Privacy Policy for Platiipus
Platiipus ("Platiipus," "the app," "we," "us," or "our") is a macOS application that lets you connect your own social media accounts and publish videos to them from one place. This Privacy Policy explains what information the app handles, how it is stored, and the choices you have.
This policy is published by Gravitek Ventures, LLC. If you have questions, contact us at privacy@gravitekventures.com.
Summary
Platiipus is designed to be local-first. The app runs on your Mac, stores your data on your Mac, and communicates directly with the social platforms you choose to connect (Google/YouTube, Meta/Facebook and Instagram). We do not operate a server that receives, stores, or processes your content or credentials. We do not sell your data, and the app contains no advertising or third-party analytics/tracking SDKs.
Information the app handles
1. Social account connections (you provide via OAuth)
When you connect an account, the app uses each platform's official OAuth sign-in flow. You authenticate directly with the platform — Platiipus never sees or receives your passwords. After you approve access, the platform returns authorization tokens. Depending on the platform, the app handles:
- YouTube / Google: an OAuth access token and refresh token; your channel information returned by the YouTube Data API (under the
youtube.uploadandyoutube.readonlyscopes). - Facebook & Instagram / Meta: an OAuth access token; your Facebook user ID and name; the list of Facebook Pages you manage and their access tokens; and any linked Instagram Business account IDs and usernames (under the
public_profile,pages_show_list,pages_manage_posts,pages_read_engagement,instagram_basic, andinstagram_content_publishscopes).
We request only the scopes needed to list your accounts and publish content on your behalf.
2. Content you choose to upload
To publish a post, you select a video file from your Mac and enter the details you want — for example titles, descriptions, tags, category, language, privacy status, and scheduling options. This content is sent directly from your Mac to the destination platform's API when you choose to upload. The app does not route it through any server we control.
3. App configuration and "brand" settings
The app lets you organize accounts into "brands" and save default upload settings (such as default tags, category, and description text). This configuration is stored locally on your device.
What the app does NOT collect
- We do not collect your name, email, or contact details for our own use.
- We do not use third-party analytics, advertising, crash-reporting, or tracking services.
- We do not have a backend server that stores your videos, tokens, or account data.
Where your data is stored
- Authorization tokens are stored in the macOS Keychain, the operating system's encrypted credential store. They are saved with device-only protection (
kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly), meaning they are not included in iCloud Keychain sync. - App data (brands, connected-account records, and default settings) is stored locally on your Mac using Apple's on-device SwiftData storage.
- Videos remain in their original location on your Mac; the app reads a file only when you select it for upload.
Because storage is local, the security of this data also depends on the security of your Mac and your macOS user account.
This website and cookies
This website is hosted using Cloudflare, a content delivery and security provider. This section is about the website itself, not the Platiipus app described above.
We do not use analytics, advertising, or tracking cookies on this site. Cloudflare may place a small number of strictly necessary cookies — for example __cf_bm, cf_clearance, _cflb, or _cfuvid — solely to protect the site from bots, abuse, and denial-of-service traffic, and to route requests reliably. These cookies do not identify you personally and are not used to track you across other websites. Because they are strictly necessary for security and site delivery, they don't require a cookie consent banner under applicable ePrivacy/GDPR rules, but we disclose them here for transparency. See Cloudflare's own Cookie Policy for details.
How your information is used
We use the information solely to:
- authenticate you with the platforms you connect;
- display your connected accounts, Pages, and channels;
- publish the videos and metadata you submit to the platforms you select;
- remember your preferences and default upload settings.
We do not use your content or account data for advertising, profiling, or training machine-learning models.
Sharing and disclosure
The only third parties your data reaches are the platforms you explicitly connect, and only to perform the actions you request:
- Google LLC (YouTube) — see Google's Privacy Policy: policies.google.com/privacy
- Meta Platforms, Inc. (Facebook, Instagram) — see Meta's Privacy Policy: facebook.com/privacy/policy
Your use of those platforms through Platiipus is also governed by their respective terms and policies. We do not sell, rent, or share your information with any other third parties.
Google API Services disclosure
Platiipus's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Platiipus uses Google user data only to provide and improve the app's stated upload features, does not transfer that data except as needed to provide those features, and does not use it for advertising.
Your choices and controls
- Disconnect an account. You can remove a connected account at any time within the app. For Google, the app revokes the token with Google's revocation endpoint and deletes it from the Keychain.
- Revoke access at the platform. You can also revoke Platiipus's access directly from your account settings:
- Google: myaccount.google.com/permissions
- Facebook: Settings → Business Integrations
- Delete local data. Removing the app and its stored data from your Mac deletes the locally stored brands, settings, and any tokens held in the Keychain for the app.
For step-by-step instructions covering all of the above, see our Data Deletion Instructions.
Data retention
Tokens and app data are retained on your device until you disconnect the relevant account, delete the data, or remove the app. We do not retain copies, because we do not receive your data on any server.
Children's privacy
Platiipus is a content-publishing tool intended for use by adults (creators and account managers). It is not directed to children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly handle personal information from children. Note that YouTube's "made for kids" setting in the app refers to how your published content is classified on YouTube, not to data collection by Platiipus.
Security
The app relies on platform-standard protections: OAuth with PKCE for authentication (no passwords or client secrets stored in the app), the macOS Keychain for token storage, the macOS App Sandbox, and HTTPS for all communication with platform APIs. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
International users
Because data is processed locally on your device and sent directly to the platforms you connect, any cross-border transfer is performed by those platforms under their own policies.
Changes to this policy
We may update this Privacy Policy as the app evolves (for example, when support for TikTok or podcast platforms is added). When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you within the app.
Contact
Questions or requests about this policy:
Gravitek Ventures, LLC
privacy@gravitekventures.com