Privacy Policy
Last updated August 6, 2026
Rabuta is private content-production software. It is not a public service and not open for general signup: access is limited to an explicit list of approved accounts. This policy describes what the application stores and what it does with data from connected social accounts.
What is collected
- Account identity. When you sign in with Google, Rabuta receives your email address and basic profile information, and uses them only to confirm you are on the approved list and to attribute your activity.
- Content you create. Drafts, scripts, notes, uploaded media, schedules and publishing history.
- Material you choose to collect. Public posts, articles and videos you save for research, along with their public engagement counts.
- Connected account tokens. Access and refresh tokens for the social accounts you link, so the application can publish at your direction.
How connected accounts are used
Data obtained from a connected platform is used for one purpose: to publish, schedule and measure content that you have created and approved in Rabuta, and to display replies to it. Platform data is never sold, never used for advertising, never used to build profiles of other people, and never shared with anyone outside the operator of this installation. Nothing is posted without an explicit action or a schedule you configured.
How credentials are stored
Access tokens are held in server-side environment variables, not in the application database, and are never returned to the browser or exposed through the API. The database stores only the name of the variable holding a credential, along with non-secret identifiers such as a page ID. Traffic is encrypted in transit and data is encrypted at rest by the hosting providers.
Service providers
Rabuta runs on Vercel (application hosting), Neon (database), and Anthropic (language model processing for drafting and analysis). Content sent for drafting is processed to return a result and is not used to train models. Media may be stored in Vercel Blob storage. No other party receives your data.
Deleting your data
To disconnect a social account, remove it in Settings inside the application. This deletes the stored reference immediately, and you should also revoke Rabuta from that platform's own connected-apps screen.
To delete everything, email the address below with the subject "Delete my data". All workspace content, saved research, tokens and publishing history for your account will be removed within 30 days, and you will get written confirmation when it is done. Because this is a private installation, there is no self-service export screen; the request is handled directly.
YouTube API Services
Rabuta uses YouTube API Services to upload videos and read the performance of videos you published through it. By connecting a YouTube channel you are also agreeing to the YouTube Terms of Service, and the Google Privacy Policydescribes how Google handles your data. You can revoke Rabuta's access to your Google account at any time at myaccount.google.com/permissions. Data retrieved from the YouTube API is stored only to display your own results inside the application and is refreshed or discarded rather than kept indefinitely.
Retention
Content and research are kept until you delete them or ask for the account to be removed. Tokens are kept until you disconnect the account or they are revoked at the platform. Audit records of publishing actions are retained so that a post can always be traced to the person who approved it.
Children
Rabuta is business software and is not directed to anyone under 18.
Changes
If this policy changes in a way that affects how connected-account data is used, the date at the top will change and the previous behaviour will not be applied retroactively.
Contact
Questions, or a deletion request: privacy@rabuta.com.