Privacy Policy
CloudNerdz LLC, a Wisconsin limited liability company (brand: CLDNRDZ; “CloudNerdz,” “we,” “us,” or “our”), runs the website www.cloudnerdz.io (the “Site”) and the PostPro application (registered with TikTok for Developers, with Meta, with Google, with LinkedIn, and with X as CLDNRDZ-PostPro, hereafter “PostPro”). This Privacy Policy explains how we collect, use, disclose, and protect personal information in connection with the Site and PostPro.
By using the Site or PostPro, you agree to the collection and use of information in accordance with this Privacy Policy.
Information We Collect
Information You Provide Directly (Site)
When you contact us through forms on the Site, we may collect the following personal information:
- Your name
- Email address
- Topic, timing, or any additional information you voluntarily provide in your message
Information Collected Automatically (Site)
When you visit the Site, we may automatically collect certain technical information, including:
- IP address (used transiently for rate limiting)
- Browser type and version
- Device type and operating system
- Pages visited and time spent on the Site
- Referring URL
Information Collected via PostPro’s TikTok Integration
PostPro integrates with TikTok for Developers using the Login Kit and Content Posting API. When an Authorized User connects a TikTok account to PostPro through TikTok’s OAuth flow, TikTok provides PostPro with limited information about that account, as detailed in the “TikTok Data Handling” section below. Connected accounts may be owned by CloudNerdz LLC (e.g. @cloudnerdz.io) or by a client or collaborator who has authorized CloudNerdz LLC to schedule and publish on their behalf.
Information Collected via PostPro’s YouTube Integration
PostPro uses YouTube API Services (the YouTube Data API and YouTube Analytics API) via Google OAuth. When an Authorized User connects a YouTube channel to PostPro through Google’s OAuth flow, Google provides PostPro with limited information about that account and channel, as detailed in the “YouTube and Google Data Handling” section below. As with TikTok, connected channels may be owned by CloudNerdz LLC or by a client or collaborator who has authorized CloudNerdz LLC to schedule and publish on their behalf.
Information Collected via PostPro’s Meta Integration
PostPro integrates with Meta platforms — Facebook Pages, Instagram professional accounts, and Threads — via Meta’s Graph API and OAuth (Facebook Login for Business for Facebook and Instagram, and the Threads API for Threads). When an Authorized User connects a Facebook Page, Instagram account, or Threads profile to PostPro, Meta provides PostPro with limited information about that account, as detailed in the “Meta Data Handling” section below. As with the other integrations, connected accounts may be owned by CloudNerdz LLC or by a client or collaborator who has authorized CloudNerdz LLC to schedule and publish on their behalf.
Information Collected via PostPro’s LinkedIn Integration
PostPro integrates with LinkedIn via LinkedIn’s OAuth and API (Sign In with LinkedIn using OpenID Connect, Share on LinkedIn, and — for Company Pages — the Community Management API). When an Authorized User connects a LinkedIn member profile or Company Page to PostPro, LinkedIn provides PostPro with limited information about that account, as detailed in the “LinkedIn Data Handling” section below. As with the other integrations, connected profiles and Pages may be owned by CloudNerdz LLC or by a client or collaborator who has authorized CloudNerdz LLC to schedule and publish on their behalf.
Information Collected via PostPro’s X Integration
PostPro integrates with X (formerly Twitter) via X’s API using OAuth 1.0a three-legged authorization. When an Authorized User connects an X account to PostPro, X provides PostPro with limited information about that account, as detailed in the “X Data Handling” section below. As with the other integrations, connected accounts may be owned by CloudNerdz LLC or by a client or collaborator who has authorized CloudNerdz LLC to schedule and publish on their behalf.
