OnceToAll ("the App") lets you write a post once and publish it to the social networks you connect. This policy explains what personal data we process, why, where it goes, and what rights you have. It is written to satisfy the EU General Data Protection Regulation (GDPR) and the Turkish Personal Data Protection Law No. 6698 (KVKK).
1. Who is responsible
The data controller is Semih Soyer, a sole proprietorship registered in Türkiye, Kartepe / Kocaeli, Türkiye (tax ID 7760651471). Privacy requests: privacy@oncetoall.com · Support: support@oncetoall.com
2. What we collect and why
| Data | Source | Purpose | Legal basis (GDPR / KVKK) |
|---|---|---|---|
| Account data: e-mail address, display name, sign-in identifier from Apple or Google, time zone, language | You / Apple / Google | Create and secure your account, send service e-mails (verification, password reset, delivery failures, token expiry warnings) | Contract (Art. 6(1)(b)) / KVKK Art. 5(2)(c) |
| Connected social accounts: network, username, display name, avatar, account ID, connection status and expiry | Social networks via our publishing partner | Publish on your behalf, show connection health, warn before a connection expires | Contract / KVKK Art. 5(2)(c) |
| OAuth authorization tokens for your social accounts | Social networks | Publish on your behalf. We do not store these tokens on our own servers; they are held by our publishing partner bundle.social (see §4) under a data processing agreement | Contract / KVKK Art. 5(2)(c) |
| Content: captions, images, videos, per-network settings, schedule times, drafts | You | Publish and schedule your posts, show your calendar and history | Contract |
| Delivery records: per-network status, error codes and messages, attempt log, permalinks | Our systems and the networks | Show you exactly what happened to each post, retry failures, notify you | Contract; legitimate interest in service reliability (Art. 6(1)(f)) |
| Subscription data: plan, purchase and renewal status, store transaction identifiers (never your card number) | Apple App Store / Google Play, via RevenueCat once paid plans launch | Manage your subscription and quota | Contract; legal obligation for invoices |
| Device and diagnostic data: device model, OS version, app version, crash reports, error traces | Your device | Fix crashes and errors | Legitimate interest (Art. 6(1)(f)) / KVKK Art. 5(2)(f) |
| Usage analytics: screens viewed, features used, coarse events (e.g. "post scheduled") tied to a random identifier | Your device | Understand which features are used and improve the App | Legitimate interest; you can turn this off in the App under Notifications → Share usage analytics |
| Push notification token | Your device | Send delivery-failure alerts and reminders you enabled | Contract / consent for optional notifications |
| Support messages | You | Answer your requests | Contract; legitimate interest |
We do not sell personal data, do not use your content to train AI models, and do not show third-party advertising. We do not track you across other apps or websites.
3. Where the data lives
- Application database and authentication: Supabase, hosted in the EU (Ireland, eu-west-1).
- Media files (images, videos): Cloudflare R2, stored under EU jurisdiction.
- Publishing and social account connections: bundle.social (Bundle sp. z o.o., Warsaw, Poland), production infrastructure in Frankfurt, Germany; media may be routed through Cloudflare's global network for delivery.
- Error monitoring: Sentry, EU region (Germany).
- Product analytics: PostHog, EU cloud (Frankfurt).
- Transactional e-mail: Resend (United States).
- Subscription management: Apple / Google; RevenueCat (United States) once paid plans launch.
4. Who we share data with (processors)
We use the following service providers, each bound by a data processing agreement and acting only on our instructions:
| Provider | Role | Location |
|---|---|---|
| Bundle sp. z o.o. (bundle.social) | Publishing API, social account connections, holds OAuth tokens | Poland / EEA (Frankfurt) |
| Supabase Inc. | Database, authentication, file processing | EU (Ireland) |
| Cloudflare Inc. | Media storage (R2), DNS, e-mail routing | EU jurisdiction storage; global network |
| Functional Software Inc. (Sentry) | Crash and error monitoring | EU (Germany) |
| PostHog Inc. | Product analytics | EU (Frankfurt) |
| Apple Inc. / Google LLC | App distribution, payments, sign-in | Global |
| RevenueCat Inc. | Subscription status, once paid plans launch | US |
| Expo (650 Industries, Inc.) | Push notification delivery | US |
| Resend Inc. | Transactional e-mail | US |
The social networks you connect (Instagram, Facebook, Threads, LinkedIn, Pinterest, Bluesky, TikTok, YouTube, X) receive the content you ask us to publish and act as independent controllers under their own privacy policies. OnceToAll is not affiliated with or endorsed by any of them.
5. International transfers
Your data is processed mainly in the European Economic Area. Because the controller is in Türkiye, transfers to processors abroad rely on each processor's data processing agreement and, where required, on standard contractual clauses (the EU Standard Contractual Clauses or the Standard Contract published by the Turkish Personal Data Protection Authority) or an adequacy decision.
6. How long we keep data
| Data | Retention |
|---|---|
| Account and connected accounts | Until you delete your account (+ 7-day undo window); after that, removed from live systems right away and from backups within 30 days |
| Posts and delivery records | Until you delete them or your account |
| Media files | Until you delete the post or your account; media of cancelled or deleted posts is purged within 30 days |
| Crash and diagnostic data | 90 days |
| Usage analytics | 12 months |
| Support e-mails | 24 months |
| Invoicing records | As required by Turkish tax law (10 years) |
7. Your rights
Under GDPR and KVKK Article 11 you can ask us to: tell you whether we process your data and give you a copy; correct it; delete it; restrict or object to processing; receive it in a portable format; and withdraw consent where processing is based on consent. Write to privacy@oncetoall.com; we answer within 30 days. You may also complain to the Turkish Personal Data Protection Board (KVKK Kurulu) or to your EU supervisory authority.
You can delete your account inside the App (Profile → Settings → Delete account) or from oncetoall.com/delete-account.
8. Security
Data is encrypted in transit (TLS) and at rest. Access to production systems is limited to the controller. Social network tokens are never stored on your device or on our servers. We will notify you without undue delay of a personal data breach that is likely to affect you.
9. Children
The App is not intended for anyone under 13, and the social networks you connect require you to meet their own age rules. We do not knowingly collect data from children.
10. Changes
We will announce material changes in the App and update the date at the top. Continued use after the effective date means you accept the new policy.