 6(1)(f) GDPR). They never rely on profiling and never assess you as a person. If your registration is refused and you believe it should not have been, write to [email protected] or [email protected]: a human reviews the case and can create the account manually.

Account suspension for breach of the Terms of Use is always decided by a person, never automatically, and you are told why and can reply.

3.6 AI-Powered Features

Several features of Upload-Post are powered by generative AI. So that you know exactly what leaves our servers, this is what is sent, to whom, and for what:

We use the paid tier of the Gemini API. Under the Google APIs Terms of Service for paid services, Google does not use the content submitted through it to train or improve its own models, and does not use it for any purpose other than returning the response we requested. Google LLC is certified under the EU-U.S. Data Privacy Framework, and EU Standard Contractual Clauses apply in addition. The legal basis for providing an AI feature you request is the performance of our contract with you (Article 6(1)(b) GDPR).

Third parties in your videos. If the media you submit shows or records other people, you are responsible for having a lawful basis to process their data and for informing them, as set out in our Data Processing Agreement and in Section 4.5 below.

Our own model training, and how to opt out. We do not use your User Content in identifiable form to train shared AI models. We reserve the right to use User Content and associated analytics in aggregated and/or de-identified form to develop, train, evaluate and improve our own caption and title models, which power features offered to all users; where we do, the training corpus excludes the profile user name and any account identifier. We do not operate such a training pipeline at present — the AI features in the Services run on third-party models that are named on our Sub-processors page and that do not train on the content we submit. The legal basis is our legitimate interest in improving the Services (Article 6(1)(f) GDPR).

You can object at any time (Article 21 GDPR). Email [email protected] with the subject "AI Training Opt-Out" and we will record the objection against your account and honour it for all future training. Business customers can also have the exclusion written into their Data Processing Agreement.

All AI providers that process Personal Data on our behalf are named on our Sub-processors page.

3.7 AI Assistants and MCP Integrations

You can use Upload-Post through third-party AI assistants (for example Claude or ChatGPT) via our MCP server and API integrations. When you do, we receive only the specific tool inputs the assistant sends to Upload-Post (for example a caption, a media file, or a scheduling request) and we return the corresponding outputs. We never receive your full conversation with the assistant. Your conversation with the assistant itself is governed by the assistant provider's own terms and privacy policy, not by this Privacy Policy.

4. Information Sharing and Disclosure

We do NOT sell your personal data. We may share your information in the following circumstances:

4.1 Service Providers and Sub-processors

We engage the third parties named below to operate the Services. This table, the public Sub-processors page and Annex III of our Data Processing Agreement are generated from the same source and are therefore identical. Last updated: September 4, 2026.

