Privacy Policy

Privacy Policy for GoPost.io

Last updated: 22 June 2026

Thank you for visiting GoPost.io, a product of Doohma Limited (“we”, “us”, or “our”). This Privacy Policy explains how we collect, use, share, and protect your personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other applicable UK privacy laws. It also explains how we handle any data received through integrations with Google APIs (e.g., YouTube, Google Drive), in compliance with Google’s API Services User Data Policy, including the Limited Use requirements.

By using GoPost.io, you agree to the practices outlined in this Privacy Policy. If you do not agree, please do not use our service.

1. Who We Are

Doohma Limited
Registered in England and Wales
Email: admin@doohma.com

GoPost.io helps users migrate content across platforms like YouTube, Instagram, LinkedIn, Facebook, TikTok, and Google Drive through API integrations, offering a seamless social content repurposing experience.

1a. Acceptance of YouTube Terms

By using GoPost.io to connect or post content to YouTube, you acknowledge and agree that you are bound by the YouTube Terms of Service (https://www.youtube.com/t/terms) in addition to GoPost.io’s own Terms of Service and Privacy Policy.

1b. Acceptance of TikTok Terms

By using GoPost.io to connect your TikTok account or post content to TikTok, you acknowledge and agree that you are bound by the TikTok Terms of Service (https://www.tiktok.com/legal/terms-of-service) and the TikTok Community Guidelines (https://www.tiktok.com/community-guidelines) in addition to GoPost.io's own Terms of Service and Privacy Policy.

2. What Personal Data We Collect

We may collect and process the following personal data:

  • Identity Data: Name, email address, social platform IDs

  • Contact Data: Email address, phone number (if provided)

  • Account Credentials: OAuth tokens for third-party platforms (e.g., YouTube, Google Drive, LinkedIn, TikTok, Facebook etc.)

  • Usage Data: IP address, browser type, pages visited, and usage patterns

  • Transaction Data: Subscription and payment records (if applicable)

  • Content Data: Files and metadata (e.g., videos, thumbnails, tags) explicitly provided for publishing workflows

We do not collect sensitive data (e.g., health, biometrics, religion) or knowingly collect data from individuals under the age of 18.

In the future, GoPost.io may retrieve analytics and performance data from YouTube (such as views, likes, watch time, and engagement metrics) for videos you post through our service.

Any analytics data collected from YouTube API Services will be:

  • Stored for a maximum of 30 days.

  • Used only to provide or improve user-facing features, such as workflow automation and reporting.

  • Never used for advertising, profiling, or any purposes outside your authorized workflows.

3. How We Use Your Data

We process your data to:

  • Provide and operate the GoPost.io service.

  • Enable integration with connected platforms (YouTube, Google Drive, LinkedIn, Instagram, Facebook, TikTok).

  • Respond to your queries and support requests.

  • Improve and personalise your experience.

  • Ensure security, detect and prevent fraud.

  • Comply with legal obligations.

4. Legal Basis for Processing

We process your personal data based on the following UK GDPR grounds:

  • Consent: For marketing communications and third-party integrations.

  • Contract: To deliver services you’ve subscribed to.

  • Legal Obligation: Where we are required to comply with UK laws.

  • Legitimate Interests: To improve our services and understand user behaviour (where such interests are not overridden by your rights).

You may withdraw your consent at any time by contacting admin@doohma.com.

5. Third-Party Integrations

GoPost.io integrates with:

YouTube (YouTube API Services)

GoPost.io uses YouTube API Services to enable video publishing, playlist management, and workflow automation for users who connect their YouTube accounts.

For information on how Google collects and uses your data, please review the https://www.google.com/policies/privacy

Google Drive

Instagram & Facebook (via Meta APIs)

  • Access rights: Publish content, retrieve business account details.

  • Data: Only content specified in your workflows is accessed and published.

  • Consent & Purpose: When you connect your Instagram or Facebook account, you explicitly authorize GoPost to access your videos, thumbnails, titles, descriptions, and business account information to perform the workflows you configure in GoPost. This data will only be used for executing your content migration and posting workflows, and will not be used for advertising, analytics, or other purposes outside your workflow. You may disconnect your account at any time, after which all associated data will be deleted from GoPost systems.

