Privacy
Last updated 9 September 2026
Ventuff publishes content to social accounts you connect and, when enabled, runs keyword-triggered Instagram Comment-to-DM replies. This page says what we hold, why, and how to end it.
What we hold
- Access to the accounts you connect. When you connect Instagram, Threads, Facebook, TikTok or YouTube, the platform gives us a token that lets us use the account permissions you authorize, including publishing and the Instagram automation described below. We store that token. We never see or store your password.
- The content we publish for you, and the settings you choose - your look, your topics, your schedule.
- Public performance figures for posts we published: views, reach, likes, comments, shares and saves. We use them to decide what to publish next.
- An email address, so we can reach you about your account.
What we do not do
- We do not sell your data, and we do not share it with advertisers.
- We do not use Comment-to-DM to monitor unrelated private conversations.
- We do not post anything you have not asked us to publish.
Instagram Comment-to-DM
When an account owner enables this feature for a post, we read comments on
that post to identify its configured keyword. A matching comment can trigger
an automated private reply and a public acknowledgment. For a conversation
opened by this feature, we retrieve recent message text to identify the
person's response, such as FOLLOWING. This can include other recent
messages in that same conversation while we look for the response; we do not
use this feature to scan unrelated conversations.
For a follow-required resource, we ask Instagram whether the person follows the connected account. A typed reply is not proof of following: the resource link is sent only after Instagram confirms the follow status. An unavailable or uncertain result does not release the link. These checks and replies use fixed rules, not an AI chatbot. Comment and DM text processed by this feature is not sent to an AI model for generation or training.
We store matching comment text, account and recipient identifiers, post, comment, conversation and message identifiers, timestamps, campaign settings and resource links. We also keep recognized-response events, delivery and follow-check outcomes, and retry and duplicate-prevention records. These records let us process requests, diagnose failures and avoid repeated messages. The feature reads DM message text in memory to recognize a response; it does not retain the raw DM text in its queue, session records or polling state.
The account owner can turn Comment-to-DM off for an agent or disconnect Instagram to stop new automated processing. This cannot recall a message already sent or a request already accepted by Instagram. Turning the feature off or disconnecting does not by itself erase saved automation records. Those records are not automatically deleted when a messaging window expires. To request their deletion, including records of your own interaction with a connected account, use the contact details below.
Who else is involved
Publishing means sending your content to the platform you chose. Their handling of it is governed by their own terms: Meta (Instagram, Threads, Facebook), TikTok, and Google (YouTube).
YouTube
Where Ventuff publishes to YouTube it uses YouTube API Services. By connecting a YouTube channel you also accept the YouTube Terms of Service, and Google's handling of data is described in the Google Privacy Policy.
Ventuff requests two Google permissions. youtube.readonly lets us
read the connected channel's identifier, title and handle so we can show and
verify which channel you connected. youtube.upload lets us upload
the video, title, description and tags you approve or authorize through your
publishing settings. We do not read your viewing history, contacts, email,
private messages or Google password.
We store the channel identifier, title, handle and OAuth refresh token on our server for as long as the channel remains connected. We use this Google user data only to provide the visible channel connection and YouTube publishing features in Ventuff. We do not sell it, use it for advertising, use it to train general-purpose AI models, or transfer it to third parties except Google and YouTube as needed to provide those features.
Ventuff's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
You can revoke Ventuff's access to your Google account at any time at myaccount.google.com/permissions. Doing so stops us publishing to that channel. You can also disconnect a channel in Ventuff; we revoke the Google token and delete the stored channel connection. If authorization can no longer be verified, we remove the associated stored Google data within seven days.
How we protect it
These measures apply to everything listed above, including the Google user data described in the YouTube section.
- In transit. Every request between Ventuff and a platform API -
Google, Meta, TikTok - travels over HTTPS with TLS, and the dashboard is
served over HTTPS. Session cookies are marked
HttpOnly,SameSite=LaxandSecure, so a session identifier cannot be read by page scripts and is not sent over a plain connection. - At rest. OAuth tokens, including the Google refresh token, are held on the server in a directory reachable only by the single system account that runs the service, with restrictive file permissions applied at the moment each token is written. They are not stored in the application database, are not written to logs or error reports, and are never returned by any page or API response - a connected channel is always shown by its name, never by its credential. TikTok browser session data is additionally encrypted at rest with AES-256-GCM under a key kept in a separate permission-restricted file.
- Access control. The dashboard requires a password before any connected account can be viewed or used. Passwords are stored only as a salted scrypt hash and are compared in constant time; we cannot read them. Sessions are signed with a key derived from that stored hash, so changing the password immediately invalidates every existing session on every device.
- Least privilege. We request the narrowest scopes each feature needs, and we do not request scopes for features you have not enabled. Google user data is used only to provide the channel connection and the YouTube publishing features described above, and is never used to train generalized AI models.
- Single-operator installation. The service runs on a server holding only the accounts of the operator who runs it. There is no shared multi-customer store of platform credentials.
- Deletion. Disconnecting a channel revokes the token with the provider and deletes the stored connection. If authorization can no longer be verified, the associated stored Google data is removed within seven days. Closing your account deletes what we hold for you.
No system is perfect. If you believe your account or a connected channel has been compromised, disconnect it in the dashboard, revoke our access at the provider, and write to us at the address below.
Ending it
Disconnect an account in your dashboard and we delete its token. Ask us to close your account and we delete what we hold for you. Posts already published belong to your account on that platform and stay there unless you remove them.
Contact
Write to andterianda5555@gmail.com.