1.Who we are
Onecast is a service for scheduling and publishing social media posts. The controller of personal data processed in connection with the Account, agreements, billing, support and security of Onecast is a sole trader registered in CEIDG:
- Name
- Onecast Paweł Zaręba
- Address
- ul. Piastowska 17, 42-256 Przymiłowice, Polska
- Tax ID (NIP)
- 9492285992
- REGON
- 545521872
- Phone
- +48786583222
- kontakt@onecast.pl
2.What data we collect and where it comes from
Data you provide directly
- at registration: name, e-mail address, password (stored only as a hash) and a record of your declarations — acceptance of the Terms and confirmation that you have read the Privacy Policy (document type, version, language, date and context),
- when creating an Organization and Workspaces: name, time zone and — optionally — icon, logo, brand colour, description and website address,
- when inviting others to an Organization or Workspace: the invitee’s e-mail address and assigned role,
- when connecting a Channel: access tokens issued by the platform and profile data (name, handle, avatar, account ID),
- content and media (images, video) of posts you create, schedule and publish, including platform-specific settings (e.g. a YouTube title, TikTok privacy settings),
- when buying a paid plan (Checkout): name or company name, address, postal code, city, country, optionally tax ID (NIP), and a record of the two Checkout declarations (authorization of recurring charges and the request to start the service) — see “Billing” and “Contract confirmation and evidence of declarations”,
- when contacting Support: the message content, e-mail address and any attachments,
- optionally: a passkey or two-factor authentication (2FA) secret, as well as notification settings and interface preferences.
Data retrieved from connected platforms
- publication metadata of your Channels (ID, link, text or description, thumbnail, publication date) — for posts published through Onecast and, if you start a history import, for publications created earlier directly on the platform,
- statistics of published posts (e.g. likes, comments, shares, reach, views) and Channel follower counts — retrieved periodically and stored as history; these are aggregate numbers, not data about individual followers,
- comments under your posts — only for platforms where this feature is enabled (see “Comments”),
- notifications from platforms that send them (webhooks) — e.g. that a post was deleted directly on the platform or that authorization was revoked.
Data collected automatically
- IP address and browser information (User-Agent) stored in the active session record — to keep you signed in and for security; the record is removed when you sign out or the session expires,
- the date of your last sign-in,
- technical application logs (e.g. errors, platform API responses) — for diagnostics and security,
- on the sign-in and registration pages: technical browser signals analysed by Cloudflare Turnstile to tell humans from bots.
When recording declarations made at registration and in Checkout, we do not store your IP address or browser information.
3.What we use data for
- to provide the service — running the Account, Organizations and Workspaces, scheduling and publishing posts on connected Channels and showing statistics,
- to show comments under your posts and let you reply — where the feature is enabled,
- to send service messages: about publication status, the need to reconnect a Channel, invitations, the trial, billing matters and the upcoming deletion of an Account without an Organization or of an Organization without an active plan,
- to conclude and perform the paid agreement, handle payments and subscriptions (through Stripe) and meet tax and accounting obligations,
- to deliver the contract confirmation on a durable medium and document concluded agreements and declarations,
- to establish, exercise or defend legal claims,
- to handle requests, complaints, withdrawals and data requests,
- to keep the Account and the service secure and detect abuse.
We do not use your data for advertising or for profiling with legal effects, we do not share it with third parties for marketing and we do not sell it.
6.Comments under your posts (third-party data)
Comments contain third-party data: the comment text, display name, handle, avatar and ID of the author, and the like count. That is why Onecast stores them locally only for platforms where this feature has been explicitly enabled, and only for a limited time:
- for supported platforms (Facebook, Instagram, Threads, YouTube, Bluesky) we keep a comment for 30 days from when it was posted on the platform and then delete it automatically — regardless of the plan,
- when the platform reports that a comment was deleted, we immediately delete its text, author data and avatar; only a technical marker without this data remains (IDs and dates), needed so the comment does not reappear — kept for up to 72 hours and never longer than the comment itself,
- disconnecting a Channel or permanent loss of access to it immediately deletes all of that Channel’s stored comments; the “needs reconnection” state alone does not delete them — they then expire after 30 days,
- comments from LinkedIn are neither retrieved nor stored,
- when the comments feature is disabled for a platform, we stop retrieving new comments and stored ones expire on the normal schedule.
For comments, Onecast acts as a processor on behalf of your Organization — see the GDPR & data processing page.
7.Publications and their history
- Onecast stores publication metadata and statistics linked to a specific Channel — for posts published through Onecast and for publications imported at your request.
- On a standard disconnection, publications imported from the platform are deleted, while the history of posts published through Onecast remains in the Workspace. For YouTube only data created in Onecast remains — statistics and data retrieved from YouTube are deleted as described under “Google/YouTube integration”.
- When disconnecting you may tick “Also delete this profile’s history from Onecast” — we then delete all of that Channel’s publications and statistics, its comments and follower history, and its entries in posts; a post that no longer has any other Channel is deleted entirely.
- Deleting data in Onecast does not delete content already published on the social platform.
8.Google/YouTube integration
Onecast uses YouTube API Services. If you connect a YouTube channel, Onecast uses Google OAuth 2.0 and — after your consent on the Google screen — gets access to:
- basic channel and video data (name, ID, thumbnail) — to maintain the connection and confirm publications,
- publishing videos on your behalf when you choose to publish them from Onecast,
- basic video and channel statistics provided by the YouTube Data API (e.g. views, likes, comments, subscribers),
- reading comments under your videos and adding comments — if this feature is enabled.
