99Posts

Privacy Policy

Version 1.0 - Effective July 15, 2026

This policy explains what 99Posts processes when you connect social accounts, schedule and publish short videos, collaborate with another account group and use subscriptions or insights.

Controller and contact

The controller is STRICS IT GmbH, Florian-Gmainer-Strasse 4, 4240 Freistadt, Austria. For privacy requests or support, contact hello@strics.at.

This policy covers the 99Posts iOS app, its Firebase backend and the 99Posts legal pages. It explains the data used to connect social accounts, schedule and publish videos, coordinate collaborations, provide subscriptions and display post insights.

Account and sign-in data

You can sign in with Apple or Google. We receive the Firebase user identifier and, depending on your choice and provider settings, your name, email address and profile information. Authentication credentials are handled by Apple, Google and Firebase Authentication; 99Posts does not receive your Apple or Google password.

We use this information to create and secure your account, restore access, associate your account groups and subscription, and respond to support or deletion requests.

Connected social accounts

When you connect YouTube, Instagram or TikTok, the provider returns an account identifier, username, profile image, granted permissions and OAuth access or refresh tokens. Tokens are encrypted with AES-256-GCM before storage in Firestore, and the encryption key and provider secrets are held in Google Secret Manager.

99Posts uses those credentials only to show the connected account, obtain supported publishing settings, upload or manage content you schedule, retrieve publication status and insights, and revoke access when you disconnect or delete your account. You can also revoke 99Posts in the provider's own account settings.

Posts, media and scheduling

To create a post, you may provide a video, selected or uploaded cover image, title, caption or description, hashtags, first comment, manually entered location, disclosure settings, collaborators, visibility and platform-specific options. We store the original video and low-resolution JPEG cover in Firebase Storage and the post metadata, schedule, warnings and publication status in Firestore.

At the scheduled time, our backend sends the selected content and settings directly to the official YouTube, Instagram or TikTok APIs. Each platform processes the content under its own terms and privacy policy. Some settings are not supported by every platform; the app records a warning and publishes the supported fields when you continue.

Collaborations

If you invite another 99Posts account group, we share the post identifier, source and target account-group names, schedule, selected platforms and publishing status with the owner of that group. Each participant can choose the platform accounts made available for that collaboration.

Only invite people who should receive this information. Removing an invite does not remove content that another participant has already received or published through a connected platform.

Subscriptions and purchases

Apple processes payment details. StoreKit provides product, transaction, renewal, expiration, refund and revocation information so we can verify your Hobby, Pro or MAX access and enforce account-group, scheduling and post limits.

We store the verified entitlement state, an account-linked StoreKit identifier and limited notification or restore records needed for access, fraud prevention and support. We do not receive your full payment-card details.

Insights and product interaction

For published posts, 99Posts can periodically retrieve normalized metrics such as views, likes, comments and shares from the connected platform. These metrics are linked to the post target and account group and are used to provide the Insights feature and show what is working on your accounts.

We do not include advertising SDKs, sell personal data or use this information for cross-app advertising tracking.

Security and diagnostic data

Firebase App Check and Apple App Attest process device-attestation assertions to reduce automated abuse. Requests to our backend also expose technical data such as IP address, function or endpoint, timestamp, app and operating-system version, user agent, result, duration and error type to Google Cloud infrastructure.

We use this data to authenticate requests, prevent fraud, enforce limits, troubleshoot failures and keep publishing idempotent. 99Posts does not use the advertising identifier and does not include Firebase Analytics or Firebase Crashlytics.

Purposes and legal bases

We process account, connected-platform, media, collaboration, subscription and insight data to perform our contract with you and provide the features you request. We process security, diagnostic and proportionate operational data for our legitimate interests in preventing abuse, protecting accounts, controlling service cost and maintaining reliability.

We process billing and legally required records to meet accounting, consumer and legal obligations. Where consent is required, you may withdraw it, although the affected feature may stop working.

Providers and international transfers

We use Apple for Sign in with Apple and App Store subscriptions; Google for Google Sign-In, Firebase Authentication, App Check, Firestore, Storage, Cloud Functions, Cloud Scheduler, Secret Manager and operational logs; Meta for Instagram; Google for YouTube; TikTok for TikTok publishing; and Vercel for these public legal pages.

These providers process data under their applicable terms and data-protection commitments. Processing can occur outside the European Economic Area using applicable safeguards such as adequacy decisions or standard contractual clauses.

Retention

Original videos are deleted after successful publication or completion of a test post. Cancelled originals are deleted after 24 hours and failed originals after 7 days. An unattached upload expires after at most 24 hours or when the subscription expires, whichever comes first. Low-resolution JPEG covers remain in post history until you delete your account.

Webhook summaries expire after 7 days, Meta deletion receipts after 30 days, and StoreKit restore, notification and exhausted-publication records after at least 90 days or longer when needed for an active subscription, accounting, disputes, security or law. Post records, connected-account summaries and insight snapshots remain until account deletion or until no longer needed to provide the service.

Deletion and disconnection

You can disconnect an individual social account or delete your 99Posts account from Account settings. Account deletion revokes Firebase sessions, attempts to revoke provider access, deletes OAuth tokens, account groups, posts, media, collaboration records and linked insights, and then deletes the Firebase Authentication account.

Limited subscription-restore, security, deletion-confirmation or legal records may remain for their stated retention period. Account deletion does not cancel an Apple subscription and cannot remove posts already published to YouTube, Instagram or TikTok; manage those in the platform and cancel subscriptions in your Apple Account settings.

Your rights

Depending on applicable law, you may request access, correction, deletion, restriction, portability or objection and may withdraw consent. Contact hello@strics.at. You may complain to the Austrian Data Protection Authority or your local supervisory authority.

99Posts is not directed to children under 13. If local law requires parental consent at a higher age, a parent or guardian must provide it. We may update this policy when the app, providers or law changes; the current version and effective date will remain available in the app and online.