Social USB-C — Data Deletion Instructions
Draft — not yet reviewed by a lawyer.
Last updated: 30 September 2026
Note: this page is published in English so that the review teams at Google, Meta and TikTok can read it. A French version will follow.
This page explains how to delete the data that Social USB-C holds about you, including the data we received from Facebook, Instagram, Threads, YouTube, TikTok and the other platforms you connected. Social USB-C is operated by YANNIS HAISMANN OÜ (registration number 17576158, Estonia). Questions: privacy@socialusbc.com.
What we hold about you
Depending on what you connected and used, we may hold:
- your Social USB-C account details (email address, name, login credentials, plan);
- for each connected platform: the platform's identifier for your account or page, your public profile name and picture, and the access tokens that let us publish on your behalf;
- the videos, images and text you uploaded, and your drafts and scheduled posts;
- a list of the posts we published for you, with the platform's post identifier and basic performance figures;
- billing records handled through Stripe;
- technical logs (IP address, browser, actions in the app) and support emails.
The full list, with retention periods, is in our Privacy Policy at https://socialusbc.com/privacy.
Option 1: delete from the app
To delete the data of one platform only:
- Sign in to Social USB-C.
- Go to Settings, then Connected accounts.
- Click Disconnect next to the platform.
We immediately stop publishing to that account, revoke the access token where the platform allows it, and delete the token, the platform identifiers, the cached profile and analytics data, and any media still stored for that platform. Posts already published stay on the platform.
To delete everything:
- Sign in to Social USB-C.
- Go to Settings, then Account, then Delete my account.
- Confirm by typing your email address.
Your account is closed at once. All connected platforms are disconnected, scheduled posts are cancelled, and your data is deleted as described under "What is deleted" below.
Option 2: ask us by email
Write to privacy@socialusbc.com with the subject "Data deletion request". Please:
- write from the email address of your Social USB-C account, or, if you cannot, give us enough detail to find you (the platform, your username or page name, and roughly when you connected it);
- say whether you want us to delete one platform's data or your whole account.
We confirm receipt within 5 business days, may ask you to prove that the account is yours, and complete the deletion within 30 days of your request. You receive an email when it is done. If we cannot delete something because the law requires us to keep it, we tell you what and why.
Option 3: remove Social USB-C from the platform
You can also revoke our access directly on the platform. This stops us from accessing your data on that platform and, for Meta, sends us an automatic deletion request.
- Facebook: Settings & privacy, then Settings, then Apps and websites, then Social USB-C, then Remove. Facebook then sends us a data deletion request (see the technical section below). We delete your Facebook data within 30 days and give you a confirmation code and a status link on Facebook's confirmation screen.
- Instagram: Settings, then Apps and websites (or Website permissions), then Social USB-C, then Remove.
- Threads: Settings, then Account, then Apps and websites, then Social USB-C, then Remove.
- YouTube and Google: go to https://security.google.com/settings/security/permissions, select Social USB-C and click Remove access. We delete all the data we received from YouTube for you within 30 days, in line with the YouTube API Services policies.
- TikTok: Settings and privacy, then Security and permissions, then Manage app permissions, then Social USB-C, then Remove.
- Other platforms: see the support page at https://socialusbc.com/support.
Revoking access on the platform does not by itself close your Social USB-C account. To delete everything, use option 1 or option 2.
What is deleted
When you delete your account, or when we process your request, we delete:
- your account profile and login credentials;
- all access and refresh tokens for every connected platform, after asking each platform to revoke them where its API allows;
- the platform identifiers, profile names, pictures, page lists and any other data received from the platforms;
- all uploaded media, drafts and scheduled posts;
- the list of published posts and the cached performance figures;
- your preferences and calendar.
Backups are overwritten within 30 days, so a copy may survive in an encrypted backup for at most 30 days after deletion.
What we keep, and why
- Invoices and payment records: 7 years, because Estonian accounting law requires it. They contain your name, email, amount and date, not your platform data.
- A record of your deletion request (the email address used, the date, the confirmation code, and what was deleted): 12 months, so that we can prove that we handled it.
- Security and abuse logs: up to 90 days, then deleted automatically.
- Correspondence about an open dispute or legal claim: until the matter is closed.
- Statistics that no longer identify anyone (for example, the number of posts published per month): indefinitely.
Content you already published on a platform stays on that platform. To remove it, delete it on the platform itself.
Checking the status of a request
Every deletion request that arrives through a platform callback or by email receives a confirmation code. You can check its status at https://socialusbc.com/data-deletion/status?code=YOUR_CODE. The page shows one of three states: pending, completed (with the completion date), or refused (with the reason, for example a legal retention duty).
Technical note: Meta Data Deletion Request Callback
This section describes the endpoint that Social USB-C exposes so that Meta can send deletion requests automatically. It is here so the behaviour is public and so that it can be implemented later. It applies to the Facebook Login, Instagram and Threads products of our Meta app; each product has its own "Data Deletion Request URL" field in the Meta App Dashboard, and all of them point to the same endpoint.
Endpoint: POST https://socialusbc.com/api/meta/data-deletion
What Meta sends: an HTTP POST with a form field named signed_request. Its value has two parts separated by a dot: a base64url-encoded signature, then a base64url-encoded JSON payload. The payload contains user_id (the app-scoped user identifier), algorithm (always HMAC-SHA256), issued_at and expires.
What the endpoint does:
- Split the value on the first dot and base64url-decode both parts.
- Recompute the signature: HMAC-SHA256 of the encoded payload, keyed with the app secret. Reject the request with HTTP 400 if it does not match the signature received, or if
algorithmis notHMAC-SHA256. - Read
user_idand look up every connected account that has this app-scoped identifier (Facebook page, Instagram account, Threads account). - Create a deletion job with a random confirmation code, mark it pending, and queue it. The job deletes everything listed under "What is deleted" for that identifier, revokes and deletes the tokens, and records the completion date.
- Return HTTP 200 with a JSON body containing two fields:
url, the status page for this request, andconfirmation_code, the code the user can quote to us.
Example response:
{
"url": "https://socialusbc.com/data-deletion/status?code=8f3c2a1b",
"confirmation_code": "8f3c2a1b"
}
The status page must be reachable without logging in and must show the state of the request and, if refused, the reason.
Related callback: Meta also sends a signed_request to the "Deauthorize Callback URL" when a user removes the app without asking for deletion. The same parsing applies. On deauthorisation we revoke and delete the tokens for that user and stop all scheduled posts for the affected accounts, and we keep the rest of the data until the user deletes it or the retention periods expire.
Where to configure: in the Meta App Dashboard, under App settings, then Basic, fill in "Privacy Policy URL" with https://socialusbc.com/privacy, "Terms of Service URL" with https://socialusbc.com/terms, and either "Data Deletion Instructions URL" with https://socialusbc.com/data-deletion or "Data Deletion Request URL" with the endpoint above. Until the endpoint is live, use the instructions URL.