Privacy Policy
Last updated: August 31, 2026
Squeeezy is a native application for iPhone (iOS) and Mac (macOS) that lets you upload videos to Facebook, Instagram, LinkedIn, and YouTube. It is distributed on the App Store for iPhone and on the Mac App Store for Mac. Facebook, Instagram, LinkedIn, and YouTube work with the accounts you connect. We are committed to protecting your privacy. This Privacy Policy explains what information is processed, how it is used, and your rights — including those under the EU General Data Protection Regulation (GDPR).
1. Data Controller
The data controller for the purposes of GDPR is the individual developer operating under the name Squeeezy (bundle identifier me.squeeezy.app), reachable at [email protected]. Given the nature of the App — where personal data remains on your device and we do not operate a user database — the practical scope of controller responsibilities is minimal.
2. What Data Is Processed and Where It Lives
Squeeezy is designed to process the absolute minimum. Almost everything stays on your device:
- OAuth tokens — When you connect a social media account, the platform issues an access token (and, where applicable, a refresh token). These are stored exclusively in your device Keychain using
kSecAttrAccessibleWhenUnlockedThisDeviceOnly. They are never transmitted to our servers and never written to disk in plain text. - Video files and upload metadata — Videos and the titles, captions, descriptions, and other fields you enter are sent from your device to each platform's official API. For YouTube and LinkedIn, that transfer is direct from your device. For Instagram and Facebook, the App briefly stages your video on our relay server so Meta can fetch it (see Section 7a). Staged files are deleted automatically after publish — we do not retain your video content.
- Local upload history, drafts, and stats — Squeeezy keeps a local history of your uploads (date, platforms, outcome, post links), any drafts you save, and optional upload statistics in a SQLite database on your device. This data stays on your device by default.
- Optional anonymized stats sharing — If you turn on “Share stats anonymously,” the App periodically sends an aggregate usage summary (upload counts, platform mix, and feature rates such as caption or cover use), plus a random id so successive summaries can be linked for product trends. When you are signed into iCloud, that id may sync between your Apple devices so Mac and iPhone summaries can be grouped without collecting your email. It does not include titles, captions, filenames, post links, bookmarks, or your email. You can turn this off at any time.
- iCloud Key-Value sync (optional) — Platform visibility preferences and (when stats sharing is enabled) the random stats-share id may sync between your Apple devices signed into the same iCloud account via Apple's Key-Value store. No OAuth tokens or video content are synced.
- No account or advertising profile — We do not collect your name or email address for a Squeeezy account, and we do not sell personal data or use advertising SDKs. There is no Squeeezy user database of accounts. Connection IPs may appear in normal relay server logs when the App contacts our relay (including optional stats sharing).
- Website contact form — If you write via squeeezy.me/contact.html, we receive the name, email, optional company, and message you send so we can reply. We do not use this for marketing.
3. Legal Basis for Processing (GDPR Article 6)
Because all processing occurs locally on your device at your explicit direction, the applicable legal basis is:
- Article 6(1)(b) — Performance of a contract: Processing your tokens and metadata is necessary to deliver the upload service you have chosen to use.
- Article 6(1)(f) — Legitimate interest: Storing local upload history and draft data serves your legitimate interest in reviewing past uploads and resuming work-in-progress, with no impact on your privacy since the data stays on your device by default.
- Article 6(1)(a) — Consent: Optional anonymized stats sharing runs only when you enable it. Sending a message through the website contact form is also based on your request that we reply.
4. How We Use Your Information
The OAuth tokens stored on your device are used solely to authenticate API requests to the platforms on your behalf. Specifically:
- To upload videos to your connected social media accounts
- To refresh your authentication session automatically when a token expires
- To retrieve the minimum account identifiers needed to complete the upload (for example a LinkedIn member or organization URN, or a Facebook or Instagram account ID)
We do not use any data for advertising, profiling, or any purpose beyond providing the core upload functionality you request.
