Privacy Policy
Last updated: 16 August 2026
Esport Adria Social Tool ("SocialTool") is a social media publishing tool operated by EsportAdria ("we", "us"). Teams use it to schedule and publish content to social media accounts they own or manage, and to collect engagement statistics for those accounts. EsportAdria's own media team is its first user; access for new teams is set up by us on request.
Data we collect and store
- Panel user accounts: name, email address, and authentication credentials of the people invited to use the tool. Accounts are created by an administrator during onboarding.
- Connected social accounts: account identifiers, display names, and OAuth access tokens for the accounts a team connects on X, Facebook, Instagram, Discord, YouTube, and TikTok. Tokens are stored encrypted at rest.
- Content: the posts, images, and videos composed, scheduled, and published through the tool.
- Engagement metrics and content: aggregate statistics (such as views, likes, comments, shares, and follower counts) returned by the connected platforms' APIs for connected accounts and their posts. We also fetch the text of comments, direct messages, and mentions on those accounts and posts, and store it on our server so the team that owns the connection can review and respond to them in the engagement inbox.
What we use it for
Solely to operate the publishing panel: publishing and scheduling content to connected accounts, monitoring the health of account connections, and reporting on the performance of content published from those accounts. We do not sell data, we do not serve advertising, and we do not use the data for anything beyond operating the panel for its users.
Where data lives
All data is stored on servers we operate in the European Union (Hetzner, Germany/Finland). Data is shared only with the social media platforms listed above, through their official APIs, as necessary to publish content and retrieve statistics.
How we protect your data
Security procedures are in place to protect the confidentiality of the data described above, including the data we obtain from Google APIs:
- Encryption in transit. The panel is served over HTTPS only, and every call we make to a platform API is made over TLS.
- Encrypted credentials at rest. OAuth access and refresh tokens are sealed with AES-256-GCM under a key held outside the database, and reach storage only in that sealed form. They are unsealed in memory for the duration of an API call, and are never written to logs, error messages, or exported data.
- Access control. The panel has no public sign-up. Accounts are created only by an administrator, every page and API route requires an authenticated session, and actions that change a connection or delete content are recorded in an audit log.
- Protected media. Uploaded images and videos are served through signed links that expire, so a file cannot be reached by guessing its address.
- Isolated infrastructure. The database is reachable only from the application itself, and not from the public internet. Uploaded files are held in a private bucket that only the application holds credentials for, and are never served to anyone directly from storage.
- Limited human access. Only the small team that operates the service can reach the servers, and they access user data only where it is necessary to operate, maintain, or secure the service, or where we are required to do so by law.
YouTube API Services
SocialTool uses YouTube API Services to upload videos to and retrieve analytics for the YouTube channels its users connect. By using this tool with YouTube, you agree to the YouTube Terms of Service. Google's handling of data is described in the Google Privacy Policy. Stored YouTube authorization can be revoked at any time via Google security settings or by disconnecting the channel inside SocialTool, which deletes the stored tokens.
SocialTool's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Information we receive from Google APIs is used only to provide the publishing, engagement, and reporting features described in this policy, to the team that connected the channel. We do not use it for advertising, we do not sell it or transfer it to data brokers, information resellers, or credit-assessment services, and we do not use it to develop, improve, or train generalized artificial-intelligence or machine-learning models.
Retention and deletion
OAuth tokens are deleted immediately when a social account is disconnected or when the platform notifies us of deauthorization. Inbox content (comment and message text fetched for the engagement inbox) is deleted with its connection, and when a platform reports a data-deletion request for that account. Published content and engagement metrics are retained while the tool is in use for reporting purposes. Panel user accounts are deleted when a team member leaves or when a team stops using the tool. To request deletion of any data, contact us via the contact form at adria.gg/contact.
Cookies
The panel uses session cookies strictly for signing in its users. There are no tracking or advertising cookies.
Contact
EsportAdria, via the contact form at adria.gg/contact. We answer data requests within 30 days.