Skip to content

ERDI POSTIZ app privacy

What data the tool I use to produce my Instagram content handles, where it is stored and how to request its deletion.

Last updated: 2026-08-25

This policy covers ERDI POSTIZ only: the app registered on the Meta platform that I use to manage my own Instagram account. Website privacy is explained separately, in the www.elrincondeisma.com privacy policy.

In one sentence: ERDI POSTIZ is a personal tool I run on my own computer to manage my own Instagram account. It has no registered users, no servers and it collects no data from third parties.

1. Who is the data controller

2. What this app is

ERDI POSTIZ is a command-line application for internal, personal use that runs locally on my computer. It does two things:

  • Produce my own content: compose the image carousels I publish on the @elrincondeismaoficial profile.
  • Read my own account: fetch the profile, published posts, their comments and their metrics, and keep a local backup of that history.

The app offers no sign-up and no login to third parties. The only possible user is me, as the account owner, authenticated with my own access token.

3. What data is processed

All data comes from a single account: mine, retrieved through the Instagram API (graph.instagram.com) with my explicit authorisation.

DataWhat it is used for
Account profile: id, username, account type, number of posts and followersIdentify the connected account and check that access works
My own posts: images, videos, captions, dates and linksList the history and download a local backup
Comments received on my own postsRead them and keep them alongside the backup
Account and post metrics: reach and interactionsAnalyse how my own content performs

No other category of data is processed. There is no data from other users of the app, because there are none. Third-party comments on my posts are read exactly as they are public on Instagram: they are not analysed, not profiled and not shared with anyone.

4. Where it is stored

Only on my personal computer, in local files. There is no remote database, no server of my own and no cloud service storing this information.

The API access token is kept in a local configuration file that is never pushed to any repository nor shared.

5. Who it is shared with

Nobody. The data is not sold, transferred or published. The app talks to these services and only for what is stated:

  • Meta / Instagram: to read my own account through the official API.
  • OpenAI: to generate the slide illustrations from text descriptions I write myself. No Instagram data is sent to it.
  • Buffer: to schedule and publish the finished content, under my own account and subject to Buffer's privacy policy.

Processing is based on the consent of the data subject, who is also the only user of the app (art. 6.1.a GDPR), and on the legitimate interest in managing and analysing the account's own activity (art. 6.1.f GDPR).

7. How long it is kept

For as long as I keep the files on my computer. There is no automatic retention anywhere else. The access token expires after 60 days and is renewed manually.

8. Rights and deletion

Since the data is mine and lives on my machine, I can access, rectify or delete it at any time. The step-by-step procedure is on the data deletion instructions page.

Anyone may write to ismael@elrincondeisma.com to exercise their rights of access, rectification, erasure, objection, restriction and portability under the GDPR, and to lodge a complaint with the Spanish Data Protection Agency if they see fit.

9. Cookies

The app is not a website: it uses no cookies, no analytics and no trackers.

10. Changes to this policy

If the app changes what it does, this page is updated and the date in the header changes with it.