MagpieFeed

Privacy policy

MagpieFeed reads the product feed you give it and turns items into finished social posts. This page describes the data that involves, in the same detail the software actually works in. If something here is vague, assume the narrow reading and ask us.

1Who we are

MagpieFeed (magpiefeed.com) is operated by Toni Ilić, a freelance developer based in Rijeka, Croatia. For anything in this policy — access, deletion, questions, complaints — write to [email protected]. A person reads that address.

For the data you put into MagpieFeed, we are the data processor and you are the controller: it is your feed and your customers' shop. For your own account data (your email, your login), we are the controller.

2What we collect

Your account

  • Your email address, and a hashed password if you signed up with one.
  • Your plan, your timezone, when your account was created, when your trial window ends, and when you finished onboarding.
  • If you used the Google button: Google's permanent account identifier for you (the sub claim), your verified email address, and the date you linked it. We ask Google for three scopes only — openid, email, profile. We do not store Google's access token, and we never ask for a refresh token (the request uses access_type=online), so MagpieFeed cannot act on your Google account — the sign-in proves who you are and nothing else.

Your brand settings

  • Brand name, website, tone of voice, notes, colour palette, font choice, default hashtags, your affiliate-disclosure text, and any logo you upload.

Your feeds, and what is in them

  • The feed URL, how often it should be polled, your field mapping, and any authentication header you give us so the poller can read a private feed.
  • A record of each poll: HTTP status, bytes read, how long it took, how many items were seen, created, updated or removed, and the error text when a poll fails.
  • For every item in the feed: its id, title, description, price and sale price, currency, image URL, product URL, availability, brand, category, GTIN — and the raw source record as we received it, stored as JSON. If your feed carries a field we do not map, it is still in that raw copy.
  • The changes we derive: new item, price up, price down, back in stock, out of stock, removed, with the old and new price.

Do not put personal data in your product feed. MagpieFeed stores the whole raw record of every item. It is built for products — titles, prices, images, links — and a feed that carries customer names, addresses, order details or anything similar will be stored verbatim and is not something this service is designed to handle.

The posts we generate

  • The caption, the rendered image or clip, the link, the schedule, the status, and which template and rule produced it.
  • A delivery log for every publishing attempt: the endpoint called, the HTTP status, how long it took, the error code and message, and the request and response bodies. Those bodies are scrubbed before they are written — any field whose name looks like a credential is replaced with [redacted], so access tokens do not land in the log.

Channels you connect

  • The platform, the page/account id and name, the avatar URL, the granted scopes, the OAuth access token and refresh token, and when the token expires.
  • If you bring your own app credentials (BYOC), the client id and client secret you supply.
  • Tokens and BYOC secrets are encrypted at rest (Fernet/AES) with a key held in the server's configuration, not in the database. A database dump on its own does not yield a working token.

API keys

  • We never store an API key. We keep a SHA-256 digest of it plus a short non-secret prefix for lookup and display, so a key cannot be recovered from our database — if you lose one, you rotate it. We also record when a key was last used, from which IP address, and how many requests it has made.

Technical data

  • A session cookie when you are signed in, and a CSRF cookie. Both are strictly necessary to run a logged-in website: the session cookie is HttpOnly, SameSite=Lax, and lasts 14 days.
  • Server logs, which include IP addresses, requested URLs and error traces.

We run no third-party analytics, no advertising trackers and no third-party scripts or fonts on our public pages. There is no cookie banner because there is nothing to consent to beyond the two cookies above.

To see whether the sign-up path works, our own server keeps aggregate daily counts of a few steps (for example "landing page viewed" or "account created"): one number per step per day, set without cookies or scripts, and stored with no IP address, user id, browser details or any other identifier.

3Why, and the lawful basis

WhatWhyLawful basis (GDPR Art. 6)
Account, brand, feeds, items, posts, channelsTo provide the service you signed up forPerformance of a contract, 6(1)(b)
Delivery logs, poll history, channel healthSo you can see why a post failed, and so we can keep it workingContract, 6(1)(b); legitimate interests, 6(1)(f)
Server logs, IP addresses, rate limitsSecurity, abuse prevention, debuggingLegitimate interests, 6(1)(f)
Google sign-inTo let you sign in without another passwordContract, 6(1)(b) — you choose whether to use it
Email about your account (a broken feed, a dead token)To tell you the service stopped doing its jobContract, 6(1)(b)

We do not profile you, we do not make automated decisions about you, and we do not sell or rent data to anyone.

4Who we share it with

Only the following, and only for the reasons given.

WhoWhat they getWhy
Hetzner Online GmbHEverything — they host the server the whole application runs on, in FinlandHosting
CloudflareTraffic to magpiefeed.com passes through their network; they also route our emailDNS, proxy, email routing
GoogleOnly if you use the Google button: the sign-in exchange itselfSign-in

That is the complete list of our sub-processors. We do not use a third-party analytics, error-tracking, email-marketing, CRM or support vendor.

