BarlaPost
Features One composer, every platform Platforms Bluesky, Mastodon, LinkedIn, and more FAQ Answers before you connect an account
Changelog Release history and new features
Contact Questions, feedback, or a bug Privacy Policy What we store, and what we never do Terms of Service The rules for using the app
Get the app

Product

Features One composer, every platform Platforms Bluesky, Mastodon, LinkedIn, and more FAQ Answers before you connect an account

Resources

Changelog Release history and new features

Company

Contact Questions, feedback, or a bug Privacy Policy What we store, and what we never do Terms of Service The rules for using the app
Get the app

Updated · September 20, 2026

Privacy Policy

BarlaPost collects only what it needs to publish your posts and keep your account secure. This policy explains what that is, why we hold it, and the choices you have.

It applies to the BarlaPost mobile app, operated by BarlaPost ("BarlaPost", "we", "us"). By using the app, you agree to the practices described here.

Information we collect

We collect only what's needed to run the app:

  • Account information — the email address you sign up with, your name if you give one, and your password (stored as a salted hash, never in plain text). If you sign in with Google or Apple instead, that provider shares your name and email address with us; with Apple you can choose to hide your email, in which case we receive a private relay address that forwards to you. We never see your Google or Apple password.
  • Content you create — the text of posts you write in BarlaPost, the photos and videos you attach to them, and which connected accounts you chose to publish them to.
  • Connected social accounts — for each platform you connect (Bluesky, Mastodon, LinkedIn, X, TikTok, YouTube, Threads or Pinterest), we store the account's handle or username, its identifier on that platform, and the credentials needed to publish on your behalf (an app password for Bluesky, or an OAuth access token for the others). For platforms that offer it, we also fetch statistics about your own account and posts to show them to you in the app.
  • Feedback you send — if you use "Send feedback" in the app, we receive your message together with the app version, operating system version and device model, so we can reproduce what you saw. Nothing is sent unless you send it.
  • Basic technical data — standard request metadata (such as IP address and timestamps) generated when your device talks to our servers, used for security and abuse prevention.

We do not sell your data, and we do not use your post content or connected-account data for advertising.

How we use your information

  • To create and secure your account, and let you sign in.
  • To publish the posts you write, with their photos or video, to the social accounts you select, exactly as you compose them — right away or at the time you schedule.
  • To show you statistics about your own connected accounts, where a platform makes them available.
  • To send you account-related email — email verification codes, password reset codes, and important service notices.
  • To detect abuse, debug problems, and keep the service running reliably.

How we store and protect your data

BarlaPost's backend runs on Railway, and your data is stored in a PostgreSQL database. Photos and videos you attach to posts are stored in a private Cloudflare R2 bucket in the EU; the app only ever receives short-lived links to them. All traffic between the app and our servers is encrypted in transit (HTTPS). Sensitive credentials — your connected social accounts' OAuth tokens and app passwords — are additionally encrypted at rest, so they aren't stored as plain text in our database.

No system is perfectly secure, but we apply industry-standard practices and keep improving them as the app matures.

Third-party services we use

BarlaPost relies on a small number of third-party services to function:

  • Google Sign-In and Sign in with Apple — optional ways to create and sign in to your account. Each shares your name and email address with us and nothing else; we never receive your Google or Apple password.
  • Cloudflare R2 — stores the photos and videos you attach to posts, privately, until you remove them or delete your account.
  • Brevo — sends transactional email on our behalf (email verification codes, password reset codes, replies to your feedback). Brevo only receives your email address and the message content needed to deliver these emails.
  • Bluesky, Mastodon, LinkedIn, X, TikTok, YouTube, Threads and Pinterest APIs — when you connect an account and publish a post, we send that post's content and media to the corresponding platform's API using the credentials you authorized. We only share what's needed to publish the specific post you asked us to send.

Each of these services has its own privacy policy governing how they handle data once it reaches them.

Data retention

We keep your account data for as long as your account exists. Photos and videos stay until you remove them from a post or delete the post. If you disconnect a social account, we delete the stored credentials for that account. If you delete your BarlaPost account (see below), everything tied to it — posts, media, connected accounts, feedback — is removed.

Your rights and account deletion

You can permanently delete your account, your workspace, every connected social account, and all associated data directly from the app: open You → Delete account. To make sure it's really you, the app asks for your password — or, if you only ever signed in with Google or Apple, to sign in with them once more. Deletion is immediate and irreversible — we don't hold a "soft-deleted" copy afterward.

Depending on where you live, you may also have the right to:

  • Ask what personal data we hold about you and request a copy of it.
  • Ask us to correct inaccurate data.
  • Ask us to delete your data (equivalent to the in-app deletion above).
  • Object to, or ask us to restrict, certain processing of your data.

To exercise any of these rights, contact us at [email protected].

GDPR and KVKK

If you're in the European Economic Area, BarlaPost processes your personal data as described in this policy under the legal bases of contract performance (running the service you signed up for) and legitimate interest (security and abuse prevention), consistent with the EU General Data Protection Regulation (GDPR).

If you're in Türkiye, the same principles apply under the Personal Data Protection Law No. 6698 (KVKK): we process your data (email, name, connected-account credentials, post content and media) only for the purposes described above, on the basis of the performance of the contract you enter into by using BarlaPost, and you can exercise your KVKK Article 11 rights — including access, correction, and deletion — using the contact details below.

Children's privacy

BarlaPost is not directed at children, and we don't knowingly collect data from anyone under 16. If you believe a child has provided us with personal data, contact us and we'll remove it.

Changes to this policy

We may update this policy as BarlaPost evolves. If we make material changes, we'll update the "Last updated" date above; continued use of the app after a change means you accept the updated policy.

Contact

Questions about this policy or your data? Reach us at [email protected].

Post everywhere,
from one place.

Stay up to date

BarlaPost

One post, every platform.

App

iPhone and Android.

Product

  • Features
  • Platforms
  • Changelog
  • FAQ

Company

  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 BarlaPost · [email protected]