Privacy Policy for CrossPost Pro
Note. This English version is provided for convenience only. The German version is legally binding.
1. Controller
The controller within the meaning of the General Data Protection Regulation ("GDPR") is:
Bastian Aunkofer
Burgunderweg 8
93326 Abensberg
Germany
Email: bastian.aunkofer@gmail.com
Phone: +49 9443 700051
No data protection officer has been appointed. Data protection inquiries can be made using the contact details above.
2. Scope
This Privacy Policy applies to the "CrossPost Pro" iOS app, the backend interfaces under crosspostpro.app, the public website, support communication, and technically associated status, redirect, and legal pages.
CrossPost Pro is a tool that allows users to select or import videos, prepare them locally, define platform texts and settings, connect social-media accounts via OAuth, publish immediately or schedule content on selected platforms such as YouTube, Instagram, and TikTok, edit planned publications before they start, and optionally activate rules that observe future public video posts and transfer them to selected destination platforms.
3. Short overview
- The app does not use an advertising ID, app tracking, analytics SDKs, or marketing SDKs.
- The website does not use analytics or marketing cookies. It may store a technically functional language-preference cookie if you select a language.
- Videos, covers, texts, tags, platform settings, and OAuth data are processed for publication.
- If you activate an automation, CrossPost Pro regularly observes the selected source account for future public completed videos. TikTok and YouTube source transfer also uses separately authorized provider data-portability exports; provider export availability and delay are outside CrossPost Pro's control.
- Uploaded media is technically made available through temporary, publicly retrievable URLs so that selected platforms can retrieve the media. Anyone who knows such a URL can access it during its technical availability.
- Media for immediate posts is deleted no later than 14 days after upload or creation. Media for planned posts is retained until the scheduled publication and deleted no later than 14 days after the latest scheduled time.
- Error and crash reports are transmitted only after the user's express confirmation and are deleted after no more than 6 months.
- According to the operator, hosting, domain/DNS, and server operation are provided by Hetzner in Helsinki, Finland/EU.
- Payments and subscriptions are processed through the Apple App Store. CrossPost Pro verifies signed StoreKit transaction and subscription-status data on the backend for server automations, but does not receive payment-card or Apple Account credentials.
4. Processing in detail
| Purpose | Data | Legal basis | Storage / control |
|---|---|---|---|
| Website and API provision | IP address, short-lived keyed one-way rate-limit value derived from the IP address, date/time, path/URL, HTTP status, user agent, technical log data | Art. 6 para. 1 lit. f GDPR: secure and stable operation, abuse and error analysis; when using the app additionally Art. 6 para. 1 lit. b GDPR | The rate-limit value expires no later than one hour after creation. Server logs are generally retained for up to 30 days and then deleted or anonymized, unless longer storage is required to investigate abuse, attacks, or legal claims. |
| App installation, local use, and anonymous backend session | Anonymous backend user identifier, access/refresh token, high-entropy anonymous recovery credential, installation date, trial status, local settings, sorting, guide status | Art. 6 para. 1 lit. b GDPR: provision of app functions; Art. 6 para. 1 lit. f GDPR: security and abuse prevention | Access tokens are short-lived and refresh tokens are designed for 120 days. The recovery credential is kept in the iOS Keychain; the backend stores a one-way lookup hash and an encrypted copy. While the Keychain credential remains available, the app can automatically restore the same anonymous UUID after a refresh token expires or is rejected, without creating an account. Further deletion can be requested through the contact details. |
| Local media selection and editing | Selected videos from Photos or Files, local video copy, preview images, covers, titles, descriptions, tags, platform states | Art. 6 para. 1 lit. b GDPR: requested app function | Local drafts remain stored until deleted by the user. After successful publication on all selected platforms, the app automatically deletes completed local videos after a short follow-up period. |
| OAuth account connection | OAuth state/PKCE, authorization code, access token, refresh token, expiration times, platform ID, username, avatar/profile restrictions | Art. 6 para. 1 lit. b GDPR: connection and publication through selected platforms; Art. 6 para. 1 lit. f GDPR: secure token management | Platform tokens are stored encrypted in production and retained until the relevant platform account is disconnected, until a justified deletion request is made, or until they are no longer required for the service. Tokens may be refreshed for functionality. |
