Legal
Privacy Policy
Last updated: September 11, 2026
FavStash lets you save links to social posts (Instagram Reels, TikTok, YouTube Shorts, LinkedIn posts), organize them, and search across what you saved. The links point at publicly available content on those platforms — we keep a pointer plus the small amount of context needed to make it searchable for you.
What we collect
- Your account. Your email address (and an optional display name) so we can sign you in and contact you about your account.
- What you save. The URLs you submit and any notes, tags, or collections you add. We also derive helper text — caption, transcript when one is available, a short summary — from each public link so you can search by meaning later.
- Connected social accounts (if you link them). If you connect an Instagram, YouTube, TikTok, or LinkedIn account for scheduling and supported analytics, we store the account’s ID, display name, username or connected-account email, and profile picture, plus the OAuth access tokens the platform issues. Details below under “Connected social accounts.”
- Posts you schedule. The caption, media you upload, platform settings, and publish time for each post you schedule, plus the resulting post link and platform post ID after publishing.
- API keys (if you create them). We store a hash of each key, not the secret itself, plus a name and last-used time.
- Standard technical logs. Things like request IDs and error messages needed to keep the service running and to investigate abuse.
- Public-site analytics. When you visit our landing page, Google Analytics records visits, referral source, approximate location, browser and device information, and the calls to action you use. Microsoft Clarity records interaction signals such as clicks, scrolling, and page layout so we can generate heatmaps and session replays. Clarity masks sensitive content by default. FavStash’s landing-page analytics integration is not enabled inside the authenticated dashboard.
What we don’t do
- We don’t sell or rent your information.
- We don’t share it with advertisers.
- We don’t use your saves to train any AI model, ours or anyone else’s.
How we use it
- To run your account and show you your stash.
- To enrich each save (transcript, short summary, search index) so you can find it later.
- To authenticate API and AI-agent requests you make against your own stash.
- To keep the service secure, prevent abuse, and comply with law.
- To understand landing-page performance and improve its content, navigation, and calls to action.
Connected social accounts
Connecting a social account is always optional and always started by you. When you connect one, the platform asks for your consent and then issues FavStash scoped OAuth tokens. Here is exactly what we do with them:
- What we access. Your basic channel profile (ID, display name, username or connected-account email, and picture), permission to publish the posts youschedule, and—where the provider exposes them—the performance metrics of your account and posts (reach, views, likes, watch time, followers, and similar) when you ask for analytics. LinkedIn personal-profile analytics and owned-post history are not available through its self-serve API.
- What we do with it. Publish content only when you (or an AI agent you authorized) schedule it, and display analytics back to you. If you explicitly authorize an AI agent or script, we return the social-account data it requests through your FavStash API connection so it can analyze your account or carry out your instruction. We do not otherwise disclose that data — no browsing your messages, contacts, or feed, and no posting without an instruction from you.
- Token storage. Access tokens live in a dedicated, encrypted-at-rest datastore that only our publishing and analytics systems can read. They are never exposed to your browser, other users, or third parties, and are deleted immediately when you disconnect the account.
- Revoking access. Disconnect any channel from the FavStash dashboard at any time. For YouTube, Disconnect asks Google to revoke FavStash’s authorization immediately and then deletes the local tokens and connected-channel record. You can also revoke FavStash from the platform side: Instagram (Settings → Website permissions → Apps and websites), Google (Google security settings), TikTok (Settings → Security → Apps), or LinkedIn (Settings & Privacy → Data privacy → Permitted services).
YouTube. FavStash uses YouTube API Services to upload the videos you schedule and to read your channel’s identity, owned-video metadata, publication status, public counters, and owner-only analytics. We also receive the Google profile information and OAuth credentials needed to identify and maintain the connection. By connecting a YouTube account you also agree to the YouTube Terms of Service; the Google Privacy Policy applies to Google’s handling of your data. FavStash’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Instagram connections use Meta’s Instagram API; Meta’s Privacy Policy governs Meta’s side. TikTok connections use the TikTok for Developers API under TikTok’s Privacy Policy. LinkedIn personal-profile connections use LinkedIn’s OpenID Connect and Share on LinkedIn products under the LinkedIn Privacy Policy; FavStash uses them for account identity and user-instructed publishing, not personal analytics or feed access. Platform data we fetch (analytics) is shown to you and cached briefly for performance. It is returned to an AI agent or script only when you have expressly authorized that client and instructed it to access your data. We don’t sell it, share it for advertising, or use it to train AI models. See Data deletion for removal instructions.
How we protect your information, including Google user data
The safeguards below apply to personal information and connected-account data that FavStash handles, including Google profile information, YouTube channel and video data, YouTube Analytics data, and Google OAuth access and refresh tokens.
