Privacy Policy

Effective date: 11 September 2026

Twincast ("the App") is an Android application that lets you view your own Instagram posts and share them to TikTok. This policy explains what data the App handles and how. The short version: your Instagram data stays on your device and we keep no user database. The App is a paid download and shows one Google AdMob interstitial ad before a share; you can remove ads permanently with a one-time in-app purchase (see §5).

1. Who we are

Twincast is operated by its developer (the "Operator"). Contact: hello@twincast.app.

2. Data the App processes

Data Source Where it is stored Purpose
Instagram access token, Instagram user ID and username Instagram (Instagram API with Instagram Login), after you sign in on Instagram's own login page and grant permission Only on your device, in encrypted storage (Android Keystore) Reading the list of your posts
Metadata of your Instagram posts (caption, media type, permalink, timestamp, thumbnail URL) and the media files you choose to share Instagram API Only on your device (local database and app-private cache) Showing your feed inside the App and handing a selected post to the TikTok app
One-time OAuth authorization code Instagram redirect at the end of login Sent once to our token-exchange endpoint (see §3); not stored Exchanging the code for an access token without embedding secrets in the App
Advertising identifier (Android Advertising ID), approximate location derived from IP, device and ad-interaction data Collected by the Google AdMob SDK inside the App when an ad is shown Processed by Google; not stored by us Serving and measuring the ad shown before a share (until you buy the ad-free upgrade)
Purchase state of the "remove ads" product and your advertising-consent choice Google Play Billing / Google's consent SDK Purchase record at Google Play; a yes/no copy and your consent choice on your device Hiding ads for buyers and honouring your consent choice
Local flags such as "already shared" Your actions in the App Only on your device Filtering your feed

The App does not collect your contacts, precise location, crash reports or usage analytics, it does not access your TikTok account, and it never sends your Instagram posts, captions or media anywhere except to the TikTok app you hand them to. Advertising data (see §5) is collected by Google's SDK, not by us, and only until you buy the ad-free upgrade. Sharing to TikTok is performed by the TikTok app itself through TikTok's Share Kit; you review and publish the post inside TikTok.

3. Our server

We operate a single, stateless endpoint (https://twincast.app/exchange, hosted on Cloudflare Workers). It receives the one-time authorization code from your device, forwards it to Instagram together with our application secret, and returns the resulting access token to your device. The endpoint keeps no database and no request logs; tokens and codes are held in memory only for the duration of the request.

4. Third parties

We do not sell or share personal data with anyone else.

5. Advertising and how to switch it off

The App shows a single full-screen ad from Google AdMob immediately after you tap "Share on TikTok" and before the media is prepared. Ads never appear anywhere else in the App.

6. Retention and deletion

All data listed in §2 stays on your device until you remove it. You can delete everything at any time:

Because we store nothing server-side, there is no account to delete on our end. See Data Deletion Instructions.

7. Your rights

Depending on where you live (including under the GDPR and the Turkish Personal Data Protection Law, KVKK) you may have rights of access, rectification, erasure, restriction and objection. Since the App keeps your data only on your device, you exercise these rights directly through the App and your Instagram account settings. For any question, contact hello@twincast.app.

8. Children

The App is not directed at children under 13 and requires an Instagram account, which itself requires a minimum age. We do not knowingly process data of children.

9. Security

Tokens are stored using Android's encrypted preferences backed by the hardware Keystore; network traffic uses HTTPS only; Android backup of the App's data is disabled.

10. Changes

We may update this policy. The effective date above changes when we do; material changes will be announced inside the App.