  • Privacy Policy: https://gopost.io/privacy-policy

LinkedIn

  • Access rights: Post content to your company page/profile.

  • Data: Only data provided during publishing is used.

All third-party credentials (OAuth tokens) are securely encrypted and never shared. We follow Google’s Limited Use Policy, meaning your data is only used to provide or improve user-facing features and is never used for advertising.

TikTok (via TikTok Content Posting API)


GoPost.io uses the TikTok Content Posting API to let you publish or upload video content to your TikTok account and to configure posting options for that content.


Access rights: Read your basic profile information (e.g. display name, avatar) and creator account settings, and post or upload video content to your TikTok account on your behalf.


Creator settings: When you prepare a post, we retrieve your current account settings from TikTok (such as available privacy levels and whether comment, Duet, or Stitch interactions are permitted) solely to display accurate posting options to you before you publish.


Consent & Purpose: When you connect your TikTok account, you explicitly authorise GoPost.io to access the information above and to publish the videos, captions, and settings you specify. This data is used only to execute the posting workflows you configure in GoPost.io and is never used for advertising, profiling, or any purpose outside your authorised workflows.


Data handling: Only the content you specify in a workflow is accessed and posted. We do not store your TikTok profile data beyond what is needed to operate the connection, and content files uploaded for posting are deleted after the workflow completes.


Revoke access: You can disconnect your TikTok account in GoPost.io at any time, or revoke access directly in the TikTok app under Settings → Security & permissions → Manage app permissions. On disconnection, associated data is deleted from GoPost systems.

5A. Sharing and Disclosure of User Data

We do not sell or rent your personal data, including any data received from Google, LinkedIn, TikTok or Meta platforms. Data may only be disclosed in the following scenarios:

With Service Providers:
We use the following trusted third-party providers to operate GoPost. Each is contractually bound to protect your data and may only access it for the purposes described below.

  • Cloudflare (United States) — DNS, CDN, and TLS termination for gopost.io and app.gopost.io. Data passes through in transit.

  • Ionos (United Kingdom) — VPS hosting and PostgreSQL database. Stores user account data, OAuth tokens, and content metadata at rest.

  • Google Cloud Storage (United States) — Temporary storage of content files uploaded directly by users (e.g. videos and thumbnails) for publishing workflows. Files are deleted after publication. This service does not store content retrieved from Instagram, Facebook, YouTube, or other connected platforms.

  • Paddle (United Kingdom) — Payment processor and Merchant of Record for paid subscriptions. Receives billing email and transaction data.

  • DeepSeek (China) — AI language model API used to generate suggested titles and captions. Receives only the specific post text needed for the task; no OAuth tokens, account credentials, or profile data are transmitted. See Section 5B for details.

  • Google Analytics 4 (United States) — Website analytics on gopost.io. Collects pseudonymous usage data; no social account credentials, OAuth tokens, or content are transmitted.

  • Microsoft Clarity (United States) — Session analytics on gopost.io. Collects pseudonymous behavioural data; no social account credentials, OAuth tokens, or content are transmitted.

Where data is transferred outside the UK, we rely on UK-approved transfer mechanisms such as Standard Contractual Clauses (SCCs) or UK adequacy decisions.

With User Consent: When users explicitly authorise data to be shared through their configured workflows, we may transmit data to third-party platforms (e.g., post videos to YouTube, Instagram, Facebook, TikTok, or LinkedIn).

Legal Compliance: We may disclose data in response to legal obligations, such as a court order or lawful request.

Developer Access (Controlled): Some authorised developers or support teams may be based outside the UK and may access user data only for debugging or support under strict security controls. Only authenticated users can access their own data. Administrative staff do not have routine access to personal user data.

Meta Platform Compliance: GoPost follows all Meta Platform Terms and Developer Policies when accessing Instagram and Facebook data. Our use of Meta APIs is strictly limited to executing user-authorised workflows as described in this policy.

We strictly follow Google's Limited Use requirements, and Google user data is used only to provide or improve user-facing features, never for advertising or analytics.

