Privacy Policy
Last Updated: October 23, 2025
Introduction
Welcome to Boring API ("we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our API service for social media management and publishing.
Information We Collect
1. Account Information
When you connect your social media accounts, we collect:
- Google Account: Email address, name, and profile picture
- Facebook Pages: Page ID, page name, and access tokens
- Instagram Accounts: Account ID, username, profile picture, and account type
- Threads Accounts: User ID, username, and profile picture
- YouTube Channels: Channel ID, channel name, and thumbnails
2. Authentication Tokens
We store OAuth access tokens and refresh tokens to:
- Maintain persistent authentication
- Publish content on your behalf
- Retrieve performance analytics
- Automatically refresh expired tokens
3. Published Content
We log information about published posts including:
- Post content (text, media URLs)
- Publish timestamps
- Target social media platform
- Success or failure status
- Error messages (if applicable)
4. Performance Data
For accounts with Performance API enabled, we collect:
- Page/Account metrics (impressions, engagements, followers)
- Post/Media performance (views, likes, comments, shares)
- Analytics data provided by social media platforms
- Historical snapshots for trend analysis
5. API Usage Data
- API key usage timestamps
- Request logs for debugging
- Error tracking information
How We Use Your Information
We use the collected information to:
Provide Core Services
- Authenticate and authorize your social media accounts
- Publish content to Facebook, Instagram, Threads, TikTok, and YouTube
- Retrieve and display performance analytics
- Maintain account connections
Service Improvement
- Debug and fix technical issues
- Monitor API performance
- Improve service reliability
- Develop new features
Security
- Detect and prevent unauthorized access
- Validate API requests
- Protect against fraud and abuse
Data Storage and Security
Storage Location
- All data is stored in MongoDB databases hosted on DigitalOcean
- Hosted in secure, enterprise-grade data centers
- Regular backups are performed
Security Measures
- OAuth 2.0 authentication for all social media connections
- JWT tokens for API authentication
- HTTPS encryption for all data transmission
- Access tokens are encrypted at rest
- API keys follow industry-standard security practices
Data Retention
- Active Accounts: Data is retained as long as your account is active
- Disabled Accounts: Soft-deleted accounts are marked as disabled but data is preserved
- Published Content Logs: Retained indefinitely for historical records
- Performance Snapshots: Stored for long-term analytics
Data Sharing and Disclosure
We DO NOT sell, trade, or rent your personal information to third parties.
We may share information only in the following circumstances:
- With Your Consent: When you explicitly authorize data sharing
- Social Media Platforms: We transmit content to Facebook, Instagram, Threads, TikTok, and YouTube as requested by you
- Legal Requirements: If required by law, court order, or government regulation
- Service Providers: With trusted service providers (e.g., MongoDB hosting) under strict confidentiality agreements
Your Rights and Choices
You have the right to:
1. Access Your Data
- View all connected social media accounts
- Review published content history
- Access performance analytics data
2. Control Your Data
- Connect or disconnect social media accounts at any time
- Regenerate or delete API keys
- Stop data collection by disconnecting accounts
3. Data Deletion
To request complete data deletion:
- Contact us at: rainsnoopy@gmail.com
- We will delete your data within 30 days
- Note: Some data may be retained for legal compliance
Third-Party Services
Our service integrates with:
Social Media Platforms
- Facebook/Meta: Meta Privacy Policy
- Instagram: Instagram Privacy Policy
- Threads: Threads Privacy Policy
- YouTube/Google: Google Privacy Policy
Infrastructure Providers
- Google Cloud Platform: For hosting Cloud Functions
- DigitalOcean: For MongoDB database hosting
Each third-party service has its own privacy policy governing the use of your data on their platforms.
Permissions and Scopes
Facebook Permissions
pages_show_list: View your pagespages_read_engagement: Read engagement datapages_manage_posts: Publish and manage postspages_read_user_content: Read page content
Instagram Permissions
instagram_basic: Basic account informationinstagram_content_publish: Publish contentpages_show_list: View connected pagespages_read_engagement: Read engagement metricsbusiness_management: Manage business accounts
Threads Permissions
threads_basic: Basic account informationthreads_content_publish: Publish contentthreads_manage_insights: Access analyticsthreads_manage_replies: Manage replies (for thread posts)threads_read_replies: Read replies
YouTube Permissions
youtube.upload: Upload videosyoutube: Manage YouTube accountyoutube.readonly: View account informationyt-analytics.readonly: Access analytics data
Children's Privacy
Our service is not intended for users under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.
International Data Transfers
Your data may be transferred to and processed in countries other than your country of residence. By using our service, you consent to such transfers.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. Continued use of our service after changes constitutes acceptance of the updated policy.
Contact Us
If you have questions or concerns about this Privacy Policy, please contact us:
- Email: rainsnoopy@gmail.com
- Website: https://boring.aiagent-me.com
- Documentation: https://boring-doc.aiagent-me.com
Compliance
We are committed to compliance with:
- General Data Protection Regulation (GDPR)
- California Consumer Privacy Act (CCPA)
- Other applicable data protection laws
For GDPR or CCPA requests, please contact us at the email address above.
Service Information
- Service Name: Boring API
- Service URL: https://boring.aiagent-me.com
- Documentation: https://boring-doc.aiagent-me.com
- Provider: EZlighting