AutarchiSocial

Privacy Policy

Last updated: 1 July 2026

This Privacy Policy explains how Autarchi Social, operated by KRONOLITH Europe, processes personal data when you use the Service. We are committed to data minimisation: we process only what is needed to publish the content you ask us to publish.

1. Controller

The controller responsible for data processing is KRONOLITH Europe (see the Imprint for full contact details). Email: pascal@kronolith.com.

2. What data we process

  • Connection & authentication data: when you connect a social account, we store the access/refresh tokens issued by that platform and the associated account identifier and display name, so the Service can publish on your behalf. We never receive or store your passwords for those platforms.
  • Content you create: the text, images, videos and scheduling metadata of the posts you draft and schedule.
  • Basic profile data returned by a connected platform's API (e.g. username, avatar, account ID) needed to display and target the correct account.
  • Technical logs: minimal server logs (e.g. timestamps, error records) used to operate and secure the Service.

The Service is a publishing tool for account owners; it does not collect personal data about the audiences or followers of your connected accounts beyond what a platform's API returns for your own account.

3. Platform data access (incl. TikTok)

For each platform you connect, the Service requests only the permissions ("scopes") required to read your basic profile and to create and publish content. For example, for TikTok this covers basic account information and content-posting permissions. Access is granted by you during the platform's own OAuth consent flow and can be revoked by you at any time — either inside the Service by disconnecting the account, or in the platform's own settings.

4. Purposes & legal bases

  • To provide the Service — scheduling and publishing your content — under Art. 6(1)(b) GDPR (performance of a contract).
  • To keep the Service secure and reliable under Art. 6(1)(f) GDPR (legitimate interest).

5. Sharing & recipients

When you publish or schedule a post, the relevant content and access token are transmitted to the target platform you selected (e.g. TikTok, Instagram, Facebook, LinkedIn, YouTube, X (Twitter), Pinterest, Threads, Mastodon, Bluesky) in order to carry out your instruction. We do not sell your data, and we do not share it with advertisers or use it for advertising or profiling. The Service runs on our own dedicated server hosted in Germany (Hetzner Online GmbH) as a data processor for hosting infrastructure.

6. International transfers

Publishing to a third-party platform may involve transferring content to servers outside the EU/EEA, governed by that platform's own safeguards and privacy policy. This happens only as a result of your explicit publishing instruction.

7. Retention

Connection tokens are stored until you disconnect the account or request deletion. Post content and scheduling data are retained while needed for the Service and can be deleted by you. Technical logs are kept only for a short period for security and troubleshooting.

8. Security

Access tokens and data are stored on our own server with access controls and encryption in transit (HTTPS). We take reasonable technical and organisational measures to protect your data.

9. Cookies

The Service uses only strictly necessary cookies required to keep you signed in. It does not use advertising or third-party tracking cookies.

10. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict and port your personal data, and to object to processing based on legitimate interest. You may also lodge a complaint with a supervisory authority. To exercise any right, contact pascal@kronolith.com.

11. Data deletion

You can delete your data at any time by disconnecting your accounts inside the Service, or by emailing pascal@kronolith.com with a deletion request. Disconnecting an account revokes and removes its stored access token.

12. Changes

We may update this Policy; the "Last updated" date reflects the latest version.