- Encryption in transit. FavStash uses HTTPS/TLS for traffic between your browser or app and FavStash, between FavStash services, and between FavStash and social platform APIs.
- Encryption at rest. Account data, connected-channel metadata, scheduled posts, cached analytics, and OAuth tokens are stored using server-side encryption at rest. Provider client secrets are kept in encrypted secret storage rather than in source code.
- Token isolation and least-privilege access. OAuth access and refresh tokens are kept in a dedicated datastore separate from user-readable channel records. FavStash does not return those tokens to the browser, mobile app, other users, or connected AI clients. Only the backend functions that need a token for authorization, publishing, credential refresh, or analytics receive narrowly scoped access to that datastore.
- Authentication and account isolation. FavStash requires authenticated requests for private account features and applies owner-based authorization and server-side ownership checks so one user cannot access another user’s stash, connected channels, scheduled posts, or analytics. Personal API keys are stored as one-way hashes and can be limited by scope and revoked.
- Credential lifecycle and deletion. OAuth grants are limited to the permissions shown during consent. Disconnecting YouTube asks Google to revoke the grant and then deletes FavStash’s stored tokens and connection record. Account deletion also removes connected-account credentials and data as described under “Retention and deletion.”
- Operational controls. Direct public access to FavStash’s storage buckets is blocked, administrative access is limited to authorized personnel who need it to operate, support, or secure the service, and technical logs are used to investigate errors, security events, and abuse.
No internet service can guarantee absolute security. If we learn of a security incident affecting your personal information, we will investigate and provide notices as required by applicable law.
Service providers
We rely on a small number of trusted third parties to run the service: a cloud infrastructure provider (hosting, databases, sign-in, and in-house transcription), transcription and AI providers (for fallback extraction, visual analysis, summaries, and semantic search), and — if you subscribe — a payment processor. For public-site analytics, Google provides aggregated traffic measurement and Microsoft provides Clarity heatmaps and session replays. They process information only to provide their service to us and are bound by their own terms.
AI and automated processing
When you save a link, automated systems pull what’s publicly available about it (such as a caption or available transcript) and can produce a summary plus a search index. For eligible videos, we may temporarily retrieve public audio or video for in-house transcription and select frames for visual analysis. Temporary processing files are cleaned up after the processing attempt; source videos are not offered as downloads or retained for user playback. Extracted transcripts may be cached to avoid repeating processing of the same public source.
Depending on the enrichment step, we send the public source URL, extracted text, thumbnails, or selected video frames to a transcription or AI provider. Selected frames may be staged temporarily in our storage while visual analysis or a retry completes. By default, what we send is not used to train their models. AI-generated text can be wrong — please don’t rely on it for anything consequential without checking.
If you connect Claude, ChatGPT, or any other agent to your stash, that agent acts on your instructions. Data returned to that agent is then handled by its provider under that provider’s terms and privacy policy. You control this access through your FavStash OAuth connection or API key scopes and can revoke that access at any time.
Cookies and similar storage
We use a small number of session cookies to keep you signed in and to remember your theme/UI preferences. The public landing page loads Google Analytics and Microsoft Clarity, which may set analytics cookies or use similar browser storage. We keep advertising storage and personalization disabled and do not use these tools for retargeting.
Retention and deletion
We keep your information while your account is active. You can delete individual saves from the app, disconnect any social account (which deletes its tokens immediately), or delete your whole account, which starts a 30-day deletion workflow covering your saves, scheduled posts, connected-account records, and tokens. A small amount of data may persist in backups or security logs for a limited period where required. Step-by-step instructions are on the Data deletion page.
Media you upload for social publishing is temporary staging data, not permanent file storage. FavStash marks each uploaded image, video, or PDF document to expire from our object storage 30 days after its most recent upload, scheduling, or rescheduling. Scheduling is limited to 21 days ahead, and scheduling refreshes that 30-day period so media is not removed before its publish time. Incomplete multipart uploads are aborted after one day. Cloud storage lifecycle deletion is asynchronous, so final removal can occur shortly after the 30-day eligibility point.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your information, and to object to or restrict certain processing. Email contact@sketricsolutions.com and we’ll handle it. EU/UK residents may also lodge a complaint with their local data protection authority.
Children
FavStash isn’t directed at children under 13 (or the age required where you live), and we don’t knowingly collect information from them.
Changes
We’ll post any updates here and refresh the “Last updated” date. For material changes we’ll notify you in the app or by email where required.
Contact
Sketric Solutions — contact@sketricsolutions.com. See also our Terms of Use.