Last updated: 2026-08-24
This Privacy Policy explains what information Vayvia (“Vayvia,” “we,” “us”) collects when you use the Vayvia application (the “Service”), how we use it, and the choices you have. Vayvia is a social media scheduling and publishing tool built on top of the open-source, AGPL-licensed Postiz project. If you were given access to a Vayvia instance by an organization or individual operating their own deployment, that operator — not Vayvia the software project — is responsible for how your data is handled on that instance. This policy describes the practices of the reference Vayvia deployment.
Account information. When you create an account, we collect your name and email address, and either a password (stored as a salted hash, never in plain text) or, if enabled, identity information from Firebase Authentication.
Connected social accounts. When you connect a social media account (for example Instagram, Facebook, YouTube, TikTok, LinkedIn, or another supported platform), that platform shares with us the access tokens, profile identifiers, and profile details (such as display name, username, and profile picture) needed to publish content and read basic account information on your behalf. We only request the access scopes required for the features you use, and access tokens are stored encrypted at rest.
Content you provide. Posts, captions, media files (images and video), and scheduling information you create in Vayvia in order to publish or schedule content to your connected accounts. Media is stored in Google Cloud Storage.
Usage and log data. Basic technical data generated by your use of the Service, such as IP address, browser type, pages visited, and timestamps, used for security, debugging, and keeping the Service running reliably.
We retain your account information and content for as long as your account is active. If you disconnect a social account, we delete the associated access tokens. If you delete your account, we delete your personal information and content within a reasonable period, except where we are required to retain it for legal or security reasons.
You may access, correct, export, or delete your account and content at any time from within the Service, or by contacting us at the address below. You can disconnect any connected social account at any time from the Integrations page, which revokes Vayvia’s access to that platform going forward.
You can delete the data Vayvia holds about you at any time, in one of the following ways:
We action deletion requests within 30 days and confirm by email once the data has been removed. Some records may be retained for a short period afterwards where we are required to keep them for legal, security, or fraud-prevention reasons; these are deleted once that requirement ends.
Deleting data from Vayvia does not delete the posts themselves from the social platforms you published them to. To remove published content, delete it on that platform directly.
We use industry-standard technical and organizational measures to protect your information, including encryption in transit and at rest for access tokens. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
The Service is not directed to, and we do not knowingly collect information from, anyone under 16 years of age.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by posting the updated policy on this page with a new effective date.
Questions about this Privacy Policy or your data can be sent to cor.yahya@gmail.com.