Legal

Privacy Policy

Last updated: July 21, 2026

FavStash lets you save links to short-form posts (Instagram Reels, TikTok, YouTube Shorts), organize them, and search across what you saved. The links point at publicly available content on those platforms — we keep a pointer plus the small amount of context needed to make it searchable for you.

What we collect

  • Your account. Your email address (and an optional display name) so we can sign you in and contact you about your account.
  • What you save. The URLs you submit and any notes, tags, or collections you add. We also derive helper text — caption, transcript when one is available, a short summary — from each public link so you can search by meaning later.
  • Connected social accounts (if you link them). If you connect an Instagram, YouTube, or TikTok account for scheduling and analytics, we store the account’s ID, username, and profile picture, plus the OAuth access tokens the platform issues. Details below under “Connected social accounts.”
  • Posts you schedule. The caption, media you upload, platform settings, and publish time for each post you schedule, plus the resulting post link and platform post ID after publishing.
  • API keys (if you create them). We store a hash of each key, not the secret itself, plus a name and last-used time.
  • Standard technical logs. Things like request IDs and error messages needed to keep the service running and to investigate abuse. We do not run ad trackers or product-analytics SDKs.

What we don’t do

  • We don’t sell or rent your information.
  • We don’t share it with advertisers.
  • We don’t use your saves to train any AI model, ours or anyone else’s.

How we use it

  • To run your account and show you your stash.
  • To enrich each save (transcript, short summary, search index) so you can find it later.
  • To authenticate API and AI-agent requests you make against your own stash.
  • To keep the service secure, prevent abuse, and comply with law.

Connected social accounts

Connecting a social account is always optional and always started by you. When you connect one, the platform asks for your consent and then issues FavStash scoped OAuth tokens. Here is exactly what we do with them:

  • What we access. Your basic channel profile (ID, username, picture), permission to publish the posts you schedule, and the performance metrics of your account and posts (reach, views, likes, watch time, followers, and similar) when you ask for analytics.
  • What we do with it. Publish content only when you (or an AI agent you authorized) schedule it, and display analytics back to you. If you explicitly authorize an AI agent or script, we return the social-account data it requests through your FavStash API connection so it can analyze your account or carry out your instruction. We do not otherwise disclose that data — no browsing your messages, contacts, or feed, and no posting without an instruction from you.
  • Token storage. Access tokens live in a dedicated, encrypted-at-rest datastore that only our publishing and analytics systems can read. They are never exposed to your browser, other users, or third parties, and are deleted immediately when you disconnect the account.
  • Revoking access. Disconnect any channel from the FavStash dashboard at any time. For YouTube, Disconnect asks Google to revoke FavStash’s authorization immediately and then deletes the local tokens and connected-channel record. You can also revoke FavStash from the platform side: Instagram (Settings → Website permissions → Apps and websites), Google (Google security settings), or TikTok (Settings → Security → Apps).

YouTube. FavStash uses YouTube API Services to upload the videos you schedule and to read your channel’s analytics. By connecting a YouTube account you also agree to the YouTube Terms of Service; the Google Privacy Policy applies to Google’s handling of your data. FavStash’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Instagram connections use Meta’s Instagram API; Meta’s Privacy Policy governs Meta’s side. TikTok connections use the TikTok for Developers API under TikTok’s Privacy Policy. Platform data we fetch (analytics) is shown to you and cached briefly for performance. It is returned to an AI agent or script only when you have expressly authorized that client and instructed it to access your data. We don’t sell it, share it for advertising, or use it to train AI models. See Data deletion for removal instructions.

Service providers

We rely on a small number of trusted third parties to run the service: a cloud infrastructure provider (hosting, databases, sign-in), an AI provider (for transcripts, summaries, and semantic search), and — if you subscribe — a payment processor. They process information only to provide their service to us and are bound by their own terms.

AI and automated processing

When you save a link, automated systems pull what’s publicly available about it (caption, transcript when one exists) and produce a short summary plus a search index. We send only the link and that derived text to our AI provider. By default, what we send is not used to train their models. AI-generated text can be wrong — please don’t rely on it for anything consequential without checking.

If you connect Claude, ChatGPT, or any other agent to your stash, that agent acts on your instructions. Data returned to that agent is then handled by its provider under that provider’s terms and privacy policy. You control this access through your FavStash API key scopes and can revoke the key at any time.

Cookies and similar storage

We use a small number of session cookies to keep you signed in and to remember your theme/UI preferences. We don’t set advertising, retargeting, or third-party analytics cookies.

Retention and deletion

We keep your information while your account is active. You can delete individual saves from the app, disconnect any social account (which deletes its tokens immediately), or delete your whole account, which starts a 30-day deletion workflow covering your saves, scheduled posts, connected-account records, and tokens. A small amount of data may persist in backups or security logs for a limited period where required. Step-by-step instructions are on the Data deletion page.

Media you upload for social publishing is temporary staging data, not permanent file storage. FavStash marks each uploaded image or video to expire from our object storage 30 days after its most recent upload, scheduling, or rescheduling. Scheduling is limited to 21 days ahead, and scheduling refreshes that 30-day period so media is not removed before its publish time. Incomplete multipart uploads are aborted after one day. Cloud storage lifecycle deletion is asynchronous, so final removal can occur shortly after the 30-day eligibility point.

Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your information, and to object to or restrict certain processing. Email contact@sketricsolutions.com and we’ll handle it. EU/UK residents may also lodge a complaint with their local data protection authority.

Children

FavStash isn’t directed at children under 13 (or the age required where you live), and we don’t knowingly collect information from them.

Changes

We’ll post any updates here and refresh the “Last updated” date. For material changes we’ll notify you in the app or by email where required.

Contact

Sketric Solutions — contact@sketricsolutions.com. See also our Terms of Use.