We use data from Google APIs only for the features described — we do not sell it or use it for ads. Onecast’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Processing on Google’s side is described in the Google Privacy Policy.
How long we keep YouTube data
- video titles, descriptions and thumbnails, channel profile data and YouTube’s response on publishing are kept for at most 30 days from when they were last retrieved from YouTube — before that we refresh them from YouTube, and if we cannot (e.g. the channel is disconnected or the video was deleted), we delete them; a video imported from YouTube that cannot be refreshed is removed from Onecast entirely,
- statistics (views, likes, comments, subscribers) are kept as long as needed for analytics, provided that at least every 30 days we confirm Onecast’s access to the channel is still authorized; after a YouTube channel is disconnected or access to it is confirmed lost we delete them without undue delay, and also when authorization cannot be confirmed for 30 days,
- the content and media of a post created in Onecast and its publication time and status are your Account data, not data retrieved from YouTube — they remain as described under “Publications and their history”,
- when you disconnect a YouTube channel in Onecast or revoke its connection to your Google account, we delete all data retrieved from YouTube without undue delay — including the channel’s name, handle, avatar and ID, and video IDs and links; when access to the channel cannot be confirmed (e.g. the channel needs reconnection), this data may remain and be refreshed for at most 30 days, after which the channel is disconnected and the data deleted in the same way; the history of posts published through Onecast remains, without data identifying the channel, and the channel is shown in it as “Disconnected YouTube channel”; reconnecting that channel creates a new profile in Onecast,
- YouTube comments are kept for no longer than 30 days (see “Comments”).
Besides disconnecting the Channel in Onecast, you can revoke Onecast’s access to your data at any time on the Google security settings page. If you ask us to delete data retrieved from YouTube, we will delete it within 7 days at the latest. Send privacy questions and complaints to kontakt@onecast.pl.
9.Billing
Payments and payment methods are handled by Stripe (for European customers — Stripe Payments Europe, Limited). You enter full card details directly into the Stripe form — Onecast neither receives nor stores them. Stripe acts as our processor for payment processing and as a separate controller for its own purposes, including fraud prevention, risk management and anti-money-laundering obligations — in line with Stripe’s privacy policy.
Onecast stores locally: Stripe customer, subscription, payment and invoice IDs, subscription status, plan, billing period, amounts and charge dates, payment method type and the last four digits of the card, as well as the billing details entered in Checkout (recorded in the agreement terms). The billing country is used to check whether a paid plan is available (currently Poland only), and a tax ID (NIP) to mark a business purchase in the agreement documents.
10.Contract confirmation and evidence of declarations
We keep a record of the declarations made at registration (acceptance of the Terms, confirmation of having read the Privacy Policy) and in Checkout (authorization of recurring charges, request to start the service): document type, version, language, date and context. This documents the terms on which the agreement was concluded and serves to establish, exercise or defend legal claims.
After a paid agreement is concluded, we issue a contract confirmation (a PDF with your details, billing details, the agreement terms and the wording of the declarations) and send it by e-mail together with the Terms in the version in force. We keep copies in private document storage — the Owner can download them in “Plan & billing” as long as the Organization exists. Issued documents are never changed.
What happens to this data after the Account is deleted:
- if you never concluded a paid agreement — all declaration records are deleted with the Account,
- if you concluded a paid agreement — the personalised confirmation PDF is deleted and minimal evidence remains: the agreement terms (plan, price, dates, Terms version, declaration wording, Stripe IDs, buyer type and country) without your name, e-mail address, Organization name or billing details, linked to you only by a pseudonym — a cryptographic hash of your e-mail address created with a secret key. This is pseudonymisation, not anonymisation: if you give us your e-mail address (e.g. in a dispute), we can find these records. The confirmation of having read the Privacy Policy is deleted. The non-personalised Terms in the given version remain in the archive,
- we delete the minimal evidence automatically after the period described on the GDPR & data processing page under “Retention periods”,
- exception: if there is a dispute about a specific agreement, we may keep exactly the document you received (including the personalised PDF) until the dispute ends.
11.Support
Support requests (content, e-mail address, attachments) go to the Onecast team and are stored with the correspondence history. Attachments are stored privately — only you and the Onecast team can access them. Requests are not deleted automatically with the Account, as they may document complaints and arrangements; after the Account is deleted they are no longer linked to it. You may ask us to delete them — we will, unless they are needed to establish, exercise or defend legal claims.
12.Data security
- all communication with Onecast uses an encrypted HTTPS connection,
- Channel access tokens are stored encrypted and passwords only as hashes,
- media files, agreement documents and attachments are stored privately and served only through short-lived signed URLs or after signing in,
- you can additionally secure the Account with a passkey or two-factor authentication (2FA).
13.Who we share data with and how long we keep it
The list of recipients and processors, information on transfers outside the EEA and the retention period for each category of data are on the GDPR & data processing page. How to delete data and what exactly disappears in each case — on the Data deletion page.
14.Your rights
You have the right to access, rectify and erase your data, to restrict processing, to data portability, to object, and to lodge a complaint with the President of the Polish Personal Data Protection Office — details on the GDPR & data processing page. Contact for personal data matters: kontakt@onecast.pl.
15.Changes to this Privacy Policy
We update this Policy when the way Onecast works or the law changes. We announce material changes by e-mail or in the app before they take effect. The date of the last update is shown at the top of the page.