Basira — Privacy Policy
Last updated: 2026-09-28. This version adds publishing, advertising management and the optional services, which Basira now offers.
Who operates Basira
Basira is a Windows desktop application for social media account management, published by Saad Hasson (contact: contact@x13labs.com). It is used by a social media manager to analyse, publish to and advertise the accounts he manages for his clients on YouTube, Facebook, Instagram and TikTok.
Basira runs on the user's own computer. There is no Basira account and no sign-up, and the data Basira collects, the reports it writes and the posts it prepares stay on that computer. We, the publisher, never receive them.
The linking relay
To let people link their accounts without registering developer apps of their own, Basira uses the publisher's apps on Google, Meta and TikTok. Those apps' secrets cannot be placed inside a program people download, so they are kept in a small relay at auth.x13labs.com (a Cloudflare Worker). The relay is used only for the moment an authorization code is exchanged for a token, when a token is refreshed or checked, and when access is revoked. It adds the app secret, forwards that single request to the platform's official token address, and returns the platform's answer to the user's computer. It stores nothing and logs nothing: no tokens, no account data, no statistics, no posts. People who register their own developer apps in Basira's settings do not use the relay at all.
Platform connections and the permissions requested
Basira connects to a platform only after the account owner (or a person the platform authorizes to grant access) signs in on that platform's official authorization screen. Each permission below is requested only when the user turns on the feature that needs it.
| Platform | Permission | Why |
|---|---|---|
| YouTube (Google) | youtube.readonly, yt-analytics.readonly, openid, email |
Channel and video information and YouTube Analytics reports; the email only records which Google account granted access. |
youtube.upload |
Upload a video, and set its thumbnail, that the user selected and approved in Basira's publishing window. Nothing is uploaded otherwise. | |
| Facebook Pages and Instagram professional accounts (Meta) | pages_show_list, pages_read_engagement, read_insights, instagram_basic, instagram_manage_insights, business_management |
List the Pages the person manages to pick the client's Page; read Page and Instagram posts and their statistics. business_management only where Meta requires it to read a Page owned by a business portfolio. |
pages_manage_posts, instagram_content_publish |
Publish a video post or Reel, with the cover the user chose, that the user approved in Basira. Basira does not edit or delete existing posts. | |
| TikTok | user.info.basic, user.info.profile, user.info.stats, video.list |
Account identity, follower/like/video counts, and the public videos with their view, like, comment and share counts. |
| Meta Ads | ads_read, ads_management |
Read the results of the ad account's campaigns. ads_management is requested separately and used only to create a campaign the user approved, within the spending limit the user set; campaigns are created paused unless the user chooses otherwise. |
| Google Ads | adwords |
Read campaign results and the account's image assets (to pick an ad logo), and create a campaign the user approved, within the user's spending limit. |
Basira never manages comments or direct messages, never reads revenue data, never deletes content, and never publishes or spends money without the user's explicit approval of that specific post or campaign.
Optional services the user may turn on
- Claude (Anthropic) as the report writer. Off by default: reports are written by a model running on the user's computer. If the user chooses Claude and enters their own Anthropic API key, the statistics, post texts and client names needed to write each report or ad text are sent to Anthropic under Anthropic's commercial terms. Authorization tokens and passwords are never sent.
- Telegram notifications. Through a bot the user creates. Only an alert category and a count are sent — no client names, account names or figures.
- Off-computer backup copy. If the user picks a Google Drive or OneDrive folder, Basira places a copy of its backup file there, and the user's own sync client uploads it to the user's own cloud storage.
How the data is used
Data is used only to show performance, write reports and recommendations, publish the posts and create the campaigns the user approves, all for the connected account and its manager. It is not used for any other advertising, not sold, and not shared with anyone except as described above. Each client's data is kept separate and is never combined with another client's.
Basira's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Where the data is stored
- In a local database on the user's computer, with daily local backups.
- Authorization tokens and API keys are stored in Windows Credential Manager, never in the database, backups, reports or logs.