5B. AI Processing of Content

When you use GoPost features that suggest titles, captions, or metadata for your content, the relevant text (for example, your Instagram caption) is sent to a third-party AI service provider (currently DeepSeek) to generate a suggestion. Only the specific text needed for the task is sent. We do not send your access tokens, account credentials, or profile information to AI providers. Generated suggestions are returned to GoPost and shown to you for review before use. You remain in control of whether to accept, edit, or discard any AI-generated output.

6. Cookies & Tracking

We use cookies and analytics tools (including Google Analytics) to:

  • Understand site usage

  • Enhance user experience

  • Improve service performance

You can manage your cookie preferences via browser settings.

7. Data Retention

We retain personal data only as long as necessary to:

  • Deliver requested services

  • Fulfil legal obligations

  • Support account management

  • Resolve disputes

  • Any statistics or metrics retrieved from YouTube API Services are stored only for up to 30 days and then automatically deleted.

You may request data deletion at any time via admin@doohma.com.

8. Data Security

We take appropriate security measures, including:

  • SSL encryption for all communications

  • Encrypted storage of personal data and credentials

  • Strict access controls

  • Regular audits and monitoring

  • No admin access to user data

While no system is 100% secure, we make every reasonable effort to protect your information.

9. Your Rights (UK GDPR)

You have the following rights:

  • Access your data

  • Correct inaccurate data

  • Request deletion (“right to be forgotten”)

  • Restrict or object to processing

  • Withdraw consent at any time

  • Request data portability

Contact admin@doohma.com to exercise your rights.
You may also lodge a complaint with the UK Information Commissioner’s Office (ICO): https://ico.org.uk

10. Children’s Privacy

GoPost.io is not intended for users under the age of 18. We do not knowingly collect data from children.

11. International Transfers and Developer Access

Some of our developers and contractors may operate outside the UK in countries without equivalent data protection laws. In such cases:

  • All staff are under NDAs and data protection contracts

  • Standard Contractual Clauses (SCCs) are used for compliance

  • No developer has access to user content without authorization

  • Google user data is never used for analytics or ads, in full compliance with the Google API Services User Data Policy

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or posted on our site.

13. Contact Us

If you have any questions or concerns:

Email: admin@doohma.com
Company: Doohma Limited, Registered in England and Wales


Privacy Policy for GoPost.io

Last updated: 22 June 2026

Thank you for visiting GoPost.io, a product of Doohma Limited (“we”, “us”, or “our”). This Privacy Policy explains how we collect, use, share, and protect your personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other applicable UK privacy laws. It also explains how we handle any data received through integrations with Google APIs (e.g., YouTube, Google Drive), in compliance with Google’s API Services User Data Policy, including the Limited Use requirements.

By using GoPost.io, you agree to the practices outlined in this Privacy Policy. If you do not agree, please do not use our service.

1. Who We Are

Doohma Limited
Registered in England and Wales
Email: admin@doohma.com

GoPost.io helps users migrate content across platforms like YouTube, Instagram, LinkedIn, Facebook, TikTok, and Google Drive through API integrations, offering a seamless social content repurposing experience.

1a. Acceptance of YouTube Terms

By using GoPost.io to connect or post content to YouTube, you acknowledge and agree that you are bound by the YouTube Terms of Service (https://www.youtube.com/t/terms) in addition to GoPost.io’s own Terms of Service and Privacy Policy.

1b. Acceptance of TikTok Terms

By using GoPost.io to connect your TikTok account or post content to TikTok, you acknowledge and agree that you are bound by the TikTok Terms of Service (https://www.tiktok.com/legal/terms-of-service) and the TikTok Community Guidelines (https://www.tiktok.com/community-guidelines) in addition to GoPost.io's own Terms of Service and Privacy Policy.

2. What Personal Data We Collect

We may collect and process the following personal data:

  • Identity Data: Name, email address, social platform IDs

  • Contact Data: Email address, phone number (if provided)

  • Account Credentials: OAuth tokens for third-party platforms (e.g., YouTube, Google Drive, LinkedIn, TikTok, Facebook etc.)

  • Usage Data: IP address, browser type, pages visited, and usage patterns

  • Transaction Data: Subscription and payment records (if applicable)

  • Content Data: Files and metadata (e.g., videos, thumbnails, tags) explicitly provided for publishing workflows

We do not collect sensitive data (e.g., health, biometrics, religion) or knowingly collect data from individuals under the age of 18.

