Who we are
itK Publish (“Publish,” “we,” “us”) is a content-management dashboard operated by Kenneth Jackson, doing business as itK Publish, an independent service for small businesses. Our customers (“Customers”) sign in to draft, schedule, and publish social media content to their own connected accounts.
This policy describes what data we collect from Customers, what we do with it, and how a Customer can remove it.
What we collect
When a Customer connects their accounts and uses Publish, we store:
- Organization-level identifiers for the Customer’s connected accounts (Facebook Page IDs, Instagram Business Account IDs, YouTube channel IDs, Google Business Profile location IDs).
- OAuth access and refresh tokens for those accounts, stored encrypted at rest in our Supabase database and never exposed to third parties.
- Draft and scheduled post content the Customer authors in Publish — captions, blog bodies, scheduled times, channel selections.
- References to media assets (image, video, document) the Customer uploads or links for publishing.
- Basic account information for the Customer’s team members (name, email, organization role) so we can authenticate them into the dashboard.
- Operational logs of publishing activity (which post was sent to which channel, when, and the provider-returned post URL), for the Customer’s own audit trail.
What we don’t collect
We do not collect, store, or process:
- End-user data belonging to the Customer’s followers — no names, profile photos, follower lists, direct messages, comments, or engagement metrics tied to individual people.
- Audience demographics or any personally identifying information about anyone who follows or interacts with the Customer’s published content.
- Direct messages, inboxes, or any private conversations from connected platforms.
How we use the data
The data we collect is used solely to:
- Authenticate the Customer’s team into their dashboard.
- Publish the Customer’s approved content to the channels they connected, at the times they scheduled.
- Show the Customer their own publishing history and queue.
- Operate the service (error monitoring, backups, security).
We do not sell Customer data. We do not use it for advertising. We do not train machine-learning models on Customer content outside the Customer’s own organization.
Data retention
While a Customer’s organization is active, we retain their drafts, scheduled posts, and publishing records so they remain usable in the dashboard.
When a Customer offboards or requests deletion, we retain audit records of past publishing activity (social_publishes) for up to 90 days so we can answer post-incident questions, then delete them. The Customer’s historical post bodies (social_posts) may be retained indefinitely as a Customer-owned content archive unless the Customer asks us to delete them — see the deletion process on the Data Deletion page.
Third-party processors
We rely on a small number of vetted infrastructure providers to run the service. Each operates under their own privacy commitments:
- Vercel — hosts the Publish web application and runs our scheduled publishing jobs.
- Cloudflare — provides DNS and content delivery for our domains.
- Supabase — stores Customer account, draft, and operational data, including OAuth tokens encrypted at rest.
We do not share Customer data with any other third party except the connected publishing platforms the Customer explicitly authorized (Facebook, Instagram, YouTube, Google Business Profile), and only for the purpose of fulfilling the Customer’s own publishing actions.
Deleting your data
A Customer can request deletion of their data at any time. See the Data Deletion page for the two ways to initiate this.
Contact
Questions, concerns, or requests about this policy can be sent to service@kennethjackson.tech.