Recipient What they do for us Processing location Transfer safeguard
Hetzner Online GmbH Cloud hosting and infrastructure: application servers, MongoDB and Redis databases, back-up staging, GPU/staging server (balrog) and every self-hosted service listed below. Germany (EU) Intra-EEA; no third-country transfer.
Cloudflare, Inc. R2 object storage for media files uploaded for publication (media.upload-post.com and the scheduler bucket), plus CDN and DNS for our domains. European Union (R2 EU jurisdictional restriction) / United States (corporate access) EU-U.S. Data Privacy Framework (Cloudflare, Inc. is certified) and EU Standard Contractual Clauses (Decision (EU) 2021/914) for any transfer outside the EEA.
Google Cloud EMEA Limited / Google LLC (Google Cloud Storage) Encrypted-at-rest object storage for database back-ups, compressed server logs, copied profile pictures and scheduler payloads (buckets mongodb-img2html, logs-back, pfp-social-pics-upload-post-eu3, upload-post-schedulers-eu3). European Union (EU multi-region buckets) / United States (corporate access) EU-U.S. Data Privacy Framework (Google LLC is certified) and EU Standard Contractual Clauses, under the Google Cloud Data Processing Addendum.
Google LLC (Gemini API, paid tier) AI features: analysis of the full video you submit to the Shorts analyser (image and audio), generation of captions, titles, descriptions and hashtags, the support assistant and the documentation assistant. United States EU-U.S. Data Privacy Framework and EU Standard Contractual Clauses. On the paid tier Google does not use the submitted content to train its models (Google APIs Terms of Service — Paid Services).
Google Ireland Limited / Google LLC (Google Ads) Advertising measurement: the gtag conversion tag on the website (marketing cookies only, and only with your consent) and the Offline Conversions API, to which a SHA-256 hash of the buyer email address is sent when a subscription is paid. Ireland (EU) / United States EU-U.S. Data Privacy Framework and EU Standard Contractual Clauses, under the Google Ads Data Processing Terms.
Reddit, Inc. Advertising measurement for our Reddit campaigns: the Reddit advertising pixel (marketing cookies only, and only with your consent) and the Reddit Conversions API, to which a SHA-256 hash of the buyer email address is sent when a subscription is paid. United States EU Standard Contractual Clauses (Decision (EU) 2021/914) and supplementary measures.
Stripe Payments Europe, Ltd. / Stripe, Inc. Hosted checkout, subscription billing, invoicing, automatic VAT calculation and VAT-number collection. Card data is entered on Stripe pages and never reaches our servers. Ireland (EU) / United States EU-U.S. Data Privacy Framework and EU Standard Contractual Clauses.
Amazon Web Services EMEA SARL (Amazon SES) Transactional email delivery: magic sign-in links, account and billing notifications. France (eu-west-3) Intra-EEA primary processing; EU Standard Contractual Clauses for incidental support access.
Namecheap, Inc. (PrivateEmail / Titan) Hosted mailbox for [email protected] — receipt of customer correspondence and support requests — and fallback SMTP relay when Amazon SES is unavailable. United States EU Standard Contractual Clauses.
Listmonk (self-hosted by TONVI TECH SL) Self-hosted Newsletter and product-marketing email list (churnkiller.upload-post.com). Only subscribers who opted in receive marketing email; every message carries a one-click unsubscribe link. Germany (EU) — our own server at Hetzner Intra-EEA; no third-party processor involved.
OpenPanel (self-hosted by TONVI TECH SL) Self-hosted Product and website analytics (api.openpanel.fotoexamen.com). The browser SDK is served from www.upload-post.com itself, so no third-party host sees your IP address. Analytics only runs with your consent. Germany (EU) — our own server at Hetzner Intra-EEA; no third-party processor involved.
Upload-Post media processing service "balrog" (self-hosted by TONVI TECH SL) Self-hosted Server-side video processing with ffmpeg (trimming, re-encoding, subtitles, format conversion) for the media you submit. Processed results are deleted after 24 hours. Germany (EU) — our own server at Hetzner Intra-EEA; no third-party processor involved.
Upload-Post affiliate platform (self-hosted by TONVI TECH SL) Self-hosted affiliates.upload-post.com — attribution of affiliate clicks and commissions. Receives the affiliate code, landing page, referrer and any advertising click identifiers, and later the conversion, plus the payout details of affiliates who join the programme. Germany (EU) — our own server at Hetzner Intra-EEA; no third-party processor involved.
Aikount — TONVI TECH SL Self-hosted Statutory invoicing and accounting for the invoices we are legally required to issue and keep (api.aikount.com). Receives the billing identifiers of the transaction (Stripe customer id, amounts, tax data). Spain (EU) — operated by the controller itself Intra-EEA; same corporate group as the controller.
Telegram Messenger Inc. Internal operational and security alerts to the engineering channel (failed payments, sign-up abuse, platform restrictions). Being phased out; the alerts currently sent contain only pseudonymised identifiers (an 8-character hash plus the email domain) and a truncated IP address, never a full email address. Outside the EEA (United Arab Emirates / United Kingdom) EU Standard Contractual Clauses are not available for this channel; the transfer is minimised to pseudonymised identifiers and the channel is being replaced by an internal alerting system.

Two corrections to earlier versions of this policy, made in version 2.4:

4.2 Social Media Platforms

When you use our Services to post content, your content and associated metadata are transmitted to the social media platforms you have connected. This transmission is necessary to provide our core service functionality. You acknowledge that once content is transmitted to a third-party platform, it is subject to that platform's terms and privacy policies, and we cannot guarantee its retrieval, modification, or deletion from those platforms.

These platforms may process data in countries outside the European Economic Area, including the United States and other jurisdictions, under their own roles as independent controllers and their own transfer mechanisms. You should review the privacy policy and platform terms of each connected social media service.

4.3 Legal Requirements

We may disclose your information if required by law, court order, or governmental authority, or when we believe disclosure is necessary to:

4.4 Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you of any such change and your choices regarding your data.

4.5 Data About People Who Are Not Our Customers (Article 14 GDPR)

When a customer uses Upload-Post, the Services necessarily handle data about people who have no relationship with TONVI TECH SL. We set this out expressly, as Article 14 GDPR requires when personal data is not obtained from the data subject:

Roles. For all of the above, the customer is the data controller and Upload-Post acts solely as a processor on their documented instructions, under our Data Processing Agreement. We do not use this data for our own purposes, we do not sell it, we do not send comments or direct messages of third parties to any AI provider, and we do not build advertising profiles from it.

What this means for our customers. If you use Upload-Post you are responsible for having a lawful basis for processing the data of these people and for informing them, in your own privacy notice, that you use a publishing and engagement tool that stores their messages and audience data on your behalf. If you publish media featuring identifiable people, you are responsible for the consent or other lawful basis required.

If you are one of those people and you wish to exercise your rights, address your request to the customer who operates the account — they are the controller. You may also write to [email protected]: we will forward the request to the relevant customer without undue delay and assist them in answering it, as Article 28(3)(e) GDPR requires.