TikTok Data Handling (PostPro)
This section describes specifically what TikTok user data PostPro receives, how it is used, and how it is stored. The fields below correspond to the scopes granted by an operator when they authorize PostPro via TikTok Login Kit.
| TikTok scope | Fields PostPro receives | How PostPro uses it |
|---|---|---|
user.info.basic |
open_id, display name, avatar URL |
Shown as the “connected account” label inside the scheduler UI so the operator can verify which TikTok account a draft will publish to. |
user.info.profile |
username, bio_description, profile_web_link, profile_deep_link, is_verified |
Shown in PostPro’s account panel so the operator can confirm profile details at a glance. |
user.info.stats |
Follower count, likes count, following count, video count | Displayed inside PostPro’s in-app analytics dashboard to track account growth alongside scheduled posts. |
video.list |
Metadata for videos already published on the authorized account | Lets operators see recent posts in PostPro so they don’t duplicate content or schedule against an already-published video. |
video.upload |
Upload status for a video PostPro is sending to TikTok | Uploads a video to TikTok as a draft so an operator can finalize and publish from inside the TikTok app. |
video.publish |
Publish status for a video PostPro is posting on the operator’s behalf | Directly posts scheduled content to the authorized TikTok profile at the time the operator selected inside PostPro. |
Storage. TikTok data described above is stored on the self-hosted PostPro instance, which runs on infrastructure controlled by CloudNerdz LLC and located in the United States. Access tokens and refresh tokens are stored in the PostPro database on a private network, with operator-restricted access at the host and database layers. Tokens are scoped to the specific TikTok account that issued them, and PostPro enforces organization-level isolation in the application so that one Authorized User cannot access another’s tokens or connected-account data through the UI. Authorized User sessions are protected by standard session-cookie security.
Retention. We retain TikTok user data only for as long as the authorization is active and as needed to operate PostPro. If an account owner disconnects PostPro, if we end the related engagement, or if we revoke our developer registration, we delete the associated tokens and cached profile/stats data within thirty (30) days, except where retention is required by law.
Deletion requests. The owner of a connected TikTok account may request deletion of all data PostPro holds about that account at any time by emailing hello@cloudnerdz.io. You may also revoke PostPro’s access directly from your TikTok account settings; once revoked, PostPro will be unable to read any new data, and cached data will be removed on the next sync.
No sale or sharing. We do not sell, rent, share, or transfer TikTok user data to any third party. TikTok user data is used solely inside PostPro for the purposes listed above.
Compliance. Our use of TikTok user data complies with the TikTok Developer Terms of Service and the TikTok Developer Platform policies, including the data-use and retention requirements set out therein.
YouTube and Google Data Handling (PostPro)
PostPro uses YouTube API Services. This section describes specifically what Google user data PostPro receives, how it is used, and how it is stored. The fields below correspond to the Google OAuth scopes granted by an operator when they connect a YouTube channel to PostPro.
| Google scope | Fields PostPro receives | How PostPro uses it |
|---|---|---|
userinfo.profile |
Google account name, avatar URL | Shown as the “connected account” label inside the scheduler UI so the operator can verify which YouTube channel a draft will publish to. |
userinfo.email |
Email address of the authorizing Google account | Shown alongside the account label so the operator can confirm the identity of the connection. |
youtube / youtube.force-ssl |
Channel metadata; status of video posts PostPro creates or updates | Creates and updates the video posts the operator schedules (titles, descriptions, tags, thumbnails) on the authorized channel. |
youtube.readonly |
Metadata for videos already published on the authorized channel | Lets operators see recent posts in PostPro so they don’t duplicate content or schedule against an already-published video. |
youtube.upload |
Upload status for a video PostPro is sending to YouTube | Uploads the scheduled video files to the authorized channel at the time the operator selected. |
youtubepartner |
None used | Requested by the upstream Postiz YouTube provider as part of its fixed scope set; PostPro does not use YouTube partner/CMS features and does not read or store partner data. |
yt-analytics.readonly |
Aggregate channel and video statistics | Displayed inside PostPro’s in-app analytics dashboard to track channel performance alongside scheduled posts. |
Storage. Google user data described above is stored on the same self-hosted PostPro instance as TikTok data: infrastructure controlled by CloudNerdz LLC and located in the United States. Google access tokens and refresh tokens are stored in the PostPro database on a private network, with operator-restricted access at the host and database layers. Tokens are scoped to the specific Google account that issued them, and PostPro enforces organization-level isolation in the application so that one Authorized User cannot access another’s tokens or connected-channel data through the UI.
