חזרה לבלוג
Legal

Day2 Social Publisher — Privacy Policy

Privacy Policy for Day2 Social Publisher, the social-media publishing service operated by Day2 AI.

מנהל מערכת
1 בינואר 2026
7 דק׳ קריאה

Day2 Social Publisher — Privacy Policy

Last updated: July 22, 2026

This Privacy Policy describes how Day2 AI ("Day2", "we", "us") collects, uses, and protects personal data in connection with Day2 Social Publisher (the "Service"), our social-media publishing tool available at https://postiz.day2-ai.com, which publishes content to TikTok, Instagram, and Facebook on behalf of our business clients ("Clients") via those platforms' official APIs.

1. Data We Collect

  • Account data. Name, email address, and login credentials for the Service itself (for Client team members who sign in to the Service).
  • Social account connection data. When a Client connects a social account through the platform's official OAuth flow, we receive and store: the platform account identifier (e.g., Facebook Page ID, Instagram professional account ID, TikTok open ID), the account's display name and avatar, and the OAuth access and refresh tokens issued by the platform. We never receive or store your social-media password.
  • Content data. The media (videos, images) and text (captions, hashtags) that Clients provide to be published, along with scheduling metadata (when and where to publish).
  • Publishing metadata. Post identifiers, publish status, and basic engagement metrics returned by the platform APIs (where the granted permissions include them), used to show Clients the status and performance of their own posts.
  • Technical logs. Standard server logs (IP address, timestamps, request identifiers) kept for security and troubleshooting.

2. How We Use the Data

  • To publish content to the Client's own connected social accounts, at the Client's instruction, via the official TikTok and Meta APIs. This is the core and only purpose of the tokens we store.
  • To show Clients the status of their scheduled and published posts.
  • To secure, maintain, and troubleshoot the Service.
  • We do not sell personal data. We do not use Client content or social-account data for advertising, profiling, or training machine-learning models. We do not read or collect data from accounts other than those explicitly connected by the Client.

3. Legal Bases (GDPR)

Where the GDPR applies, we process data on the basis of: performance of a contract with the Client (Art. 6(1)(b)); our legitimate interests in securing and operating the Service (Art. 6(1)(f)); and consent expressed through the platform OAuth authorization, which you may withdraw at any time by revoking the app's access.

4. Storage and Security

  • The Service is self-hosted on Day2-controlled servers in the European Union (Germany). Data is not shared with third-party analytics or advertising providers.
  • OAuth tokens are stored encrypted at rest and transmitted only over HTTPS/TLS.
  • Access to production systems is restricted to authorized Day2 personnel under least-privilege access controls, and access is logged.

5. Sharing

We share data only with: (a) the social platforms themselves (TikTok, Meta) — sending them the content to be published and the API calls needed to publish it, under their own terms and privacy policies; and (b) infrastructure providers that host the Service (server and network providers), acting as processors under contract. We do not share data with any other third parties unless required by law.

6. Retention

  • OAuth tokens are kept only while the social account remains connected. When a Client disconnects an account — or revokes the app's access from the platform's settings — the associated tokens are deleted from the Service.
  • Media and captions are kept while the Client uses the Service, so scheduled posts can be published and the post history displayed, and are deleted upon Client request or termination of the Client relationship.
  • Technical logs are retained for up to 12 months for security purposes.

7. Your Rights

Subject to applicable law (including the GDPR and Israel's Privacy Protection Law), you have the right to access, rectify, delete, or receive a copy of your personal data, to restrict or object to its processing, and to withdraw consent at any time. Revoking the app's access from your TikTok, Facebook, or Instagram security settings immediately invalidates the stored tokens for that account.

8. Data Deletion Requests

To request deletion of your data — including connected-account data, tokens, and any stored media — email [email protected]. We will confirm and complete deletion within 30 days.

9. Children

The Service is a business tool and is not directed at children under 16. We do not knowingly collect data from children.

10. Changes

We may update this policy from time to time. The "Last updated" date above reflects the latest revision; material changes will be communicated to active Clients.

11. Contact

Data controller: Day2 AI, Israel. Privacy contact: [email protected].

תגיות:

legalprivacy

מוכנים להתקדם?

צוות Day2 AI כאן בשבילכם — דברו איתנו ונשמח לעזור.