Platforms you connect yourself

When you connect a channel and approve a post, we send that post — the caption, the image or clip, and the link — to the platform you chose, using the token you granted. Today that can be Facebook, Instagram, X, Telegram or Discord. What happens to it there is governed by that platform's own terms and privacy policy, not ours. You decide which platforms are involved by deciding which ones to connect.

Your own webhook, exports and RSS

If you configure a webhook, we POST the post's id, brand name, caption, media URL, link, schedule and platform hint to the endpoint you supply, signed with HMAC-SHA256. If you use the ZIP pack, CSV, calendar or RSS exports, that data goes wherever you take the file. Those destinations are your choice and your responsibility.

Caption generation

Captions can be written either by a deterministic template that runs entirely on our own server, or by an external language model. Right now no language-model provider is configured, so nothing is sent anywhere for caption generation — every caption is produced on our server from your item and brand settings.

If we do enable a provider, what would be sent is the item's own fields (title, trimmed description, prices, availability, link) and your brand voice settings (name, tone, language, notes, hashtags). Never your password, your channel tokens, your API keys or your feed's authentication header. We will name the provider on this page and update the sub-processor table above before any customer data is sent to it.

5Where it is stored

The application, the database and the rendered media sit on a server in Finland, rented from Hetzner — inside the EU/EEA. Nothing is copied to another region by us.

Two of the parties above are US-headquartered. Cloudflare handles traffic on a global network, and Google processes the sign-in itself; either may involve processing outside the EEA under the transfer safeguards in their own data-processing terms. If you connect a social platform, the post you asked us to publish goes to that platform's own infrastructure, which is generally outside the EEA.

6How long we keep it

  • Rendered images and clips: 30 days after a post is finished — published, published manually, or skipped. A nightly job deletes the file and blanks the reference. Posts that are not finished keep their media, so a Studio Mode post waiting for you to export it is never swept out from under you.
  • Feed items, change events, posts, delivery logs and poll history: for as long as your account exists. There is no automatic purge of these, and we would rather say so than imply one. Deleting a feed deletes its items, events and poll history with it; deleting a brand deletes its feeds, channels and posts with it.
  • Your session cookie: 14 days, or until you sign out.
  • Your account and everything attached to it: until you ask us to delete it (see below).

7How it is protected

  • Everything runs over HTTPS with a valid certificate.
  • Passwords are hashed with Django's password hasher. We cannot read yours.
  • Channel tokens, BYOC client secrets and private-feed authentication headers are encrypted at rest with Fernet.
  • API keys exist only as SHA-256 digests.
  • Credential-looking fields are redacted out of delivery logs before they are stored.
  • Each account only ever sees its own brands, feeds and posts; that scoping is enforced in the queries themselves and covered by tests.

If you give a private feed an authentication header so we can read it, that header is encrypted at rest like every other credential we hold. Even so, prefer a read-only or feed-specific token there rather than a password you use for anything else — that is good practice regardless of what we do.

We are a small operation, not a certified one. This page claims no ISO or SOC audit, because there has not been one.

8Your rights

If you are in the EU/EEA, the GDPR gives you the right to:

  • Access — get a copy of what we hold about you.
  • Rectification — have wrong data corrected.
  • Erasure — have it deleted.
  • Restriction — have us pause processing while a dispute is sorted out.
  • Portability — get it in a machine-readable form. Your posts are already exportable as CSV, ZIP, RSS and calendar files from inside the app.
  • Objection — object to processing we base on legitimate interests.

Email [email protected] and we will answer within 30 days. There is no charge, and we will not ask you to explain why.

If you are unhappy with how we handled it, you can complain to the Croatian data protection authority, AZOP (Agencija za zaštitu osobnih podataka, Zagreb — azop.hr), or to the supervisory authority where you live.

9Deleting your data

Email [email protected] from the address on the account and say you want it deleted. We will confirm, delete it, and tell you when it is done.

Deleting your account removes your user record and everything hanging off it: your brands and their settings and logos, your feeds and their stored authentication headers, every item and change event ingested from them, your automations, your generated posts and their delivery logs, your rendered media, your API keys, and your connected channels — including the encrypted access and refresh tokens stored on them. Removing a single channel deletes that channel's stored tokens along with it, because the tokens live on the channel record itself.

Two things to be straight about:

  • There is no self-serve delete button yet, and no self-serve "disconnect channel" button either. Both are done by us, by hand, on request to the address above. When the buttons ship, this section will change.
  • You do not need us in order to cut off access. You can revoke MagpieFeed's permission yourself, immediately, in the platform's own settings — Facebook and Instagram under Business Integrations, X under connected apps, Google under third-party access. That invalidates the token no matter what we still hold, and it takes effect instantly.

10Changes to this policy

If we change this page we update the date at the top. If a change materially affects what we do with your data — a new sub-processor, a language model going live, a new category of data — we will email account holders rather than quietly editing the page.

Questions

[email protected] — MagpieFeed, operated by Toni Ilić, Rijeka, Croatia. See also our terms of service.