Retention. We retain Google user data only for as long as the authorization is active and as needed to operate PostPro. If a channel owner disconnects PostPro, if we end the related engagement, or if we delete our Google API project, we delete the associated tokens and cached profile/statistics data within thirty (30) days, except where retention is required by law.
Deletion and revocation. The owner of a connected YouTube channel may request deletion of all data PostPro holds about that channel at any time by emailing hello@cloudnerdz.io. You may also revoke PostPro’s access to your Google data at any time via your Google security settings; once revoked, PostPro will be unable to read any new data, and cached data will be removed on the next sync.
No sale or sharing. We do not sell, rent, share, or transfer Google user data to any third party. Google user data is used solely inside PostPro for the purposes listed above. We do not use Google user data for advertising, and we do not allow humans to read it except with the account owner’s consent, for security purposes, to comply with applicable law, or as necessary to operate PostPro under the account owner’s instructions.
Compliance. Because PostPro uses YouTube API Services, Authorized Users who connect a YouTube channel are also agreeing to the YouTube Terms of Service. Google’s handling of your data is described in the Google Privacy Policy.
Meta Data Handling — Facebook, Instagram & Threads (PostPro)
PostPro integrates with Meta platforms via the Graph API and OAuth. This section describes specifically what Meta user data PostPro receives, how it is used, and how it is stored. The fields below correspond to the permissions granted by an operator when they connect a Facebook Page, an Instagram professional account, or a Threads profile to PostPro. Facebook and Instagram are authorized through Facebook Login for Business; Threads is authorized through the separate Threads API.
| Meta permission | Fields PostPro receives | How PostPro uses it |
|---|---|---|
pages_show_list |
The list of Facebook Pages the authorizing user manages (Page id and name) | Lets the operator select which Facebook Page a scheduled post will publish to, shown in the scheduler UI. |
business_management |
The Business/Page management relationship of the authorizing user | Confirms the operator is authorized to act on the selected Page so PostPro can publish on its behalf. |
pages_manage_posts |
Publish status for a post PostPro is creating on the Page | Creates and publishes the scheduled posts to the authorized Facebook Page at the time the operator selected. |
pages_manage_engagement |
Comment/engagement objects on posts PostPro publishes | Manages engagement (e.g. replying to comments) on posts PostPro publishes, on the operator’s behalf. |
pages_read_engagement |
The Page’s existing posts and engagement metadata | Lets operators reference the Page’s recent posts inside PostPro so they don’t duplicate content. |
read_insights |
Aggregate Page and post insights | Displayed inside PostPro’s in-app analytics dashboard to track Page performance alongside scheduled posts. |
| Meta permission | Fields PostPro receives | How PostPro uses it |
|---|---|---|
instagram_basic |
Instagram account id, username, and profile details | Shown as the “connected account” label inside the scheduler UI so the operator can verify which Instagram account a draft will publish to. |
pages_show_list |
The Facebook Pages linked to the Instagram professional account | Used to resolve and select the correct Instagram professional account (which is linked to a Facebook Page). |
pages_read_engagement |
The linked Page’s posts and engagement metadata | Used to resolve the linked account and let operators reference past posts to avoid duplicates. |
business_management |
The Business relationship linking the Instagram account to the operator | Confirms the operator is authorized to publish to the connected Instagram account. |
instagram_content_publish |
Publish status for media PostPro is posting | Publishes the scheduled photos, videos, and Reels to the authorized Instagram account at the time the operator selected. |
instagram_manage_comments |
Comment objects on media PostPro publishes | Reads and manages comments on media PostPro publishes, on the operator’s behalf. |
instagram_manage_insights |
Aggregate account and media insights | Displayed inside PostPro’s in-app analytics dashboard to track account performance alongside scheduled posts. |
Threads
| Meta permission | Fields PostPro receives | How PostPro uses it |
|---|---|---|
threads_basic |
Threads profile id and basic identity | Shown as the “connected account” label inside the scheduler UI so the operator can verify which Threads profile a draft will publish to. |
threads_content_publish |
Publish status for a Threads post PostPro is creating | Publishes the scheduled Threads posts to the authorized profile at the time the operator selected. |
threads_manage_replies |
Reply objects on posts PostPro publishes | Reads and manages replies to posts PostPro publishes, on the operator’s behalf. |
threads_manage_insights |
Aggregate post and profile insights | Displayed inside PostPro’s in-app analytics dashboard to track performance alongside scheduled posts. |
Storage. Meta user data described above is stored on the same self-hosted PostPro instance as the other integrations: infrastructure controlled by CloudNerdz LLC and located in the United States. Access tokens are stored in the PostPro database on a private network, with operator-restricted access at the host and database layers. Tokens are scoped to the specific Meta account that issued them, and PostPro enforces organization-level isolation in the application so that one Authorized User cannot access another’s tokens or connected-account data through the UI.