5. Third-Party Platforms
Squeeezy integrates with the following platforms. When you connect your accounts and upload content, you are subject to each platform's own privacy policy:
- Facebook / Meta — Meta Privacy Policy
- Instagram / Meta — Instagram Privacy Policy
- LinkedIn — LinkedIn Privacy Policy
- YouTube / Google — Google Privacy Policy
We request only the minimum permissions required to upload content on your behalf. You can revoke Squeeezy's access at any time either within each platform's own settings or through the Squeeezy Settings page.
6. Google / YouTube API Data Use
Squeeezy uses the YouTube Data API v3. YouTube sign-in uses OAuth with PKCE (localhost redirect on Mac; Apple's in-app browser on iPhone) — no client secret is stored in the app. Our use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements:
- We request the
youtube.uploadandyoutubescopes needed to publish on your behalf - YouTube user data is not stored on any server we operate
- YouTube user data is not shared with any third party
- YouTube data is used solely to perform uploads you explicitly initiate
7. Facebook and Instagram API Data Use
Squeeezy uses the Meta Graph API to post Reels to Instagram and videos to Facebook Pages. We confirm:
- We only request the permissions necessary for video upload and page management
- We do not store, share, or sell any Meta user data on external servers
- Meta user data is used solely for the purpose of uploading content you explicitly initiate
- You can disconnect your Facebook and Instagram accounts at any time in Squeeezy Settings
7a. Temporary Video Staging Relay (Instagram & Facebook)
Meta's APIs require a publicly reachable HTTPS URL to fetch your video. Because your file lives on your device, Squeeezy temporarily uploads it to our relay (upload.squeeezy.me), hosted on Cloudflare R2, solely to give Meta a fetch URL for the publish request you initiated.
- Purpose: Technical staging only — not storage, analytics, or training
- Duration: Minutes at most; the file is deleted from the relay after publish completes (or on failure cleanup, typically within 48 hours)
- Access: Bearer-authenticated uploads from the App; public read only for the short-lived URL Meta needs
- No profiling: We do not associate staged files with your identity on our servers — there is no Squeeezy account or user database
- Not used for YouTube or LinkedIn: Those platforms receive video data directly from your device
8. LinkedIn API Data Use
Squeeezy uses the LinkedIn Posts API and Videos API. We confirm:
- We only request the
w_member_social,openid, andprofilescopes - We do not store, share, or sell any LinkedIn user data on external servers
- LinkedIn user data (the identifier for the connected account, stored locally in Keychain) is used solely to identify that account for upload requests you explicitly initiate
- You can disconnect your LinkedIn account at any time in Squeeezy Settings
9. Disconnecting accounts and requesting deletion
Squeeezy does not create a Squeeezy user account. You control data as follows:
- Disconnect a platform — In Settings, open Facebook, Instagram, LinkedIn, or YouTube and choose Disconnect. That removes the tokens and cached account labels for that platform from your device Keychain. You can also revoke access in that platform’s own security or apps settings.
- Local history, drafts, and stats — Clear them in the App (History, Saved, Analytics) or uninstall Squeeezy. Uninstalling removes local databases and Keychain items for this app on that device.
- Optional anonymous stats — Turn off “Share stats anonymously” in Settings to stop further sends. To ask us to delete the anonymous share id and stored summaries on the relay, email [email protected] from a message that includes the device you used (we cannot look up your identity from the random id alone, so we will explain what we can delete).
- Relay-staged videos (Instagram and Facebook) — Staged files are deleted automatically after publish, or during failure cleanup (typically within 48 hours). To request confirmation that a staged file is gone, contact [email protected] with the approximate time of the upload. We do not keep a user-linked archive of those files.
We will respond to deletion and access requests at [email protected] within 30 days.
