Last updated June 24, 2026
This Privacy Policy explains how Schedlytics ("Schedlytics", "we", "us", "our") collects, uses, shares, and protects information when you use our content scheduling, link tracking, and analytics application and website at schedlytics.com (together, the "Service"). It also describes your choices and rights. By using the Service you agree to the practices described here. If you do not agree, please do not use the Service.
Schedlytics is the data controller for the personal information described in this policy. For privacy questions or requests, contact privacy@schedlytics.com.
When you create an account we collect your name, email address, and any profile details you choose to provide. Sign in is handled by Google Firebase Authentication; if you sign in with Google, we receive your basic Google profile (name, email, and profile image). We never receive your Google password.
When you connect a platform (Instagram, Facebook, TikTok, YouTube, Pinterest, Twitch, or Patreon) through its official OAuth login, that platform issues us a limited access token and refresh token. We use these only to read the data you authorize and to perform the actions you request. Depending on the platform and the permissions you grant, this can include your public profile, follower, subscriber, and view counts, post and video statistics, comments you choose to manage, and engagement metrics. We never receive or store your social account password.
We store the posts, captions, media references, schedules, campaigns, and links you create inside the Service so we can publish and display them for you.
When you create a trackable short link and someone clicks it, we record the click and the destination so we can show you traffic analytics. To count unique visitors without storing personal data, we create a one-way fingerprint by hashing the visitor's IP address together with their browser user agent and the link identifier. We store only this irreversible hash and aggregate counts. We do not store raw IP addresses for link clicks, and we do not use this data to identify individuals.
We may collect basic technical information such as browser type, device, approximate request metadata, and pages visited, to keep the Service secure, reliable, and working as intended.
We use strictly necessary cookies and your browser's local storage to keep you signed in and to remember your in-app settings. We do not use third-party advertising or cross-site tracking cookies.
Where the GDPR or UK GDPR applies, we process your information under these legal bases: to perform our contract with you (providing the Service), our legitimate interests (securing and improving the Service), your consent (where required, such as connecting an optional platform), and compliance with legal obligations. You may withdraw consent at any time by disconnecting a platform or deleting your account.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share data only in these limited cases:
We do not own the data we read from the platforms you connect. That data belongs to you and to the respective platforms, and remains subject to their terms. We act only as a limited processor of it on your behalf, and we access it solely through each platform's official, approved API using the authorization you grant. We do not scrape platforms or use unauthorized access methods.
Our access, use, storage, and transfer of information received through these APIs follow each provider's requirements, including the Google API Services User Data Policy and its Limited Use requirements, the Meta Platform Terms and Developer Policies, the TikTok Developer Terms, the Pinterest Developer Guidelines, the Twitch Developer Services Agreement, and the Patreon Platform terms. We request only the minimum permissions needed for the features you use. Information received from these APIs is not used for advertising and is not sold or transferred except as described in this policy or with your consent.
We keep your information for as long as your account is active or as needed to provide the Service. When you disconnect a platform, we delete the stored access and refresh tokens for that platform. When you delete your account, we delete your account record, stored tokens, cached profile and statistics, and the content, schedules, campaigns, and links you created. We may retain limited records where required by law or to resolve disputes. Aggregate, de-identified statistics that cannot reasonably be linked to you may be retained.
Deleting your account or data removes information on our side only. It does not delete or change anything on the connected platforms themselves. Your posts, videos, comments, followers, and accounts on Instagram, Facebook, TikTok, YouTube, Pinterest, Twitch, and Patreon remain exactly as they are. To remove content from a platform, you must do that on the platform directly.
We use reasonable administrative and technical measures to protect your information. We connect to platforms only through OAuth, so we never see your platform passwords. Access and refresh tokens are held server side and used only to serve your requests. Traffic is encrypted in transit using HTTPS, and link visitor data is stored only as an irreversible hash. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Depending on where you live, you may have rights under the GDPR, the UK GDPR, or the California Consumer Privacy Act (CCPA/CPRA), including the right to know, delete, correct, and to not be discriminated against for exercising your rights. We do not sell or share personal information as those terms are defined under the CCPA. To exercise any right, contact privacy@schedlytics.com. You also have the right to lodge a complaint with your local data protection authority.
You can request deletion of all data we hold about you on our Data Deletion page, or by emailing privacy@schedlytics.com from your account email with the subject "Data deletion request". We process valid requests promptly. That page also explains how to revoke Schedlytics access directly at each platform. Remember that this deletes data on our side only and does not remove anything from the platforms themselves.
We and our service providers may process and store information in countries other than your own, including the United States. Where required, we rely on appropriate safeguards, such as standard contractual clauses, for international transfers.
The Service is not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect their personal information. If you believe a child has provided us information, contact us and we will delete it.
We may update this Privacy Policy from time to time. We will post the new version here and update the date above. Material changes will be highlighted where appropriate.
Questions or requests about this policy can be sent to privacy@schedlytics.com.