Social USB-C

Social USB-C — Data Deletion Instructions

Draft — not yet reviewed by a lawyer.

Last updated: 30 September 2026

Note: this page is published in English so that the review teams at Google, Meta and TikTok can read it. A French version will follow.

This page explains how to delete the data that Social USB-C holds about you, including the data we received from Facebook, Instagram, Threads, YouTube, TikTok and the other platforms you connected. Social USB-C is operated by YANNIS HAISMANN OÜ (registration number 17576158, Estonia). Questions: privacy@socialusbc.com.

What we hold about you

Depending on what you connected and used, we may hold:

The full list, with retention periods, is in our Privacy Policy at https://socialusbc.com/privacy.

Option 1: delete from the app

To delete the data of one platform only:

  1. Sign in to Social USB-C.
  2. Go to Settings, then Connected accounts.
  3. Click Disconnect next to the platform.

We immediately stop publishing to that account, revoke the access token where the platform allows it, and delete the token, the platform identifiers, the cached profile and analytics data, and any media still stored for that platform. Posts already published stay on the platform.

To delete everything:

  1. Sign in to Social USB-C.
  2. Go to Settings, then Account, then Delete my account.
  3. Confirm by typing your email address.

Your account is closed at once. All connected platforms are disconnected, scheduled posts are cancelled, and your data is deleted as described under "What is deleted" below.

Option 2: ask us by email

Write to privacy@socialusbc.com with the subject "Data deletion request". Please:

We confirm receipt within 5 business days, may ask you to prove that the account is yours, and complete the deletion within 30 days of your request. You receive an email when it is done. If we cannot delete something because the law requires us to keep it, we tell you what and why.

Option 3: remove Social USB-C from the platform

You can also revoke our access directly on the platform. This stops us from accessing your data on that platform and, for Meta, sends us an automatic deletion request.

Revoking access on the platform does not by itself close your Social USB-C account. To delete everything, use option 1 or option 2.

What is deleted

When you delete your account, or when we process your request, we delete:

Backups are overwritten within 30 days, so a copy may survive in an encrypted backup for at most 30 days after deletion.

What we keep, and why

Content you already published on a platform stays on that platform. To remove it, delete it on the platform itself.

Checking the status of a request

Every deletion request that arrives through a platform callback or by email receives a confirmation code. You can check its status at https://socialusbc.com/data-deletion/status?code=YOUR_CODE. The page shows one of three states: pending, completed (with the completion date), or refused (with the reason, for example a legal retention duty).

Technical note: Meta Data Deletion Request Callback

This section describes the endpoint that Social USB-C exposes so that Meta can send deletion requests automatically. It is here so the behaviour is public and so that it can be implemented later. It applies to the Facebook Login, Instagram and Threads products of our Meta app; each product has its own "Data Deletion Request URL" field in the Meta App Dashboard, and all of them point to the same endpoint.

Endpoint: POST https://socialusbc.com/api/meta/data-deletion

What Meta sends: an HTTP POST with a form field named signed_request. Its value has two parts separated by a dot: a base64url-encoded signature, then a base64url-encoded JSON payload. The payload contains user_id (the app-scoped user identifier), algorithm (always HMAC-SHA256), issued_at and expires.

What the endpoint does:

  1. Split the value on the first dot and base64url-decode both parts.
  2. Recompute the signature: HMAC-SHA256 of the encoded payload, keyed with the app secret. Reject the request with HTTP 400 if it does not match the signature received, or if algorithm is not HMAC-SHA256.
  3. Read user_id and look up every connected account that has this app-scoped identifier (Facebook page, Instagram account, Threads account).
  4. Create a deletion job with a random confirmation code, mark it pending, and queue it. The job deletes everything listed under "What is deleted" for that identifier, revokes and deletes the tokens, and records the completion date.
  5. Return HTTP 200 with a JSON body containing two fields: url, the status page for this request, and confirmation_code, the code the user can quote to us.

Example response:

{
  "url": "https://socialusbc.com/data-deletion/status?code=8f3c2a1b",
  "confirmation_code": "8f3c2a1b"
}

The status page must be reachable without logging in and must show the state of the request and, if refused, the reason.

Related callback: Meta also sends a signed_request to the "Deauthorize Callback URL" when a user removes the app without asking for deletion. The same parsing applies. On deauthorisation we revoke and delete the tokens for that user and stop all scheduled posts for the affected accounts, and we keep the rest of the data until the user deletes it or the retention periods expire.

Where to configure: in the Meta App Dashboard, under App settings, then Basic, fill in "Privacy Policy URL" with https://socialusbc.com/privacy, "Terms of Service URL" with https://socialusbc.com/terms, and either "Data Deletion Instructions URL" with https://socialusbc.com/data-deletion or "Data Deletion Request URL" with the endpoint above. Until the endpoint is live, use the instructions URL.