Privacy Policy
Last updated: September 2026
Who we are
Automation Lab is operated by RENEWEARTH SL, company tax identification number B26785923. Registered address: Paseo de Reding 43, 1 Izq, 29016 Malaga, Spain.
RENEWEARTH SL is the data controller responsible for personal data processed through Automation Lab. Questions about this policy, or any request concerning your personal data, can be sent to legal@automationlab.agency.
Automation Lab ("the app") lets a signed-in user connect their own social media accounts (currently YouTube, Instagram and Facebook, with TikTok in progress) and publish content to them through this app. This policy explains what personal data the app processes, why, on what legal basis, and what you can do about it.
What we collect
- Account information you provide: a username, email address, and password (stored only as a one-way hash, never in plain text) if you register with email and password.
- Profile information from Google sign-in: your name, email address and account identifier, if you sign in that way instead.
- Connected-account credentials: when you connect a YouTube, Instagram or Facebook account, we store the access token (and, where the platform issues one, a refresh token) needed to publish on your behalf, the permissions granted, and a label identifying the account, such as its username, channel or Page name.
- Content you choose to publish: the file identifier and filename of each video you queue, the caption you write, the destination account, and the scheduled time.
- Publishing records: whether each item published successfully, when it published, and the error reported if it did not.
- A session cookie, which is strictly necessary to keep you signed in. The app sets no advertising or analytics cookies.
How video files are handled
Video files are read from the cloud storage folder you nominate. To publish one, the app downloads it to temporary storage on the server, passes it to the destination platform, and then deletes the temporary copy. We do not retain copies of your video files.
Instagram and Facebook do not accept a direct upload; they retrieve the file from a URL the app supplies. That URL contains a randomly generated, single-purpose token and stops working as soon as publishing finishes.
Why we process it, and on what legal basis
Under the UK and EU General Data Protection Regulation, we rely on the following bases:
- Performance of a contract — processing your account details, connected-account tokens and queued content is necessary to provide the service you have asked for. Without it the app cannot publish anything.
- Legitimate interests — keeping records of what was published, and of failures, so that the service can be operated, supported and debugged, and so that we can show what was delivered.
- Legal obligation — where we are required to retain certain records.
What we do not do
- We do not sell your personal data, or share it with third parties for advertising.
- We do not publish anything you have not queued yourself.
- We do not read your private messages, comments or direct messages, and we do not request the permissions that would allow it.
- We do not carry out automated decision-making or profiling that produces legal or similarly significant effects.
Who else processes your data
Connecting an account means that platform's own privacy policy also applies to how they handle your data on their side:
- Google Privacy Policy — YouTube and Google Drive
- Meta Privacy Policy — Facebook and Instagram
- TikTok Privacy Policy — once TikTok support is enabled
We also use service providers who process data on our instructions: our hosting provider, which runs the application and stores its database, and our network and DNS provider, which serves this website.
International transfers
The application and its database are hosted within the European Economic Area. However, publishing to a social platform necessarily sends your content and the associated account credentials to that platform, and Google, Meta and TikTok process data outside the EEA, including in the United States. Those transfers are governed by each platform's own safeguards, including the European Commission's standard contractual clauses and, where applicable, the EU–US Data Privacy Framework.
How long we keep it
- Connected-account tokens are deleted immediately when you disconnect that account.
- Account details and publishing records are retained for as long as your account remains open, so that the history of what was published stays available to you.
- Temporary video files are deleted as soon as publishing completes.
- When you ask us to delete your account, the associated records are removed.
Your rights
If you are in the European Economic Area or the United Kingdom, you have the right to request access to the personal data we hold about you; to have inaccurate data corrected; to have your data erased; to restrict or object to processing; to receive your data in a portable format; and, where processing is based on consent, to withdraw that consent at any time.
To exercise any of these, contact legal@automationlab.agency. We will respond within the period required by law.
You also have the right to lodge a complaint with a data protection supervisory authority. In Spain this is the Agencia Española de Protección de Datos.
Security
Passwords are stored only as one-way hashes. Connected-account tokens are held in the application's database and are used solely to carry out the publishing actions you request. Access to the administrative interface requires a sign-in.
Removing your data
You can disconnect any connected account at any time from the dashboard, which deletes the stored access token for that account immediately. We recommend also reviewing the connected-applications settings on the platform itself. To delete your account entirely, or for any other privacy question, contact legal@automationlab.agency.
Step-by-step instructions are on the data deletion page.
Changes to this policy
If this policy changes, the revised version will be published on this page with an updated date above.