| Immediate and planned publication on third-party platforms | Video/cover files, temporary media URLs, draft text, title, description, tags, visibility, selected destinations, scheduled date/time, TikTok/Instagram/YouTube settings, external posting IDs, error status | Art. 6 para. 1 lit. b GDPR: execution of the immediate or scheduled publication order initiated by the user | Planned content and settings remain available so they can be displayed and edited until publication starts. Media and completed or canceled plan metadata are deleted no later than 14 days after the final publication outcome; the privacy and deletion rules of the respective platform also apply after transfer. |
| Automated observation and cross-platform publication | Selected source and destination accounts, rule state, observation cursor and timestamps, source post ID/type/publication time/title/caption/preview, snapshotted destination settings, processing states, provider upload IDs, errors, and the lawfully obtained original video | Art. 6 para. 1 lit. b GDPR: execution of the automation activated by the user | Only future public completed videos after activation or reactivation qualify. Pausing, entitlement loss, or authorization loss stops new work. Private automation media and terminal item metadata are regularly deleted no later than 14 days after the final outcome; a TikTok review remains available for no more than 7 days. |
| Source data-portability exports | Separate OAuth credentials and scopes, export request/job IDs and status, archive download metadata, public uploaded videos and profile/post information included by the provider | Art. 6 para. 1 lit. b GDPR: acquisition of an original required for the automation selected by the user | TikTok and Google/YouTube control eligibility, archive contents, frequency, and delivery time. CrossPost Pro requests only the documented categories needed for the active rule, validates and extracts the matching video, and deletes archives and derived media under the automation retention rule. |
| Temporary public media provision | Public media URL, video/cover file, derived conversion files | Art. 6 para. 1 lit. b GDPR: technical provision for platform retrieval | The URLs are not intended as a public feed or search service, but are technically retrievable without login while they exist. For planned posts, availability can continue until the scheduled publication and for no more than 14 days afterward; CrossPost Pro cannot control copies held by platforms or third parties. |
| Error and crash reports | Type of report, error message, stack trace/crash text, iOS version, app version, device model, locale, trial/Pro status, installation date, timestamp | Transmission after consent: Art. 6 para. 1 lit. a GDPR; analysis for troubleshooting and security: Art. 6 para. 1 lit. f GDPR | Transmission only after express confirmation. No screenshots. Deletion after no more than 6 months, unless longer storage is required for security or legal cases. |
| Support communication | Email address, message text, information provided by the user, and, where applicable, device data inserted by the mail draft | Art. 6 para. 1 lit. b GDPR for support relating to app/contract; Art. 6 para. 1 lit. f GDPR for efficient communication; Art. 6 para. 1 lit. c GDPR for statutory retention obligations | Routine support emails are generally retained for up to 3 years after completion of the matter. Business, tax, or legally relevant correspondence may be retained longer in accordance with statutory obligations, generally 6 or 10 years. Spam and irrelevant messages are deleted earlier. |
| Apple subscriptions and server entitlement | Signed StoreKit transaction and App Store Server Notification, product ID, transaction/original transaction ID, app account token derived from the anonymous backend UUID, environment, purchase/expiration/grace/revocation time, notification UUID and ordering time | Art. 6 para. 1 lit. b GDPR: activation and server-side verification of paid Pro automations; Art. 6 para. 1 lit. f GDPR: fraud and replay prevention | Payment, invoices, card data, Apple Account credentials, and refunds are handled by Apple. CrossPost Pro stores only verified subscription entitlement data and deduplicated notification identifiers needed for access control and audit. |
| Automation notifications | APNs device token, production/sandbox environment, language, generic notification type, related automation item ID, delivery status | Art. 6 para. 1 lit. a GDPR: notification permission and requested push delivery; Art. 6 para. 1 lit. b GDPR: opening the relevant automation item | The token is encrypted in production and removed or disabled after deregistration, account reassignment, or an invalid-token response from Apple. Notification text does not include captions, platform tokens, or video content. The in-app inbox remains authoritative. |
| Website language preference | Language value such as de or en | Section 25(2) TDDDG for a language function selected by the user; Art. 6 para. 1 lit. f GDPR or Art. 6 para. 1 lit. b GDPR for user-friendly display | The cookie is used exclusively for language selection and not for tracking. You can delete it in your browser. |
App permissions and local storage
- Photos/media: The app requests iOS access to the photo library so that you can select videos. Network access may be required if a selected iCloud asset first needs to be downloaded.
