Data · version 0.1.0 · effective: DRAFT

Account Connection and Authorisation

DRAFT — requires review by qualified counsel in each jurisdiction. Not in force.

In one line

How you connect your social channels to qypu, what access you give us, what we record, and how to take it back at any time.

The short version

This short version helps you understand the full text. Read the full text for the complete terms.

  • You connect channels with the platform's own "Log in with" screen (OAuth). We never ask for or store your passwords. (Full text, section 2)
  • You see the exact permissions before you agree. We ask only for those we need. (Section 3)
  • We keep a signed Authorisation record: who connected the channel, when, which permissions, and for which workspace. (Section 4)
  • Access tokens are stored encrypted. (Section 5)
  • You can disconnect at any time, in qypu or on the platform. We delete the tokens straight away. (Section 6)
  • If the platform tells us you removed qypu, or asks us to delete data, we do it. (Section 7)

Full text

Read the full text (about 2 minutes)

1. Scope

This policy covers how qypu connects to Meta (Facebook and Instagram), TikTok, LinkedIn, Google (YouTube), and any other platform we add.

2. Connection method

2.1 Channels are connected through the platform's official OAuth flow. You sign in on the platform's own page. qypu never sees your platform password.

2.2 A channel owner can also be invited by email to connect a channel. The invitation link is single-use, expires, and can be revoked.

3. Permissions

3.1 Before you agree, the platform shows the permissions requested. We request only the permissions needed for the features you use: publishing posts, reading basic profile and page information, and reading insights and comments for your results.

3.2 We use each permission only for the purpose shown in our platform app review submissions.

4. Authorisation record

4.1 When you connect a channel, qypu creates an Authorisation record. It contains the person who connected the channel, the workspace, the platform, the scopes granted, the time, and a signed confirmation of your authorisation for qypu to publish signed posts on that channel.

4.2 Authorisation records are kept for the life of the workspace plus the period in the retention policy, so you and the platform can verify that every post had authority.

5. Token security

5.1 Access and refresh tokens are encrypted at rest with authenticated encryption (AES-256-GCM). In place.

5.2 Per-workspace encryption keys bound to each record, and key rotation. Planned (code built; being connected).

5.3 Tokens are never shown in the interface, never sent to AI models, and filtered from logs and error reports. Log filtering: in place for the main paths; being extended to all platform callbacks (Planned until complete).

6. Disconnecting

6.1 You can disconnect a channel at any time in Settings, then Channels. We revoke the token with the platform where it supports revocation, and delete it from qypu immediately.

6.2 You can also remove qypu on the platform:

  • Facebook and Instagram: Settings, then Apps and websites.
  • Google and YouTube: Google Account, then Security, then Third-party connections.
  • TikTok: Settings, then Security, then Manage app permissions.
  • LinkedIn: Settings, then Data privacy, then Permitted services.

6.3 After disconnection, scheduled posts for that channel are cancelled and you are told.

7. Platform signals

7.1 We process Meta deauthorisation and data deletion callbacks. A deletion request returns a confirmation code and a status page at /legal/data-deletion.

7.2 We refresh or delete platform data within the time each platform's terms require (for example, YouTube API data that is not refreshed within 30 days is deleted).

8. Disclosed, client-owned channels only

qypu connects only channels owned by the customer business, or that it is authorised to manage, and that clearly represent that business.

Change log

  • 2026-10-10 · 0.1.0 · First draft.

Open questions for counsel

We publish these while the page is a draft, so you can see what is not settled yet.

  • Confirm the "signed authorisation" text shown at connection is sufficient evidence of agency for each platform's terms.
  • Confirm each platform's current data refresh and deletion periods before publication.

Useful for: Business owners, IT and security reviewers, Platform reviewers. To save this page as a PDF, use your browser's Print command. Back to the trust centre.