In the future, GoPost.io may retrieve analytics and performance data from YouTube (such as views, likes, watch time, and engagement metrics) for videos you post through our service.

Any analytics data collected from YouTube API Services will be:

  • Stored for a maximum of 30 days.

  • Used only to provide or improve user-facing features, such as workflow automation and reporting.

  • Never used for advertising, profiling, or any purposes outside your authorized workflows.

3. How We Use Your Data

We process your data to:

  • Provide and operate the GoPost.io service.

  • Enable integration with connected platforms (YouTube, Google Drive, LinkedIn, Instagram, Facebook, TikTok).

  • Respond to your queries and support requests.

  • Improve and personalise your experience.

  • Ensure security, detect and prevent fraud.

  • Comply with legal obligations.

4. Legal Basis for Processing

We process your personal data based on the following UK GDPR grounds:

  • Consent: For marketing communications and third-party integrations.

  • Contract: To deliver services you’ve subscribed to.

  • Legal Obligation: Where we are required to comply with UK laws.

  • Legitimate Interests: To improve our services and understand user behaviour (where such interests are not overridden by your rights).

You may withdraw your consent at any time by contacting admin@doohma.com.

5. Third-Party Integrations

GoPost.io integrates with:

YouTube (YouTube API Services)

GoPost.io uses YouTube API Services to enable video publishing, playlist management, and workflow automation for users who connect their YouTube accounts.

For information on how Google collects and uses your data, please review the https://www.google.com/policies/privacy

Google Drive

Instagram & Facebook (via Meta APIs)

  • Access rights: Publish content, retrieve business account details.

  • Data: Only content specified in your workflows is accessed and published.

  • Consent & Purpose: When you connect your Instagram or Facebook account, you explicitly authorize GoPost to access your videos, thumbnails, titles, descriptions, and business account information to perform the workflows you configure in GoPost. This data will only be used for executing your content migration and posting workflows, and will not be used for advertising, analytics, or other purposes outside your workflow. You may disconnect your account at any time, after which all associated data will be deleted from GoPost systems.

  • Privacy Policy: https://gopost.io/privacy-policy

LinkedIn

  • Access rights: Post content to your company page/profile.

  • Data: Only data provided during publishing is used.

All third-party credentials (OAuth tokens) are securely encrypted and never shared. We follow Google’s Limited Use Policy, meaning your data is only used to provide or improve user-facing features and is never used for advertising.

TikTok (via TikTok Content Posting API)


GoPost.io uses the TikTok Content Posting API to let you publish or upload video content to your TikTok account and to configure posting options for that content.


Access rights: Read your basic profile information (e.g. display name, avatar) and creator account settings, and post or upload video content to your TikTok account on your behalf.


Creator settings: When you prepare a post, we retrieve your current account settings from TikTok (such as available privacy levels and whether comment, Duet, or Stitch interactions are permitted) solely to display accurate posting options to you before you publish.


Consent & Purpose: When you connect your TikTok account, you explicitly authorise GoPost.io to access the information above and to publish the videos, captions, and settings you specify. This data is used only to execute the posting workflows you configure in GoPost.io and is never used for advertising, profiling, or any purpose outside your authorised workflows.


Data handling: Only the content you specify in a workflow is accessed and posted. We do not store your TikTok profile data beyond what is needed to operate the connection, and content files uploaded for posting are deleted after the workflow completes.


Revoke access: You can disconnect your TikTok account in GoPost.io at any time, or revoke access directly in the TikTok app under Settings → Security & permissions → Manage app permissions. On disconnection, associated data is deleted from GoPost systems.

5A. Sharing and Disclosure of User Data

We do not sell or rent your personal data, including any data received from Google, LinkedIn, TikTok or Meta platforms. Data may only be disclosed in the following scenarios:

With Service Providers:
We use the following trusted third-party providers to operate GoPost. Each is contractually bound to protect your data and may only access it for the purposes described below.

  • Cloudflare (United States) — DNS, CDN, and TLS termination for gopost.io and app.gopost.io. Data passes through in transit.

  • Ionos (United Kingdom) — VPS hosting and PostgreSQL database. Stores user account data, OAuth tokens, and content metadata at rest.

