Privacy Policy
Last updated: 24 June 2026
CrossPost ("we", "us", "our") is a web application available at https://www.getcrosspost.com that lets you upload a video once and publish it to all of your connected social media accounts at once. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and your rights in relation to it.
For the purposes of UK GDPR and EU GDPR, CrossPost is the data controller for the personal data described in this policy. Our contact address for all privacy matters is hello@getcrosspost.com.
By using CrossPost, you consent to the collection and use of your personal data as described in this policy. If you do not agree, do not use the Service.
1. What personal data we collect and why
1.1 Data collected via TikTok Login (OAuth)
When you connect TikTok, TikTok shares the following data with us through their official API, which you explicitly authorise during the OAuth consent screen:
- TikTok open_id — a unique, stable, pseudonymous identifier assigned by TikTok to your account. This is used as your primary identifier for your TikTok connection within CrossPost and never changes. We use this to identify your connected account across sessions.
- Display name — your public TikTok display name, shown in your CrossPost dashboard so you can confirm which account is connected.
- Avatar URL — a link to your TikTok profile picture, used for display purposes in your dashboard only.
- Access token and refresh token — OAuth credentials issued by TikTok. These are used solely to authenticate API requests to publish videos to your TikTok account on your behalf. They are never used for any other purpose and are never shared with third parties beyond the TikTok API itself.
1.2 Data collected via YouTube / Google Login (OAuth)
When you connect YouTube, Google shares the following data with us through their official API, which you explicitly authorise during the OAuth consent screen:
- YouTube channel ID — a unique, stable identifier for your YouTube channel. This is used as the primary identifier for your YouTube connection within CrossPost and to confirm which channel is connected.
- Channel name and avatar — your public channel name and picture, shown in your CrossPost dashboard so you can confirm which account is connected.
- Access token and refresh token — OAuth credentials issued by Google. These are used solely to authenticate API requests to publish videos to your YouTube channel on your behalf. They are never used for any other purpose and are never shared with third parties beyond the Google/YouTube API itself.
1.3 Video uploads
- Uploaded video files and captions — the video you upload and the caption you write are used solely to publish your post to the platforms you select. Video files are stored only transiently while being published and are deleted promptly once posting completes.
1.4 Session data
- Session cookie (cp_session) — a signed, HTTP-only, encrypted cookie that keeps you logged in. This is used solely to maintain your session and expires after 30 days. It contains no sensitive credentials.
1.5 Server and usage logs
We may collect basic server logs including IP addresses, timestamps, and HTTP request data for security monitoring and debugging purposes only. These logs are retained for a maximum of 30 days and are never used for tracking, profiling, or marketing.
2. What we do not collect
We do not collect or store:
- Your TikTok, YouTube, or other platform passwords or login credentials
- Your private messages, DMs, or inbox content on any platform
- Your follower lists, following lists, likes, or engagement data
- Your Google account credentials or login information
- Long-term copies of your video content — uploaded videos are stored only transiently while being published and are deleted promptly after posting
- Payment card details or financial information of any kind
- Device identifiers, advertising IDs, or cross-site tracking data
- Location data beyond what is implicit in server logs
We do not use third-party analytics tools, advertising networks, or tracking pixels on our website or in our application.
3. Legal basis for processing (UK/EU GDPR)
- Contract performance (Article 6(1)(b)) — processing your account identifiers, OAuth tokens, and uploaded content is necessary to deliver the CrossPost service you have signed up for.
- Legitimate interests (Article 6(1)(f)) — server logs are retained for security monitoring and debugging. This is in our legitimate interest and yours, as it protects the integrity of the Service.
- Consent (Article 6(1)(a)) — where you have explicitly authorised specific platform API scopes during the OAuth consent flow (for TikTok: user.info.basic, video.upload, video.publish; for YouTube: permission to upload videos to your channel).
4. How we use your data
Your personal data is used exclusively for the following purposes:
- Identifying your connected accounts within CrossPost
- Authenticating API requests to TikTok, YouTube, and other connected platforms on your behalf
- Publishing the videos you upload to the connected accounts you select, as you direct
- Displaying your connected account information in your personal dashboard
- Maintaining the security and integrity of the Service
We do not use your data for advertising, profiling, marketing, AI training, or any purpose beyond operating the Service as described above.