Retention. We retain Meta user data only for as long as the authorization is active and as needed to operate PostPro. If an account owner disconnects PostPro, if we end the related engagement, or if we remove our Meta app, we delete the associated tokens and cached profile/insights data within thirty (30) days, except where retention is required by law.
Deletion and revocation. The owner of a connected Meta account may request deletion of all data PostPro holds about that account at any time by emailing hello@cloudnerdz.io. You may also revoke PostPro’s access at any time from your Facebook settings (Business Integrations), your Instagram app permissions, or your Threads account settings; once revoked, PostPro will be unable to read any new data, and cached data will be removed on the next sync.
No sale or sharing. We do not sell, rent, share, or transfer Meta user data to any third party. Meta user data is used solely inside PostPro for the purposes listed above, and is not used for advertising.
Compliance. Our use of Meta user data complies with the Meta Platform Terms and the Meta Developer Policies, including their data-use and retention requirements. Meta’s handling of your data is described in the Meta Privacy Policy.
LinkedIn Data Handling (PostPro)
PostPro integrates with LinkedIn via LinkedIn’s OAuth and API. This section describes specifically what LinkedIn user data PostPro receives, how it is used, and how it is stored. The fields below correspond to the OAuth scopes requested by the upstream Postiz LinkedIn provider, which PostPro runs unmodified, when an operator connects a LinkedIn member profile or Company Page.
rw_organization_admin, w_organization_social, r_organization_social) are part of LinkedIn’s Community Management API, for which PostPro has submitted an access request. Until that access is approved by LinkedIn, PostPro publishes only to the authorizing member’s own profile and does not read or write Company Page data.
| LinkedIn scope | Fields PostPro receives | How PostPro uses it |
|---|---|---|
openid |
An OpenID Connect authentication token identifying the authorizing member | Part of Sign In with LinkedIn (OpenID Connect); establishes which LinkedIn member authorized PostPro. |
profile |
The member’s basic profile (name, headline, avatar) | Shown as the “connected account” label inside the scheduler UI so the operator can verify which LinkedIn identity a draft will publish to. |
w_member_social |
Publish status for a post PostPro is creating on the member’s profile | Publishes the scheduled posts to the authorizing member’s LinkedIn profile at the time the operator selected (Share on LinkedIn). |
r_basicprofile |
Basic profile fields, including the member’s vanity name | Shown in PostPro’s account panel so the operator can confirm profile details. Requested by the upstream Postiz LinkedIn provider. |
rw_organization_admin |
The LinkedIn Company Pages the member administers | Lets the operator select a Company Page to publish to (Community Management API — access pending; see callout above). |
w_organization_social |
Publish status for a post PostPro is creating on a Company Page | Publishes the scheduled posts to an authorized LinkedIn Company Page (Community Management API — access pending). |
r_organization_social |
A Company Page’s existing posts and engagement metadata | Lets operators reference a Page’s recent posts inside PostPro so they don’t duplicate content (Community Management API — access pending). |
Storage. LinkedIn user data described above is stored on the same self-hosted PostPro instance as the other integrations: infrastructure controlled by CloudNerdz LLC and located in the United States. Access tokens are stored in the PostPro database on a private network, with operator-restricted access at the host and database layers. Tokens are scoped to the specific LinkedIn account that issued them, and PostPro enforces organization-level isolation in the application so that one Authorized User cannot access another’s tokens or connected-account data through the UI.
