ERDI POSTIZ app privacy
What data the tool I use to produce my Instagram content handles, where it is stored and how to request its deletion.
Last updated: 2026-08-25
This policy covers ERDI POSTIZ only: the app registered on the Meta platform that I use to manage my own Instagram account. Website privacy is explained separately, in the www.elrincondeisma.com privacy policy.
In one sentence: ERDI POSTIZ is a personal tool I run on my own computer to manage my own Instagram account. It has no registered users, no servers and it collects no data from third parties.
1. Who is the data controller
- Owner: Ismael Catala
- Tax ID: 52892862S
- Address: Madrid (España)
- Contact email: ismael@elrincondeisma.com
2. What this app is
ERDI POSTIZ is a command-line application for internal, personal use that runs locally on my computer. It does two things:
- Produce my own content: compose the image carousels I publish on the @elrincondeismaoficial profile.
- Read my own account: fetch the profile, published posts, their comments and their metrics, and keep a local backup of that history.
The app offers no sign-up and no login to third parties. The only possible user is me, as the account owner, authenticated with my own access token.
3. What data is processed
All data comes from a single account: mine, retrieved through the Instagram
API (graph.instagram.com) with my explicit authorisation.
| Data | What it is used for |
|---|---|
| Account profile: id, username, account type, number of posts and followers | Identify the connected account and check that access works |
| My own posts: images, videos, captions, dates and links | List the history and download a local backup |
| Comments received on my own posts | Read them and keep them alongside the backup |
| Account and post metrics: reach and interactions | Analyse how my own content performs |
No other category of data is processed. There is no data from other users of the app, because there are none. Third-party comments on my posts are read exactly as they are public on Instagram: they are not analysed, not profiled and not shared with anyone.
4. Where it is stored
Only on my personal computer, in local files. There is no remote database, no server of my own and no cloud service storing this information.
The API access token is kept in a local configuration file that is never pushed to any repository nor shared.
5. Who it is shared with
Nobody. The data is not sold, transferred or published. The app talks to these services and only for what is stated:
- Meta / Instagram: to read my own account through the official API.
- OpenAI: to generate the slide illustrations from text descriptions I write myself. No Instagram data is sent to it.
- Buffer: to schedule and publish the finished content, under my own account and subject to Buffer's privacy policy.
6. Legal basis and purpose
Processing is based on the consent of the data subject, who is also the only user of the app (art. 6.1.a GDPR), and on the legitimate interest in managing and analysing the account's own activity (art. 6.1.f GDPR).
7. How long it is kept
For as long as I keep the files on my computer. There is no automatic retention anywhere else. The access token expires after 60 days and is renewed manually.
8. Rights and deletion
Since the data is mine and lives on my machine, I can access, rectify or delete it at any time. The step-by-step procedure is on the data deletion instructions page.
Anyone may write to ismael@elrincondeisma.com to exercise their rights of access, rectification, erasure, objection, restriction and portability under the GDPR, and to lodge a complaint with the Spanish Data Protection Agency if they see fit.
9. Cookies
The app is not a website: it uses no cookies, no analytics and no trackers.
10. Changes to this policy
If the app changes what it does, this page is updated and the date in the header changes with it.