Legal Documents
  • Terms of Service
  • Privacy Policy
  • License Agreement
  • Refund Policy
  • DMCA / Copyright
Data and Privacy

Privacy Policy

Last Updated: July 23, 2026  ·  Version 1.5

1. Overview

This Privacy Policy explains how TRESSO collects, uses, stores, and protects information related to the TRESSO website, desktop software, subscriptions, support systems, and connected platform integrations.

TRESSO was designed around a desktop-first workflow focused on content creator control, local storage, and minimal unnecessary data collection. By using TRESSO, you agree to this Privacy Policy.

2. Where Your Data Lives

TRESSO is a desktop application, not a cloud video platform. We do not overstate this. Here is precisely what stays on your computer, what reaches TRESSO, and what reaches a social platform when you publish.

Stays on your computer

Your video and media files, captions, hashtags, titles, the scheduling queue, posting history, app logs, and settings are stored on your own computer. Your connected-platform access tokens are also stored on your computer (see the connection note below). Your media files are never uploaded to TRESSO to be stored or hosted.

Goes to TRESSO

Your license key, the email used at purchase, and a device fingerprint are sent to TRESSO to activate and verify your subscription. When you connect a platform, the secure sign-in is completed through TRESSO's connection broker so that platform secrets do not have to ship inside the app; the resulting access token is then stored on your computer. For Threads, the access token is held on TRESSO's server to complete publishing. An optional, opt-in diagnostics heartbeat, and any support message or diagnostics report you choose to send, also reach TRESSO.

Goes to the platform when you publish

When you publish, the selected video, caption, hashtags, and the privacy and interaction settings you chose are sent from your computer directly to that platform's API (Instagram, YouTube, TikTok, Pinterest, Facebook, or Threads). Your media stays on your computer unless you choose to publish it to a connected platform. For Threads, publishing is relayed through TRESSO's server.

Connected platform data and tokens are used only to support connecting your account and publishing on your behalf, never for any other purpose. TRESSO does not sell or rent your personal data.

3. Information We May Collect

Account and Subscription Information

  • Email address, billing status, subscription tier, purchase history, license status, transaction identifiers

Technical and Diagnostic Information

  • Application version, device type, operating system details, installation status, crash reports, error logs, diagnostic events, licensing verification data

Support Information

If you contact support, TRESSO may collect support emails, attachments you voluntarily send, technical screenshots, and diagnostic logs you choose to provide.

Platform Integration Information

When you connect supported third-party services such as Instagram, YouTube, TikTok, or Facebook Page, TRESSO may store limited authentication and integration data necessary for publishing functionality. Connected platform functionality depends on official third-party APIs.

4. Local Storage and User Responsibility

TRESSO is designed so that core workflow data remains on your local machine whenever reasonably possible. You are solely responsible for your computer, device access, local backups, file recovery, antivirus protection, password management, physical device security, and internet connectivity.

TRESSO is not responsible for lost files, corrupted files, deleted media, hardware failures, compromised devices, or user-side security failures.

5. How Information Is Used

Information may be used to:

  • Operate the software and process subscriptions and billing
  • Validate active licenses and provide customer support
  • Improve application stability and diagnose software issues
  • Detect abuse or fraud and maintain operational security
  • Comply with legal obligations and enforce Terms and policies

6. Payment Processing

Payments may be processed through third-party providers such as Stripe. TRESSO does not directly store full payment card information on TRESSO-controlled systems. Payment providers maintain their own independent privacy and security practices. See Stripe's Privacy Policy.

7. Third-Party Platforms and APIs

TRESSO integrates with third-party services including Instagram, YouTube, TikTok, and related platform APIs. These services operate independently from TRESSO and may collect information under their own terms and privacy policies. TRESSO does not control third-party platform policies, API availability, platform moderation decisions, platform security practices, or third-party data handling.

Google API Services - Limited Use: TRESSO's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Google user data we collect: When you connect your own YouTube channel, TRESSO collects your YouTube channel identity (channel ID and channel title), your connection status, and the OAuth access and refresh tokens required to establish and maintain the connection. During a repost or retry, TRESSO also reads your channel's own recent uploads (the uploads playlist and those videos' IDs, titles, publication timestamps, and durations) to avoid publishing a duplicate. If you choose to import a video from Google Drive, TRESSO collects only the specific file or files you select in the Google Picker. TRESSO does not collect any other Google user data.

How we use Google user data: TRESSO uses Google user data solely to provide the user-facing features you request from inside the app — identifying your connected YouTube channel, verifying connection health, checking your channel's recent uploads to prevent duplicate posts, and uploading videos you choose to publish. TRESSO does not use Google user data for advertising, and does not use it to develop, improve, or train generalized or non-personalized artificial-intelligence or machine-learning (AI/ML) models. TRESSO affirms that data obtained through Google Workspace APIs, including the Google Drive API used by the optional Drive import, is not used to develop, improve, or train non-personalized AI and/or ML models.

How we store Google user data: Your refresh token is stored only on your own computer, encrypted at rest using your operating system's protected credential storage (on Windows, DPAPI through the application framework's safe-storage); it is never written in plaintext and is never stored on TRESSO's servers. Short-lived access tokens are held in memory only and are never written to disk. Your channel identity and any upload result (such as the resulting video ID) remain on your computer only while the connection is active. Duplicate-check data is used in the moment and is not stored.