10. Apple App Store & Device Permissions
Squeeezy is distributed on the App Store for iPhone and on the Mac App Store for Mac. In line with Apple's requirements:
- Privacy manifests — The App includes Apple Privacy Manifest files declaring use of required-reason APIs (e.g. UserDefaults for local preferences). We do not use tracking or advertising SDKs.
- Photos (iPhone) — The iPhone app asks for Photo Library access only so you can pick a video or cover photo to upload.
- No cross-app tracking — Squeeezy does not track you across other companies' apps or websites.
11. Data Storage and Security
All authentication tokens are stored in your device Keychain using Apple's secure storage APIs with kSecAttrAccessibleWhenUnlockedThisDeviceOnly access control. This means:
- Tokens are only accessible when your device is unlocked
- Tokens cannot be transferred to or read from another device (except via a new OAuth sign-in)
- Tokens are never written to disk in plain text
- Tokens are never transmitted to our servers
Local history and draft data are stored in SQLite databases in the App’s private storage on your device, inaccessible to other apps.
12. International Data Transfers
When you use Squeeezy to upload content, your video and metadata are transferred from your device to the servers of the respective platforms (Meta, LinkedIn, Google). For Instagram and Facebook, video may pass briefly through our Cloudflare-hosted relay before Meta fetches it. These companies are headquartered in the United States and operate under their own privacy frameworks and EU data transfer mechanisms (such as Standard Contractual Clauses). We do not maintain a persistent store of your personal data on our servers.
13. Data Retention
- OAuth tokens — Retained locally until you disconnect the account in Settings, or uninstall the App.
- Upload history — Retained locally until you clear it within the App, or uninstall the App.
- Drafts — Retained locally until you delete them in the App, or uninstall the App.
- Relay-staged videos — Deleted after publish, or on failure cleanup (typically within 48 hours). See Section 9.
- Optional anonymous stats — Stored on the relay only while sharing is enabled; stop sending anytime in Settings. See Section 9 to request deletion.
We do not operate a Squeeezy user database. Short-lived relay files, optional stats summaries, and ordinary connection logs (such as IP addresses) are the only data that may exist off-device, as described above.
14. Your Rights Under GDPR
If you are located in the European Union or European Economic Area, you have the following rights under the GDPR. Most of the data Squeeezy processes lives on your device, which you can control directly. Off-device items (relay staging and optional stats) are covered in Section 9.
- Right of access (Art. 15) — You can view data Squeeezy holds about you in the App (history, drafts, connected-account labels). For relay or stats questions, contact us as in Section 9.
- Right to rectification (Art. 16) — You can edit or update your data directly within the App at any time.
- Right to erasure (Art. 17) — Disconnect accounts, clear history and drafts, and/or uninstall the App. For relay files or optional stats on our side, follow Section 9 or email [email protected].
- Right to restriction of processing (Art. 18) — You can stop all processing by closing or uninstalling the App.
- Right to data portability (Art. 20) — Your data is already on your device in standard formats (Keychain entries, SQLite databases). You can access it directly.
- Right to object (Art. 21) — You can object to processing based on legitimate interest by contacting us at [email protected].
- Right not to be subject to automated decision-making (Art. 22) — Squeeezy performs no automated decision-making or profiling.
- Right to lodge a complaint — You have the right to lodge a complaint with your national data protection authority (DPA). In the EU, you can find your local DPA at edpb.europa.eu.
To exercise any right or ask a question about your data, contact us at [email protected]. We will respond within 30 days.
15. Children's Privacy
Squeeezy is not directed at children under the age of 16 (or the applicable minimum age in your EU member state). We do not knowingly collect any personal information from children. If you believe a child has used the App and data may have been stored locally, please contact us and we will provide guidance on how to remove it.
16. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of material changes through the App. The latest version is always available at squeeezy.me/privacy.html. If changes are material in terms of GDPR, we will provide at least 30 days' notice before they take effect.
17. Contact
For any questions, requests, or concerns about this Privacy Policy or your data, please contact us at [email protected]. We aim to respond within 30 days.