Legal document

Privacy Policy

Last updated: September 3, 2026. Effective: September 3, 2026.
Leia este documento em português

TurboPost is an application that helps you create, schedule and publish videos and posts to your own social media accounts (YouTube, TikTok, Instagram and Facebook). This policy explains plainly what data we use, why, for how long, and what you can demand from us at any time.

The data controller is Ralph Carvalho, developer of TurboPost, reachable at ralphniesscarvalho@gmail.com.

This is an English translation provided for convenience. In case of any conflict, the Portuguese version prevails.

1. Data we collect

Account data

Your login email and password, stored encrypted by our authentication provider. We do not collect national ID numbers, addresses or phone numbers.

Social account authorizations

When you connect an account, we securely store the access token granted by that platform, along with the account's public name and avatar — so you can see on screen which profile is connected. We never receive or store your passwords for those networks.

Content you create

The titles, descriptions, captions, images and videos you upload or generate inside the app, plus a record of each post (network, account, date, status).

Public metrics

When you use the metrics panel, we store a daily snapshot of your accounts' public numbers (followers, views) in order to draw the growth chart.

Technical data

Minimal operational and error logs, used only to diagnose problems. We use no tracking cookies, do no advertising profiling, and embed no third-party trackers in the app.

2. Why we use this data

We use your data solely to do what you ask: authenticate your access, publish or schedule your posts to the accounts you connected, generate the texts and images you requested, show your history and metrics, and provide support when you write to us.

The legal basis is performance of the contract between you and TurboPost (article 7, V of the Brazilian LGPD) and, where applicable, compliance with legal obligations. We do not use your data for any other purpose — in particular, we do not use it for advertising, nor to train artificial intelligence models.

3. TikTok API Services

TurboPost uses the TikTok Login Kit and the TikTok Content Posting API. When you connect your account, TikTok grants us permission to view your basic profile (display name, avatar and public statistics) and to publish videos to your profile, always under your command. We securely store the authorizations (tokens) needed for this, and nothing is published unless you determine it.

We do not read, modify or delete pre-existing content on your TikTok account. By using the app you also agree to the TikTok Terms of Service and the TikTok Privacy Policy. You may revoke TurboPost's access at any time in the TikTok app, under Settings and privacy → Security and permissions → Manage app permissions.

4. YouTube API Services

TurboPost uses YouTube API Services to upload videos to your channel and display its name on screen. If you authorize optional YouTube Analytics access, the dashboard retrieves aggregated video views by country; TurboPost does not store that report in its database. By using the app you also agree to the YouTube Terms of Service and the Google Privacy Policy. You may revoke TurboPost's access to your Google account at any time at myaccount.google.com/permissions.

Limited Use of Google data

TurboPost's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell this data and do not use it for advertising.

5. Meta (Instagram and Facebook)

When you connect your Instagram professional account or a Facebook Page, Meta grants us permission to view the account name, to publish the content you created and, if you enable the inbox, to display received direct messages — always under your command. We securely store the authorizations (tokens) needed for this. By using the app you also agree to the Meta Terms and the Meta Privacy Policy. You may revoke access at any time in your account's app settings.

6. Artificial intelligence

The AI features use the API key you configure yourself, and that key is stored only in your browser — it is never sent to our server. When you request a text or an image, the topic you typed is sent to the chosen AI provider to generate the response. We do not send the provider your account data, your tokens or your social media content.

7. How long we keep it

8. Storage, security and international transfer

Your data is held in a protected database (Supabase) with row-level security: each user can access only their own data. Communication with the app is encrypted (HTTPS), and the application runs on Vercel infrastructure.

These providers may process data outside Brazil. Such transfers rely on the contractual safeguards they offer, and occur only to make the service work.

No system is immune to incidents. If a breach occurs that poses a relevant risk to you, we will notify you and the Brazilian Data Protection Authority, as the LGPD requires.

9. Sharing

We do not sell and do not share your data with third parties for commercial or advertising purposes. Your content is sent only to the platforms you connected yourself, at the moment you determined.

The only third parties involved are the infrastructure providers needed for the service to work (Supabase, Vercel and the AI provider you choose), each handling only the minimum necessary. We may also share data if legally compelled by a court order or competent authority.

10. Your rights

Under the Brazilian LGPD, at any time you may:

To disconnect a network, the fastest route is inside the app itself, under Conectar contas — this immediately deletes the stored tokens. For all other requests, write to ralphniesscarvalho@gmail.com with the subject Data deletion or My data. We respond within 30 days.

11. Minors

TurboPost is intended for people aged 18 and over and does not knowingly collect data from children or adolescents. If we learn that an account was created by a minor, it will be closed and the data deleted.

12. Changes to this policy

We may update this policy as the product evolves or legislation changes. The date of the last update is always shown at the top of this page, and significant changes will be communicated in the app or by email.

13. Contact

Questions about this policy, or any request regarding your data: ralphniesscarvalho@gmail.com. We reply within 2 business days.