01Who we are
TallyReel Post is a social media scheduling service available at this website and in our iOS and Android apps. It is operated by [Your legal name], an individual developer based in Pakistan (“TallyReel Post”, “we”, “us”). We are the controller of the personal data described in this policy.
Questions, requests or complaints: [hello@tallyreel.com — create this mailbox first]. We aim to reply within 30 days.
02What we collect
We only collect what the product needs to work. Specifically:
| Data | Examples | Why |
|---|---|---|
| Account details | Name, email address, password (stored only as an Argon2id hash), timezone, whether you verified your email | To create and secure your account and show times in your timezone |
| Brand voice | The optional description of your tone that you write in settings | To guide the AI features |
| Connected social accounts | Account id, handle, display name and avatar URL; access and refresh tokens, Bluesky app passwords, Telegram bot tokens and Discord webhook URLs | To publish on your behalf. All tokens and secrets are encrypted at rest with AES-256-GCM. |
| Posts | Post text, per-network versions, scheduled time, status, the networks and options you chose (e.g. subreddit, board, page), and the link and id of each published post, plus error messages if publishing fails | To schedule, publish and show your posts and their history |
| Media | Images and videos you upload, their size, type, dimensions and alt text | To attach them to posts and send them to the networks |
| Workspaces and teams | Workspace names, who belongs to each and their role, pending invites (the invited email address, role and who sent it), comments on posts, and each post’s activity (who created, edited, sent for approval, approved or published it, and when) | To let teams share channels and posts, review posts before they go out, and show who did what |
| Linked apps | For each desktop app you link (such as TallyReel Studio), the name it gave itself, which platform it runs on, when it was linked, when it was last used, and a hashed copy of its token | To let an app you approved upload a finished video and leave a post here, to show you which apps are linked, and to let you unlink them. A linked app can only upload media and create posts — it cannot publish, read your existing posts or change your account. Media it uploads is stored exactly like media you upload yourself. |
| Push notification tokens | A device token issued by Apple or Google, and the device platform | To notify you when a post publishes, fails or needs approval. You can turn this off at any time. |
| Security and technical data | IP address, browser or app version, request logs, hashed session tokens, error reports | To keep the service secure, rate-limit abuse and fix bugs |
We do not read your direct messages, your followers’ data or your feeds. We only request the permissions each network needs to publish posts and list the pages, boards, blogs or locations you can post to.
We do not sell your personal data, share it for cross-context behavioural advertising, or use it to build advertising profiles.
03AI features and DeepSeek
TallyReel Post’s AI features — tailoring a post for each network, suggesting hooks, drafting from an idea and the content planner — are powered by DeepSeek, an AI provider based in the People’s Republic of China.
When you use an AI feature, we send DeepSeek only what that feature needs:
- the post text, idea or goal you entered,
- the networks you selected, and
- your brand voice description, if you wrote one.
We do not send your name, email address, social account tokens or media. AI features only run when you press an AI button — nothing is sent to DeepSeek otherwise, and you can use TallyReel Post without ever using them.
Data sent to DeepSeek is processed and may be stored on servers in China, under DeepSeek’s own privacy policy (opens in a new tab). Chinese law may allow authorities there to access that data. If you are not comfortable with this, don’t use the AI features, and avoid putting personal or confidential information in text you send to them.
04Why we’re allowed to use it
If you are in the EU, UK or a similar jurisdiction, we rely on these legal bases:
- Contract — to provide the service you signed up for: your account, scheduling, publishing, media storage and notifications.
- Consent — for AI features (you choose to use them each time) and push notifications (you can withdraw consent in settings or on your device).
- Legitimate interests — to keep the service secure, prevent abuse, and diagnose errors.
- Legal obligation — to keep payment records once paid plans exist, and to respond to lawful requests.
05Connected networks
When you connect a social account, you authorise TallyReel Post to act on that network for you. What we publish there, and when, is exactly what you schedule. Once content is published, it is governed by that network’s own terms and privacy policy, and deleting it from TallyReel Post does not delete it from the network.
YouTube and other Google services
TallyReel Post uses YouTube API Services to upload videos you schedule. By connecting YouTube you agree to be bound by the YouTube Terms of Service (opens in a new tab), and Google’s handling of your data is described in the Google Privacy Policy (opens in a new tab). You can revoke TallyReel Post’s access at any time from your Google security settings (opens in a new tab), in addition to disconnecting the channel in TallyReel Post.
TallyReel Post’s use and transfer of information received from Google APIs (YouTube and Google Business Profile) adheres to the Google API Services User Data Policy (opens in a new tab), including the Limited Use requirements. In particular, we use Google user data only to provide the publishing features you see in the app; we don’t transfer it except as needed to provide those features, for security, or to comply with law; we don’t use it for advertising; we don’t let humans read it unless you ask us to (for support), it’s needed for security, or the law requires it; and we don’t send it to AI providers or use it to train AI models.
