Skip to document

Slatepost Privacy Policy

Slatepost schedules posts to social media accounts you connect. That means we hold access tokens for those accounts and the content you ask us to publish. This policy sets out exactly what we hold, why, for how long, and how you get rid of it.

Last updated

1. Who we are

Slate is operated by Vantage Thinking of 427 Pitt Street, Sydney NSW 2000, Australia. For the purposes of the UK and EU General Data Protection Regulation, we are the controller of the personal data described in this policy. You can reach us about anything in this policy at joel@vantage.fyi.

This policy covers the hosted service at slatepost.lol. It does not cover the social media platforms you connect — once your content is published to TikTok, or any other platform, that platform’s own privacy policy governs what happens to it there.

2. What we collect

Categories of personal data Slate collects
CategoryWhat it includesWhere it comes from
Account dataYour email address, name, password hash, organisation name, team membership and role, language and timezone preference.You, when you register and configure your account.
Connected channel dataFor each social account you connect: the platform’s identifier for that account, the display name and username, the profile picture, and the OAuth access and refresh tokens issued to us.The platform, through its OAuth flow, after you authorise us.
Content dataPost text, titles, hashtags, per-platform publishing settings, scheduled times, and the images, video and other media you upload to the library.You, when you compose and schedule posts.
Publishing resultsWhether a post succeeded or failed, the error a platform returned, and the identifiers a platform assigned to the published post.The platform, when we publish on your instruction.
Technical dataIP address, browser and device information, and server and application logs including timestamps and error traces.Automatically, when you use the service.

We do not knowingly collect special category data, and you should not put it into Slate beyond what is inherent in the posts you choose to publish.

3. TikTok: what we access and why

When you connect a TikTok account, you are taken to TikTok to sign in and approve a specific set of permissions (“scopes”). We never see your TikTok password. TikTok returns an access token and a refresh token to us, and those tokens are the only way we can act on your account.

Slate requests the following scopes. TikTok lists them on the consent screen before you approve, and you can decline.

TikTok scopes requested by Slate
ScopeWhat it grantsWhere Slate uses it
user.info.basicYour TikTok open ID, avatar, display name and username.Identifying which TikTok account a post will go to, and rendering the channel in the composer, calendar and settings.
video.uploadPermission to send content to your TikTok inbox as a draft.The “Send to inbox” posting method, where you finish and publish inside the TikTok app.
video.publishPermission to publish content directly to your profile.The “Direct post” posting method, where Slate publishes at your scheduled time.

What we never do with TikTok data

  • We do not sell it, rent it, or share it with advertisers or data brokers.
  • We do not use it to train machine learning models, our own or anyone else’s.
  • We do not read your direct messages. No scope we request grants that, and TikTok does not offer one.
  • We do not post to your account except at a time and with content you set up in Slate.
  • We do not use your TikTok data for any purpose other than operating the features described in the table above.

4. TikTok: what we store, where and for how long

TikTok data stored by Slate
DataStored inRetention
TikTok user identifier (open ID)Our application database, as the channel’s internal identifier.Until you remove the channel.
Display name and usernameOur application database.Until you remove the channel.
Profile pictureThe URL is stored in our database; a copy of the image is stored in our object storage so the avatar renders reliably.Until you remove the channel.
Access tokenOur application database, on the channel record.Overwritten each time it is refreshed. TikTok access tokens are short-lived and Slate treats them as valid for about 24 hours.
Refresh tokenOur application database, on the channel record.Until you disconnect the channel in Slate or revoke Slate in TikTok.
Post content and settingsOur application database; media in our object storage.Until you delete the post, or until your account is deleted.
Publish identifier and resulting video identifierOur application database, on the post record.With the post record.

Tokens are held so that Slate can publish at the time you scheduled, which may be hours or weeks after you closed the browser. They are restricted to our application servers and background workers, and are never sent to your browser, never written into logs, and never shared with third parties.

