Skip to content
UnReposter app iconUnReposter

Privacy Policy

Last Updated: July 25, 2026

This Privacy Policy governs UnReposter ("UnReposter", "the Product") — both the mobile application for iOS and Android and the UnReposter browser extension — operated by STOCKIMG AI YAZILIM TEKNOLOJILERI ANONIM SIRKETI ("the Company", "we", "us"), registered in Türkiye.

Where a rule applies to only one of the two, it says so. Everything else applies to both.

1. Local-First Operation

UnReposter has no registration, no login form of its own and no cloud account system. Your session tokens, configuration settings, saved backups and activity logs are processed and stored strictly locally on your device. We do not see, store, or log your TikTok or Instagram credentials, videos, or repost history.

  • We never ask for your password. Both the app and the extension work through the session you are already signed into on TikTok or Instagram.
  • Browser extension: it reads the session cookie of the site you are on (tiktok.com / instagram.com) only inside your own browser, in order to call that site's own endpoints on your behalf. The cookie is never sent to us or to anyone else.
  • Saved backups: covers and links archived by the premium "Save & Delete" feature are written to your browser's or device's local storage only. They never reach our servers.
  • Uninstalling the app, or removing the extension, deletes this local data with it.

2. Data We Collect

To keep the Product stable and to understand which features are actually used, we collect minimal, non-personally identifiable diagnostic data. The mobile app and the extension use separate Firebase projects and analytics properties, so their data is never mixed:

  • Firebase Crashlytics (mobile app): technical logs related to software crashes (e.g., device model, OS version) to fix bugs.
  • Google Analytics (app and extension): aggregated, anonymous usage statistics (e.g., installs, session duration, which buttons were pressed, whether a fetch or delete succeeded or failed) tied to a randomly generated identifier. The extension sends these events directly to Google Analytics via the Measurement Protocol; it bundles no analytics SDK and executes no remote code.
  • Remote configuration (app and extension): the Product downloads a small configuration document (feature flags, free-tier limits, endpoint fixes) so it can be repaired without waiting for a store review. Fetching it exposes only what any web request exposes — your IP address and browser/app version — and it sends us nothing about you.
  • RevenueCat: tracks purchase status, active subscriptions and transaction history against a random identifier generated on your device. It does not store your card details.

We do not sell your data, and we do not use it for advertising, ad targeting, credit scoring or lending. Analytics data is aggregated and cannot be used by us to identify you.

3. Payments (Paddle & RevenueCat)

How your payment data is handled depends on where you bought Premium.

  • Apple App Store / Google Play (mobile app): Apple or Google is the seller of record. They process the payment and share only anonymised purchase state with us through RevenueCat. We never see your card or billing details.
  • Browser extension (web checkout): billing runs on RevenueCat + Paddle. Paddle.com Market Ltd acts as the merchant of record and reseller for that purchase — meaning Paddle, not the Company, is your contractual counterparty for the payment itself, and Paddle handles payment processing, invoicing, fraud checks and sales tax / VAT.
  • What Paddle collects: the email address, name, billing address, country and payment method you enter into Paddle's own checkout form, which is hosted by Paddle. That form is never part of the extension, and card data never passes through UnReposter. Paddle processes this data as an independent controller under its own Paddle Buyer Terms and Privacy Policy (paddle.com), and uses your email to send receipts, renewal notices and other transactional messages.
  • What we can see: order records in Paddle's seller dashboard — transaction ID, date, amount, currency, billing country, subscription status and the email used at checkout — which we use for accounting, tax obligations, refunds and support. We can never see full card numbers.
  • How a purchase is linked to you: the extension generates a random identifier (for example `unrp_…`) in your browser and appends it to the checkout link so RevenueCat knows which install to unlock. It contains no name, email or account data. The same identifier, shown to you as a recovery code, is what moves your Premium to another computer — so treat it as private and share it with nobody.

Purchase and billing records are retained for as long as tax, accounting and consumer-law obligations require (typically 10 years under Turkish law), even after a refund or cancellation.

4. Bug Reports & Support Email

The in-product "Report a Bug" form is anonymous by default: it sends your description together with technical context (operating system, product version, language) to our Firebase project. The extension writes to its own project, separate from the mobile app's.

