Gecko

Privacy Policy

Last updated: September 3, 2026

Gecko ("the app," "we," "us") is published by Rikraj Haldar, trading as Horrac ("Horrac"). This policy explains what data the app accesses, where it goes (including the parts that now run on servers we operate, not just on your own device), and how you can remove it.

The short version

When you connect a YouTube, Twitch, Instagram, or TikTok account, Gecko talks to that platform's own servers using an authorization you grant through their official sign-in screen. Some of what Gecko does happens locally, on your own device. Some of it happens on a small backend we operate (we call it "the relay"): keeping your credentials so background checks can run, generating Channel Reports and anomaly alerts automatically, and staging content for scheduled publishing. It needs to keep working even while the app itself is closed, which is why it lives on a server rather than only on your device. We never sell your data, never use it for advertising, and don't run any third-party analytics or tracking SDK inside the app.

What the app accesses, and why

PlatformScopes requestedWhat each is used for
YouTubeyoutube.readonly, yt-analytics.readonlyYour channel name, subscriber count, and your own video/analytics data (views, watch time, traffic sources, audience demographics). The same data YouTube Studio shows you.
YouTubeyoutube.uploadOnly if you use the scheduling/publishing feature. Lets Gecko upload a video to your channel on your explicit instruction (you choose the file, caption, and schedule). Gecko never uploads anything without you initiating that specific action.
Twitchmoderator:read:followersYour channel name and follower count.
Instagraminstagram_business_basic, instagram_business_manage_insightsYour account name, follower count, and your own posts' reach/engagement numbers.
Instagraminstagram_business_content_publishOnly if you use the scheduling/publishing feature. Lets Gecko publish a post to your account on your explicit instruction.
TikTokuser.info.basic, user.info.stats, video.listYour display name, follower count, and your own recent videos' view/like/comment/share counts.
TikTokvideo.publishOnly if you use the scheduling/publishing feature. Lets Gecko publish a video to your account on your explicit instruction. Until our TikTok integration passes TikTok's own audit, anything published this way is visible only to you (SELF_ONLY); that's TikTok's own restriction, not one Gecko imposes.

None of these scopes grant access to private messages, other users' data, payment information, or the ability to read or modify your account settings. The publishing scopes let Gecko post on your instruction. They never let Gecko delete, edit, or read content you didn't create through the app, and Gecko never publishes automatically without you reviewing and confirming what's being scheduled first.

Gecko's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Where your data is stored

Gecko has two places data can live, and which one depends on what you're using:

Credential encryption. Access tokens and any platform-app secrets we store server-side are encrypted at rest using AES-GCM, with the encryption key held separately from the database itself.

Nothing is shared with third parties, and there are no advertising or analytics/tracking SDKs embedded in the app.

Data security

All traffic between the app and our servers is encrypted in transit (TLS). Server-side and local credentials are encrypted at rest as described above. Our database provider (Cloudflare) keeps hourly backups for 24 hours and offers point-in-time recovery for up to 30 days, for disaster-recovery purposes only; we don't use this to work around a deletion request, but it means data can theoretically be recoverable by us for up to 30 days after deletion, for that limited purpose. If we become aware of a data breach affecting your personal data, we'll notify the ICO where required by law and, where there's a real risk to you, notify you directly without undue delay.

Reporting a security issue. If you believe you've found a security vulnerability in Gecko or our backend, email support@horrac.com with details. Give us a reasonable opportunity to investigate and fix the issue before disclosing it publicly, and we won't pursue legal action against good-faith, non-destructive security research reported this way.

Automated background checks (Channel Report, Content Anomaly, Cadence Insight)

For platforms where this is enabled, Gecko periodically checks your connected account's public performance data on our servers, even while the app is closed, to keep your Channel Report current and flag unusual video/post performance. This uses the same read-only data described in the table above. It never posts, comments, or changes anything on your account. You can see exactly when a report last ran, and you can delete a platform's stored report data at any time (see Data Deletion below).

AI features (Channel Report, Suggestions Chat, Pre-Publish Critique, the Prediction Model, Media Kit, Recurring Patterns)

These features send the relevant content, meaning your account's public content/performance data described above, and (for video-based features) a small, representative sample of your own videos, to Google's Gemini API or Anthropic's Claude API through our relay, using a credential we own, never one you provide. Specifically:

Every call to Google's Gemini API or Anthropic's Claude API uses a paid, billing-enabled key on our side, never a free one. Both providers' paid tiers contractually exclude submitted content from being used to train their models, which a free tier would not guarantee. AI-generated output (reports, critiques, predictions, suggestions) is not reviewed by a human before being shown to you, and should be treated as a starting point, not a guarantee. See the Terms of Service for more on this.

Trend and topic search. For Instagram and TikTok, some features (Suggestions Chat, the Prediction Model) ground their answers in a search of current trends or events on the open web. This normally goes through Google's own search-grounding tool as part of a Gemini call. On the rare occasion our daily grounding budget for that is exhausted, we fall back to Parallel.ai's Search API instead, sending only a short search topic or query, never your personal account or content data.

Scheduled publishing

If you use Gecko's scheduling feature, the media file you select (and a custom thumbnail, if you set one), its caption or title, and its scheduled time are uploaded to our servers so the post can go out at the right time even if the app is closed. Once a scheduled post is published (or you cancel it), that staged media and thumbnail are deleted from our servers. Nothing is published without you first reviewing it and confirming the schedule.

Our legal basis for processing your data

Under UK GDPR Article 6, we process your data on these bases:

International data transfers

Gecko's backend runs on Cloudflare's infrastructure, and AI processing runs on Google's and Anthropic's infrastructure. All three have data-processing operations outside the UK/EEA, so using them involves an international transfer of personal data. The safeguard differs slightly by provider:

The ICO has indicated both UK transfer mechanisms may be updated during 2026. We'll keep this section current as that happens. If you have questions about a specific transfer, contact us at the address below.

Your rights

Under UK GDPR Articles 15 to 22, if you're in the UK or EEA you have the right to:

You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk) if you believe we've mishandled your data. We'd appreciate the chance to address it directly first, at the contact below.

These are your statutory rights under UK GDPR if you're in the UK or EEA. If you're elsewhere, we'll still honor equivalent access, correction, and deletion requests as a matter of practice. See Data Deletion below.

Data deletion

See our Data Deletion page for how to disconnect an account, delete server-side report/schedule data, or request full account erasure.

Children's privacy

Gecko's Terms of Service require you to be at least 18, or the age of majority in your jurisdiction, to use it. Gecko is not directed at children, and we do not knowingly collect data from anyone under that age.

Changes to this policy

If this policy changes, we'll update the "Last updated" date above. Material changes will be noted in the app's release notes.

Contact

Questions about this policy: support@horrac.com