5. TikTok: what we send when you publish

At the moment a scheduled TikTok post runs, Slate sends TikTok the media and the settings you chose in the composer, and nothing else. Specifically:

Data Slate sends to TikTok when publishing
FieldValuesWhen it applies
MediaThe video file, or up to 35 images for a photo carousel, together with the cover image you selected.Always.
Caption or titleThe text you wrote. TikTok caps titles at 90 characters.Always.
AudiencePUBLIC_TO_EVERYONE, MUTUAL_FOLLOW_FRIENDS, FOLLOWER_OF_CREATOR or SELF_ONLY.Direct post only.
Allow comments, Duet, StitchOn or off, as you set them. Duet and Stitch exist for video only; TikTok has no equivalent for photo posts.Direct post only.
Auto-add musicYes or no.Photo posts, direct post only.
AI-generated labelOn or off, as you set it.Video posts, direct post only.
Commercial content disclosureWhether the post promotes your own brand, is branded content on behalf of a third party, or both.Direct post only.
Posting methodDIRECT_POST or UPLOAD.Always.

We do not add watermarks, our own branding, or any tracking to your content. We do not attach your Slate account details, your email address, or data from any other connected channel.

6. TikTok: how to revoke access and delete your data

There are two independent switches, and we recommend using both.

1. Disconnect the channel in Slate

Open Settings, find the TikTok channel, and choose Disconnect or Delete. Slate immediately stops publishing to that account, stops refreshing its tokens, and stops collecting metrics for it. Any posts still scheduled to that channel will not be sent.

To be precise about what this does to the stored record: removing a channel marks it as deleted and takes it out of the product. The underlying row, including the tokens, remains in our database in that deleted state until it is purged, which happens within 30 days. That is why the second step matters.

2. Revoke Slate inside TikTok

In the TikTok app, go to Profile, then the menu, then Settings and privacy, then Security & permissions, then Manage app permissions. Select Slate and remove it. TikTok invalidates our tokens straight away, so they cannot be used again even before our copies are purged. This is the authoritative revocation and it is entirely under your control.

To have everything erased rather than simply disconnected — the channel record, the posts sent to it, the media, and the stored metrics — email joel@vantage.fyi from your account address and ask for erasure. We will complete it within 30 days and confirm when it is done. Deleting your whole Slate account erases all connected channels with it.

Content that has already been published to TikTok stays on TikTok. Deleting it in Slate does not delete it from your TikTok profile; you need to delete the post in TikTok as well.

7. Cookies and similar technologies

Slate sets a small number of strictly necessary cookies. Without them you cannot stay signed in.

Cookies set by Slate
CookiePurposeType
authKeeps you signed in. Contains your session token.Strictly necessary
i18nextRemembers your interface language.Preference

9. Who we share data with

We do not sell personal data, and we do not share it for cross-context behavioural advertising. We disclose it only to the following categories of recipient, each under a written contract that limits them to processing it on our instructions.

Categories of recipient
RecipientWhat they receiveWhy
Social platforms you connect, including TikTokThe post content and settings you scheduled to that platform.To publish on your instruction.
Railway CorporationAll service data, as the infrastructure it runs on.Application hosting, database and background job processing.
no third-party object storage; uploaded media is stored on the application server's own diskUploaded media and cached channel avatars.Storing and serving media files.
transactional email (password reset only) is relayed via a self-hosted HTTPS-to-SMTP bridge on Vercel and delivered through Google WorkspaceYour email address and the contents of service emails.Sending account activation, password reset and notification email.
Sentry (only if this deployment sets a Sentry DSN)Error reports: a stack trace, the page it happened on, and browser and version information. Never tokens, never post content.Diagnosing faults. Slate loads no product analytics, no advertising pixels, no tag manager and no session recording.

We may also disclose data where we are legally required to, to establish or defend legal claims, or as part of a merger or acquisition — in which case we will tell you before your data becomes subject to a different privacy policy.

