Output Privacy Policy

Last updated September 8, 2026.

This policy describes how Output, at output.social and in the Output iOS app, handles your data.

What we collect

When you sign in, we store your email address and a unique account ID. If you sign in with Google, Google also provides your name and profile picture, which we show on your profile, and you may pick a YouTube channel in the same step (see YouTube below).

When you connect a platform (YouTube, Instagram, Threads, Facebook Pages, Bluesky, X, LinkedIn or TikTok), we store the access tokens the platform issues so Output can read your comments and publish on your behalf, and the account details you connect: handle, display name, profile ID and profile picture URL. Bluesky has no OAuth, so for Bluesky we store the app password you enter.

When you use the inbox, we cache what it shows so the app loads quickly: comments and replies on your posts, mentions of your account, and, on Bluesky and on Instagram accounts connected through Instagram Login, your direct messages and story replies. Each cached item holds the author's name and picture URL, the text, a like count and a timestamp.

When you publish through Output, we store the post, its status on each platform and a link to the result. Photos and videos you upload for publishing are stored on Cloudflare R2 so the platforms can fetch them.

If you turn on notifications in the iOS app, we store your device's push token so we can send them. If you subscribe, Stripe (on the web) or Apple (in the iOS app) processes your payment. We do not see or store your card number; we store your subscription status and renewal date.

YouTube

Output uses YouTube API Services. By connecting a YouTube channel you agree to the YouTube Terms of Service, and Google's handling of your data is governed by the Google Privacy Policy.

We request two YouTube scopes. youtube.force-ssl lets Output list your recent uploads, read the comments on them (including comments held for review), post the replies you write, remove comments you choose to remove, and upload the videos you publish through Output with the title, description, thumbnail, captions and playlist you set. yt-analytics.readonly lets Output read your own channel's daily views, watch time, subscriber changes, audience retention and traffic sources for the Analytics page. If you sign in with Google, the same approval also shares your email address, name and profile picture, which create or sign into your Output account.

We store your OAuth tokens, your channel and uploads-playlist IDs, a cache of recent comments (author name, avatar URL, comment text, like count and timestamp), and the daily analytics numbers for your recent videos. Comments and per-video analytics rows are deleted 30 days after they were last refreshed. Output's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Nothing from your Google account is used for advertising, shared with third parties, or sold.

You can revoke Output's access to your YouTube account at any time from Google's security settings, or by disconnecting the channel in Accounts.

Instagram, Threads and Facebook

Output uses Meta's APIs. For an Instagram account we read the comments on your posts and post your replies, publish the photos, videos and stories you choose, read your own account and post insights for Analytics, and, for accounts connected through Instagram Login, read and answer your direct messages and story replies. For Threads we read replies to your posts, post your replies, publish your posts and read your own insights. For a Facebook Page we publish the posts you choose and read and answer the comments on them. We store the tokens Meta issues, the account or Page IDs and names, and the cached comments, replies, messages and insight numbers described above.

You can revoke Output's access from Facebook's Business Integrations settings, from Instagram's Apps and Websites settings, or from Threads' Apps and Websites settings, or by disconnecting the account in Accounts. Meta can also send us a data deletion request on your behalf; we delete that account's data and publish a confirmation code you can check at output.social/deletion-status.

TikTok

When you connect a TikTok account, we store the OAuth tokens TikTok issues, your display name and avatar URL, and, for videos you publish through Output, the video ID and its view, like, comment and share counts. We upload only videos you choose and post nothing without you clicking publish.

You can revoke Output's access at any time from TikTok's settings under Security, then Apps and websites, or by disconnecting the account in Accounts.

X, Bluesky and LinkedIn

For X we store the OAuth tokens X issues and your user ID and handle, read replies to your posts and mentions of you, post your replies, and publish your posts and media. For Bluesky we store the app password you enter, read replies, mentions and direct messages, post your replies and messages, and publish your posts. For LinkedIn we store the token LinkedIn issues and your profile ID, and publish the posts you choose; LinkedIn does not let Output read comments. Revoke access in each platform's connected apps settings, or by disconnecting the account in Accounts. A Bluesky app password can also be deleted in Bluesky's settings.

How long we keep things

Cached comments, replies, mentions and messages are deleted 30 days after they were last fetched, and are refreshed from the platform whenever you open the inbox. Notification records, which say which items you have already been alerted about, are deleted on the same 30-day cycle.

Analytics keeps the account-level numbers it charts (views, likes, comment counts, follower counts) for as long as your account exists. Per-video daily analytics and the underlying API responses are deleted 30 days after they were last refreshed.

Credentials are kept until you disconnect the platform or delete your account. Photos and videos you upload for publishing are deleted automatically once the platforms have fetched them: one day after a post publishes everywhere, three days after a post that failed somewhere (so you can retry it), and in every case within 30 days of upload. Deleting your account deletes them at once.

How we protect your data

Every connection to Output, and every call Output makes to Google, Meta, TikTok, X, Bluesky, LinkedIn and our own providers, is encrypted in transit with TLS. Data at rest is encrypted by the providers that hold it: Supabase encrypts the database and Cloudflare encrypts media stored in R2.

Access tokens, including the Google OAuth tokens for your YouTube channel, are the most sensitive thing we hold. They are stored in the database under row-level security, so a signed-in user can reach only their own rows, and the browser and the iOS app never query that table directly. Tokens are read on the server, inside functions that run with a service key which is never shipped to a client. A short-lived Google access token is handed to your browser or phone only when you upload a video straight to YouTube, and only for that upload. Scheduled server jobs are protected by a secret that is generated inside the database and never leaves it.

On your phone the app keeps your Output sign-in session in the iOS Keychain. Uploaded photos and videos are reachable only through signed links that expire within a day, and are deleted on the schedule described above. Cached comments, messages and analytics are kept for 30 days and then deleted automatically.

Access to production systems is limited to the operator of Output and protected by the providers' account security. If we ever discover a breach affecting your data, we will tell you by email without undue delay and in any case within 72 hours of confirming it, and describe what was affected and what we have done.

What we don't do

We don't sell your data, and we don't show advertising. We don't read your comments, messages or posts for any purpose other than showing them to you and, if you use the AI features, generating the suggestion you asked for. We don't post anything without you clicking publish. The website and the app use no analytics trackers; the only thing stored in your browser is your sign-in session.

AI features

The AI features are paid and run only when you use them. Reply suggestions send the comment or message text and a few of your own past replies (for tone) to Anthropic's Claude API. The voice profile sends your own captions and replies to the same API to describe how you write. Thumbnail ideas send a frame of your video and its title to Anthropic for concepts, and to Google's Gemini API to render the image. None of this text or imagery is used to train models under those providers' API terms, and none of it is kept by Output beyond the result you see.

Who processes your data

Output runs on Supabase (database, sign-in and functions) and Cloudflare (website, API and media storage). Payments go through Stripe or Apple. AI requests go to Anthropic and Google as described above. Each connected platform receives only what is needed to publish or reply on your behalf.

Deleting your data

Disconnecting a platform in Accounts deletes the stored credentials for that platform. Delete account in Settings deletes your credentials, cached comments and messages, analytics, publish history, uploaded media and profile at once. Meta's data deletion requests are handled automatically as described above. For any other deletion request, contact us.

Contact

Questions about this policy: [email protected].