Who we are and what this policy covers
Scaling With Social ("SWS," "we," "us," or "our") provides content-production, publishing, and customer-conversation services to clients. This policy applies to the Scaling With Social Publishing web application and its client-authorized YouTube publishing and Instagram conversation features.
The application uses YouTube API Services. Use of YouTube is also governed by the YouTube Terms of Service and the Google Privacy Policy.
The application also uses the Instagram API. Use of Instagram is governed by the applicable Meta and Instagram terms and privacy policies. Instagram is a service of Meta Platforms, Inc. SWS is not affiliated with or endorsed by Meta or Instagram.
Information we access and collect
- Channel information: channel identifiers and channel names available to the Google account that authorizes the connection.
- Authorization information: an OAuth refresh token and the permission scopes granted by the user. The token is encrypted before storage. We do not receive or store the user's Google password.
- Publishing information: client-provided video files, thumbnails, titles, descriptions, category and audience settings, requested publishing times, YouTube video identifiers and URLs, and upload or processing status.
- Instagram account information: the connected professional account identifier, username, display name, profile picture, authorization status, and the limited permission scopes granted by the account owner.
- Instagram conversation information: identifiers and available profile details for people who message the connected professional account, inbound and outbound message text, supported attachment files and metadata, owned-post or Reel links selected for sharing, timestamps, read or delivery state, and the most recent inbound-message time used to enforce Meta's reply window.
- Operational information: connection timestamps, security and audit events, error details, and limited request information used to protect and troubleshoot the service.
We do not request access to Gmail, contacts, Google Drive, YouTube viewing history, comments, messages, analytics, or advertising data. For Instagram, we do not request advertising, post or Story publishing, comment-management, or insights permissions.
How we use information
We use the information above only to provide or improve visible, client-requested features:
- identify and select the intended client channel;
- confirm that the authorization remains valid;
- upload and schedule client-approved videos and thumbnails with the supplied metadata;
- show publishing progress, results, and share links inside the SWS application;
- show inbound Instagram conversations to authorized SWS team members and let them manually reply on the client's behalf while Meta's reply window is open; and
- secure, maintain, troubleshoot, and document the connected-account workflows.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
We do not sell Google user data, use it for targeted advertising, build advertising profiles, or use it to train generalized or personalized AI models.
How information is shared
We share information only as needed to provide the connected-account services:
- Google and YouTube: to authenticate the user and perform the channel actions the user authorized.
- Meta and Instagram: to authenticate a professional account, receive authorized message events, retrieve conversation history, and send a reply requested by an authorized SWS team member.
- Service providers: infrastructure, database, storage, monitoring, and security providers that process data for us under access and confidentiality restrictions.
- The applicable client: authorized SWS team members and client representatives may see channel selection, publishing status, and Instagram conversation information for that client.
- Legal and safety needs: when required by law or reasonably necessary to protect users, the service, or others.
We do not permit third parties to serve advertising based on Google user data obtained through this application.
Storage, security, and cookies
OAuth credentials are encrypted before storage in access-restricted, server-side systems. We use technical and organizational safeguards designed to limit access to authorized personnel and services. No internet service can guarantee absolute security.
The application uses only necessary cookies and similar state values for secure sessions, OAuth request validation, and fraud prevention. These are not used for behavioral advertising.
Retention, deletion, and revocation
We keep an active OAuth credential only while the client connection is needed. For active connections, an automated daily process refreshes the stored YouTube channel identifiers and names through the YouTube API. In every case, stored authorized YouTube API data is refreshed or deleted within 30 calendar days.
YouTube video identifiers, YouTube URLs, resumable-upload details, and API-returned upload or error details are deleted from our publishing records no later than 30 calendar days after the applicable publishing job is completed, failed, or cancelled. Client-provided source files, titles, descriptions, requested publication times, and internal workflow records are not YouTube API data and may be retained to provide the contracted content-production service.
When a connection is removed through SWS, we request revocation from Google and immediately delete the stored credential, channel connection metadata, selected channel identifier, and YouTube API-derived publishing results associated with that client. We honor other verified deletion requests as soon as possible and within seven calendar days. Deleting information stored by SWS does not delete videos or other information stored by YouTube; those items must be deleted through YouTube or another authorized application that supports deletion. We may retain security or business records that do not contain authorized Google user data when reasonably required by law, fraud prevention, or accounting obligations.
Instagram message content, sent attachment files and metadata, reply-attempt records, and webhook receipts are retained for no more than 90 days while a client connection is active. We may retain smaller conversation summaries and internal workflow records, such as participant identity, assignments, lead statuses, follow-up tasks, and exclusions, while the connection is active so the service can preserve the client's workflow. Older message history remains available through Instagram. When Meta sends a deauthorization or data-deletion request, or when an authorized client requests disconnection, we revoke or disable the connection and delete the stored Instagram credential, account metadata, conversation messages, participant details, attachment files and metadata, and related webhook records. A deletion confirmation code is returned for Meta data-deletion requests. We honor verified direct deletion requests as soon as possible and within seven calendar days.
Users can also revoke access from the Google Account permissions page. To request disconnection or deletion directly from SWS, email hunter@hunternelson.com. We may ask for enough information to identify the correct client connection without asking for a Google password.
Instagram users or account owners may use the same email address to request access, disconnection, or deletion. A request should identify the connected client or Instagram professional account; never send an Instagram password. Disconnecting SWS does not delete messages or account information stored by Instagram itself.
Children
This business publishing application is not directed to children under 13 and is not intended for child-directed use. It does not knowingly collect personal information from children through its channel-connection workflow.
Changes and contact
We may update this policy to reflect changes to the service, law, or Google and YouTube requirements. The effective date at the top will be updated when changes are published.
For privacy questions, complaints, access requests, or deletion requests, contact Scaling With Social at hunter@hunternelson.com.