  • Optional fields: if you type an email address or a username into the form so we can reply, that information is personal data and is stored with the report. Leaving them blank is fine — the report still reaches us.
  • Email: when you write to support@stockimg.ai, we process your address and the contents of your message solely to answer you and to resolve the issue.

5. Browser Extension Permissions

Chrome requires an extension to declare what it can touch. UnReposter asks for the narrowest set that makes the feature work, and each one has a single purpose:

  • Access to tiktok.com and instagram.com: to list your reposts and delete them via those sites' own endpoints, using the session you are already signed into.
  • Cookies: to confirm you are logged in and to authorise those requests inside your browser. The extension holds no permission for any other website.
  • Storage: to keep your settings, daily quota counters, saved backups and the random purchase identifier on your machine.
  • Scripting / tabs / side panel / alarms: to open the panel, run the deletion routine in the tab you are on, and pace requests so the platform does not rate-limit your account.
  • Network access is limited to RevenueCat (entitlement checks), Google Analytics (anonymous usage events), Firebase (bug reports and remote configuration) and the platforms themselves.

In line with the Chrome Web Store User Data Policy, including the Limited Use requirements: user data obtained through the extension is used only to provide and improve the features described here, is never sold or transferred to third parties except as set out in this policy, is never used for advertising or creditworthiness purposes, and is never read by a human except with your explicit consent, to resolve a support request you raised, or where the law requires it.

6. Third-Party Services

UnReposter interacts with external providers that operate under their own privacy frameworks:

  • TikTok: for session-based authentication and executing repost removals.
  • Instagram / Meta (browser extension, and the Instagram features of the app): for the same purpose on that platform.
  • Google Firebase & Google Analytics: for crash reporting, anonymous analytics, remote configuration and bug reports.
  • RevenueCat: for subscription tracking and purchase verification.
  • Paddle: merchant of record and payment processor for purchases made outside the mobile app stores.
  • App Store / Google Play / Chrome Web Store: for distribution and standard platform analytics.

UnReposter is an independent utility tool and is not affiliated, associated, authorized, endorsed, sponsored by, or in any way officially connected with TikTok, ByteDance Ltd., Instagram, Meta Platforms, Inc., or any of their subsidiaries or affiliates. "TikTok", "Instagram" and related names are trademarks of their respective owners and are used here for descriptive purposes only. Your use of those platforms remains entirely governed by their own terms and policies.

7. International Data Transfers & KVKK / GDPR

Anonymous technical data (Firebase, Google Analytics), purchase-state data (RevenueCat) and billing data (Paddle) may be stored on servers located outside your country, including outside the EEA, the United Kingdom and Türkiye. Paddle is established in the United Kingdom and processes payment data there and in the countries of its own sub-processors.

These transfers rely on the safeguards set out in Article 9 of the Turkish KVKK and, for GDPR-covered users, on Standard Contractual Clauses or an adequacy decision as applicable.

8. Your Rights & Deleting Your Data

Because your operational data lives on your own device, most of it is yours to erase directly: clear the app's data or uninstall it, or remove the extension from your browser.

  • Access, correction, deletion, objection, portability: for anything we hold outside your device — bug reports, support emails, purchase records — write to us and we will act on the request within 30 days.
  • Identifying your data: since we hold no account, please include whatever lets us find the record — the recovery code / purchase identifier for an extension purchase, the checkout email, or the order number from your Paddle receipt. Send it to support@stockimg.ai.
  • Billing records may have to be retained despite a deletion request, where tax or accounting law obliges us to keep them.
  • Paddle-held data: because Paddle is an independent controller for checkout data, you may also address requests about it directly to Paddle.

9. Children

UnReposter is not directed at children under 13 (or the minimum age set by your country's law), and we do not knowingly collect data from them. If you believe a child has provided us with personal data, contact us and we will delete it.

10. Contact & Changes

We may update this policy occasionally; the date at the top of this page always reflects the current version. Continued use of the Product constitutes acceptance of the updated policy.

  • Company: STOCKIMG AI YAZILIM TEKNOLOJILERI ANONIM SIRKETI
  • Email: support@stockimg.ai