Retention. We retain LinkedIn user data only for as long as the authorization is active and as needed to operate PostPro. If an account owner disconnects PostPro, if we end the related engagement, or if we remove our LinkedIn app, we delete the associated tokens and cached profile data within thirty (30) days, except where retention is required by law.
Deletion and revocation. The owner of a connected LinkedIn account may request deletion of all data PostPro holds about that account at any time by emailing hello@cloudnerdz.io. You may also revoke PostPro’s access at any time from your LinkedIn Permitted Services settings; once revoked, PostPro will be unable to read any new data, and cached data will be removed on the next sync.
No sale or sharing. We do not sell, rent, share, or transfer LinkedIn user data to any third party. LinkedIn user data is used solely inside PostPro for the purposes listed above, and is not used for advertising.
Compliance. Our use of LinkedIn user data complies with the LinkedIn API Terms of Use and the LinkedIn Developer Program terms. LinkedIn’s handling of your data is described in the LinkedIn Privacy Policy.
X Data Handling (PostPro)
PostPro integrates with X (formerly Twitter) via X’s API. This section describes specifically what X user data PostPro receives, how it is used, and how it is stored. Unlike the other integrations, X authorizes PostPro through OAuth 1.0a, which does not use granular permission scopes; instead PostPro’s X application holds a single application-level permission (Read and write) that an operator grants when they connect an X account.
| X app permission | Fields PostPro receives | How PostPro uses it |
|---|---|---|
Read and write |
The authorizing account’s basic profile: user id, @handle (username), display name, avatar URL, and verified status |
The profile is shown as the “connected account” label inside the scheduler UI so the operator can verify which X account a draft will publish to, and the write permission is used to publish the scheduled posts to that account at the time the operator selected. OAuth 1.0a grants this as a single Read-and-write permission covering both reading the connected profile and posting on its behalf. |
Storage. X user data described above is stored on the same self-hosted PostPro instance as the other integrations: infrastructure controlled by CloudNerdz LLC and located in the United States. The per-account access token and secret are stored in the PostPro database on a private network, with operator-restricted access at the host and database layers. Tokens are scoped to the specific X account that issued them, and PostPro enforces organization-level isolation in the application so that one Authorized User cannot access another’s tokens or connected-account data through the UI.
Retention. We retain X user data only for as long as the authorization is active and as needed to operate PostPro. If an account owner disconnects PostPro, if we end the related engagement, or if we remove our X app, we delete the associated tokens and cached profile data within thirty (30) days, except where retention is required by law.
Deletion and revocation. The owner of a connected X account may request deletion of all data PostPro holds about that account at any time by emailing hello@cloudnerdz.io. You may also revoke PostPro’s access at any time from your X Connected apps settings; once revoked, PostPro will be unable to read any new data or publish, and cached data will be removed on the next sync.
No sale or sharing. We do not sell, rent, share, or transfer X user data to any third party. X user data is used solely inside PostPro for the purposes listed above, and is not used for advertising.
Compliance. Our use of X user data complies with the X Developer Agreement and Policy. X’s handling of your data is described in the X Privacy Policy.
How We Use Site Information
We use information collected through the Site for the following purposes:
- Communication: To respond to inquiries you submit through our contact and booking forms.
- Operations: Rate-limiting and abuse prevention on our API endpoints (transient IP-based checks via Upstash Redis).