Meta, TikTok, X and others
The same principle applies to every network: we use the data they give us only to connect your account and publish your posts, and you can disconnect at any time. Disconnecting deletes the stored tokens and, where the network supports it, revokes TallyReel Post’s access. See also our data deletion instructions.
06Who processes your data
We use a small number of service providers (sub-processors) who handle data on our behalf:
| Provider | Purpose | Data |
|---|---|---|
| Google Cloud | Hosting for the API, database and job queue | All account and post data |
| Cloudflare | Serving this website, CDN, and media storage (R2) | Uploaded media, request metadata |
| DeepSeek (China) | AI features, only when you use them | Text you submit to an AI feature, brand voice |
| Resend | Sending account emails (email verification, password reset, security notices) | Name, email address |
| Sentry | Error monitoring | Error details and technical data, which may include your account id |
| Lemon Squeezy | Payments on the web, as merchant of record (it is an independent controller for the purchase) | Name, email, account id, billing details (we never see card numbers) |
| RevenueCat | Managing App Store and Google Play subscriptions bought in our apps | Account id, purchase receipts and subscription status |
| Apple and Google | In-app purchases and push notifications | Purchase receipts, device push tokens |
The social networks you connect receive the content you publish to them. They are independent controllers, not our processors.
07International transfers
We are based in Pakistan, and our providers process data in several countries, including the United States, the European Union and — for AI features only — China. Where the law requires it, we rely on the providers’ standard contractual clauses or equivalent safeguards. Because DeepSeek does not offer such safeguards in the same way, AI features are strictly optional.
08Cookies and local storage
The website uses only the cookies it needs to keep you signed in:
- Session cookies (
__Host-tallyreel_at,__Host-tallyreel_rt) — httpOnly cookies holding your sign-in tokens. JavaScript can’t read them. - Expiry hint (
tallyreel_exp) — a non-secret timestamp so the app knows when to refresh your session. - Active workspace (
tallyreel_ws) — the id of the workspace you last opened, so the app reopens it. Cleared when you log out.
We also save your light/dark theme choice in your browser’s local storage. There are no advertising cookies, no third-party trackers and no analytics cookies, so there is no cookie banner.
09How long we keep it
- Account, posts and connected accounts — for as long as your account exists. Deleting a post or disconnecting a channel removes it immediately.
- Uploaded media — as long as a post uses it. Uploads that are never attached to a post are deleted automatically after 24 hours.
- Sign-in sessions — refresh tokens expire automatically and are revoked when you log out.
- Server logs and error reports — up to 30 days.
- Database backups — deleted data can remain in encrypted backups for up to 30 days before being overwritten.
- Payment records — kept by us and our payment providers as long as tax law requires.
10Deleting your account
You can delete your account at any time in Settings → Delete account on the web or in the app. Deletion is immediate and permanent: your profile, posts, media, connected channels and their tokens, push tokens and sessions are erased, pending scheduled posts are cancelled, and we ask each network to revoke TallyReel Post’s access where it supports that.
Posts that were already published stay on the networks — delete them there if you want them gone. Full instructions are on the data deletion page.
Team workspaces. Content in a workspace belongs to that workspace and is controlled by its owner. Deleting your account deletes the workspaces you own, with everything in them. Posts, media, channels and comments you created in workspaces owned by someone else stay with those workspaces (shown without your name), because they are the team’s data; your membership, profile and sessions are erased. If you own a workspace that has other members, you need to transfer ownership (or remove the members) before you can delete your account.
11Your rights
Wherever you live, you can ask us to:
- Access your data or get a copy — you can download everything as a JSON file from Settings, or email us. The export contains everything in the workspaces you own, and only what you created (posts, media, comments) in workspaces owned by others; their owners can export the rest.
- Correct it — most details can be edited directly in Settings.
- Delete it — see above.
- Restrict or object to processing based on legitimate interests.
- Port it to another service (the export is machine-readable).
- Withdraw consent — stop using AI features, or turn off notifications.
California residents have the right to know, delete and correct personal information, and to not be discriminated against for exercising these rights. We do not sell or share personal information as those terms are defined in the CCPA/CPRA.
Contact [hello@tallyreel.com — create this mailbox first] to exercise any right. We may need to verify your identity first. If you are in the EU or UK and are unhappy with our response, you can complain to your local data protection authority.
12Security
Passwords are hashed with Argon2id. Social account tokens and secrets are encrypted with AES-256-GCM before they are stored. Sign-in tokens are kept in httpOnly cookies on the web and the device’s secure storage in the apps, and all traffic uses HTTPS. No system is perfectly secure; if we learn of a breach that affects you, we will tell you and the relevant authorities as the law requires.
13Children
TallyReel Post is not for children. You must be at least 13 years old to use it, or 16 if you are in the European Economic Area or UK (or older where local law requires). We don’t knowingly collect data from children; if you believe a child has created an account, contact us and we’ll delete it.
14Changes to this policy
If we change this policy, we’ll update the date at the top. If the change is significant — for example a new sub-processor that receives your content — we’ll tell you by email or in the app before it takes effect.
See also: Privacy policy · Terms of service · Delete your data