Skip to content

Version française →

7DayPost Privacy Policy

Version of 7 October 2026

This policy describes the data 7DayPost processes when you use the service, why, for how long, and your rights. It applies to the 7daypost.com website and the application it hosts. This is a translation: in case of discrepancy the French version prevails.

1. Data controller

The 7DayPost service is published by a private individual, acting as a non-professional publisher, whose contact details have been provided to the hosting provider. For any question about your data: taneflitgpt@gmail.com.

2. The service and your workspace

7DayPost works without an account: no email address, name or password is asked for. “Get started free” creates a workspace, identified by a random identifier (it starts with esp_).

  • Your browser keeps access to the workspace through a session cookie (section 14). The server only stores a fingerprint (SHA-256 hash) of the session secret, never the secret itself.
  • The personal link you can create from “Mon espace” (My workspace) is a secret that opens the workspace without a password. Only its fingerprint is stored: it cannot be recovered, by you or by us. Never share it.
  • For security, the service records when the workspace was created, when it was last seen and on how many browsers it is open — with no IP address and no device description.

3. Data processed

3.1 Your media

The videos and images you import are stored on the service’s server so they can be published. Images are re-saved without their metadata (EXIF, GPS location). Videos keep their file metadata, which may include a location, and are sent as they are to the platform you choose.

Public media addresses. Imported files are served at an address of the form https://7daypost.com/m/<fingerprint> so the platforms can fetch them. Anyone who has that address can open the file, including a video published as “Only me”. Files are deleted after publication when the after-publication purge is enabled, when you delete the media or the workspace, or by the inactivity purge (section 11).

3.2 Your posts

The texts and settings of your posts, your schedules, the history and the status of each upload (with, where relevant, the failure reason returned by the platform). For TikTok, a record of the options TikTok offered for your account when you approved the post is kept: it shows that the choices presented came from TikTok.

3.3 Technical logs

  • Calls to the platforms’ interfaces are logged (endpoint, response code, duration, log identifier) for troubleshooting; tokens and secrets are removed from them.
  • The web server (nginx) records for each request the IP address, the requested address (including terms typed into the application’s search) and the browser (user agent). These logs are kept for 14 days.
  • Anti-abuse counters (limits on workspace creation, link opening, imports) use a truncated, keyed hash of the IP address, never the address itself; they are deleted after 48 hours.

4. TikTok

7DayPost uses TikTok’s Login Kit and Content Posting API. The permissions requested are exactly:

  • user.info.basic: your account identifier for the app (open_id), the identifier shared across the same developer’s apps (union_id), display name and avatar address (cached for about 2 hours);
  • video.publish: post directly to your account. Before each post, 7DayPost reads the creator information (creator_info): allowed privacy options, interaction settings, maximum video duration;
  • video.upload: send a video as a draft to your TikTok inbox, for you to finish in the TikTok app.

Access and refresh tokens are encrypted (AES-256-GCM). For each upload, 7DayPost keeps the publish identifier returned by TikTok and its status. Videos are sent to TikTok; photos are fetched by TikTok from their https://7daypost.com/m/… address.

7DayPost reads neither your existing videos, nor their statistics, nor your messages, nor your followers. When you disconnect the account, 7DayPost asks TikTok to revoke the authorisation, then erases the tokens. Processing by TikTok is governed by TikTok’s privacy policy.

5. Meta: Facebook, Instagram, Threads

This section applies to the Facebook, Instagram and Threads connection. Until Meta completes its review of the app (Development mode), only accounts that have a role on the 7DayPost Meta app can connect.

  • Permissions requested: public_profile, pages_show_list, pages_read_engagement, pages_manage_posts, instagram_basic, instagram_content_publish; for Threads: threads_basic, threads_content_publish. Optional, for statistics: read_insights, pages_read_user_content, instagram_manage_insights, threads_manage_insights.
  • Data kept: the list of your Pages (name, picture) and one token per Page; the identifier, username and picture of your Instagram professional accounts; the identifier, name and photo of your Threads profile and its token (valid for 60 days, refreshed). Tokens are encrypted.
  • Media are fetched by Meta from their https://7daypost.com/m/… address.
  • Processing by Meta is governed by Meta’s privacy policy.

Data deletion

You can have your data deleted in several ways:

  1. In 7DayPost, one account at a time: Comptes → Déconnecter (Accounts → Disconnect). The account’s tokens and the schedules that depend on it are deleted immediately.
  2. The whole workspace: Mon espace → “Supprimer définitivement cet espace” (Delete this workspace permanently). Everything is deleted immediately (accounts, media and their files, schedules, history), and authorisations are revoked at the platforms that allow it.
  3. From Facebook: Facebook → Settings and privacy → Settings → Apps and websites → 7DayPost → Remove. Meta then notifies 7DayPost (callback address https://7daypost.com/api/meta/data-deletion), which deletes the linked accounts and gives you a confirmation code and an address to follow the request.
  4. By email to taneflitgpt@gmail.com, giving your workspace identifier (esp_…, shown in Mon espace) — never your personal link.
  5. Lost your link? Withdraw 7DayPost’s access at the platform: TikTok (Settings and privacy → Security → App permissions), Google (https://myaccount.google.com/permissions), LinkedIn (permitted services), Facebook (as in point 3). Nothing is published any more, and the workspace is deleted automatically after 30 days without a visit (its accounts can no longer publish), and in any case after 90 days without a visit.

Deadlines: immediate for ways 1, 2 and 3; 30 days at most for way 4. Copies in backups disappear within 14 days (backup retention).