- Routing: To pass your inquiry to our team via Slack so we can respond promptly.
- AI-assisted routing: When you interact with the chat widget, your message is sent to OpenAI (model
gpt-4o-mini) so that the assistant can route your question to the most relevant practice area. We do not store this message server-side beyond the lifetime of the request.
How We Share Information
We do not sell, rent, or trade your personal information. We share information only with service providers strictly required to operate the Services:
- Vercel — hosting for the Site and serverless functions.
- Upstash — transient rate-limit counters (IP hashes; no message content).
- OpenAI — processes chat-widget messages to route inquiries.
- Slack — receives a notification when you submit a booking form so we can follow up.
- TikTok for Developers — provides the OAuth and content-publishing APIs used by PostPro.
- Google (YouTube API Services) — provides the OAuth, video-upload, and analytics APIs used by PostPro’s YouTube integration.
- Meta Platforms — provides the OAuth and Graph APIs (Facebook, Instagram, and Threads) used by PostPro’s Meta integration.
- LinkedIn — provides the OAuth and content-publishing APIs used by PostPro’s LinkedIn integration.
- X (Twitter) — provides the OAuth 1.0a and content-publishing APIs used by PostPro’s X integration.
We may also disclose information if required by law, in response to a valid legal process, or to protect the rights, safety, or property of CloudNerdz LLC, our users, or the public.
Cookies and Tracking
The Site uses only the cookies strictly necessary for it to function. We do not currently run third-party analytics or advertising trackers. If we add analytics in the future, we will update this Privacy Policy and disclose the provider.
Data Security
We implement reasonable administrative, technical, and physical safeguards to protect personal information, including HTTPS in transit, encrypted tokens at rest for PostPro, and restricted operator access. However, no method of transmission over the Internet or method of electronic storage is 100% secure, and we cannot guarantee absolute security.
Your Rights
Depending on your location, you may have rights regarding your personal information, including:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate or incomplete information.
- Deletion: Request deletion of your personal information, subject to certain exceptions.
- Opt-Out: Decline to share information by not submitting forms, by revoking PostPro’s TikTok authorization, by revoking PostPro’s Google authorization via your Google security settings, by revoking PostPro’s Meta access via your Facebook Business Integrations, by revoking PostPro’s LinkedIn access via your LinkedIn Permitted Services settings, or by revoking PostPro’s X access via your X Connected apps settings.
- Portability: Request a copy of your data in a structured, commonly used format.
To exercise any of these rights, contact us at hello@cloudnerdz.io.
For California Residents (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect and how it is used, and the right to request deletion. We do not sell personal information.
For European Residents (GDPR)
If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR), including the right to access, rectify, erase, restrict processing, and object to the processing of your personal data. Our legal basis for processing your information is your consent (provided when you contact us or authorize PostPro) and our legitimate business interests.
Third-Party Links
The Site may contain links to third-party websites or services that are not operated by us. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party sites or services. We encourage you to review the privacy policies of any third-party sites you visit, including the TikTok Privacy Policy, the Google Privacy Policy, the Meta Privacy Policy, the LinkedIn Privacy Policy, and the X Privacy Policy.
Children’s Privacy
The Services are not directed to individuals under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have inadvertently collected information from a child under 13, we will delete that information as quickly as possible. If you believe we may have collected information from a child under 13, please contact us immediately.
Authorized Users of PostPro must additionally be 18 years of age or older to access the application, as stated in our Terms of Service.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, or legal requirements. When we make changes, we will update the “Last Updated” date at the top of this page. Continued use of the Services after any changes constitutes your acceptance of the updated Privacy Policy.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, our data practices, or PostPro’s TikTok, YouTube, Meta, LinkedIn, or X integrations, please contact us at:
CloudNerdz LLC
Wisconsin, United States
Email: hello@cloudnerdz.io
Website: www.cloudnerdz.io
This Privacy Policy is provided for informational purposes and does not constitute legal advice. We recommend consulting with a legal professional if you have specific questions about your privacy obligations.