Privacy Policy
Last updated: 17 August 2026
This Privacy Policy explains how Made by Felipe ("we", "us") collects, uses, stores and protects information when you use our social media publishing service (the "Service"), available at social.madebyfelipe.agency.
In short: we store only what is needed to publish content to the social media accounts you connect, on your instruction. We do not sell your data, we do not use it for advertising, and we do not share it with anyone other than the platforms you explicitly connect.
1. Who we are
The Service is operated by Made by Felipe, a digital agency based in Brazil. For any question about this policy or about your data, contact us at byonichip@gmail.com.
2. Information we collect
| Category | What it includes | Why we need it |
|---|---|---|
| Account information | Your name, email address and password (stored as a cryptographic hash) | To create and secure your account on the Service |
| Social account credentials | OAuth access tokens and refresh tokens issued by the platforms you connect, plus the public profile name, handle and avatar of those accounts | To publish on your behalf and show you which accounts are connected |
| Content you create | Post text, images, videos, scheduling dates and per-platform settings | To store your drafts and publish them at the time you choose |
| Publishing results | Success or failure of each publication, error messages returned by the platforms, and the resulting post identifiers | To show you what was published and to diagnose failures |
| Analytics from platforms | Aggregate metrics such as views, likes and comments, when the connected platform provides them | To display performance of the posts you published through the Service |
| Technical logs | IP address, timestamps and request paths in web server logs | Security, abuse prevention and troubleshooting |
We do not collect biometric data, precise location data, payment card details, or any special category of personal data.
3. Information from connected platforms
When you connect a social media account, the platform (for example TikTok, Instagram, LinkedIn or X) asks for your consent and then issues us an access token limited to the permissions shown to you at that moment.
We use that access strictly to perform actions you request: publishing or scheduling content, reading the basic profile information needed to identify the account, and retrieving analytics for posts made through the Service. We do not read your private messages, we do not browse your contacts, and we do not take any action on your accounts that you have not asked for.
4. How we use your information
- To operate the Service: store your drafts and publish them at the scheduled time.
- To authenticate you and keep your account secure.
- To display the status and performance of your publications.
- To diagnose technical problems and to protect the Service against abuse.
- To communicate with you about the Service when necessary.
We do not use your information to train machine learning models, to build advertising profiles, or for any purpose unrelated to running the Service.
5. Sharing
We do not sell, rent or trade your personal information. We share data only in these cases:
- With the platforms you connect. Publishing a post necessarily transmits its content to the platform you chose. That content is then governed by that platform's own privacy policy.
- With our infrastructure provider. The Service runs on a private virtual server rented from Contabo GmbH, located in Europe. Contabo provides the hardware and network; it does not process your data for its own purposes.
- When legally required. If compelled by a valid legal order, we may disclose information to the extent required by law.
6. Storage and security
Your data is stored on a dedicated private server operated by us, not on shared third-party SaaS infrastructure. We apply the following measures:
- All traffic to the Service is encrypted in transit with TLS (HTTPS).
- Access tokens are stored encrypted at rest.
- Administrative access to the server is restricted to SSH key authentication; password login and root login are disabled.
- Databases and internal services are not exposed to the public internet; only the encrypted web endpoint is reachable.
- The server is protected by a firewall and automated intrusion prevention.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authorities as required by applicable law.
7. Retention
We keep your data for as long as your account is active. Specifically:
- Access tokens are deleted immediately when you disconnect a social account.
- Posts and media are kept until you delete them or close your account.
- Technical logs are rotated and retained for a limited operational period.
When you close your account, we delete your personal data within 30 days, except where retention is required by law.
8. Your rights
Under the Brazilian General Data Protection Law (LGPD, Law 13.709/2018) and, where applicable, the EU General Data Protection Regulation (GDPR), you have the right to:
- Confirm whether we process your data, and access it.
- Correct incomplete, inaccurate or outdated data.
- Request anonymisation, blocking or deletion of unnecessary or excessive data.
- Request portability of your data to another provider.
- Withdraw consent, and disconnect any social account at any time.
- Object to processing, and lodge a complaint with a supervisory authority.
To exercise any of these rights, write to byonichip@gmail.com. We respond within 15 days.
9. Revoking access
You can disconnect any social account directly in the Service at any time, which deletes the stored token. You can also revoke our access from the platform's own settings:
- TikTok: Settings and privacy → Security and permissions → Manage app permissions
- Instagram: Settings → Apps and websites
- Facebook: Settings → Apps and websites
- LinkedIn: Settings → Data privacy → Permitted services
- X: Settings → Security and account access → Apps and sessions
10. Children
The Service is not directed at children and is not intended for anyone under 18 years of age. We do not knowingly collect personal data from children. If we learn that we have, we delete it.
11. International transfers
Our server is located in Europe. If you are in Brazil, your data is transferred to and stored in Europe. We rely on the adequacy of the safeguards described in section 6 and on your consent for this transfer.
12. Changes to this policy
We may update this policy as the Service evolves. The date at the top of this page always reflects the current version. Material changes will be communicated to account holders by email.
13. Contact
Made by Felipe
Email: byonichip@gmail.com
Web: madebyfelipe.agency