1. Who we are and what this covers
Punch Kun Data (“we,” “us,” or “our”) provides this website and social media publishing and automation apps. This Privacy Policy applies to the website and each app that links to it. For questions or requests, contact punchkundata@gmail.com.
The information processed depends on the app, features you use, and permissions you grant. A platform being mentioned here does not mean every app connects to it. Each app’s permission screen and any additional privacy notice describe its particular access. This policy does not cover the independent practices of social media platforms or other websites.
2. Information we process
- Information you provide: contact details, support messages, and account or workspace details supplied to an app.
- Connected account information: platform user IDs, usernames, profile information, and the pages or channels you authorize an app to manage.
- Authorization information: access tokens, refresh tokens, granted permissions, and their expiration information, when needed to maintain a connection. Platform authorization happens through the platform; do not give us your social media password.
- Publishing content: text, images, videos, captions, titles, descriptions, destination accounts, visibility choices, schedules, and other settings you submit for processing or publication.
- Platform responses: post or video identifiers, upload results, publishing status, errors, and performance metrics when the app offers reporting and you authorize the relevant access.
- Technical information: IP address, browser and device information, timestamps, request logs, and diagnostic information generated when you access the Services.
Information comes from you, your use of the Services, and the platforms you connect. We request access for the features you choose, rather than treating authorization as permission to use your data for unrelated purposes.
3. How we use information
We process information to connect authorized accounts; execute your publishing instructions and schedules; display publishing results and available reports; maintain sessions; troubleshoot failures; answer support requests; protect the Services against abuse; and meet applicable legal obligations.
We do not sell personal information or use connected account data for targeted advertising. We do not use data obtained through social platform APIs to train general-purpose AI models. Access to account information does not authorize us to post content outside the actions or workflows you approve.
4. Legal grounds for processing
Where applicable law requires a legal basis, we rely on performance of our agreement with you for requested services, consent for optional permissions and activities that require it, legal obligations, and legitimate interests such as service security and troubleshooting where those interests do not override your rights. You may withdraw consent at any time; this does not affect the lawfulness of earlier processing.
6. Storage, retention, and security
We keep information only for as long as necessary for the purpose for which it was collected. Connected account credentials are retained while needed for an active authorized connection. Drafts, media, schedules, and publishing records are retained while needed to provide the requested workflow or history. Diagnostic and support records are retained only as needed for troubleshooting, security, and resolving requests.
When information is no longer needed, we delete or anonymize it, subject to applicable legal requirements. Limited records may need to be retained for legal obligations or disputes, and backup copies may remain until their normal replacement cycle. Retained data remains protected and is not used to resume a disconnected automation. Platform-specific deletion requirements take precedence when stricter.
We use reasonable technical and organizational safeguards appropriate to the information processed, including limiting access to authorized persons. No storage or transmission method can be guaranteed completely secure.
7. Disconnect accounts and delete data
You can revoke an app’s permissions in the connected platform’s account settings, usually under apps, integrations, or business integrations. Where the app provides a disconnect control, you may use it as well. Revocation stops further authorized access once it takes effect; it does not itself remove copies of previously stored data.
- Email punchkundata@gmail.com with the subject Data deletion request.
- Identify the Punch Kun Data app, the relevant platform, and your account email or public account/channel identifier. Specify whether you want all associated data deleted or only particular information.
- We may ask for the minimum information needed to verify your authority. Never send a password, access token, or unnecessary identity document.
We will review and respond within the period required by applicable law and platform rules, delete the associated information we control, and explain any lawful retention exception. For YouTube API data, we complete deletion as soon as possible and within seven calendar days of a user request; revocation of authorization also triggers deletion of the authorized data within that period.
Deleting data from our Services does not delete posts already published on a social network. Manage or remove those posts directly on that platform, including posts already scheduled there.
8. Google and YouTube integrations
Apps that offer YouTube publishing use YouTube API Services. With your authorization, these apps may access channel identifiers and details, upload videos and their metadata, and retrieve video or publishing status information needed for enabled features. Reporting data is accessed only when a reporting feature and the corresponding permission are enabled.
Google handles information under the Google Privacy Policy. You can revoke our access through your Google security settings, in addition to requesting deletion as described above.
Our use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is used only to provide or improve the user-facing features you request. Human access is limited to your affirmative agreement for specific information, security investigations, legal obligations, or other uses expressly permitted by that policy.
10. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or obtain a portable copy of your personal information; restrict or object to processing; withdraw consent; or request information about sharing. This may include rights under Brazil’s LGPD and, where applicable, the GDPR or other local privacy laws.
Send requests to punchkundata@gmail.com. We may verify your identity before acting and will explain any legally permitted limits. You may also complain to the competent data protection authority. We do not penalize you for exercising privacy rights.
11. International processing and children
Social media platforms and operational providers may process information in countries other than your own. Where international transfer rules apply, we use the safeguards required by applicable law.
The Services are intended for adults aged 18 and over and are not directed to children. If you believe a child has provided personal information, contact us so we can investigate and remove it as appropriate.
12. Updates and contact
We may update this policy to reflect changes in the Services or privacy requirements. The date above identifies the latest revision. We will give appropriate notice of material changes and request consent when required before introducing a new use of information.
For privacy questions, complaints, or requests, email punchkundata@gmail.com. Include the name of the app your request concerns.