Information we process
HF Signal processes the handle, provider account identifier, granted permission scopes, access tokens, refresh tokens, and token expiration details returned when an administrator connects a social account.
The service also stores thread metadata, administrator-edited drafts, generated media references, publication status, provider post identifiers, and operational error logs needed to review and deliver approved posts.
Support requests store the email address, subject, and message supplied by the requester so the HF Signal operator can respond and resolve the request.
HF Signal does not request or store a connected platform account password.
How information is used
Connected-account information is used only to authenticate with the selected provider, publish content after explicit administrator approval, refresh authorization when permitted, prevent duplicate posts, and diagnose delivery failures.
HF Signal does not sell personal information, build advertising profiles, or use connected-account data to train machine-learning models.
Google and YouTube API data
When an administrator connects YouTube, HF Signal requests the YouTube read-only and upload permissions. The read-only permission is used only during account connection to retrieve the channel ID, channel title, and custom channel URL so the administrator can verify that the intended channel was connected. The upload permission is used only to upload videos that the administrator explicitly approves in HF Signal.
HF Signal does not use these permissions to read subscriptions, viewing history, comments, subscribers, analytics, private videos, or other channel content. It does not collect aggregated or anonymized Google user data. Google account data is not used for advertising, sold, transferred to data brokers, or used to train generalized artificial-intelligence or machine-learning models.
YouTube channel identifiers and authorization details are retained only while the YouTube connection remains active. OAuth access and refresh tokens are encrypted at rest. Disconnecting YouTube deletes the stored authorization record and prevents future API access. Publication identifiers and non-token delivery history may be retained for duplicate prevention, security, and audit purposes until a verified deletion request is completed.
Google user data is shared only with Google and YouTube as required to authorize the connection and perform an administrator-approved upload, and with the infrastructure provider that securely operates HF Signal. HF Signal's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Review the Google API Services User Data Policy for more information about those requirements.
Reddit API data
If Reddit grants explicit Data API access and an administrator connects the dedicated HF Signal app account, HF Signal requests only the identity and submit permissions. Identity is used to verify the connected account. Submit is used only to create a self-post that an administrator has reviewed and explicitly approved.
HF Signal does not request Reddit's read scope and does not collect Reddit feeds, posts, comments, messages, votes, moderation data, follower data, or third-party user profiles. It does not vote, comment, message users, perform moderation, or post to third-party subreddits.
Reddit authorization details are encrypted and retained only while the connection remains active. Disconnecting Reddit deletes the stored OAuth authorization record. A returned post identifier, URL, status, and timestamp may be retained for duplicate prevention, security, and audit purposes.
Sharing and service providers
Information is sent to a social platform only when necessary to authorize an account or carry out an approved publishing request. Limited information may also be processed by the infrastructure providers that operate the application and database.
HF Signal does not disclose connected-account data to unrelated third parties.
Data protection mechanisms for sensitive data
HF Signal protects Google user data and other connected-account data in transit using HTTPS with Transport Layer Security (TLS). Provider authorization callbacks, account-connection requests, and approved publishing traffic are transmitted over encrypted HTTPS connections.
OAuth access tokens, refresh tokens, provider client credentials, and temporary OAuth verifiers are encrypted before database storage using AES-256-GCM authenticated encryption. Each encryption operation uses a new random 96-bit initialization vector and an authentication tag. The encryption secret is kept in protected server environment configuration and is not stored with the encrypted database values.
Credentials are decrypted only inside server-side application code when an account-connection or administrator-approved provider request requires them. OAuth token values are not intentionally exposed through public pages or client-side application data. Administrative pages are access-controlled, and publishing actions require an authorized administrator workflow.
HF Signal requests only the provider permissions needed for the features described in this policy. Structured application logs redact security-sensitive fields such as tokens, passwords, client secrets, authorization headers, cookies, and credentials before output. Server and database access are restricted to authorized service administration and the infrastructure components necessary to operate HF Signal.
Connected-account credentials are retained only while the integration remains active. Disconnecting an account deletes its stored authorization record, including encrypted token values, and prevents future API publishing through that connection. An account owner may also revoke access directly through the connected provider.
No online service can guarantee absolute security. HF Signal reviews operational failures and provider changes so access can be disabled or credentials removed if continued operation could create a security risk.
Retention and deletion
Connected-account credentials are retained while the integration remains active. Disconnecting an account removes its stored authorization record and prevents future publishing through that connection.
Support messages are retained only as long as reasonably needed to answer the request, maintain service security, and document the resolution.
Instructions for requesting deletion are available on the Data Deletion page.
Contact and updates
Privacy questions can be directed to the HF Signal operator through HFTools.org.
This policy may be updated when the service or provider requirements change. The effective date above identifies the current version.