OnceToAll

OnceToAll Privacy Policy

Version 1.0 · 8 September 2026

OnceToAll ("the App") lets you write a post once and publish it to the social networks you connect. This policy explains what personal data we process, why, where it goes, and what rights you have. It is written to satisfy the EU General Data Protection Regulation (GDPR) and the Turkish Personal Data Protection Law No. 6698 (KVKK).

1. Who is responsible

The data controller is Semih Soyer, a sole proprietorship registered in Türkiye, Kartepe / Kocaeli, Türkiye (tax ID 7760651471). Privacy requests: privacy@oncetoall.com · Support: support@oncetoall.com

2. What we collect and why

DataSourcePurposeLegal basis (GDPR / KVKK)
Account data: e-mail address, display name, sign-in identifier from Apple or Google, time zone, languageYou / Apple / GoogleCreate and secure your account, send service e-mails (verification, password reset, delivery failures, token expiry warnings)Contract (Art. 6(1)(b)) / KVKK Art. 5(2)(c)
Connected social accounts: network, username, display name, avatar, account ID, connection status and expirySocial networks via our publishing partnerPublish on your behalf, show connection health, warn before a connection expiresContract / KVKK Art. 5(2)(c)
OAuth authorization tokens for your social accountsSocial networksPublish on your behalf. We do not store these tokens on our own servers; they are held by our publishing partner bundle.social (see §4) under a data processing agreementContract / KVKK Art. 5(2)(c)
Content: captions, images, videos, per-network settings, schedule times, draftsYouPublish and schedule your posts, show your calendar and historyContract
Delivery records: per-network status, error codes and messages, attempt log, permalinksOur systems and the networksShow you exactly what happened to each post, retry failures, notify youContract; legitimate interest in service reliability (Art. 6(1)(f))
Subscription data: plan, purchase and renewal status, store transaction identifiers (never your card number)Apple App Store / Google Play, via RevenueCat once paid plans launchManage your subscription and quotaContract; legal obligation for invoices
Device and diagnostic data: device model, OS version, app version, crash reports, error tracesYour deviceFix crashes and errorsLegitimate interest (Art. 6(1)(f)) / KVKK Art. 5(2)(f)
Usage analytics: screens viewed, features used, coarse events (e.g. "post scheduled") tied to a random identifierYour deviceUnderstand which features are used and improve the AppLegitimate interest; you can turn this off in the App under Notifications → Share usage analytics
Push notification tokenYour deviceSend delivery-failure alerts and reminders you enabledContract / consent for optional notifications
Support messagesYouAnswer your requestsContract; legitimate interest

We do not sell personal data, do not use your content to train AI models, and do not show third-party advertising. We do not track you across other apps or websites.

3. Where the data lives

  • Application database and authentication: Supabase, hosted in the EU (Ireland, eu-west-1).
  • Media files (images, videos): Cloudflare R2, stored under EU jurisdiction.
  • Publishing and social account connections: bundle.social (Bundle sp. z o.o., Warsaw, Poland), production infrastructure in Frankfurt, Germany; media may be routed through Cloudflare's global network for delivery.
  • Error monitoring: Sentry, EU region (Germany).
  • Product analytics: PostHog, EU cloud (Frankfurt).
  • Transactional e-mail: Resend (United States).
  • Subscription management: Apple / Google; RevenueCat (United States) once paid plans launch.

4. Who we share data with (processors)

We use the following service providers, each bound by a data processing agreement and acting only on our instructions:

ProviderRoleLocation
Bundle sp. z o.o. (bundle.social)Publishing API, social account connections, holds OAuth tokensPoland / EEA (Frankfurt)
Supabase Inc.Database, authentication, file processingEU (Ireland)
Cloudflare Inc.Media storage (R2), DNS, e-mail routingEU jurisdiction storage; global network
Functional Software Inc. (Sentry)Crash and error monitoringEU (Germany)
PostHog Inc.Product analyticsEU (Frankfurt)
Apple Inc. / Google LLCApp distribution, payments, sign-inGlobal
RevenueCat Inc.Subscription status, once paid plans launchUS
Expo (650 Industries, Inc.)Push notification deliveryUS
Resend Inc.Transactional e-mailUS

The social networks you connect (Instagram, Facebook, Threads, LinkedIn, Pinterest, Bluesky, TikTok, YouTube, X) receive the content you ask us to publish and act as independent controllers under their own privacy policies. OnceToAll is not affiliated with or endorsed by any of them.

5. International transfers

Your data is processed mainly in the European Economic Area. Because the controller is in Türkiye, transfers to processors abroad rely on each processor's data processing agreement and, where required, on standard contractual clauses (the EU Standard Contractual Clauses or the Standard Contract published by the Turkish Personal Data Protection Authority) or an adequacy decision.

6. How long we keep data

DataRetention
Account and connected accountsUntil you delete your account (+ 7-day undo window); after that, removed from live systems right away and from backups within 30 days
Posts and delivery recordsUntil you delete them or your account
Media filesUntil you delete the post or your account; media of cancelled or deleted posts is purged within 30 days
Crash and diagnostic data90 days
Usage analytics12 months
Support e-mails24 months
Invoicing recordsAs required by Turkish tax law (10 years)

7. Your rights

Under GDPR and KVKK Article 11 you can ask us to: tell you whether we process your data and give you a copy; correct it; delete it; restrict or object to processing; receive it in a portable format; and withdraw consent where processing is based on consent. Write to privacy@oncetoall.com; we answer within 30 days. You may also complain to the Turkish Personal Data Protection Board (KVKK Kurulu) or to your EU supervisory authority.

You can delete your account inside the App (Profile → Settings → Delete account) or from oncetoall.com/delete-account.

8. Security

Data is encrypted in transit (TLS) and at rest. Access to production systems is limited to the controller. Social network tokens are never stored on your device or on our servers. We will notify you without undue delay of a personal data breach that is likely to affect you.

9. Children

The App is not intended for anyone under 13, and the social networks you connect require you to meet their own age rules. We do not knowingly collect data from children.

10. Changes

We will announce material changes in the App and update the date at the top. Continued use after the effective date means you accept the new policy.