Privacy policy
Last updated 15 September 2026
This policy explains what personal data flodots videos (“the service”, “we”, “us”) collects, why, how long we keep it, who we share it with, and the rights you have. The service lets you upload a video once and post it to YouTube, TikTok and Facebook accounts you connect.
1. Who we are
The service is run by [Your full legal name], a sole trader trading as flodots. For UK data protection law, we are the controller of your personal data.
- Address: [Postal address]
- Email: support@flodots.uk
2. What we collect
- Account details
- Your email address and a one-way hash of your password. We never store your password itself.
- Connected platform accounts
- When you connect YouTube, TikTok or Facebook, we receive and store: the account or channel ID and name, the permissions you granted, and access and refresh tokens that let us post on your behalf. See section 4.
- Videos and post details
- The video files you upload, technical details we read from them (resolution, length, file size, codec), and the title, description, tags, visibility and “made for kids” setting you enter. We also keep a record of each post: which platforms you chose, whether it succeeded, and the link to the published video.
- Technical data
- Our servers log requests to the site, including your IP address, the page requested, the time and your browser’s user agent. We use this to keep the service secure and to fix problems.
We don’t use analytics, advertising trackers or third-party scripts, and we don’t sell your data.
3. Why we use it, and our lawful basis
| Purpose | Lawful basis (UK GDPR) |
|---|---|
| Creating and running your account, storing your uploads, and posting to the platforms you choose | Contract: we need it to provide the service you asked for |
| Keeping the service secure, preventing abuse, and fixing faults | Legitimate interests: running a safe, working service |
| Replying when you contact us | Contract, or legitimate interests if you aren’t a user |
| Keeping records the law requires, for example for tax | Legal obligation |
We don’t make decisions about you based solely on automated processing.
4. Connected platforms
We only access a platform account after you connect it and approve the permissions on that platform’s own screen. We use the access only to do what you ask: publish the videos you submit, with the details you enter, and show you which account is connected. We don’t read your existing videos, comments, messages or analytics, and we don’t use platform data for advertising.
YouTube
The service uses the YouTube API Services. When you connect YouTube, we request permission to upload videos and to read basic channel information (your channel ID and name). Google’s handling of your data is covered by the Google Privacy Policy.
Our use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
You can remove our access at any time by disconnecting YouTube on your dashboard, or from your Google account’s third-party connections page. If you remove access through Google, we delete the tokens we hold for that channel within 7 days of finding out.
TikTok
When TikTok support is available and you connect TikTok, we request permission to read your basic profile (display name and avatar) and post videos to your account. TikTok’s handling of your data is covered by the TikTok Privacy Policy. You can disconnect TikTok on your dashboard or remove our access in TikTok’s app settings.
When Facebook support is available and you connect Facebook, we request permission to publish videos and Reels to the Pages you choose and to read those Pages’ names and IDs. Meta’s handling of your data is covered by the Meta Privacy Policy. You can disconnect Facebook on your dashboard or remove our access in your Facebook settings under “Apps and websites”.
5. Who we share it with
- The platforms you post to. When you submit a post, we send the video and the details you entered to each platform you ticked. From then on, that platform’s own terms and privacy policy apply to it. YouTube (Google), TikTok and Meta are based outside the UK, mainly in the United States. We send data to them only because you instruct us to, as part of the service you asked for.
- Nobody else, except where the law requires. We run the service on our own servers in the United Kingdom. We may disclose data if a law, court order or regulator requires it.
6. How long we keep it
| Data | How long |
|---|---|
| Uploaded video files | Deleted 48 hours after the last platform finishes posting. Uploads that are never finished are deleted after 24 hours. |
| Platform tokens | Until you disconnect the account, or within 7 days of the access expiring or being revoked |
| Account details and post history | Until you delete your account |
| Server logs | 30 days |
| Emails with us | Up to 2 years after the conversation ends |
Database backups can keep deleted data for up to 30 days before it drops out of them.
7. Security
Connections to the site use HTTPS. Platform tokens are encrypted (AES-256) before they’re stored, and passwords are stored only as salted hashes (Argon2). Our database and storage aren’t reachable from the internet, and access to the servers is limited to the operator. No system is perfectly secure. If a breach puts your personal data at risk, we’ll tell you and the Information Commissioner’s Office (ICO) as the law requires.
8. Cookies
We use a single cookie, socials_session, to keep you logged in. It is strictly necessary for the
service to work, so it doesn’t need your consent. It expires after 14 days, or when you log out. We don’t use any
other cookies or similar technologies.
9. Your rights
Under UK data protection law you have the right to:
- get a copy of your personal data;
- have inaccurate data corrected;
- have your data deleted;
- restrict or object to how we use it;
- receive the data you gave us in a portable format.
To use any of these rights, email support@flodots.uk. We’ll reply within one month. It’s free unless a request is clearly unfounded or excessive.
If you’re unhappy with how we handle your data, please tell us first. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk.
10. Deleting your data
- Disconnect a platform: on your dashboard, click “Disconnect” next to the account. We revoke our access where the platform supports it, and delete the stored tokens immediately.
- Delete your account and everything in it: email support@flodots.uk from the address you signed up with. We’ll delete your account, connected accounts, remaining video files and post history within 30 days, and confirm when it’s done.
Deleting your data here doesn’t remove videos already published on YouTube, TikTok or Facebook. Delete those on the platform itself.
11. Changes and contact
If we change this policy, we’ll update the date at the top. If a change is significant, we’ll tell users by email or on the dashboard before it takes effect. Questions: support@flodots.uk.
See also our terms of service.