  • Google Cloud Storage (United States) — Temporary storage of content files uploaded directly by users (e.g. videos and thumbnails) for publishing workflows. Files are deleted after publication. This service does not store content retrieved from Instagram, Facebook, YouTube, or other connected platforms.

  • Paddle (United Kingdom) — Payment processor and Merchant of Record for paid subscriptions. Receives billing email and transaction data.

  • DeepSeek (China) — AI language model API used to generate suggested titles and captions. Receives only the specific post text needed for the task; no OAuth tokens, account credentials, or profile data are transmitted. See Section 5B for details.

  • Google Analytics 4 (United States) — Website analytics on gopost.io. Collects pseudonymous usage data; no social account credentials, OAuth tokens, or content are transmitted.

  • Microsoft Clarity (United States) — Session analytics on gopost.io. Collects pseudonymous behavioural data; no social account credentials, OAuth tokens, or content are transmitted.

Where data is transferred outside the UK, we rely on UK-approved transfer mechanisms such as Standard Contractual Clauses (SCCs) or UK adequacy decisions.

With User Consent: When users explicitly authorise data to be shared through their configured workflows, we may transmit data to third-party platforms (e.g., post videos to YouTube, Instagram, Facebook, TikTok, or LinkedIn).

Legal Compliance: We may disclose data in response to legal obligations, such as a court order or lawful request.

Developer Access (Controlled): Some authorised developers or support teams may be based outside the UK and may access user data only for debugging or support under strict security controls. Only authenticated users can access their own data. Administrative staff do not have routine access to personal user data.

Meta Platform Compliance: GoPost follows all Meta Platform Terms and Developer Policies when accessing Instagram and Facebook data. Our use of Meta APIs is strictly limited to executing user-authorised workflows as described in this policy.

We strictly follow Google's Limited Use requirements, and Google user data is used only to provide or improve user-facing features, never for advertising or analytics.

5B. AI Processing of Content

When you use GoPost features that suggest titles, captions, or metadata for your content, the relevant text (for example, your Instagram caption) is sent to a third-party AI service provider (currently DeepSeek) to generate a suggestion. Only the specific text needed for the task is sent. We do not send your access tokens, account credentials, or profile information to AI providers. Generated suggestions are returned to GoPost and shown to you for review before use. You remain in control of whether to accept, edit, or discard any AI-generated output.

6. Cookies & Tracking

We use cookies and analytics tools (including Google Analytics) to:

  • Understand site usage

  • Enhance user experience

  • Improve service performance

You can manage your cookie preferences via browser settings.

7. Data Retention

We retain personal data only as long as necessary to:

  • Deliver requested services

  • Fulfil legal obligations

  • Support account management

  • Resolve disputes

  • Any statistics or metrics retrieved from YouTube API Services are stored only for up to 30 days and then automatically deleted.

You may request data deletion at any time via admin@doohma.com.

8. Data Security

We take appropriate security measures, including:

  • SSL encryption for all communications

  • Encrypted storage of personal data and credentials

  • Strict access controls

  • Regular audits and monitoring

  • No admin access to user data

While no system is 100% secure, we make every reasonable effort to protect your information.

9. Your Rights (UK GDPR)

You have the following rights:

  • Access your data

  • Correct inaccurate data

  • Request deletion (“right to be forgotten”)

  • Restrict or object to processing

  • Withdraw consent at any time

  • Request data portability

Contact admin@doohma.com to exercise your rights.
You may also lodge a complaint with the UK Information Commissioner’s Office (ICO): https://ico.org.uk

10. Children’s Privacy

GoPost.io is not intended for users under the age of 18. We do not knowingly collect data from children.

11. International Transfers and Developer Access

Some of our developers and contractors may operate outside the UK in countries without equivalent data protection laws. In such cases:

  • All staff are under NDAs and data protection contracts

  • Standard Contractual Clauses (SCCs) are used for compliance

  • No developer has access to user content without authorization

  • Google user data is never used for analytics or ads, in full compliance with the Google API Services User Data Policy

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or posted on our site.

13. Contact Us

If you have any questions or concerns:

Email: admin@doohma.com
Company: Doohma Limited, Registered in England and Wales