Privacy Policy

Last updated: August 21, 2026

This Privacy Policy explains what information BarlaPost ("BarlaPost", "we", "us") collects when you use the BarlaPost mobile app, why we collect it, and the choices you have. By using BarlaPost, you agree to the practices described here.

1. Information we collect

We collect only what's needed to run the app:

  • Account information — the email address you sign up with, and your password (stored as a salted hash, never in plain text).
  • Content you create — the text of posts you write in BarlaPost, and which connected accounts you chose to publish them to.
  • Connected social accounts — for each platform you connect (Bluesky, Mastodon, LinkedIn), we store the account handle/username, and the credentials needed to publish on your behalf (an app password for Bluesky, or an OAuth access token for Mastodon and LinkedIn).
  • Basic technical data — standard request metadata (such as IP address and timestamps) generated when your device talks to our servers, used for security and abuse prevention.

We do not sell your data, and we do not use your post content or connected-account data for advertising.

2. How we use your information

  • To create and secure your account, and let you sign in.
  • To publish the posts you write to the social accounts you select, exactly as you compose them.
  • To send you account-related email — email verification codes, password reset codes, and important service notices.
  • To detect abuse, debug problems, and keep the service running reliably.

3. How we store and protect your data

BarlaPost's backend runs on Railway, and your data is stored in a PostgreSQL database. All traffic between the app and our servers is encrypted in transit (HTTPS). Sensitive credentials — your connected social accounts' OAuth tokens and app passwords — are additionally encrypted at rest, so they aren't stored as plain text in our database.

No system is perfectly secure, but we apply industry-standard practices and keep improving them as the app matures.

4. Third-party services we use

BarlaPost relies on a small number of third-party services to function:

  • Brevo — sends transactional email on our behalf (email verification codes, password reset codes). Brevo only receives your email address and the message content needed to deliver these emails.
  • Bluesky, Mastodon, and LinkedIn APIs — when you connect an account and publish a post, we send that post's content to the corresponding platform's API using the credentials you authorized. We only share what's needed to publish the specific post you asked us to send.

Each of these services has its own privacy policy governing how they handle data once it reaches them.

5. Data retention

We keep your account data for as long as your account exists. If you disconnect a social account, we delete the stored credentials for that account. If you delete your BarlaPost account (see below), everything tied to it is removed.

6. Your rights and account deletion

You can permanently delete your account, your workspace, every connected social account, and all associated data directly from the app: open Settings → Delete account. This is immediate and irreversible — we don't hold a "soft-deleted" copy afterward.

Depending on where you live, you may also have the right to:

  • Ask what personal data we hold about you and request a copy of it.
  • Ask us to correct inaccurate data.
  • Ask us to delete your data (equivalent to the in-app deletion above).
  • Object to, or ask us to restrict, certain processing of your data.

To exercise any of these rights, contact us at [email protected].

7. GDPR & KVKK

If you're in the European Economic Area, BarlaPost processes your personal data as described in this policy under the legal bases of contract performance (running the service you signed up for) and legitimate interest (security and abuse prevention), consistent with the EU General Data Protection Regulation (GDPR).

If you're in Türkiye, the same principles apply under the Personal Data Protection Law No. 6698 (KVKK): we process your data (email, connected-account credentials, post content) only for the purposes described above, on the basis of the performance of the contract you enter into by using BarlaPost, and you can exercise your KVKK Article 11 rights — including access, correction, and deletion — using the contact details below.

8. Children's privacy

BarlaPost is not directed at children, and we don't knowingly collect data from anyone under 16. If you believe a child has provided us with personal data, contact us and we'll remove it.

9. Changes to this policy

We may update this policy as BarlaPost evolves. If we make material changes, we'll update the "Last updated" date above; continued use of the app after a change means you accept the updated policy.

10. Contact

Questions about this policy or your data? Reach us at [email protected].