Privacy Policy
egged is a social media scheduling and automation tool operated by JD Lion Ecom LLC, 21750 Hardy Oak Blvd Ste 104 PMB 591784, San Antonio, TX 78258, United States — the company responsible for the data described below. Each user connects the social media accounts they own or operate and uses egged to schedule posts and automate replies on those accounts. This policy explains what data egged processes and why. Questions about this policy, or any request concerning your data, go to scott.bryan.chen@gmail.com.
What egged accesses, collects, stores and uses
The list below is everything egged holds, including API Data it receives from the platforms you connect. egged does not sell any of it, does not use it for advertising or to build advertising profiles, and does not share it with third parties other than the platform APIs themselves, as technically required to carry out an action you asked for.
Your egged account
Your email address, a cryptographically hashed password (egged never stores your password in a readable form), the workspaces you belong to and your role in each, and the invitation code you signed up with. Used to sign you in and to decide what you are allowed to do.
Accounts you connect
For each connected account: the platform, the account's identifier on that platform, its username or page/channel title, an access or refresh token, and the token's expiry. egged never receives or stores your password for any connected platform. Used only to act on the account you connected, as you direct.
API Data egged receives
YouTube: your channel's id and title, and the ids and upload status of videos egged itself uploaded — nothing else (see the YouTube API Services section below). Instagram and Facebook: for the comment and DM automations you enable, the platform forwards the interaction — the person's platform user id, username and display name, whether they follow the account, and the text of the comment or message — so egged can send the reply you configured. Threads and X: the account id and username, plus the id of each post egged publishes.
Content you schedule
The media files you upload, captions and titles, the visibility you choose, the scheduled time, the publication status, any error the platform returned, and the id the platform assigns to the published post.
People who interact with your connected accounts
Where you enable messaging automations, egged keeps a record of the conversation so the automation can run and a human can take over: the person's platform id, username and display name, the messages exchanged, any tags you apply, an email address if the person volunteers one to a lead-capture step you configured, and — if you use egged's link tracking — how many times a tracked link was opened and when. Automated conversations are disclosed as automated at their start.
Storage on your device
egged sets no cookies, and runs no advertising, tracking or third-party analytics scripts. It stores exactly two values in your browser's local storage, on the device you sign in from:
egged-admin-token— your signed session token, so you stay signed in between visits. It is removed when you log out.egged-theme— whether you chose light or dark mode.
Neither is shared with anyone, and neither is used to track you across other websites. You can remove both at any time by logging out, or by clearing site data in your browser. egged does not place, access or recognise any other identifier on your device.
Google user data
This section states plainly, for Google's OAuth verification, exactly how egged handles Google user data — the data egged obtains from Google APIs when you connect a Google (YouTube) account.
- What Google user data egged accesses. Only two things: your YouTube channel's id and title, and the ids and upload status of videos egged itself uploaded on your behalf. egged does not access your Google profile, your email, your contacts, your other videos, your subscribers, your comments, or any other Google user data.
- How egged uses Google user data. The channel id and title are used once, at connect time, to show you the channel name so you can confirm you linked the right one. The upload scope is used only to publish the videos you schedule to your own channel. Google user data is never used for advertising, never used to build a profile of you, and never processed for any purpose other than the feature you asked for.
- With whom egged shares Google user data. No one. egged does not sell, rent, trade, transfer, or otherwise disclose your Google user data to any third party. The only transfer that occurs is back to Google's own APIs, as technically required to carry out the action you requested (for example, uploading your video). egged does not use it with AI/ML models, and does not share it with data brokers or advertisers.
- How egged protects Google user data. It is encrypted in transit (HTTPS/TLS) and the credential that grants access to it is encrypted at rest with AES-256-GCM, decrypted only in memory at the moment of a call you requested. Access is restricted to the workspace that connected the account. It is deleted immediately when you disconnect the channel or delete the workspace, and otherwise refreshed from the API or deleted within 30 days.
egged's use of Google user data adheres to the Google API Services User Data Policy, including the Limited Use requirements.
YouTube API Services
egged uses YouTube API Services. With the scopes you grant, egged:
youtube.readonly — reads your connected channel's id and title (shown so you can confirm
the correct channel) and the status of videos egged itself uploaded; and youtube.upload
— publishes the videos you schedule to your own channel. egged reads only your channel's identity
and the status of videos egged uploaded, and writes only the videos you schedule.
egged's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell this data, do not use it for advertising, and do not share it with third parties except the platform APIs themselves as technically required to perform the action you requested. See also the Google Privacy Policy and the YouTube Terms of Service.
You can revoke egged's access to your YouTube data at any time through your Google security settings, or by disconnecting the channel in egged (Accounts → Disconnect). The only YouTube data egged retains is your channel's id and title, plus the ids of videos egged itself uploaded; egged refreshes this from the API or deletes it within 30 days, and deletes it immediately when you disconnect the channel.
Authorization tokens
When you connect an account, the platform issues egged an access or refresh token through that platform's official sign-in. How egged handles it:
- Encrypted at rest. Tokens are encrypted with AES-256-GCM before they are written to the database. They are decrypted only in memory, at the moment egged makes a call you asked for.
- Used only within your consent. A token is used solely for the actions covered by the permissions you granted — publishing the content you schedule, and running the automations you configured on the account you connected. It is never used to access anything else, and never on behalf of anyone but you.
- Kept only while the connection is active. egged retains a token only for as long as you keep that account connected. Disconnecting the account (Accounts → Disconnect) deletes the stored token immediately, as does deleting the workspace.
- Dropped when it stops being valid. If you revoke egged's access at the platform, the token stops working; egged ceases using it and removes it. Tokens are not retained for inactive or departed users.
Storage, retention and deletion
Data is stored in a private database, and access is restricted to the workspace that connected the account. You can disconnect any account at any time, which deletes its stored token and conversation data. You can request deletion of all data we hold about you — see data deletion instructions or email scott.bryan.chen@gmail.com; requests are honored within 30 days.
Requests from public authorities
If a public authority requests personal data, we review the request's legality, challenge requests we consider unlawful or overbroad, disclose only the minimum necessary, and document each request and our response.
Your rights
If you are in the EU/EEA (GDPR) or a comparable jurisdiction, you have the right to access, correct and erase your personal data and to object to its processing. Contact scott.bryan.chen@gmail.com. The data controller is the operator of egged, reachable at the same address.
Last updated: August 2026