6. YouTube and Google

7DayPost uses YouTube API Services. By connecting a channel, you agree to the YouTube Terms of Service (https://www.youtube.com/t/terms). Data processed by Google is governed by the Google Privacy Policy (https://policies.google.com/privacy).

Permissions requested:

  • youtube.upload: upload to your channel the videos you approved;
  • youtube.readonly: read your channel’s information and the status of the videos sent by 7DayPost, with their public counters;
  • yt-analytics.readonly (optional): read the YouTube Analytics statistics of the videos sent by 7DayPost only.

Data read and kept: the channel’s identifier, name, handle and picture; its verification status; for each video sent by 7DayPost, its identifier, title, status and applied visibility, and its dated statistics; the tokens, encrypted. Data sent to YouTube: the video file, title, description, visibility, “made for kids” declaration, category and altered or AI-generated content declaration — everything sent is shown to you and approved by you. 7DayPost reads neither your other videos, nor your comments, nor your subscribers, and never edits or deletes a video.

7DayPost's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

This information is only used for the features described: no advertising, no profiling, no training of artificial intelligence models, no human reading except for security, to comply with the law or at your request.

Channel information not refreshed for 30 days is refreshed or deleted; statistics that could not be read again for 30 days are deleted. To withdraw access: Comptes → Déconnecter (Accounts → Disconnect; 7DayPost asks Google to revoke the refresh token), or https://myaccount.google.com/permissions.

7. LinkedIn

Permissions: openid and profile (your member identifier, name and photo) and w_member_social (post to your profile, write only). The token, encrypted, is valid for 60 days; 7DayPost warns you before it expires. Statistics are not read through the API: you may type them in yourself. To withdraw access: Comptes → Déconnecter (Accounts → Disconnect), or https://www.linkedin.com/psettings/permitted-services. Processing by LinkedIn is governed by its privacy policy.

8. Statistics

Only when the feature is enabled on the service. Read, for the posts sent by 7DayPost only: YouTube Analytics statistics (views, likes, comments, watch time), Meta statistics for Pages and Instagram, Threads statistics; for LinkedIn, the figures you type in yourself.

TikTok statistics are not collected: they would require a permission to read your videos that 7DayPost does not request; adding it would require your new consent.

Statistics are kept per post, with dated readings, and deleted with the post, the account or the workspace; YouTube statistics follow the 30-day rule of section 6.

9. Purposes and legal bases

  • Performance of the service you ask for (contract): publishing what you prepared, running your schedules, informing you of their status.
  • Legitimate interest: security of the service, abuse prevention, incident troubleshooting.

No data is used for advertising, profiling or resale.

10. Security and administrator access

  • Platform tokens are encrypted at rest (AES-256-GCM).
  • The application’s credentials with the platforms are only in the server configuration: there is no screen to enter a secret.
  • Traffic uses HTTPS, with HSTS; the application service only listens locally.
  • The administrator can, from the server only, open or delete any workspace (abuse, legal request, support at your request). Each such access to a workspace is recorded and shown in its Mon espace page. No web page can open someone else’s workspace.
  • Local backups are made daily; access is restricted to the administrator and they are kept for 14 days.

11. Retention

  • Active workspace: as long as you use it.
  • Workspace not visited for 30 days and without a successful post in that period: deleted, with the authorisations revoked at the platforms that allow it.
  • Workspace without any visit for 90 days: deleted in all cases.
  • Empty workspace (no account, no media, no schedule): deleted after 24 hours.
  • An account’s tokens: until it is disconnected or the authorisation is revoked.
  • Web server logs: 14 days. Anti-abuse counters: 48 hours.
  • Events and history: deleted with the workspace.
  • Backups: 14 days.

12. Sharing, processors, transfers

  • Your content and its settings are only sent to the platforms you ask to publish to: TikTok, Meta, Google (YouTube), LinkedIn — companies that may process data outside the European Union, notably in the United States, under their own policies.
  • Hosting of the service: OVH SAS, 2 rue Kellermann, 59100 Roubaix, France.
  • Google Cloud Storage remote storage (Firebase, Google): used only for the media of scheduled posts, so they remain available at publishing time.
  • No data is sold or rented.

13. Your rights

Under the General Data Protection Regulation (GDPR), you have the rights of access, rectification, erasure, restriction, objection and portability. To exercise them, write to taneflitgpt@gmail.com with your workspace identifier (never your personal link). You may also lodge a complaint with the French data protection authority, the CNIL (https://www.cnil.fr/fr/plaintes).

The service is reserved for people aged 15 or over who also meet the age required by each platform.

14. Cookies

  • __Host-7dp_espace: your workspace session cookie, strictly necessary (400 days at most).
  • langue: language of the application interface (preference, 1 year).
  • 7dp_alertes_vues: date of the last notifications seen on this device (functional, per device, 1 year; no tracking).

No audience measurement or advertising cookie, no third-party tracker: no consent banner is therefore needed.

15. Changes

This policy may change: the version date is shown at the top of the page, and the history below describes each significant change.

History

  • 7 October 2026: the publisher is a private individual, non-professional, whose contact details have been provided to the hosting provider (LCEN); contact by email; hosting provider specified; Facebook, Instagram and Threads connection offered, limited to accounts that have a role on the Meta app until Meta completes its review.
  • 6 October 2026: a single policy for all platforms; account-free workspaces and personal link; public media addresses; retention periods and purge of inactive workspaces; cookies; English version.
  • 23 August 2026: first version (TikTok, French only).
Privacy · 7DayPost