### privacy
how the poppang content monitor handles platform data
last updated 29 august 2026
who this covers
This policy describes the poppang content monitor, a private single-user web application operated by the owner of poppang.dev for their own use. It is not offered as a service to other people, has no sign-up, and holds no accounts other than the operator's own.
The application also connects to third-party platform APIs. Those platforms have their own privacy policies, which govern the data they hold.
what the application does
The application reads publicly and privately available statistics and comments for social media accounts belonging to the operator, and displays them together on one page. Its purpose is to avoid logging into several platform dashboards separately.
It is read-only. It does not post, publish, comment, reply, follow, like, message, or modify anything on any connected platform, and it requests read scopes only.
what data is accessed
Only data belonging to the operator's own connected accounts. Depending on which platforms are connected, this may include:
- Follower, subscriber, and view counts for the operator's own accounts
- Metadata and performance figures for the operator's own posts and videos
- Comments and replies left by others on the operator's own posts, including the commenter's public display name and comment text
- Aggregate audience information provided by the platform, such as approximate age ranges or countries
The application does not access the operator's private messages, contacts, follower lists, or any data belonging to other users' accounts. It does not search, scrape, or collect data about people other than what appears on the operator's own posts.
comments left by other people
Where a platform's API returns comments on the operator's posts, the application displays them so they can be read and replied to. This is the same information already visible in the platform's own app.
Comment text and public display names may be cached temporarily to show which comments are new since the operator last looked. This cache is private to the operator, is never published or shared, and is deleted along with everything else if the application is shut down. Replies are not sent through the application; it links out to the platform.
pinterest data specifically
In line with Pinterest's developer guidelines, Pinterest data is fetched live and displayed, and is not stored. No Pinterest analytics, pin statistics, or audience data is written to the application's database or retained after the page is closed. Time-ranged figures are requested from Pinterest's analytics endpoints at the moment of display rather than reconstructed from stored history.
where data is stored
Access tokens and cached statistics are stored server-side in a hosted key-value database, and are never exposed to the browser. All platform API calls are made from the server, so credentials do not pass through the client.
The application is deployed on Vercel and is protected by a password gate. Only the operator can reach any page that displays data.
what is not done with the data
None of the data accessed by this application is:
- Sold, rented, licensed, or transferred to anyone
- Shared with advertisers, data brokers, or analytics providers
- Used to build profiles of any person
- Used for advertising or targeting of any kind
- Combined with data from other sources to identify anyone
- Published, displayed publicly, or shown to any other user
There is no advertising in the application, and no third-party tracking or analytics scripts run on any page that displays platform data.
retention and deletion
Cached statistics are short-lived and overwritten as they refresh. Access tokens are kept only while an account is connected, and are deleted when it is disconnected.
The operator can revoke the application's access at any time from the connected platform's own account settings, under its apps or connected-services section. Revoking access there immediately stops all further data collection.
To request deletion of data held by this application, see the data deletion page.
cookies
A single session cookie is used to keep the operator signed in past the password gate. There are no advertising, tracking, or third-party cookies.
children
The application is not directed at children and is not available to anyone other than its operator.
changes
If this policy changes, the date at the top of the page is updated. Material changes affecting connected platforms will be reflected here before those integrations continue operating.
contact
Questions about this policy, including from platform reviewers, can be sent to hello@poppang.dev.