Information we collect
When you register, we store your name, email, password hash, email verification state and session records. When you authorize a platform, we receive account identifiers, display names, profile images, granted permissions and access or refresh tokens. We store uploaded media, the settings and consent for your publications, and publication identifiers, outcomes and links. For Meta Ads we request ad account details, campaigns and performance metrics when you open the Ads workspace. We use temporary hashed request identifiers to limit abuse.
Why we use it
We use this information to authenticate you, connect the accounts you authorize, display destinations, publish the content you approve, report publication status, perform the campaign actions you request and protect the service. We do not sell personal data, build advertising profiles, or use platform data to train AI models. We do not automatically modify your content or publish without your instruction.
Platform services and sharing
Relayboard uses Meta, TikTok and YouTube API Services. Content and selected settings are sent to the destination you approve. Platform tokens remain encrypted on our servers and are not returned to your browser or API clients. Our hosting, database, object storage and email infrastructure process data to operate this service. Public media delivery URLs allow the selected platform to fetch uploaded content; do not upload confidential material. Interface fonts are served from our own website without requests to Google Fonts. We do not add advertising trackers.
Use of YouTube is subject to the YouTube Terms of Service. See the Google Privacy Policy, Meta Privacy Policy and TikTok Privacy Policy.
Google API data
Relayboard’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use authorized YouTube data to provide the channel and publishing functions you request, and do not use it for advertising, data brokerage or unrelated purposes.
Retention and security
We keep account records until deletion. Sessions expire after seven days and API keys after 90 days. Uploaded media and publication records are kept for up to 30 days. Account information retrieved from platforms is refreshed at least daily while access remains valid, or removed if it cannot be refreshed within 30 days. Ad performance is retrieved on demand. Verification links expire after one hour and OAuth transactions after ten minutes. Opaque deletion status records are kept for up to 90 days.
We restrict access by user, encrypt provider credentials at rest, use HTTPS in production and store hashes rather than raw passwords, session credentials and API keys. Routine service logs must not contain provider tokens or uploaded content. Encrypted infrastructure backups may retain deleted records until their documented rotation expires; restored systems must reapply outstanding deletion requests before serving data.
Your choices and deletion
Disconnect a platform in Connections to remove its saved connection and publication data. Meta authorization applies across sibling Facebook, Instagram and Ads connections, so these may be disconnected together. Remove all saved data in Settings → Delete your account. Published posts remain on the platforms and must be managed there.
You may also revoke Google access at Google Account permissions, remove Relayboard in Facebook Apps and Websites, or use TikTok’s Manage app permissions. Revocation stops future access. To request access, correction, export or deletion, email [email protected] from your registered address. We complete deletion requests within seven days. See data deletion instructions.
Legal basis and rights
We process account and publishing data to provide the service you request, optional platform access with your authorization, and security records for our legitimate interest in preventing abuse. Where applicable, you may request access, correction, erasure, portability or restriction, object to processing, withdraw consent and complain to your local supervisory authority. Service providers may process data in countries outside your own; applicable safeguards must be maintained by the operator.
Children and changes
Relayboard is intended for adults and is not directed to children. Contact us if a child’s information has been submitted. We publish policy changes here and notify registered users of material changes.