With whom we share, transfer, or disclose Google user data: TRESSO does not sell Google user data, and does not share, transfer, or disclose it to any third party for any purpose other than providing or improving the user-facing features you request. The only transfer that occurs is sending your OAuth tokens to Google's own OAuth and YouTube Data API endpoints to perform the connection and publishing you initiate. To exchange and refresh tokens, TRESSO's license server acts only as a transient OAuth broker: tokens pass through it within a single request, are used immediately, and are never stored or logged; logs are redacted so tokens never appear in them. TRESSO does not transfer Google user data to data brokers, advertisers, or any third-party artificial-intelligence or machine-learning service.

How we protect Google user data: Google user data is protected with encryption at rest for the refresh token (your operating system's protected credential storage), memory-only handling of short-lived access tokens, encrypted transmission in transit over HTTPS/TLS, redacted server logs that never contain tokens, and least-privilege scopes limited to exactly what each feature requires.

Google user data retention and deletion: Duplicate-check data is not retained. Your YouTube channel identity, connection status, and connection metadata are retained only on your own computer and only for as long as the connection remains active. Disconnecting YouTube in TRESSO revokes the authorization at Google (it calls Google's token-revocation endpoint) and deletes the encrypted refresh token, channel ID, channel title, and connection metadata from your computer; after restart the connection stays removed and reconnecting requires a new Google consent. If revocation cannot be confirmed (for example, no internet connection), TRESSO does not report the account as disconnected and asks you to try again, so access is never silently left in an unknown state. You may also request deletion of any stored data through our support ticket form (see Section 12), or revoke TRESSO's access at any time at myaccount.google.com/permissions.

Google Drive import (optional): If you choose to import a video from Google Drive, TRESSO uses the Google Picker with the drive.file permission, which grants access only to the specific file or files you explicitly select in the picker — never your entire Drive. TRESSO never requests full-Drive or read-all-files access, and this Drive permission is separate from the YouTube connection.

Meta Platform data: TRESSO requests only the permissions needed to publish to and manage the Instagram and Facebook accounts you connect. You can revoke access at any time in your Instagram or Facebook settings, or by requesting deletion (see Section 12).

TikTok data: TRESSO uses TikTok authentication solely to publish and manage content you schedule for your connected TikTok account, in accordance with TikTok's developer terms.

8. No Sale of Personal Information

TRESSO does not sell personal information to advertisers, data brokers, or third-party marketing networks.

9. Limited Information Sharing

Information may be shared only where reasonably necessary to process payments, provide software functionality, support integrations, investigate abuse, prevent fraud, comply with legal obligations, enforce agreements, or protect rights, systems, or security.

TRESSO relies on a small number of trusted service providers to operate, including Stripe (payment processing), Brevo (transactional and account email delivery), and DigitalOcean (secure server hosting where licensing and account records are stored). These providers process information only as needed to perform their services for TRESSO and under their own privacy and security obligations.

10. Security and Operational Limitations

Reasonable administrative, technical, and operational safeguards are used to help protect information. However, no software, device, API, network, or transmission method can be guaranteed completely secure or uninterrupted. Users assume responsibility for securing their own systems and operational environments.

11. Data Retention

Information may be retained as long as reasonably necessary for operations, to comply with legal obligations, to resolve disputes, to enforce agreements, to prevent abuse or fraud, or to maintain financial and operational records. Retention periods may vary based on legal, operational, or security requirements.

12. User Rights

Depending on applicable laws, users may have rights to request access to, correction of, deletion of, or export of information, or to object to certain processing activities.

Requests may be submitted through our support ticket form (choose a Privacy Request). TRESSO may require reasonable identity verification before processing requests.

How to request deletion of your data

You may request deletion of the personal information TRESSO holds about you - including data obtained when you connect a third-party account such as Instagram, Facebook, Threads, YouTube, or TikTok - at any time by submitting a support ticket (choose Delete My Data). We will delete the requested information within 30 days, except where we are required to retain it for legal, tax, security, or fraud-prevention purposes. You can also disconnect any platform at any time from within TRESSO or from that platform's own app settings.

California residents (CCPA / CPRA)

If you are a California resident, you have the right to know what personal information we collect and how it is used, to request access to or deletion of that information, to correct inaccurate information, and to opt out of the sale or sharing of personal information. TRESSO does not sell or share your personal information, and we will not discriminate against you for exercising any of these rights. To exercise them, submit a support ticket.

EEA and UK residents (GDPR / UK GDPR)

If you are located in the European Economic Area or the United Kingdom, TRESSO processes your personal information on the following lawful bases: performance of our contract with you (to provide the software, subscription, and connected-platform features you request); our legitimate interests (to secure, maintain, and improve the service and prevent fraud); your consent (for example, when you connect a third-party account); and compliance with legal obligations. You have the right to access, correct, delete, restrict, or object to processing of your information, to data portability, and to withdraw consent at any time. You also have the right to lodge a complaint with your local data protection authority. To exercise these rights, submit a support ticket.

13. International Use

Users are responsible for complying with laws and regulations applicable to their jurisdiction, region, industry, and platform usage.

14. Children's Privacy

TRESSO is not intended for individuals under 18 years of age. TRESSO does not knowingly collect personal information from children.

15. Policy Updates

This Privacy Policy may be updated periodically. Continued use of TRESSO after changes become effective constitutes acceptance of the revised policy. If we make a material change to how TRESSO accesses, uses, stores, shares, or discloses Google user data, we will update this policy, revise the "Last Updated" date and version above, and notify affected users (for example, by email or an in-app notice) before the change takes effect.

16. Contact

Questions regarding this Privacy Policy may be submitted through our support ticket form.