Privacy Policy

Last updated August 7, 2026

This policy explains how InstaDoc Productions ("we", "us") handles information in the InstaDoc Productions Social Media Scheduler (the "Service"), a private tool that publishes short medical-education videos to social platforms on a schedule.

Who this covers

The Service is operated by InstaDoc Productions for its own channels. Accounts are created only for authorized staff. We do not offer consumer sign-ups and we do not sell, rent, or share any data with advertisers or data brokers.

What we collect

  • Account data: your email address and password hash, held by our authentication provider.
  • Platform access tokens: OAuth access and refresh tokens issued by Google (YouTube), Meta (Instagram and Facebook), and TikTok when you connect an account.
  • Platform account identifiers: channel ID, page ID, Instagram business account ID, TikTok open ID, and the display name shown for each connected account.
  • Video files and metadata: the videos you upload or sync, plus titles, descriptions, captions, hashtags, scheduled times, and generated transcripts.
  • Publishing results: the post ID, permalink, status, and any error returned by each platform.
  • Operational logs: timestamps and error messages needed to run and debug scheduled posting.

What we do not collect

We do not collect your followers' personal data, direct messages, comments, contact lists, location, payment details, or any health information about individuals. We do not use tracking or advertising cookies.

How platform data is used

Access tokens are used solely to upload and publish videos to the accounts you explicitly connect, and to read back the status and permalink of those posts. Tokens are stored encrypted at rest on our backend, are never sent to the browser, and are never shared with any third party.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use YouTube data for advertising, and we do not allow humans to read it except as needed for security, to comply with law, or with your explicit consent.

Third-party services we use

  • Supabase — database, authentication, and video file storage.
  • Google, Meta, and TikTok — the publishing destinations you connect.
  • AssemblyAI — generates captions from the audio of your videos.
  • OpenAI (via the Lovable AI Gateway) and Perplexity — generate title, description, and hashtag suggestions from video metadata.
  • Resend — sends operational email alerts to the account owner.

These providers process data only to deliver their function to us and act as our processors.

How long we keep data

  • Access tokens: until you disconnect the platform, or until they are revoked.
  • Video files: until you delete them, or 12 months after publishing.
  • Post records and logs: up to 24 months, for reporting.
  • Account data: until the account is deleted.

Deleting your data

You can disconnect any platform at any time in Settings, which deletes the stored tokens immediately. To erase everything, use our data deletion page. We complete deletion requests within 30 days and confirm by email.

You may also revoke our access directly at Google account permissions, in Facebook Settings under Business Integrations, or in TikTok Settings under Security and permissions.

Security

All traffic uses HTTPS. Data is encrypted at rest. Access is restricted by row-level security rules to the authenticated owner of each record, and tokens are only readable by server-side code.

Children

The Service is not intended for anyone under 18 and we do not knowingly collect their data.

Changes

If this policy changes materially, we will update the date above and notify account holders by email.

Contact

Questions or requests: admin@instadoc.health