Privacy Policy
This text is a translation provided for convenience. In case of any discrepancy, the English version prevails.
Twincast ("the App") is an Android application that lets you view your own Instagram posts and share them to TikTok. This policy explains what data the App handles and how. The short version: your Instagram data stays on your device and we keep no user database. The App is a paid download and shows one Google AdMob interstitial ad before a share; you can remove ads permanently with a one-time in-app purchase (see §5).
1. Who we are
Twincast is operated by its developer (the "Operator"). Contact: hello@twincast.app.
2. Data the App processes
| Data | Source | Where it is stored | Purpose |
|---|---|---|---|
| Instagram access token, Instagram user ID and username | Instagram (Instagram API with Instagram Login), after you sign in on Instagram's own login page and grant permission | Only on your device, in encrypted storage (Android Keystore) | Reading the list of your posts |
| Metadata of your Instagram posts (caption, media type, permalink, timestamp, thumbnail URL) and the media files you choose to share | Instagram API | Only on your device (local database and app-private cache) | Showing your feed inside the App and handing a selected post to the TikTok app |
| One-time OAuth authorization code | Instagram redirect at the end of login | Sent once to our token-exchange endpoint (see §3); not stored | Exchanging the code for an access token without embedding secrets in the App |
| Advertising identifier (Android Advertising ID), approximate location derived from IP, device and ad-interaction data | Collected by the Google AdMob SDK inside the App when an ad is shown | Processed by Google; not stored by us | Serving and measuring the ad shown before a share (until you buy the ad-free upgrade) |
| Purchase state of the "remove ads" product and your advertising-consent choice | Google Play Billing / Google's consent SDK | Purchase record at Google Play; a yes/no copy and your consent choice on your device | Hiding ads for buyers and honouring your consent choice |
| Local flags such as "already shared" | Your actions in the App | Only on your device | Filtering your feed |
The App does not collect your contacts, precise location, crash reports or usage analytics, it does not access your TikTok account, and it never sends your Instagram posts, captions or media anywhere except to the TikTok app you hand them to. Advertising data (see §5) is collected by Google's SDK, not by us, and only until you buy the ad-free upgrade. Sharing to TikTok is performed by the TikTok app itself through TikTok's Share Kit; you review and publish the post inside TikTok.
3. Our server
We operate a single, stateless endpoint (https://twincast.app/exchange, hosted on
Cloudflare Workers). It receives the one-time authorization code from your device, forwards it to
Instagram together with our application secret, and returns the resulting access token to your
device. The endpoint keeps no database and no request logs; tokens and codes are held in memory only
for the duration of the request.
4. Third parties
- Meta Platforms (Instagram) — authentication and the Instagram API. Governed by the Instagram Privacy Policy.
- TikTok — the TikTok app receives the media file and opens its editor. Governed by the TikTok Privacy Policy.
- Google (AdMob) — serves the interstitial ad shown before a share and acts as an independent controller for advertising data. Governed by the Google Privacy & Terms.
- Google Play (Billing) — processes the optional "remove ads" purchase. We never see your payment details; we only learn whether the product is owned.
- Cloudflare — hosts this website and the token-exchange endpoint. Cloudflare processes connection data (such as IP addresses) as our service provider.
We do not sell or share personal data with anyone else.
5. Advertising and how to switch it off
The App shows a single full-screen ad from Google AdMob immediately after you tap "Share on TikTok" and before the media is prepared. Ads never appear anywhere else in the App.
- Removing ads: Settings → Ads → Remove ads is a one-time purchase through Google Play. Once it is owned, the ad SDK is not started at all and no advertising data leaves your device. The purchase is tied to your Google account and can be restored on a new device with Restore purchase.
- Consent (EEA, UK, Switzerland): before the first ad request the App shows Google's consent form (UMP). Your choice is stored on your device and can be changed at any time via Settings → Ads → Ad privacy settings.
- Advertising ID: you can reset or delete it in Android's Settings → Privacy → Ads.
6. Retention and deletion
All data listed in §2 stays on your device until you remove it. You can delete everything at any time:
- In the App: Settings → Disconnect deletes the access token, the local post database and cached media.
- Uninstalling the App removes all of its data.
- You can also revoke the App's access on Instagram: Settings → Website permissions → Apps and websites.
Because we store nothing server-side, there is no account to delete on our end. See Data Deletion Instructions.
7. Your rights
Depending on where you live (including under the GDPR and the Turkish Personal Data Protection Law, KVKK) you may have rights of access, rectification, erasure, restriction and objection. Since the App keeps your data only on your device, you exercise these rights directly through the App and your Instagram account settings. For any question, contact hello@twincast.app.
8. Children
The App is not directed at children under 13 and requires an Instagram account, which itself requires a minimum age. We do not knowingly process data of children.
9. Security
Tokens are stored using Android's encrypted preferences backed by the hardware Keystore; network traffic uses HTTPS only; Android backup of the App's data is disabled.
10. Changes
We may update this policy. The effective date above changes when we do; material changes will be announced inside the App.