Privacy Policy
Last updated 21 September 2026 · Effective 21 September 2026
This policy explains what Social Deviser collects, why, how long we keep it, and how you get rid of it. It covers the website at socialdeviser.com and the scheduling app behind it.
1. Who we are
Social Deviser is operated by German with Levels, Berlin, Germany (“we”, “us”). For the purposes of the EU General Data Protection Regulation we are the data controller for the personal data described here.
Contact: support@germanwithlevels.com
2. What we collect
We collect only what the service needs to work. Specifically:
- Account credentials. Your name, the email address you sign in with, and your password stored only as a salted PBKDF2 hash. We never store, log or transmit your password in readable form.
- Waiting list. If you joined the waiting list before launch: the email address you entered, when you joined, and when we sent the confirmation. It is used for one launch email and nothing else, and we delete it whenever you ask.
- Session data. A random session identifier held in an HttpOnly cookie. To slow down password guessing, we store a count of failed sign-in attempts against the IP address they came from.
- Content you create. The videos and images you upload, your titles, captions and per-platform overrides, the scheduled date, time and timezone, and which accounts each post is aimed at.
- Connected platform accounts. For each social account you link: the access and refresh tokens issued by that platform (encrypted at rest), your username or handle, display name, profile picture URL, public profile link, and public follower and post counts where the platform provides them.
- Publishing records. For each attempt: its status, the timestamp, the identifier and link of the resulting post, and any error message the platform returned.
- Analytics history. Aggregate counts for your published posts, such as views, likes, comments, shares, saves and reach where available, plus a daily snapshot of each connected account's follower or subscriber count.
- Subscription status. If you subscribe to Social Deviser Pro in the app, we receive from RevenueCat and the app store which plan is active, when it renews or ends, whether it is a free trial, and which store it was bought from. Apple or Google take the payment; we never see your card or payment details.
- Push notification tokens. If you allow notifications in the app, a device token that lets us send you a message when a post has published or failed.
- Operational logs. Standard server logs kept briefly for security and debugging.
We do not collect payment details (the app stores handle payment), contact lists, location data, or analytics and advertising identifiers. There are no third-party trackers on this site or in the app.
3. How we use it
- To sign you in and keep you signed in.
- To store your scheduled posts and show them on your calendar.
- To publish those posts to the accounts you selected, at the time you selected.
- To show you which account is connected and whether its access is about to expire.
- To report back what succeeded or failed, and to let you retry.
- To compare your published posts across platforms and show how your audience grows over time.
- To keep the service secure and to fix faults.
We do not sell your data. We do not share it with advertisers. We do not use your content, captions or media to train machine-learning models.
4. Data from Instagram, TikTok and YouTube
When you connect an account, that platform asks you to approve a specific set of permissions and then issues us a token. We use it only for the purposes below.
- Instagram. Through the Instagram Graph API we request permission to publish content to the account you connected and to read its basic profile information (user ID, username, profile picture, media and follower counts). We use the publishing permission to post the media you scheduled, and the profile information to display the connected account inside the app. Where separately authorised, we also read aggregate performance of your published posts for the Analytics page. We do not read your direct messages, your feed, your comments or your followers' personal data.
- TikTok. Through the TikTok Content Posting API we request permission to publish videos and photo posts to the connected account, and basic profile information such as your display name, avatar, username, profile link and follower statistics, where granted, to display the connected account. Where authorised, we read aggregate counts for your public posts to show their performance.
- YouTube. Social Deviser uses YouTube API Services to upload videos to the channel you connected. By connecting a YouTube account you also agree to the YouTube Terms of Service. Google's handling of your information is described in the Google Privacy Policy. You can revoke Social Deviser's access to your Google account at any time at myaccount.google.com/permissions, in addition to disconnecting inside the app. We read aggregate video counts and channel subscriber totals to show post performance and audience growth.
Data obtained from these APIs is used solely to provide the scheduling, publishing and analytics features you asked for. It is never sold, never used for advertising, and never transferred to anyone except the infrastructure providers listed below.
5. Legal basis (GDPR)
- Performance of a contract (Art. 6(1)(b)): storing and publishing your posts is the service you signed up for.
- Consent (Art. 6(1)(a)): connecting a social account, which you give on the platform's own authorisation screen and can withdraw by disconnecting.
- Legitimate interests (Art. 6(1)(f)): keeping the service secure, preventing brute-force sign-in attempts, and diagnosing faults.
7. How long we keep it
- Uploaded originals: deleted from storage roughly 24 hours after the post has published everywhere it was aimed at. Media belonging to a draft, a queued post or a failed post is kept until that post is published or deleted.
- Cover thumbnails: a small preview image is kept for as long as the post exists, so your calendar history stays readable.
- Posts and publishing records: kept until you delete the post.
- Post analytics: kept until you delete the related post or your Social Deviser account.
- Daily follower snapshots: kept until you delete your Social Deviser account. Disconnecting stops new snapshots for that platform.
- Access tokens: kept until you disconnect the account, or until the platform expires them.
- Sessions: expire 30 days after sign-in, and are removed immediately when you log out.
- Subscription status: kept while your account exists. When you delete your account we also ask RevenueCat to delete its record of you.
- Push tokens: removed when you log out of the app, when the device reports the token invalid, or after 120 days without the app being opened.
- Failed-attempt records: inactive records are cleared within 24 hours.
8. How to delete your data
You can remove your data yourself, at any time, without contacting us:
- One connected account: Accounts → Disconnect. The stored tokens and cached profile for that platform are erased straight away.
- One post: open it from the calendar or the activity log and choose Delete. The record and its analytics history go immediately; its media is removed from storage shortly afterwards.
- Everything: Accounts → Delete account. After you confirm with your password, your profile, connected-account tokens, posts, analytics history, sessions and uploaded media are permanently erased from Social Deviser. You can also email support@germanwithlevels.com if you cannot sign in.
Deleting data here does not remove posts that have already been published to Instagram, TikTok or YouTube. Those live on those platforms and must be deleted there.
9. Security
- The whole site is served over HTTPS.
- Platform access tokens are encrypted (AES-GCM) before being written to the database.
- Passwords are stored only as salted PBKDF2-SHA256 hashes.
- Session cookies are HttpOnly, Secure and SameSite=Lax, so scripts cannot read them.
- Posts, connected accounts and uploaded media are isolated by creator workspace.
- Repeated failed sign-ins from one address are locked out temporarily.
No system is perfectly secure, but if a breach ever affects your personal data we will notify you and the competent supervisory authority as the GDPR requires.
10. Your rights
If you are in the EU or UK you have the right to access your data, correct it, delete it, restrict or object to its processing, receive a portable copy, and withdraw consent at any time. Write to support@germanwithlevels.com and we will respond within one month.
You also have the right to complain to a data-protection supervisory authority. In Germany, the authority for the federal state in which you live.
12. Children
Social Deviser is a tool for content creators and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, email us and we will delete it.
13. Changes to this policy
If we change this policy, we will update the date at the top of the page. We will tell you by email before any change that materially affects how we use your data takes effect.
14. Contact
Questions, complaints and data requests:
support@germanwithlevels.com
German with Levels, Berlin, Germany.