Privacy Policy
Last updated: 1 October 2026
This policy explains what personal data Shoot to Social handles, why, who receives it and what you can do about it.
1. Who is responsible
The data controller is Better Quality Assurance S.R.L. (BetterQA), registration RO39687318, Strada Transilvaniei 202, Baciu 407055, Cluj County, Romania. Contact: brad@betterqa.co.
2. What we collect
From the Telegram chats that use the bot. The Telegram chat ID; the Telegram file identifiers of the photos, videos and voice notes you send; the photos and videos themselves while they are being published; the text you type to describe a job; and, if you describe it by voice, a written transcript of the voice note. We do not keep the voice recording itself.
From the business's website administration. Some businesses also send posts from their own website's admin area. In that case we receive links to the photos or videos, the captions and the platforms to publish to.
What the service produces. The captions it writes for each platform, the list of platforms a post goes to, and a publishing record for each platform: whether it succeeded, the ID or link of the published post, and any error message.
From the connected platforms. For Facebook and Instagram: the ID of the business's Facebook Page and of its Instagram account, a Page access token and the token's expiry date. For TikTok: see section 6.
What appears in the content. Photos and videos can show people, number plates or documents. We do not analyse images to identify anyone, but whatever is in a picture you send will be published where you sent it.
3. Why we use it, and on what legal basis
- To publish the business's posts and report back on them. This is necessary to provide the service the business asked for (GDPR Article 6(1)(b)).
- To keep publishing records, so that a post can be tracked, corrected, re-sent or removed, and to keep the service secure and working. This is in our legitimate interest and that of the business (Article 6(1)(f)).
- To transcribe voice notes and write captions. This is part of providing the service (Article 6(1)(b)).
We do not sell the data, use it for advertising or build profiles from it.
4. Who receives it
- Telegram, which carries the messages between you and the bot.
- OpenAI, which receives voice notes to turn them into text (Whisper speech recognition).
- OpenRouter, which receives the text description of the job and returns the captions. It receives text only, not the photos or videos.
- Meta (Facebook and Instagram), which receives the photos, videos and captions published to the business's Page and Instagram account.
- TikTok, which receives the videos, photos and captions sent to the business's connected TikTok account.
- Supabase, which stores the photos shown in the business's website gallery and briefly holds copies of media while Instagram and TikTok fetch them.
- Railway, which hosts the service and its databases.
Some of these providers are based outside the European Economic Area, for example in the United States.
Photos sent to the website gallery are public: they appear on the business's own website.
5. How long we keep it
- Media files on our servers. The service downloads each photo or video to a temporary folder to publish it, and those files are deleted as soon as that platform's publish attempt ends. The temporary public copies used by Instagram and TikTok are removed at the same point.
- Published content. Posts stay on Facebook, Instagram and TikTok, and photos stay in the website gallery, until the business removes them or asks us to.
- Publishing records (captions, transcripts, file identifiers, chat ID, results). We keep them for as long as the business uses the service so that posts can be traced and managed. You can ask us to delete them at any time.
- Access tokens. Kept until the business disconnects the account. Disconnecting deletes them.
6. TikTok
When a business connects TikTok, it logs in on TikTok's own page and approves these permissions (scopes):
user.info.basic, used to read the account's identifier and username so we can show which account is connected;video.upload, used to upload videos to the account's TikTok inbox as drafts;video.publish, used for posts made only of photos, which TikTok creates on the account directly.
From TikTok we store the account's open ID and username, the access token and refresh token, and their expiry dates. The tokens are encrypted. We do not read the account's followers, messages, viewing history or other videos.
Videos arrive in the TikTok inbox as drafts. The account owner chooses who can see each one and posts it from the TikTok app. If they never post it, it stays a draft. For a post made only of photos, the service first asks TikTok which visibility settings the account allows and uses one of those. TikTok fetches the photos from a temporary public copy, which we delete once TikTok has finished.
You can stop the service's access to TikTok in two ways: remove Shoot to Social from the apps connected to your account in TikTok's settings, or email us. When we disconnect an account, we delete the stored TikTok data and ask TikTok to revoke the token.
7. Security
Access tokens for every platform are encrypted with AES-256-GCM before they are stored. Only Telegram chats we have explicitly allowed can use the bot. Connections to the platforms use HTTPS.
8. Your rights
Under the GDPR you have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to how we use it, and to receive it in a portable form. To use any of these rights, email brad@betterqa.co. We will answer within one month.
You also have the right to complain to the Romanian data protection authority, the National Supervisory Authority for Personal Data Processing (ANSPDCP), at www.dataprotection.ro.
9. Changes
If the service starts handling data differently, we will update this policy and the date at the top.
10. Contact
Questions about this policy or your data: brad@betterqa.co.