Legal
Privacy Policy
Last updated 27 July 2026
Bract stores the minimum it needs to post on your behalf: your account details, the posts you write, and an access token for each network you link. We do not sell your data, we do not advertise against it, and you can revoke any token or delete your account outright at any time from Settings.
Who we are
Bract is a social media management tool that lets you write a post once and publish it to the networks you have linked — currently Facebook, Instagram, TikTok and X (Twitter). This policy explains what we collect, why, and how to get rid of it. Questions go to bractservices@gmail.com.
What we collect
- Account details — Your name, email address and a password that is stored only as a salted scrypt hash. We never hold your password in a readable form.
- Verification codes — The six-digit codes we email during sign-up, stored as a hash and deleted once used or expired.
- Network access tokens — When you link a network, that network gives us an access token. It is what lets us publish on your behalf and read the impression counts for posts we published. We request only the permissions needed for that — for Facebook and Instagram, the ability to list your Pages, publish to them, and read their engagement.
- Your content — The posts you compose, their scheduled times, publication status, and the per-network results returned after publishing.
- Engagement metrics — Impression and engagement figures for posts published through Bract, so the overview page can chart them. We do not pull your wider account history or anybody else’s data.
- Subscription status — Your plan, its renewal date and its state. Card details are handled entirely by our payment provider and never reach our servers.
We do not collect analytics on your browsing, we do not run third-party trackers or advertising pixels, and we do not build a profile of you.
Why we hold it
Every item above exists to deliver a feature you asked for: to sign you in, to publish what you wrote where you told us to publish it, to show you how those posts performed, and to bill the correct plan. We do not repurpose any of it. We do not sell, rent or trade personal data, and we do not share it with advertisers.
Access tokens and revoking them
A network token is the most sensitive thing we hold, so it gets its own section. Tokens are stored server-side and are never sent to your browser or exposed through our API. We use them only to publish posts you created and to read metrics for those posts.
You can disconnect any network from Settings at any time. Disconnecting deletes the stored token and the linked account record immediately, and Bractloses all access to that network. You can also revoke our access from the network’s own settings — for Meta, under Settings › Business Integrations on Facebook. If you revoke from their side, the token we hold stops working and we discard it the next time we try to use it.
Deleting your data
Deleting a single post removes it and its metrics from our database. Disconnecting a network removes that network’s token and linked account.
To delete your account outright, email bractservices@gmail.com from the address on the account. We erase your user record, sessions, posts, metrics and every stored token within 30 days, and cancel any active subscription. Posts already published to a network stay on that network — they belong to your account there, and only that network can remove them.
Backups are retained for a further 30 days before being overwritten in the ordinary rotation.
How long we keep things
- Verification codes — Ten minutes, then deleted automatically.
- Sessions — Thirty days, or until you log out, whichever comes first.
- Posts and metrics — Until you delete them or close your account.
- Tokens — Until you disconnect the network, revoke access from the network’s side, or close your account.
Security
Passwords are salted and hashed with scrypt. Session cookies are HTTP-only, same-site and marked secure in production, and hold an opaque random identifier rather than your user id. Incoming webhook deliveries are rejected unless they carry a valid signature from the sending network. No system is perfect, and we will notify affected users promptly if a breach ever puts personal data at risk.
Your rights
Depending on where you live you may have the right to access, correct, export, restrict or erase your personal data, and to object to how we process it. Write to bractservices@gmail.com and we will respond within 30 days. You will never be charged or penalised for exercising any of them.
Children
Bract is not intended for anyone under 13, and we do not knowingly collect their data. If you believe a child has created an account, tell us and we will remove it.
Changes to this policy
If we change anything material we will update the date at the top of this page and email account holders before it takes effect. Continuing to use Bract afterwards means the revised policy applies. See also our Terms & Conditions.