Privacy

Privacy Policy

Last updated 1 October 2026

FeedStreak is a service for uploading finished short-form videos and publishing them to social accounts you connect. This policy describes the information the application actually stores and how it is used.

Who this policy covers

FeedStreak is the name of this service. A registered legal entity name is not published on this page.

FeedStreak is available at https://feedstreak.com. It is a workspace product: you sign in, upload videos, connect channels you control, and queue posts to those channels. It is not a social inbox, and it does not ask you to hand over a social network password.

Account information

When you create an account, we store your email address, the name you enter, and a salted hash of your password. We do not store the password itself. Sign-in uses that account. A session cookie keeps you signed in.

A new account creates a workspace. The workspace stores its name, the brands you add, member roles, and the timezone used for schedules.

Connected social accounts

You choose which destinations to connect. Depending on what is configured for the service, those destinations can include YouTube, Facebook, Instagram, Threads, TikTok, LinkedIn, Pinterest, and X. Connecting a destination starts an OAuth login on that platform. FeedStreak does not request, see, or store the password for that social account.

After you approve the connection, the platform may return an access token and, when that platform issues one, a refresh token. Those tokens are encrypted with AES-256-GCM before they are stored. They are used to perform the connection, token refresh, and publishing you requested for that destination. They are not used to sign in to an unrelated service.

From the platform, we store the account identifier it returns, the display name, a username when one is provided, an avatar URL when one is provided, and the permission scopes you granted. Examples of identifiers are a YouTube channel id, a TikTok open id, or a Facebook Page or Instagram account id. If you turn on analytics for a connection, we may also request the extra read scopes that platform uses for post statistics.

Content you upload and schedule

We store the videos you upload, captions and other post text, schedule times, per-platform settings such as privacy level, and the status of each publish attempt. When a platform accepts a post, we store the identifier it returns and error details if a publish fails.

Video files go to a private object-storage bucket. The browser uploads and reads a file with a short-lived signed URL. FeedStreak does not publish those files as public website objects.

Technical data used to run the service

We store workspace membership, product events such as a completed signup or a channel connection, and short-lived OAuth handshake records. The handshake stores a hash of the OAuth state value, not a token you could reuse. Server logs are not a place for captions, tokens, or credentials.

How the information is used

We use this information to:

  • authenticate you and keep your workspace separate from other customers
  • store your videos and the posts you queue
  • send a queued post to the destination accounts you selected
  • refresh a token when the platform requires it so a later publish can continue
  • show connection status, publish results, and optional post statistics you enabled
  • operate, secure, and debug the service

Service providers

The current production setup uses these providers to run the product. Each one processes the data required for its role:

  • Vercel hosts the web application.
  • Supabase provides the PostgreSQL database that stores accounts, workspaces, schedules, and encrypted tokens.
  • Cloudflare R2 stores uploaded video files in a private bucket.
  • Stripe processes a paid subscription when billing is turned on for the deployment. FeedStreak then stores the subscription status and Stripe customer identifier. Card numbers are entered with Stripe.
  • An optional caption assistant, if that feature is configured, receives the text you submit to it. The feature stays off unless the deployment has it configured. This policy does not name a model vendor, because the endpoint is configured per deployment.

Social platforms

When you connect a platform or queue a post, that platform receives the content and account data needed to complete the action you requested. YouTube and other Google services, TikTok, Meta services such as Facebook and Instagram, Threads, and any other network you connect each process that information under their own terms and privacy policies. FeedStreak does not control those policies.

Their privacy policies include: Google, TikTok, Facebook, Instagram, Threads, LinkedIn, Pinterest, and X.

Sale of personal information

FeedStreak does not sell your personal information. We share it with the providers and platforms above so the service you asked for can run.

How long information is kept

Account, workspace, and library data stay until you delete them or ask us to delete the account. There is no single retention period that applies to every record.

Videos you delete move to Recently deleted and the file is kept for 30 days, then removed. A database record of the removed file can remain so publishing history still makes sense. A workspace can optionally move videos to Recently deleted 30, 90, or 180 days after the last successful publish. That option is off unless the workspace turns it on.

Disconnecting a channel does not by itself delete the whole workspace. See the data deletion page for what happens to tokens. Some records may be kept where they are still needed to finish a publish already in progress, to protect the service from abuse, or where the law requires it. This policy does not state a fixed statutory retention period.

Access, correction, and deletion

You can review and edit your videos, captions, schedules, and connected channels inside the product. You can disconnect an individual channel from Accounts. A control that deletes the entire FeedStreak account from inside the product is not available. To ask for access, a correction, or deletion of the account, use the contact details on this page and on the data deletion page.

Depending on where you live, you may have additional privacy rights. This policy does not claim a particular certification or that every local privacy law has been formally assessed.

Security

Passwords are stored as salted hashes. Social tokens are encrypted before storage. Access to a workspace requires an authenticated session, and members see the brands in that workspace. These are ordinary safeguards for this application. They are not a certification, and no method of transmission or storage is perfectly secure.

Children

FeedStreak is a tool for people who publish short-form video. It is not directed at children under 13, and we do not knowingly collect personal information from children.

International processing

The hosting, database, and media providers named above may process information in more than one country. This policy does not claim that data stays in a single region.

Changes

We may update this policy by posting a new version at this URL. The date at the top is the date of the current version.

Contact

A public contact email is not listed on this page yet. Until an address is published here, this page cannot receive email requests.