Privacy Policy
Effective date: July 20, 2026 · Last updated: July 20, 2026
1. What we collect
Nibcast collects only what it needs to publish on your behalf:
- Connected social account OAuth tokens. When you connect Facebook, Instagram, or TikTok, we receive and store the access (and where applicable, refresh) tokens that those networks issue through their official OAuth login, along with basic account identifiers (such as the account name/ID and page or profile the token is scoped to). These tokens are stored server-side on your Nibcast server.
- Uploaded media and captions. The images, videos, captions, and any metadata you add to a post are stored so they can be scheduled and published.
- Scheduling data. The networks you target, the scheduled publish time, post status, and the per-network result of each publish attempt (success, failure, or the network's returned post reference).
- Operational logs. Basic technical logs (timestamps, request paths, error messages) used to run and troubleshoot the Service. We do not use these for advertising or profiling.
We do not collect your social-account passwords — authorization is handled entirely through each network's official OAuth flow.
2. How we use your data
We use the data above solely to operate the Service: to authenticate you to the networks you connect, to store your drafts and queue, to publish your posts at the times you schedule using each network's official API, and to report back the result of each publish. We do not sell your personal data, we do not share it with advertisers, and we do not use your content or tokens for any purpose other than delivering the Service you requested.
3. TikTok & Meta integrations
TikTok
Nibcast uses TikTok Login Kit to obtain your authorization and the TikTok Content Posting API to publish the videos and captions you create. The token TikTok issues is used only to post the content you direct Nibcast to post and to read back the resulting publish status. Nibcast follows TikTok's Content Sharing / Content Posting guidelines, including required disclosure and consent behaviors. We do not access your TikTok inbox, contacts, or private data beyond the scopes you grant, and we retain TikTok tokens only while your TikTok account is connected.
Meta (Facebook & Instagram)
Nibcast uses Meta's Graph API for Facebook and Instagram. With the permissions you grant, we use the issued token to publish posts to the Facebook Page or Instagram professional account you select, and to read back publish status. We request only the permissions needed to publish on your behalf, and we handle Meta data in accordance with the Meta Platform Terms and Developer Policies.
4. Third-party data handling
When Nibcast publishes a post, the media, caption, and scheduling instruction are transmitted to the destination network (TikTok and/or Meta) so it can display the post. Once content is published to a network, that network processes and displays it under its own privacy policy, which we encourage you to review:
Aside from the destination networks you choose, Nibcast does not share your content or tokens with any third party except infrastructure providers strictly necessary to host and run the Service, and only to the extent required to do so.
5. Storage & security
OAuth tokens, media, captions, and scheduling data are stored server-side on the Nibcast server. Access tokens are treated as secrets: they are never displayed back to you in full, never included in client-facing responses beyond what is required to operate the Service, and never written to third-party analytics. Access to the Service's API requires an API key. No system is perfectly secure, but we take reasonable measures to protect your data.
6. Data retention
- OAuth tokens are retained only while the corresponding account is connected. Disconnecting an account deletes its stored token.
- Media, captions, and posts are retained while they remain in your library or queue and until you delete them.
- Scheduling and result records are retained to show your post history until you delete the associated post or request account deletion.
- Operational logs are retained for a limited period for security and troubleshooting, then discarded.
7. Your rights & data deletion
You are in control of your data:
- Disconnect an account at any time from the Nibcast app to revoke and delete its stored OAuth token.
- Delete individual media or posts from your library and queue.
- Request full deletion. To have all of your data — connected tokens, uploaded media, captions, and scheduling records — permanently deleted, email privacy@nibcast.com from the address associated with your account, or contact support@nibcast.com. We will process verified deletion requests within a reasonable period.
You may also revoke Nibcast's access directly from each network's own app settings (TikTok and Meta both provide a connected-apps / authorized-apps screen).
8. Children's privacy
Nibcast is intended for users who meet the minimum age requirements of the social networks they connect. It is not directed to children, and we do not knowingly collect personal data from children.
9. Changes to this policy
We may update this Privacy Policy as the Service evolves or as platform requirements change. Material changes will be reflected by an updated effective date at the top of this page. Continued use of the Service after an update constitutes acceptance of the revised policy.
10. Contact us
For privacy questions or to exercise your rights, contact us at privacy@nibcast.com (or support@nibcast.com).