Privacy Policy

Last Updated: June 13, 2026

1. Introduction

directly.social("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and share information when you use our web and mobile applications (the "Service").

directly.social is operated by Thoufeeque Abdul Rahman Rafique.

2. Data We Collect

We collect information that you provide directly to us, such as when you create an account, connect social media profiles, or upload content. This may include:

  • Name and email address.

  • Profile information (e.g., avatar, bio).

  • Billing information (processed securely by our payment provider, Stripe).

  • Social media account identifiers and authentication tokens (OAuth).

  • Content you upload (e.g., videos, titles, descriptions).

  • Diagnostic data (e.g., IP addresses, crash logs, and device info used strictly for error tracking via Sentry).

3. Use of Third-Party APIs
Google / YouTube API Services Data Handling

Our application uses Google API Services (specifically YouTube APIs) to allow you to upload videos directly to your YouTube channel. By using this feature, you agree to be bound by the YouTube Terms of Service and the Google Privacy Policy.

1. Data Access: We request access to your YouTube account solely to upload media files (videos) on your behalf and to read basic channel information necessary to confirm successful uploads.

2. Data Use: The raw and derived Google user data accessed by our application is used strictly to provide the core user-facing feature of publishing your scheduled content to your YouTube channel.

3. Data Transfer: We do not transfer or share your Google user data with any third parties, data brokers, or advertisers. Data is solely transmitted securely between your device, our servers, and Google APIs.

4. Data Protection: All Google user data, including OAuth tokens, is encrypted in transit using industry-standard TLS/SSL and encrypted at rest in our secure database.

5. Data Retention & Deletion: We retain your authentication tokens only as long as your account is active to facilitate scheduled publishing. Upon account deletion or disconnecting your YouTube account, all associated Google user data and tokens are immediately and permanently deleted from our systems.

6. Prohibited Data Use & Transfer: We expressly prohibit the use of your raw, aggregated, or anonymized Google user data for targeted advertising, lending purposes, or sale to third parties.

7. AI/ML Model Training Restrictions: Raw and aggregated Google user data is strictly prohibited from being used to develop, improve, or train any generalized Artificial Intelligence (AI) or Machine Learning (ML) models. We do not transfer Google user data to any third-party AI/ML services for model training purposes.

Google API Disclosure: The use of raw or derived user data received from Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

TikTok API

We use TikTok for Developers APIs to facilitate video posting and account management. We adhere to TikTok's Developer Terms.

Data Deletion:You can request the deletion of your TikTok data from our servers at any time by disconnecting your TikTok account in the Integrations settings. Alternatively, you may revoke our application's access directly from your TikTok account's security settings. When we receive a revocation or data deletion webhook from TikTok, we immediately and permanently delete all your associated TikTok account data and credentials from our systems.

Meta (Facebook/Instagram) API

We use Meta Graph APIs to publish content to your Facebook Pages and Instagram Business accounts.

AI Content Enhancement

To provide AI-assisted content generation (e.g., generating descriptions and hashtags), we transmit relevant video metadata and styling prompts to trusted AI providers (such as OpenAI, Google, Anthropic, or Groq). Your Personal Identifiable Information (PII) is strictly excluded from these prompts unless you explicitly include it in your content. We do not allow these providers to use our API data to train their models.

Infrastructure, Payment & Telemetry

We use Stripe for secure payment processing and do not store your full credit card details on our servers. For essential infrastructure, we use Upstash for rate-limiting and security, and Resend for transactional email delivery. We also use Sentry for error monitoring and diagnostics to ensure the stability of the Service.

4. Data Retention and Deletion

Right to be Forgotten: You may request the deletion of your account and all associated data by emailing us at privacy@directly.social or by using the "Delete Account" feature in your settings.

When you initiate an account deletion, our system immediately and permanently deletes all of your associated relational database records, authentication credentials, and uploaded media assets from our cloud storage. We do not use soft-deletes or retain your core data after an explicit deletion request.

5. Contact Us

If you have any questions, please contact us at:

Email: privacy@directly.social