5. International Data Transfers

Your data may be transferred to and processed in countries outside the European Economic Area (EEA). When we transfer data outside the EEA, we ensure appropriate safeguards are in place:

6. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

7. Data Retention

We retain your personal data for as long as necessary to:

Specific retention periods, aligned with the deletion jobs that actually run on our systems:

Data Retention
Account data (profile, connected accounts, tokens)Until you delete the account, plus a 30-day grace period during which you can restore it
Invoices and transaction records6 years, as required by Article 30 of the Spanish Commercial Code and the General Tax Act. These are kept even after account deletion; that obligation overrides erasure.
User Content (media uploaded for publication)Until you delete it or the account is deleted; temporary media handled through the API is removed after 24 hours
Server logs (gs://logs-back archive included)90 days
Database back-ups30 days. A deletion request is applied to live systems immediately; back-ups age out within 30 days and are never used to repopulate deleted accounts.
Record of emails sent to you (sent_emails_log, contains sign-in links)30 days
Support chat transcripts and tickets12 months
Documentation chat questions90 days, with no IP address stored
Shorts analyser records30 days
AI usage records (which feature, when, how many tokens)12 months
Direct messages and comment logs (including third-party authors)90 days
Analytics and audience snapshots26 months
Video processing jobs and their results24 hours for the output file, 30 days for the job record
Free accounts with no sign-in activity24 months, after which we send a warning email and then delete the account
Marketing cookies and attribution identifiers60 to 90 days — see the Cookie Policy

When a retention period expires, the data is deleted or irreversibly anonymised. Where a legal obligation requires us to keep a record (invoicing, accounting, defence of legal claims), we keep only that record and restrict all other processing of it.

8. Cookies, Tracking Technologies and Marketing Consent

The complete inventory — every cookie and storage key, its provider, purpose, category and duration — is published in our Cookie Policy. This section summarises it.

No analytics or advertising script is loaded until you have given consent through our consent banner. Rejecting is as easy and as visible as accepting, and Google Consent Mode v2 is initialised in a denied state as the first instruction of every page. You can change or withdraw your choice at any time with the "Cookie settings" button in the footer of every page.

8.1 Strictly Necessary

Your consent record (up_consent) and your light/dark theme preference. Exempt from consent under Article 22.2 LSSI-CE; they cannot be disabled without breaking the site.

8.2 Analytics

OpenPanel, self-hosted on our own server at api.openpanel.fotoexamen.com (Hetzner, Germany). The browser script is served from www.upload-post.com itself, so no third-party host receives your IP address. OpenPanel sets no cookie, but it does write one sessionStorage key, which is why it still requires your consent under Article 22.2 LSSI-CE. It only runs if you accept the analytics category. We do not use Google Analytics, Google Tag Manager, Meta Pixel, TikTok Pixel, LinkedIn Insight, Hotjar, Clarity or PostHog.

8.3 Marketing and Attribution

Only with your consent: the Google Ads conversion tag, the Reddit advertising pixel, and our own first-party affiliate and attribution cookies (aff_ref, 60 days; up_attribution, 90 days; __td_conversion_id__, 90 days). We also send a SHA-256 hash of the buyer's email address to Google Ads and Reddit through their server-side conversion APIs when a subscription is paid, so that a purchase can be matched to the campaign that produced it.

8.4 Marketing Emails — a Separate Consent

Consent to marketing cookies is not consent to marketing emails, and earlier versions of this policy wrongly suggested the cookie banner covered both. There are three independent controls:

9. Your Rights (GDPR)

Under GDPR, you have the following rights regarding your personal data:

9.1 Exercising Your Rights

To exercise any of these rights, please contact us at:

We will respond to your request within one month. Where permitted by GDPR, this period may be extended by up to two additional months if the request is complex or numerous, and we will inform you of any extension within the first month. We may need to verify your identity before processing your request.

9.2 YouTube API Data

If you have authorized our application to access your YouTube data:

10. Children's Privacy

Our Services are intended exclusively for users who are at least 18 years old and have the legal capacity to enter into a binding agreement. Our Services are not directed at minors, and we do not knowingly collect personal data from anyone under 18. If we become aware that we have collected personal data from a minor, we will delete that information promptly. If you believe we have inadvertently collected data from a minor, please contact us at [email protected].

11. Third-Party Links

Our Services may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to read the privacy policies of any third-party services you access.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a prominent notice on our website at least 30 days before the changes take effect. Your continued use of our Services after the effective date constitutes acceptance of the updated Privacy Policy.

13. Supervisory Authority

If you are located in the European Union and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection authority. In Spain, this is the Agencia Española de Protección de Datos (AEPD): www.aepd.es

14. Contact Us

For any questions or concerns about this Privacy Policy or our data practices, please contact us:

Document Version: 2.4
Last Updated: September 4, 2026
Effective Date: April 27, 2024