$ cat privacy.md
Privacy policy
Last updated: 25 September 2026
This policy covers the website lucas.stream and the publishing tool that runs at postiz.lucas.stream (the "Tool"). The Tool is operated by Lucas Almeida, the owner of the old man tech channels (the "Operator"). It is a private, single-user tool: it publishes the Operator's own videos to the Operator's own social media accounts. There are no other users, no sign-up and no customers.
What the Tool does
The Tool is a self-hosted instance of the open-source scheduler Postiz. It uploads videos made by the Operator and posts them to the Operator's accounts on YouTube, TikTok, Instagram, Facebook, Threads, X and LinkedIn, after the Operator approves each post by hand.
Data the Tool accesses and stores
- Account authorisation tokens. When the Operator connects one of their own social accounts, the platform issues OAuth access and refresh tokens. These are stored encrypted at rest on the Operator's server and are used only to publish posts and read basic profile and post statistics for those accounts.
- Basic profile data of the connected accounts (account name, handle, profile picture, channel id), shown inside the Tool so the Operator can tell the accounts apart.
- Post content: the videos, titles, descriptions and scheduling times the Operator creates, plus the resulting post ids and links returned by the platforms.
- Post statistics such as views and likes, if the Operator opens the analytics screens.
The website lucas.stream itself sets no cookies and runs no analytics or trackers.
Data the Tool does not collect
The Tool does not collect data about visitors, viewers, subscribers, commenters or any person other than the Operator. It does not read private messages, contacts or friend lists. It does not sell, rent, trade or share any data with third parties, and does not use any data for advertising.
Where data lives and for how long
Everything is stored on a server controlled by the Operator and reached only through an encrypted connection. Tokens are kept while the account stays connected and are deleted when the account is disconnected inside the Tool or when access is revoked at the platform. Posts and their metadata are kept as a publishing log until the Operator deletes them.
Google and YouTube
The Tool uses YouTube API Services to upload videos to the Operator's YouTube channel and to read the channel's basic information and video statistics. By using the Tool, the Operator agrees to be bound by the YouTube Terms of Service. Google's handling of data is described in the Google Privacy Policy.
The Tool's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through YouTube API Services is stored only as described above, is refreshed no less often than every 30 days, and is never shared with any third party.
Access granted to the Tool can be revoked at any time from the Google security settings page. Revoking access deletes the stored tokens on the next connection attempt; the Operator can also delete them immediately by disconnecting the channel inside the Tool.
Other platforms
The same applies to TikTok, Meta (Instagram, Facebook, Threads), X and LinkedIn: the Tool holds only the tokens and basic profile data of the Operator's own accounts, uses them only to publish and to read post statistics, and access can be revoked at any time from each platform's connected-apps settings, which deletes the stored tokens.
Security
The Tool is reachable only over HTTPS, registration is disabled, and the single account is protected by a password. Tokens and secrets are never written to public repositories or logs.
Changes
If this policy changes, the new version is published on this page with an updated date.
Contact
Questions about this policy: contact@lucas.stream.