10. International transfers

Slate is hosted in the United States. Some of the providers listed above process data outside that region. Where personal data leaves the UK or the European Economic Area, we rely on an adequacy decision where one exists, and otherwise on the UK International Data Transfer Addendum or the European Commission’s Standard Contractual Clauses, together with additional safeguards where they are needed.

Publishing to a social platform necessarily transfers your content to that platform’s own infrastructure, wherever that is. TikTok documents its own transfers in its privacy policy.

11. How long we keep data

Retention periods
DataRetention
Account and organisation recordsFor as long as your account is open, then erased within 30 days.
Connected channel records and OAuth tokensUntil you disconnect the channel or close your account, then purged within the erasure window below.
Posts, drafts and publishing historyUntil you delete them, or until your account is closed.
Uploaded mediaUntil you delete it from the media library, or until your account is closed.
Server and application logs90 days
BackupsBackups roll off on a fixed cycle of 35 days. Deleted data can persist in a backup until that cycle completes, after which it is gone.

Once an account is closed we erase or irreversibly anonymise its data within 30 days, except where we must keep something to meet a legal obligation or to defend a legal claim.

12. Security

  • All traffic to slatepost.lol and to our API is encrypted in transit with TLS. Data is encrypted at rest by our hosting and storage providers.
  • Passwords are stored as salted one-way hashes. We never store them in a recoverable form and we never see your password for any connected platform.
  • OAuth tokens are held on the server side only. They are never sent to your browser and are excluded from application logs.
  • Access to production systems is limited to the people who need it, is individually authenticated, and is logged.
  • We keep our dependencies patched and monitor for known vulnerabilities.

No service can promise perfect security. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and tell you without undue delay where the law requires it.

13. Your rights

Depending on where you live, you have some or all of the following rights over your personal data:

  • Access. Get a copy of the personal data we hold about you.
  • Rectification. Have inaccurate data corrected.
  • Erasure. Have your data deleted, subject to the retention obligations above.
  • Restriction and objection. Ask us to pause processing, or object to processing we base on legitimate interests.
  • Portability. Receive the data you gave us in a structured, machine-readable format, or have it sent to another provider.
  • Withdraw consent. Where we rely on consent, withdraw it at any time. This does not affect processing that already happened.
  • Complain. Lodge a complaint with your local data protection supervisory authority.

If you are a California resident: we do not sell or share personal information as those terms are defined by the CCPA, and we will not discriminate against you for exercising your rights.

To exercise any of these, email joel@vantage.fyi. We respond within one month, and will tell you if we need longer because a request is complex. We may ask you to confirm your identity first.

14. Children

Slate is not intended for children. You must be at least 16, or the minimum age of digital consent in your country if that is higher, to hold an account. We do not knowingly collect data from anyone below that age; if you believe we have, tell us at joel@vantage.fyi and we will delete it.

15. Open source

Slate is free software licensed under the GNU Affero General Public License v3.0, and is a modified version of Slate (upstream release v1.47.0), Copyright © 2025 Nevo David. The complete Corresponding Source for the version running on this site is published at https://github.com/encryptedvolume/slatepost, free of charge and without needing an account.

This matters for privacy in a practical way: the code that handles your tokens and your content is published, so the claims made in this policy can be checked rather than taken on trust. Slate is not affiliated with, endorsed by, or sponsored by Slate or Nevo David.

16. Changes to this policy

We update this policy when the service changes or when a platform we integrate with changes what it requires. The “Last updated” date at the top always reflects the current version. If a change materially affects how we handle your personal data, we will tell you by email or in the product before it takes effect.

17. Contact

Privacy questions, data subject requests and complaints go to joel@vantage.fyi. Everything else goes to joel@vantage.fyi.

Vantage Thinking
427 Pitt Street, Sydney NSW 2000, Australia

You can also read our Terms of Service.