- Basira re-confirms that each authorization is still valid at least every 30 days, as required by the YouTube API Services Developer Policies; other authorized data is refreshed or deleted within 30 days.
Revoking access and deletion
An account owner can revoke Basira's access at any time: Google — myaccount.google.com/connections; Facebook — Settings → Business integrations; Instagram — Settings → Apps and websites; TikTok — Settings → Security → Manage app permissions. After revocation, or on request by email, the authorized data for that account is deleted from Basira within 7 days. Uninstalling Basira does not delete the data folder; the user can delete it themselves.
Platform terms
Basira uses YouTube API Services: by authorizing Basira for YouTube, account owners also agree to the YouTube Terms of Service, and Google's handling of data is described in the Google Privacy Policy. Meta data is used in accordance with the Meta Platform Terms; TikTok data in accordance with the TikTok Developer Terms.
Children
Basira is a professional tool and is not directed at children.
Changes
Any change to this policy, including before a new permission is requested, is published on this page with a new date.
سياسة الخصوصية — بصيرة
آخر تحديث: 27/9/2026 — أُضيف النشر وإدارة الإعلانات والخدمات الاختيارية.
- على جهازك: بصيرة تطبيق Windows يعمل على جهاز المستخدم. لا حساب ولا تسجيل، والبيانات والتقارير والمنشورات تبقى على جهازك ولا يصلنا منها شيء.
- خادم الربط: ليربط الناس حساباتهم دون إنشاء تطبيقات مطوّر، تستعمل بصيرة تطبيقات الناشر على Google وMeta وTikTok. أسرار هذه التطبيقات محفوظة في خادم صغير على
auth.x13labs.com(Cloudflare Worker) لا يُستعمل إلا لحظة تبادل رمز التفويض أو تجديده أو فحصه أو إلغائه: يضيف السر ويمرّر ذلك الطلب وحده إلى عنوان المنصة الرسمي ويعيد جوابها إلى جهازك. لا يحفظ شيئًا ولا يسجّل شيئًا. ومن يضيف تطبيقاته الخاصة في الإعدادات لا يمر بهذا الخادم أبدًا. - الربط: عبر شاشة التفويض الرسمية لكل منصة، ولا تُطلب كل صلاحية إلا عند تفعيل الميزة التي تحتاجها: القراءة والإحصاءات (YouTube وFacebook وInstagram وTikTok)، النشر (رفع فيديو وغلافه على YouTube، ونشر فيديو أو Reel على Facebook وInstagram)، والإعلانات (قراءة نتائج Meta Ads وGoogle Ads، وإنشاء حملة).
- لا شيء دون موافقتك: لا يُنشر منشور ولا تُنشأ حملة ولا يُصرف مال إلا بعد موافقتك الصريحة على ذلك المنشور أو تلك الحملة بعينها، وضمن سقف الإنفاق الذي تحدده. لا إدارة تعليقات ولا رسائل، ولا حذف محتوى، ولا بيانات إيرادات.
- خدمات اختيارية: Claude من Anthropic لكتابة التقارير إن اخترته ووضعت مفتاحك (تُرسل الإحصاءات ونصوص المنشورات وأسماء العملاء اللازمة، ولا تُرسل رموز التفويض)؛ تنبيهات Telegram (الفئة والعدد فقط)؛ ونسخة احتياطية في مجلد Google Drive أو OneDrive تختاره.
- الحفظ: قاعدة بيانات محلية مع نسخ يومية؛ رموز التفويض والمفاتيح في مخزن بيانات الاعتماد في Windows فقط؛ يُتحقق من كل تفويض كل 30 يومًا على الأقل. استخدام بيانات Google ملتزم بسياسة بيانات مستخدمي خدمات Google API ومتطلبات الاستخدام المحدود.
- الإلغاء والحذف: يلغي صاحب الحساب الوصول متى شاء من إعدادات المنصة، وتُحذف بياناته من بصيرة خلال 7 أيام من الإلغاء أو من طلب الحذف بالبريد. إزالة البرنامج لا تحذف مجلد البيانات.