SFC Publisher (the "App") is a tool that publishes your short videos to third-party platforms you choose (such as YouTube and TikTok). You connect your own accounts on those platforms, select a video, enter the post details, and the App uploads it to each platform on your behalf. This policy explains what data we handle and why. SFC Publisher is operated by Rovina OÜ (Estonia), which acts as the data controller for the processing described here.
2. Data We Collect and Why
We keep data collection to what publishing actually needs:
Device Identifier (anonymous): The App generates a random device identifier (UUID) that acts as your pseudonymous session key with our backend. It is not linked to your name, email, or a personal account.
Platform Access Tokens: When you connect a platform (for example YouTube or TikTok), that platform's OAuth authorization gives us an access token and a refresh token for your account. We store these securely on our backend so the App can upload and publish on your behalf and refresh them when they expire. Disconnecting a platform deletes them.
Your Videos and Post Details: The video you select and the details you enter (title, caption, description, hashtags, visibility, and per-platform options) are used to create your post. Your video is uploaded directly from your device to the destination platform — it does not pass through or get stored on our servers. The post details are transmitted to that platform's publishing API to create the post.
Technical & Security Signals: To operate the service and prevent abuse we may process limited technical signals such as your IP address and request metadata. These are kept only briefly (see Section 6) and are not used to build a profile of you.
We do not sell your data, show advertisements, or build advertising profiles.
3. Legal Bases for Processing
Under the EU General Data Protection Regulation (GDPR), we rely on the following legal bases:
Performance of a contract (Art. 6(1)(b)): processing your device identifier, tokens, videos, and post details to provide the publishing features you ask for.
Consent (Art. 6(1)(a)): connecting each platform account is initiated by you — you authorize the App to publish to that platform on your behalf, and you can withdraw by disconnecting it at any time.
Legitimate interests (Art. 6(1)(f)): limited technical processing to keep the service secure and reliable and to detect and prevent abuse.
4. Third-Party Service Providers & Platforms
We use a small number of providers, and we send data to the platforms you choose to publish to:
Google Firebase (Cloud Functions & Firestore): hosts our backend and securely stores your platform access tokens. The App itself never holds any platform client secrets.
YouTube (Google), TikTok, and other platforms you connect: the destinations you publish to. When you publish, your video and post details are sent to that platform under your authorization and become subject to that platform's own terms and privacy policy. We only access what each platform's publishing permission allows (for example, uploading a video); we do not read your existing content, followers, or messages.
5. Your Rights
You have the right to access, correct, or delete your data, to restrict or object to processing, to data portability, and to withdraw any consent you have given. Because we identify you only by a pseudonymous device identifier, please include that identifier (found in the App's Settings) when contacting us so we can locate the relevant records. To exercise any of these rights, contact us at the address below. You also have the right to lodge a complaint with your local data protection authority; in Estonia this is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).
6. Data Retention & Deletion
We keep each type of data only as long as it is needed:
Platform access tokens: retained while the platform stays connected. Disconnecting a platform, or uninstalling the App and letting the session lapse, removes them.
Your videos & post details: not stored by us — they are relayed to the destination platform at publish time and are thereafter retained by that platform under its own policy.
Technical & security logs: up to 30 days for debugging and abuse detection; security logs may be kept up to 90 days.
After these periods, data is automatically deleted or irreversibly anonymized.
7. How We Protect Your Data
We apply appropriate technical and organizational measures, including encryption in transit (TLS) and at rest, storage of your platform tokens where only our backend can access them via privileged server credentials (never exposed to the app or to other users), pseudonymous device identifiers instead of names or emails, and least-privilege access controls.
8. International Data Transfers
Some providers and platforms (for example Google and TikTok) operate outside the European Economic Area (EEA), which may involve transferring data to countries such as the United States. Where this happens, we rely on appropriate safeguards under Chapter V of the GDPR — such as the European Commission's Standard Contractual Clauses — so that your data continues to receive an equivalent level of protection.
For privacy-related inquiries, please contact us at: support@rovina.ee Rovina OÜ, Vanakuu 2-8, Tallinn, Harjumaa, Estonia