- Files: Videos can be imported through the iOS file picker.
- Notifications: After the first automation is activated, the app may ask for notification permission. Generic pushes are limited to TikTok review, reauthorization, an uncertain remote publication result, or terminal failure. Permission can be denied or withdrawn in iOS Settings without disabling the in-app inbox.
- No camera, microphone, location, or contacts: The app does not itself access the camera, microphone, location, or contacts. Selected videos may of course contain audio or personal content.
- Clipboard: Copying and pasting tags occurs only through user action.
- Keychain: Backend access, refresh, and anonymous recovery credentials, plus installation/trial information.
- UserDefaults: App settings, onboarding status, local platform-account cache, and local StoreKit entitlement status.
- CoreData and app files: local videos, thumbnails, covers, titles, descriptions, tags, scheduled times, editable draft data, and platform states.
No advertising, no tracking, no profiling
Based on the current state, CrossPost Pro does not use an advertising ID, an App Tracking Transparency request, external analytics SDKs, or automated individual decision-making, including profiling within the meaning of Art. 22 GDPR. Videos and support data are not used to train the provider's own AI systems.
5. Recipients and third-party providers
| Recipient / service | Role and purpose | Data |
|---|---|---|
| Hetzner Online GmbH | Hosting, servers, DNS/domain, technical infrastructure; processor according to the operator with a data-processing agreement | Backend data, media, database, technical logs, website access data |
| Apple App Store / StoreKit / APNs | Processing of purchases and subscription events, delivery of automation notifications; Apple acts independently under Apple's terms | Apple-related payment/subscription data processed by Apple; signed entitlement data, app account token, APNs device token, and generic push payload processed by CrossPost Pro |
| Google / YouTube | OAuth login, channel observation and upload notifications, Google Data Portability export, upload and publication on YouTube; Google/Gmail may also be involved as support email infrastructure | Separate regular and portability OAuth data, channel/profile and public upload metadata, export archive/video, destination title/description/visibility; support emails if you contact the provider by email |
| Meta / Instagram | OAuth login, Instagram profile and media-edge observation, retrieval of an API-supplied source media URL, publication via Instagram/Meta APIs, deauthorization and data-deletion callbacks | OAuth data, Instagram ID, username, public source-post metadata and source video, caption, destination video/cover URL, publication status |
| TikTok | TikTok login/SDK, Display API observation, Data Portability export, profile/creator information, and user-reviewed video publication | Separate source OAuth data, Open ID, username/avatar, public post metadata, export archive/video, TikTok publication settings, video or temporary video URL |
| bastian-aunkofer.com | Imprint, support, developer, and status links | When technical status/web pages are retrieved, IP address and browser/app access data may be generated in server logs |
If you use an external link or a third-party platform, the privacy information of the respective provider also applies. The most important platform notices can be found, among others, at Apple, Google/YouTube, Meta/Instagram, and TikTok.
6. Third-country transfers
According to the operator, CrossPost Pro's core technical infrastructure is operated in the EU. However, Apple, Google/YouTube, Meta/Instagram, TikTok, and Google/Gmail may transfer data to countries outside the European Economic Area or process data there.
To the extent CrossPost Pro itself initiates such a transfer and the GDPR requires this, the transfer is based on appropriate safeguards such as adequacy decisions of the European Commission, certification under the EU-U.S. Data Privacy Framework for participating U.S. companies, Standard Contractual Clauses, or the transfer required to perform the service requested by the user. For social-media platforms, publication also takes place based on your own selection and authorization of the respective platform.
