Privacy Policy
Sworeborn Postiz · Swore Born Games · Last updated 16 September 2026
Sworeborn Postiz is a private, self-hosted deployment of the open-source scheduling tool Postiz, operated by Swore Born Games (an independent game developer, referred to below as “we” or “the operator”). It is used solely to schedule and publish our own game-development content to our own social media accounts. It is not a public service: account registration is disabled, and the operator is the only user.
This policy explains what the application collects, how it is used, stored, shared and deleted, for each platform it connects to. The sections below cover YouTube and TikTok.
YouTube (YouTube API Services)
Sworeborn Postiz uses YouTube API Services. When you connect a YouTube channel to
this application, Google's handling of your information is governed by the
Google Privacy Policy
(https://policies.google.com/privacy), and your use of YouTube remains subject to the
YouTube Terms of Service.
What we access and collect
A YouTube channel is connected through Google's own OAuth 2.0 sign-in, and only channels that we own are ever connected. Through the YouTube Data API and the YouTube Analytics API, the application accesses and stores:
- basic Google account profile information (name, e-mail address and profile image), used only to show which account is connected;
- the connected YouTube channel's ID, title and avatar image URL;
- OAuth access and refresh tokens issued by Google, which are required to upload on the channel's behalf;
- the videos, titles, descriptions, tags, thumbnails, audience (“made for kids”) and visibility settings that the operator chooses to publish, and the resulting YouTube video ID and link;
- view, like and comment counts for the channel's own videos, and the channel's own analytics reports, used only to show the operator how our own videos perform.
We do not access, collect or store data about any other YouTube user or channel, and the application does not read comments, subscribers, playlists or other channels' content.
How we use it
YouTube API data is used for one purpose only: to upload and publish the operator's own videos to the operator's own channel and to display that channel's own statistics inside the application. It is never used for advertising, profiling, training machine-learning models, or any form of automated decision-making, and it is never sold.
How we share it
We do not share YouTube API data with any third party, internal or external. The only party that receives it is YouTube itself, when the operator publishes a video.
How we store it
Tokens, channel details and post records are stored in a PostgreSQL database on a single computer on the operator's own private network; they are not hosted with a third-party cloud provider. YouTube statistics are fetched on demand when the operator opens them and are cached in memory for at most one hour; they are not written to the database.
How it is deleted, and how to revoke access
- You can revoke this application's access to your Google account and YouTube data at any time
from the Google security
settings page (
https://security.google.com/settings/security/permissions). Revocation immediately stops all further access. - The channel can also be disconnected inside the application.
- When access is revoked or the channel is disconnected, we delete the stored tokens and all YouTube API data held for that channel within 7 days. A deletion request can also be sent to the contact address below.
TikTok
When a TikTok account is connected through TikTok Login Kit, this application stores:
- the TikTok
open_idfor the connected account; - basic profile information returned by TikTok - display name, username and avatar image URL;
- aggregate profile statistics returned by TikTok (for example follower and video counts);
- a list of the account's own previously published videos, used to display posting history;
- OAuth access and refresh tokens issued by TikTok, which are required to publish on the account's behalf;
- the video files and post text that the operator chooses to schedule and publish.
We do not collect data about any other TikTok user. This information is used only to display which account is connected and to upload, schedule and publish the operator's own posts to that account. Data is transmitted to and from TikTok over HTTPS. Authorization can be withdrawn at any time from TikTok under Settings and privacy › Security and permissions › Manage app permissions, which immediately invalidates our access.
Cookies and information stored on your device
The application sets a single authentication cookie in the operator's browser so that the operator stays signed in. It does not use cookies or similar technologies for advertising or analytics, does not run tracking scripts, and does not allow third parties to place cookies or serve advertisements through it.
Sharing, sale and security
No data from any platform is shared with, sold to, rented to, or otherwise disclosed to any third party. Access to the application requires authentication, and all communication with the platforms' APIs uses HTTPS.
Retention
Tokens and profile information are kept only while an account remains connected, and are deleted within 7 days of disconnection or revocation. Access tokens also expire according to each platform's own token lifetimes.
Children
This application is not directed at children and is not accessible to anyone other than the operator.
Changes
If this policy changes, the revised version will be published at this address with an updated date above.
Contact
Swore Born Games - sworeborngames@gmail.com. Questions and deletion requests are answered within 30 days.