Legal document
Last updated: September 3, 2026. Effective: September 3, 2026.
Leia este documento em português
TurboPost is an application that helps you create, schedule and publish videos and posts to your own social media accounts (YouTube, TikTok, Instagram and Facebook). This policy explains plainly what data we use, why, for how long, and what you can demand from us at any time.
The data controller is Ralph Carvalho, developer of TurboPost, reachable at ralphniesscarvalho@gmail.com.
This is an English translation provided for convenience. In case of any conflict, the Portuguese version prevails.
Your login email and password, stored encrypted by our authentication provider. We do not collect national ID numbers, addresses or phone numbers.
When you connect an account, we securely store the access token granted by that platform, along with the account's public name and avatar — so you can see on screen which profile is connected. We never receive or store your passwords for those networks.
The titles, descriptions, captions, images and videos you upload or generate inside the app, plus a record of each post (network, account, date, status).
When you use the metrics panel, we store a daily snapshot of your accounts' public numbers (followers, views) in order to draw the growth chart.
Minimal operational and error logs, used only to diagnose problems. We use no tracking cookies, do no advertising profiling, and embed no third-party trackers in the app.
We use your data solely to do what you ask: authenticate your access, publish or schedule your posts to the accounts you connected, generate the texts and images you requested, show your history and metrics, and provide support when you write to us.
The legal basis is performance of the contract between you and TurboPost (article 7, V of the Brazilian LGPD) and, where applicable, compliance with legal obligations. We do not use your data for any other purpose — in particular, we do not use it for advertising, nor to train artificial intelligence models.
TurboPost uses the TikTok Login Kit and the TikTok Content Posting API. When you connect your account, TikTok grants us permission to view your basic profile (display name, avatar and public statistics) and to publish videos to your profile, always under your command. We securely store the authorizations (tokens) needed for this, and nothing is published unless you determine it.
We do not read, modify or delete pre-existing content on your TikTok account. By using the app you also agree to the TikTok Terms of Service and the TikTok Privacy Policy. You may revoke TurboPost's access at any time in the TikTok app, under Settings and privacy → Security and permissions → Manage app permissions.
TurboPost uses YouTube API Services to upload videos to your channel and display its name on screen. If you authorize optional YouTube Analytics access, the dashboard retrieves aggregated video views by country; TurboPost does not store that report in its database. By using the app you also agree to the YouTube Terms of Service and the Google Privacy Policy. You may revoke TurboPost's access to your Google account at any time at myaccount.google.com/permissions.
TurboPost's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell this data and do not use it for advertising.
When you connect your Instagram professional account or a Facebook Page, Meta grants us permission to view the account name, to publish the content you created and, if you enable the inbox, to display received direct messages — always under your command. We securely store the authorizations (tokens) needed for this. By using the app you also agree to the Meta Terms and the Meta Privacy Policy. You may revoke access at any time in your account's app settings.
The AI features use the API key you configure yourself, and that key is stored only in your browser — it is never sent to our server. When you request a text or an image, the topic you typed is sent to the chosen AI provider to generate the response. We do not send the provider your account data, your tokens or your social media content.
Your data is held in a protected database (Supabase) with row-level security: each user can access only their own data. Communication with the app is encrypted (HTTPS), and the application runs on Vercel infrastructure.
These providers may process data outside Brazil. Such transfers rely on the contractual safeguards they offer, and occur only to make the service work.
No system is immune to incidents. If a breach occurs that poses a relevant risk to you, we will notify you and the Brazilian Data Protection Authority, as the LGPD requires.
We do not sell and do not share your data with third parties for commercial or advertising purposes. Your content is sent only to the platforms you connected yourself, at the moment you determined.
The only third parties involved are the infrastructure providers needed for the service to work (Supabase, Vercel and the AI provider you choose), each handling only the minimum necessary. We may also share data if legally compelled by a court order or competent authority.
Under the Brazilian LGPD, at any time you may:
To disconnect a network, the fastest route is inside the app itself, under Conectar contas — this immediately deletes the stored tokens. For all other requests, write to ralphniesscarvalho@gmail.com with the subject Data deletion or My data. We respond within 30 days.
TurboPost is intended for people aged 18 and over and does not knowingly collect data from children or adolescents. If we learn that an account was created by a minor, it will be closed and the data deleted.
We may update this policy as the product evolves or legislation changes. The date of the last update is always shown at the top of this page, and significant changes will be communicated in the app or by email.
Questions about this policy, or any request regarding your data: ralphniesscarvalho@gmail.com. We reply within 2 business days.