Privacy policy
Last updated 9 October 2026
Outpost is software you run on your own computer or server. This website (outpost.sultantech.id), run by Sultan Tech, only helps you log in to Threads and Instagram through our Meta app, to YouTube through our Google app, and to TikTok through our TikTok app. This policy explains what that means for your data.
What this website handles
- When you connect an account, Meta sends us a one-time login code. We exchange it for an access token and your public profile (ID, username, profile picture, account type).
- We encrypt that token with a key that only your Outpost app has, hold the encrypted copy for at most 5 minutes until your app collects it, then delete it.
- For YouTube, Google sends us a one-time login code. We exchange it for an access token, a refresh token and your channel's ID, name and picture, and hand them to your app the same encrypted way. Google requires our app secret to renew an access token, so about once an hour, while you use YouTube features, your app sends its refresh token here; we pass it to Google and return the new access token without storing or logging either.
- When your app publishes a post with a photo or video you uploaded to it, the app places a temporary copy of that file in our storage (Vercel Blob) so Meta can download it. The copy sits at an unlisted address, is deleted as soon as the post is published, and anything left over is deleted within 24 hours. We don't look at, index or reuse these files.
- We keep short-lived technical logs (time, status code, IP address) for up to 7 days to stop abuse. They contain no tokens or content.
What we never receive
- Your posts, captions, comments, replies, messages or insights. Media reaches us only as the temporary copy described above.
- A readable copy of your access token after the handoff.
TikTok user data
- For TikTok, TikTok sends us a one-time login code. We exchange it for an access token, a refresh token and your display name, username and picture, and hand them to your app the same encrypted way. TikTok requires our app secret to renew an access token, so about once a day your app sends its refresh token here; we pass it to TikTok and return the new token without storing or logging it.
- Outpost uses TikTok's APIs only to send the videos you choose to your TikTok inbox or post them with the settings you pick, and to show your account's follower, like and video counts. By connecting TikTok you agree to TikTok's Terms of Service. Revoke access any time in the TikTok app under Settings and privacy → Security → Apps and services permissions.
YouTube and Google user data
- Outpost uses YouTube API Services to upload the videos you choose to your channel and to read your videos' and channel's public counts (views, likes, comments, subscribers). By connecting YouTube you agree to the YouTube Terms of Service, and Google's use of data is covered by the Google Privacy Policy.
- Outpost's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The data is used only to provide these features to you, is never sold, and is never used for advertising.
- You can revoke Outpost's access at any time on your Google account's security page.
What the Outpost app stores on your machine
Your access tokens (encrypted), your posts and schedule, cached comments and insights, and an activity log. They live in the ~/.auto-post folder and you control them.
Your choices
- Disconnect an account in the app to delete its token and cached data.
- Remove Outpost's access in your Threads or Instagram settings under Apps and websites, for YouTube in your Google account's third-party access, or for TikTok in the TikTok app.
- See Delete your data for step-by-step instructions.
Contact
Sultan Tech · yugie@sultantech.id