Privacy Policy
This Privacy Policy explains how postiz.sinaleev (the application available at postiz.sinaleev.ru, referred to below as “postiz.sinaleev”, “the service”, “we”, “us”) collects, uses, stores and deletes information.
Effective date: 26 August 2026. Last updated: 18 September 2026.
1. Who operates postiz.sinaleev
postiz.sinaleev is operated by Pavel Sinaleev, sole proprietor, Moscow region, Russian Federation, an independent marketing studio that plans and publishes social media content for its clients. The operator is the data controller for the information described in this policy. Contact: pavel@sinaleev.ru.
2. Scope
This policy covers the website postiz.sinaleev.ru and the postiz.sinaleev application hosted on it. It applies to workspace users (studio editors and clients) and to the owners of social media accounts connected to postiz.sinaleev. It does not cover the social platforms themselves — their own privacy policies govern what happens inside TikTok, Instagram, VK, Telegram or Threads.
3. What information we collect
3.1 Workspace account data
Email address, display name and a hashed password for each person with access to a workspace, plus the workspace and client names the studio creates. Provided directly by the user.
3.2 Content submitted for publication
Videos, images, captions, hashtags, publication times, per-platform settings (for TikTok: privacy level, comment/duet/stitch settings and the commercial-content disclosure), and the drafts and approvals around them.
3.3 Data received from connected social platforms
When an account owner authorises postiz.sinaleev on a platform's own authorisation screen, we receive:
- Access and refresh tokens issued by the platform, limited to the permissions shown on that screen;
- Basic profile information of the connected account — platform user identifier, username, display name, avatar image;
- Publication results returned by the platform — the identifier and link of a published post, or the error if publishing failed.
For TikTok specifically, postiz.sinaleev requests the scopes user.info.basic, user.info.profile, video.upload, video.publish and uses the data obtained under them only to display the connected account in the workspace and to upload and publish the videos the user scheduled. We do not collect TikTok private messages, follower or following lists, viewing history, contacts, or any data about people other than the owner of the connected account.
For Threads specifically, postiz.sinaleev requests the permissions threads_basic, threads_content_publish, threads_manage_replies, threads_read_replies, threads_manage_insights, threads_keyword_search. Under them we receive and use only:
- Replies to the connected account's own posts — reply identifier, text, author's username, time and link, and whether the reply is hidden. Used to show the owner the conversation under their posts, to let the owner answer in that conversation, and to hide replies the owner considers spam or advertising;
- Public posts found by keyword search — post identifier, text, author's username, time and link, returned for keywords the account owner chose (for example, “looking for a video editor”). Used only to show the owner a list of public posts relevant to their services, so that the owner can decide whether to reply publicly from their own account;
- Insights of the connected account's own posts — views and interactions, shown to the owner.
We do not collect Threads private messages, follower lists or any non-public data of other users, we do not build profiles of the authors of public posts, and we do not sell, share or use this data for advertising.
3.4 Technical logs
Server logs of requests to the service: IP address, date and time, user agent, requested address, error codes. Used for security and troubleshooting.
We do not collect special categories of personal data, payment card data, precise location, or advertising identifiers, and we do not use tracking cookies or third-party analytics on this website. The application itself uses cookies strictly necessary to keep a signed-in session.
4. How we use the information
- To publish, at the time chosen by the user, the content the user scheduled to the accounts the user connected;
- To show which accounts are connected and what has been published, is queued, or has failed;
- To authenticate workspace users and keep their sessions;
- To keep the service secure, diagnose failures and prevent abuse;
- To answer support and privacy requests.
We do not sell personal data, we do not share it for advertising, we do not use it to build profiles, and we do not use content or platform data to train machine learning models.
5. Legal basis
We process the data to perform the agreement between the studio and its client (planning and publishing that client's content), on the basis of the consent the account owner gives on the platform's authorisation screen, and on the basis of our legitimate interest in keeping the service secure. Consent can be withdrawn at any time by disconnecting the account.
6. Who has access to the data
- The studio's authorised staff — only those working on the client's content;
- The social platforms — content and the accompanying settings are transmitted to the platform the user selected, in order to publish it there;
- Our hosting provider (Hostkey B.V., the Netherlands; the server is located in Frankfurt am Main, Germany), which provides the physical server on which the service runs and has no independent use of the data.
Beyond this, data is disclosed only where the law requires it. There are no data brokers, advertising networks or analytics vendors involved.
7. Storage and security
All data is stored on a dedicated server rented by the operator in Germany (Frankfurt am Main). Traffic to and from the service is encrypted with TLS. Access tokens are stored in a database that is not exposed to the public internet; administrative access to the server requires an SSH key. Accounts in the workspace are password-protected and access is limited to the people the studio invites.
8. How long we keep it
- Access and refresh tokens — until the account is disconnected or access is revoked on the platform's side, at which point the token is deleted;
- Content and schedules — while the workspace is active, and up to 12 months afterwards so that the publication history remains available to the client;
- Workspace account data — while the account exists;
- Public posts found by keyword search and replies under the owner's posts — up to 30 days, then deleted;
- Technical logs — up to 90 days.
9. Your rights
You may ask us to confirm what data we hold about you, to correct it, to delete it, or to stop processing it, and you may withdraw your consent at any time. The fastest way to stop all processing of a connected account is to disconnect it in the workspace or to revoke access on the platform — in TikTok: Settings and privacy → Security and permissions → Manage app permissions.
To make a request, write to pavel@sinaleev.ru naming the social accounts involved. We confirm receipt and complete deletion requests within 30 days; tokens are revoked immediately. If you believe your rights have been infringed, you may also complain to the data protection authority in your country.
10. Children
postiz.sinaleev is a business tool and is not directed at children. We do not knowingly create workspaces for, or process data of, anyone under the age of 18. If we learn that we hold such data, we delete it.
11. International transfers
The service runs on a server in Germany (Frankfurt am Main) and is operated from the Russian Federation, so data may be accessed from both countries. When content is published, it is transmitted to the social platform chosen by the user and processed by that platform under its own policy and in the jurisdictions it operates in.
12. Third-party platforms
Publishing to TikTok is performed through the TikTok Content Posting API and is additionally governed by TikTok's own terms and privacy policy, which apply to what happens to a video once it is published on TikTok. The same is true for Instagram, Threads, VK and Telegram.
13. Changes to this policy
If this policy changes, the updated version is published at https://postiz.sinaleev.ru/privacy with a new “last updated” date. Material changes are communicated to workspace users by email before they take effect.
14. Contact
Pavel Sinaleev, sole proprietor, Moscow region, Russian Federation — pavel@sinaleev.ru.