Privacy Policy
Last updated: June 7, 2026
Who we are
verticast is operated by PILEANOVA, a simplified joint-stock company (SAS) incorporated in France with share capital of €200, registered with the Paris Trade and Companies Register (RCS Paris) under number 943 186 478, whose registered office is at 60 rue François 1er, 75008 Paris, France (“PILEANOVA”, “we”, “us”, “our”). PILEANOVA is the data controller responsible for the personal data described in this policy.
If you have any question about this policy or about how we handle your data, you can reach us at privacy@verticast.io.
Scope of this policy
This policy explains what personal data we collect, why we collect it, and what rights you have. It applies to the verticast website and the verticast application, which let you compose a short-form vertical video once and publish it to TikTok, Instagram Reels, and YouTube Shorts.
Data we collect
We collect only the data we need to run the service. Specifically:
- Account data — your email address, and (optionally) your display name and profile picture. If you sign in with Google, we also store your Google account identifier.
- Authentication and security data — the one-time login codes we email you (stored only as a secure hash), your session and refresh tokens (also stored only as a secure hash), and the IP address and browser user-agent recorded with each session so we can detect and stop suspicious activity.
- Connected platform data — when you connect a TikTok, Instagram, or YouTube account, we store that account’s identifier, account name, profile picture, the permission scopes you granted, and the access and refresh tokens needed to publish on your behalf. These tokens are encrypted at rest.
- Content data — the videos you upload (stored in object storage), your shared caption and any per-platform caption overrides, your scheduling times, the platforms you target, and the results of each publish (the platform post identifier on success, or an error message on failure).
- Billing data — if you subscribe to a paid plan, we store a customer reference from our payment processor (Stripe). Your card details are entered into and handled by Stripe; we never see or store your full card number.
How we use your data and our legal bases
Under the GDPR, we process your personal data on the following legal bases:
- To provide the service — creating your account, storing your videos, and publishing your posts to the platforms you select (performance of our contract with you).
- To authenticate you and keep your account secure — login codes, sessions, and the IP / user-agent we record for fraud and abuse prevention (performance of our contract and our legitimate interest in security).
- To process payments and manage subscriptions (performance of our contract and compliance with our legal accounting obligations).
- To communicate with you about service issues, security, and changes to these terms (legitimate interest); and, where required, to send optional updates only with your consent.
- To comply with the law and to establish, exercise, or defend legal claims (legal obligation and legitimate interest).
Connected social platforms
When you connect TikTok, Instagram, or YouTube, you authorise verticast to access those accounts only to display your connected account and to publish the content you ask us to publish. We do not use connected-platform data for advertising and we do not sell it.
Google and YouTube: verticast’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can review or revoke verticast’s access at any time at https://myaccount.google.com/permissions.
Meta (Instagram): our access to your Instagram account is governed by the Meta Platform Terms and Developer Policies. You can review and remove connected apps in your Instagram or Facebook account settings.
TikTok: our access to your TikTok account is governed by TikTok’s developer terms and policies. You can manage connected apps in your TikTok account settings.
You can disconnect any platform from within verticast at any time. When you do, we delete the stored access and refresh tokens for that connection.
Who we share data with
We do not sell your personal data. We share it only with service providers who process it on our behalf to run the service, and with the platforms you choose to publish to. Our main processors are:
- Railway — cloud hosting, our PostgreSQL database, and S3-compatible object storage where your uploaded videos are kept.
- Stripe — payment processing and subscription management.
- Resend — sending transactional email (such as your login codes).
- Google, Meta, and TikTok — as the destinations where, on your instruction, your content is published.
We may also disclose data where required by law, to enforce our terms, or to protect the rights, property, or safety of our users or the public.
International transfers
Some of our processors may store or process data outside the European Economic Area. Where that happens, we rely on appropriate safeguards — such as the European Commission’s Standard Contractual Clauses — to protect your data.
How long we keep your data
- Account data — kept while your account is active. When you delete your account, we delete or anonymise your personal data, except where we must keep it to meet legal obligations.
- Uploaded videos and posts — kept until you delete them or close your account.
- Connected-platform tokens — kept until you disconnect the platform or the token expires.
- Login codes — short-lived; they expire within minutes and are deleted after use.
- Session and refresh tokens — kept for the lifetime of the session and removed on logout or expiry.
- Billing records — kept for the period required by applicable tax and accounting law.
How we protect your data
We use industry-standard measures to protect your data, including encryption in transit (HTTPS), encryption at rest for the platform tokens we store, and secure hashing of login codes and session tokens. No system is perfectly secure, but we work to keep your data safe and to respond quickly if an issue arises.
Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased;
- restrict or object to certain processing;
- receive your data in a portable format;
- withdraw any consent you have given, at any time.
To exercise any of these rights, contact us at privacy@verticast.io. You also have the right to lodge a complaint with the French data protection authority, the CNIL (www.cnil.fr), or with your local supervisory authority.
Children
verticast is not directed to children. You must be at least 16 years old, and old enough to use TikTok, Instagram, and YouTube, to use the service. We do not knowingly collect data from children below that age.
Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you. Continuing to use the service after a change means you accept the updated policy.
Contact
Questions about this policy or your data? Email us at privacy@verticast.io.