Qiscast
Features Developers Pricing
Log in Get started
Features Developers Pricing
Log in Get started
Legal

Privacy Policy

Last updated: July 15, 2026

On this page

  1. Who we are
  2. Information we collect
  3. Connected accounts and OAuth tokens
  4. How we use your data
  5. How we share data
  6. Data retention and deletion
  7. Security
  8. Your rights
  9. Contact us

1. Who we are

Qiscast ("Qiscast", "we", "us", or "our") is an API-first social publishing platform that lets creators and agencies connect their own social media accounts and schedule and auto-post content to TikTok, Instagram, and YouTube from one place. This Privacy Policy explains what data we collect, why we collect it, how we protect it, and the choices you have.

This policy applies to the Qiscast website, dashboard, and API (together, the "Service"). By using the Service you agree to the practices described here.

2. Information we collect

Account information

When you create a Qiscast account we collect your name, email address, password (stored only as a salted hash), workspace details, and, for paid plans, billing information processed by our payment provider. We do not store full card numbers.

Content you provide

We process the videos, images, captions, hashtags, and scheduling details you upload or send through the dashboard or API so that we can publish them to the platforms you choose.

Data from connected platforms

When you link a TikTok, Instagram, or YouTube account, we receive the OAuth access and refresh tokens those platforms issue, along with basic profile information (such as account name, ID, and avatar) and the publishing and status data needed to post on your behalf and report results back to you.

Usage and technical data

We collect log data such as IP address, browser type, device information, API request metadata, and timestamps to operate, secure, and improve the Service.

3. Connected accounts and OAuth tokens

OAuth tokens are encrypted at rest. The access and refresh tokens we receive from TikTok, Instagram, and YouTube are encrypted using strong, industry-standard encryption (AES-256) before they are written to our database. Encryption keys are stored separately from the encrypted data and are never exposed in logs, error reports, or API responses.

We use these tokens for one purpose only: to publish and schedule the content you ask us to publish, and to retrieve the status of those posts. We never post anything you have not explicitly created or scheduled. You can disconnect any account at any time from your dashboard, which immediately revokes Qiscast's access and deletes the stored tokens for that account.

Our use of information received from TikTok, Instagram, YouTube, and their APIs adheres to each platform's developer policies and terms, including their limited-use requirements.

4. How we use your data

  • To provide, operate, and maintain the Service, including publishing and scheduling your content.
  • To authenticate you and secure your account and workspaces.
  • To process payments and manage subscriptions.
  • To send transactional messages, such as publishing results, security notices, and account updates.
  • To monitor, debug, and improve reliability, performance, and features.
  • To detect, prevent, and respond to fraud, abuse, and security incidents.

We do not sell your personal data, and we do not use your content to train advertising profiles.

5. How we share data

We share data only as needed to run the Service:

  • Social platforms. We send your content and requests to TikTok, Instagram, and YouTube to publish on your behalf, at your direction.
  • Service providers. Trusted vendors for cloud hosting, storage, email delivery, and payment processing, bound by contractual confidentiality and data-protection obligations.
  • Legal reasons. When required to comply with applicable law, enforce our terms, or protect the rights, safety, and security of our users and the public.

We do not sell or rent your personal information to third parties.

6. Data retention and deletion

We keep your data for as long as your account is active or as needed to provide the Service. You may request deletion of your account and associated personal data at any time.

  • Disconnecting a platform account immediately deletes the stored OAuth tokens for that account.
  • Deleting your Qiscast account removes your personal data, uploaded content, and connected-account tokens, except where we are required to retain limited records for legal, tax, or security purposes.
  • To request deletion, email hello@qiscast.com from your account email, or use the delete option in your account settings. We aim to complete verified deletion requests within 30 days.

7. Security

We protect your data with encryption in transit (TLS) and at rest, encrypted OAuth token storage, scoped and revocable API keys, access controls, and regular monitoring. No system is perfectly secure, but we work continuously to safeguard your information and will notify affected users of any breach as required by law.

8. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can exercise most of these rights directly in your dashboard or by contacting us. We will not discriminate against you for exercising your rights.

9. Contact us

If you have questions about this Privacy Policy or how we handle your data, contact us at hello@qiscast.com. We may update this policy from time to time; when we make material changes, we will update the date above and, where appropriate, notify you.

Qiscast

Publish everywhere, from one API. Schedule and auto-post videos and carousels to TikTok, Instagram, and YouTube - from a dashboard or code.

Product

Features Developers Pricing How it works

Company

Contact Privacy Terms

Get in touch

hello@qiscast.com Indonesia-first, global.
© 2026 Qiscast. All rights reserved.