5. Data sharing and third-party processors
We do not sell, rent, or share your personal data with third parties for their own purposes. Data is shared only in the following limited circumstances:
- Connected platforms (TikTok, YouTube, and others you connect) — your video and caption are transmitted to the platform's official API to publish your post on your behalf, using the access token you authorised. Each platform's own Privacy Policy governs data held on that platform.
- Supabase — our managed database and storage provider, hosting your account data and tokens in the EU region. Supabase acts as a data processor under a Data Processing Agreement and is required to protect your data in accordance with GDPR.
- Vercel — our hosting and infrastructure provider. Web requests are served through Vercel's global network. Vercel acts as a data processor.
- Legal requirements — we may disclose personal data if required by law, court order, or regulatory authority, or to protect the rights, property, or safety of CrossPost or others.
All third-party processors are contractually required to handle your data in accordance with applicable data protection law.
6. Data storage and security
Your personal data is stored in a managed PostgreSQL database hosted by Supabase in the EU region. We implement the following technical and organisational security measures:
- OAuth access tokens and refresh tokens are stored encrypted at rest
- All data in transit is protected by HTTPS/TLS encryption
- Database access is restricted exclusively to server-side application code
- Row Level Security is enabled on all database tables
- No client-side code or browser-accessible endpoint can access your tokens
- Session cookies are HTTP-only, Secure, and SameSite=Lax
While we implement reasonable security precautions, no system is completely secure. If you believe your account has been compromised, contact us immediately at hello@getcrosspost.com.
7. Data retention
We retain your personal data for as long as your account is active:
- Account data (account identifiers, display names, avatar URLs) — retained until you delete your account
- OAuth tokens (access token, refresh token) — retained until you disconnect the relevant account or delete your account, then deleted within 30 days
- Uploaded videos — stored only transiently while being published, then deleted promptly once posting completes
- Post history — records of videos CrossPost has posted on your behalf are retained until you delete your account
- Server logs — retained for a maximum of 30 days
8. Cookies
CrossPost uses one essential cookie only. We do not use tracking, advertising, or analytics cookies of any kind.
- cp_session — a signed, encrypted, HTTP-only session cookie that authenticates your session. It is set when you sign in, expires after 30 days, and is deleted when you sign out. This cookie is strictly necessary for the Service to function. It cannot be disabled while using CrossPost.
9. Your rights under UK/EU GDPR
You have the following rights in relation to your personal data. To exercise any of them, email hello@getcrosspost.com and we will respond within 30 days.
- Right of access — request a copy of the personal data we hold about you
- Right to rectification — request correction of inaccurate or incomplete data
- Right to erasure — request deletion of your personal data ("right to be forgotten")
- Right to restriction of processing — request that we limit how we process your data in certain circumstances
- Right to data portability — request your data in a structured, machine-readable format
- Right to object — object to processing based on legitimate interests
- Right to withdraw consent — withdraw consent at any time where processing is consent-based, without affecting the lawfulness of prior processing
You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk or with your local EU supervisory authority if you are based in the EU.
10. International data transfers
Your data is stored in the EU (Supabase EU region) and the Service is hosted via Vercel's global network. When you use CrossPost, your data may be processed in countries outside the UK or EU — for example, when video data is transmitted to a connected platform's servers. Where such transfers occur, they are conducted under appropriate safeguards in accordance with UK GDPR, including standard contractual clauses where applicable.
11. Children's privacy
CrossPost is not directed at or intended for use by anyone under the age of 18. We do not knowingly collect personal data from children. If you believe a child under 18 has provided us with personal data, please contact us at hello@getcrosspost.com and we will delete it promptly.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the date at the top of this page and notify you via the Service or by email. Your continued use of CrossPost after changes are posted constitutes acceptance of the revised policy.
13. Contact and complaints
For any privacy-related questions, data subject requests, or concerns, please contact us at: hello@getcrosspost.com
We take privacy complaints seriously and will respond within 30 days. If you are not satisfied with our response, you have the right to complain to the ICO at ico.org.uk/make-a-complaint.