This Privacy Policy explains what data ScheduleLater (the “Service”) collects, how we use and store it, and the choices you have. By using the Service you agree to this policy.
Information we collect
- Account information — your name, email, and workspace settings.
- Content you create — the posts, captions, media, and schedules you author.
- Connected-platform data — when you connect a social account, we store an encrypted access credential and cached data returned by that platform’s API (for example, your channel or profile name and post analytics) so we can publish on your behalf and show your results.
Facebook and Instagram
ScheduleLater publishes to Facebook Pages and Instagram professional accounts through Meta’s APIs. Instagram can be connected two ways — through the Facebook Page it is linked to, or by signing in to Instagram directly — and the two ask for differently named permissions for the same job. Below is every permission ScheduleLater requests and what it is used for. We request nothing beyond this list.
On a Facebook Page.
- pages_show_list — list the Pages you manage, so you can choose which one to connect.
- pages_read_engagement — read the connected Page’s own details (its name, id and picture) to identify it in the app.
- pages_manage_posts — publish the posts you schedule to that Page. Without it a scheduled post cannot be created at all.
- pages_manage_engagement — post the first comment you wrote alongside a post, at the moment it publishes.
- pages_read_user_content — required by Meta on the same request that sets a video’s cover image. ScheduleLater does not read anyone’s posts or comments; this permission exists solely because setting the cover is refused without it.
- read_insights — read the Page’s and its posts’ performance figures, which is what the Insights charts are made of.
- business_management — see Pages that belong to a business portfolio. Without it such a Page does not appear in the list at all, so it could never be connected.
On an Instagram professional account connected through Facebook.
- instagram_basic — identify the connected Instagram account (its id, username and picture).
- instagram_content_publish — publish the posts, reels and stories you schedule.
- instagram_manage_insights — read that account’s and its posts’ performance figures for Insights.
- instagram_manage_comments — post the first comment you wrote alongside a post.
- pages_show_list, pages_read_engagement and business_management — this connection route reaches the Instagram account through the Facebook Page it is linked to, so it needs the same three Page permissions to find it.
On an Instagram account connected directly. The same four capabilities under Instagram’s own names, and no Page permissions, because this route never involves a Page: instagram_business_basic, instagram_business_content_publish, instagram_business_manage_insights and instagram_business_manage_comments.
We store an encrypted authorization for the connected account, the identifiers and handle above, the posts we published for you, and the performance figures we read back. We do not sell this data, use it for advertising, or share it with third parties for their own purposes. Meta does not offer apps a way to hand an authorization back, so disconnecting deletes our copy immediately but cannot retire it on Meta’s side — you can remove ScheduleLater yourself from the apps and websites list in your Facebook or Instagram settings, and our deletion instructions say where.
YouTube API Services
ScheduleLater’s YouTube features use YouTube API Services. By using them you also agree to the YouTube Terms of Service, and your data is handled in accordance with the Google Privacy Policy.
When you connect a YouTube channel, with your authorization ScheduleLater:
- reads your channel’s basic information (name, id, and thumbnail) to identify the connected account;
- uploads and publishes videos to your channel at the times you schedule;
- reads your video and channel analytics to show performance inside the app.
We store an encrypted OAuth token for your channel and a cached copy of the analytics and video status we retrieve. We do not sell this data, use it for advertising, or share it with third parties for their own purposes.
Storage, refresh, and deletion of YouTube data
- Refresh or purge within 30 days. Cached YouTube data (analytics snapshots and rollups) is refreshed or automatically deleted within 30 days.
- Revoke on disconnect. When you disconnect a YouTube channel or delete your account, we immediately revoke the OAuth grant with Google, delete the stored credential, and delete the cached YouTube data we hold for that channel. Content you authored in ScheduleLater is kept as your own record, separate from cached API data.
- Revoke at Google. You can also review and revoke ScheduleLater’s access at any time from your Google Account security settings.
TikTok
ScheduleLater’s TikTok features use the TikTok API. When you connect a TikTok account, with your authorization ScheduleLater:
- reads your profile’s basic information (open id, username, display name, avatar, and follower count) to identify the connected account;
- reads your account’s current posting settings — the privacy levels available to you, whether comments, duets, or stitches are turned off, and your maximum video length — immediately before each post, so the app never offers you an option your account does not allow;
- posts the videos and photos you schedule, with the visibility and disclosures you select.
We store an encrypted authorization for your account. We do not store a copy of your TikTok posting settings — they are read fresh each time and discarded — and TikTok does not make post analytics available to this app, so we hold none. We do not sell your data, use it for advertising, or share it with third parties for their own purposes.
- Revoke on disconnect. When you disconnect a TikTok account or delete it, we immediately revoke the authorization with TikTok and delete the stored credential. Content you authored in ScheduleLater is kept as your own record.
- Reconnecting after a year. TikTok authorizations expire 365 days after you first grant them, and renewing them does not extend that date. We show a reminder on the Accounts page before yours lapses; reconnecting grants a fresh year.
- Revoke at TikTok. You can also review and remove ScheduleLater’s access at any time from the TikTok app, under Settings and privacy → Security and permissions.
How we use your data
We use your data to operate the Service — to publish your scheduled content, show your analytics, secure your account, and support you. We use encrypted credentials only to perform the actions you authorize on the connected platform.
Who we share it with
We do not sell your data and we do not share it with anyone for their own purposes. We use a small number of service providers to run the product, each handling data only on our instructions:
- Hosting and database (Railway) — where the application runs and your workspace’s data is stored.
- Object storage (Cloudflare R2) — where the media you upload is kept until it is published and for a short window afterwards.
- AI text generation (Anthropic) — when you use the Discover or generation features, the text of the idea or draft you are working on is sent to be rewritten and the result returned. This happens only when you ask for it, it is never used to train a model, and your media is never sent.
- Email delivery (Resend) — the transactional messages we send you, such as email verification and password resets.
We may also disclose data where the law requires it, and we will tell you unless we are prohibited from doing so.
How long we keep it
- While your account exists, we keep what you authored — your posts, media, schedules and settings — until you delete it or delete your account.
- Cached platform data (analytics and profile details we read from a platform’s API) is kept only while that account is connected. Disconnecting the account deletes it immediately, and so does deleting your ScheduleLater account.
- YouTube data specifically is refreshed or automatically deleted within 30 days, as described above.
- Uploaded media originals are deleted 7 days after the post publishes — the platform hosts the published copy from then on. The small preview image we generated is kept so your own history still renders.
- TikTok posting settings are never stored at all: they are read immediately before each post and discarded.
Security
Platform credentials are encrypted at rest with envelope encryption, and we never log tokens or secrets. Access to your workspace’s data is isolated per tenant.
Your choices
- Disconnect any connected account at any time from the Accounts page. This deletes the stored authorization and the analytics we had cached for it, and keeps the posts you wrote.
- Remove a connected account from your workspace entirely, which additionally removes its posts.
- Delete your ScheduleLater account and everything in it — our deletion instructions explain exactly what that removes, how to ask, and how long it takes.
Changes
We may update this policy; material changes will be reflected by the “Last updated” date above.
Contact
Privacy questions can be sent to privacy@schedulelater.com.