7. Retention periods
| Data category | Regular retention period |
|---|---|
| Backend access tokens | Short-lived, regularly 60 minutes. |
| Backend refresh tokens | Regularly up to 120 days, unless reset or deleted earlier. |
| Anonymous recovery credential | The local credential remains in the Keychain until the app session is reset or its Keychain data is otherwise removed. Its backend lookup hash and encrypted copy remain until the anonymous backend session is deleted following a justified request or they are no longer required for the service. |
| OAuth state/PKCE | Short-term, regularly about 10 minutes. |
| Connected platform accounts and OAuth tokens | Until the platform account is disconnected, until a justified deletion request is made, or until they are no longer required for the service. |
| Uploaded media, covers, conversions, and temporary public URLs | For immediate posts, no later than 14 days after upload/creation. For planned posts, no later than 14 days after the latest scheduled publication; earlier after cancellation or successful manual deletion where technically possible. |
| Backend planned-post drafts, settings, scheduled times, and status | While a publication is planned and editable; after the final target is completed, fails, or is canceled, regularly no more than 14 additional days. |
| Automation media, export archives, item and destination metadata | During acquisition, review, publication, and recovery; after completion, partial success, failure, or cancellation, regularly no more than 14 additional days. TikTok review expires after 7 days. |
| Automation rules and source authorizations | Until the rule is deleted, the source is revoked/disconnected, a justified deletion request is made, or the data is no longer required. Pausing a rule does not itself delete its readable history. |
| APNs device tokens | Until device deregistration, reassignment to another anonymous session, user deletion request, or Apple reports the token as invalid. |
| Verified server subscription entitlement and notification receipts | For the duration required to enforce subscription status, notification ordering, transfer history, fraud/replay protection, and applicable legal claims; raw signed payloads are not used as payment data. |
| Local app drafts | Until deletion by the user or by the app's automatic cleanup after publication is completed. |
| Error and crash reports | Maximum 6 months. |
| Server/security logs | Generally up to 30 days; longer only in cases of misuse, security, or legal matters. |
| Support emails | Routine cases generally up to 3 years after completion; business, tax, or legally relevant correspondence according to statutory retention obligations, generally 6 or 10 years. |
| Subscription data in the app | As long as required for local entitlement verification or until the app data is deleted/updated. |
| Backups | Backups may contain data until overwrite or until the relevant backup cycle expires. Deletion in the production system does not necessarily lead to immediate deletion from already existing backups. |
8. Your rights
Subject to the GDPR, you have the right to access, rectification, deletion, restriction of processing, data portability, objection to processing based on legitimate interests, and withdrawal of consents granted with effect for the future.
To exercise your rights, send a message to bastian.aunkofer@gmail.com. Additional information for identification may be required so that the request can be assigned, especially if the app was used only with anonymous backend IDs.
Automation rules, accounts, and history are tied to the current anonymous backend session. Ordinary access/refresh-token expiry is recovered automatically while the anonymous recovery credential remains in the Keychain. A reinstall that removes Keychain data, other Keychain/session loss, or transfer to another device may still prevent technical reassignment. A verified subscription can be explicitly transferred to a new anonymous installation, but this pauses the old installation's rules and does not migrate its accounts or automation data.
Responses are generally provided within one month of receipt. This period may be extended by up to two further months for complex or numerous requests; you will be informed of this within one month.
You also have the right to lodge a complaint with a data protection supervisory authority. For the controller's registered office, the competent authority is regularly the Bavarian State Office for Data Protection Supervision, Promenade 18, 91522 Ansbach, Germany.
9. Security
CrossPost Pro protects personal data through technical and organizational measures, in particular HTTPS/TLS transport encryption, anonymous backend sessions, role- and access-restricted server access, encrypted storage of platform tokens in production, limitation of error-report fields, time-based deletion rules for media and error reports, and separation of local app data from backend data.
No internet service can guarantee absolute security. In the event of security incidents, the legally required review, documentation, and notification obligations are observed.
10. Minors and third-party content
CrossPost Pro is intended exclusively for persons aged 18 or older. Please do not use the app or transmit personal data if you are younger than 18 years old.
Videos may contain personal data of other persons, including image, voice, or potentially sensitive information. Upload and publish such content only if you are authorized to do so and the necessary consents, rights, or other legal bases exist.
11. Changes to this Privacy Policy
This Privacy Policy will be adjusted if functions, processing operations, providers, or legal requirements change. The current version is made available through this website. In the case of material changes, additional notices or consents will be obtained to the extent legally required.