Privacy Policy
What Duta is
Duta is a private tool for scheduling social media posts. One person writes a post, chooses which of their own connected accounts should receive it, and Duta publishes it at the chosen time. It is not open to public sign-up.
What Duta stores
- Your email address, used to sign in.
- For each social account you connect: the account identifier the platform gives, your display name and profile picture on that platform, and which permissions you granted.
- The access tokens that let Duta publish on your behalf.
- The posts you write, the times you schedule them for, and whether publishing succeeded or failed.
- A record of actions taken — connecting an account, scheduling a post, a failed publish — with the reason a platform gave when something did not work.
Duta does not read your feed, your followers, your messages, or anything else on the platforms you connect. It asks only for permission to publish.
Access tokens
Connecting an account gives Duta a token — a key that lets it publish as you. Those tokens are encrypted before they are stored, with AES-256-GCM, and the encryption key is held separately from the database. Nobody reads a token by reading the database.
Disconnecting a channel deletes its tokens from Duta immediately. You can also revoke Duta's access from the platform's own settings at any time, and Duta will stop being able to publish the moment you do.
Where the data lives
- Supabase — the database, hosted in Singapore.
- Vercel — runs the application itself.
- Cloudflare R2 — stores uploaded media. Media files are served over public HTTPS addresses because the social platforms have to fetch them. Those addresses are impractical to guess, but they are not password-protected.
- Railway — runs the small service that tells Duta, once a minute, to check for posts that are due. It holds no personal data.
Who else receives your data
The social platforms you choose, and only those. When you schedule a post to a Facebook Page, Duta sends that post's text and media to Facebook. It sends nothing anywhere you did not select.
Duta does not sell data, does not share it with advertisers, and does not use it to train anything.
How long it is kept
- Posts and their publishing history: until you delete them.
- Access tokens: until you disconnect the channel or delete your account.
- Records of actions taken: 90 days.
- Server logs: 30 days.
Deleting a post in Duta removes Duta's copy. It does not remove anything already published on a platform — that has to be deleted on the platform itself.
Getting your data out, or deleting it
You can disconnect any channel, delete any post, or ask for the whole account and everything in it to be erased. See Delete my data for how.
Malaysia — PDPA
Duta is operated from Malaysia and follows the Personal Data Protection Act 2010: data is collected with consent, used only for scheduling and publishing as described here, and deleted on request.
Changes
If what Duta does with data changes, this page changes with it, and the date at the top moves.
Contact
Questions about privacy, or a request to delete your data: hello [at] baloot [dot] my