Basira

Basira — Privacy Policy

Last updated: 2026-09-28. This version adds publishing, advertising management and the optional services, which Basira now offers.

Who operates Basira

Basira is a Windows desktop application for social media account management, published by Saad Hasson (contact: contact@x13labs.com). It is used by a social media manager to analyse, publish to and advertise the accounts he manages for his clients on YouTube, Facebook, Instagram and TikTok.

Basira runs on the user's own computer. There is no Basira account and no sign-up, and the data Basira collects, the reports it writes and the posts it prepares stay on that computer. We, the publisher, never receive them.

The linking relay

To let people link their accounts without registering developer apps of their own, Basira uses the publisher's apps on Google, Meta and TikTok. Those apps' secrets cannot be placed inside a program people download, so they are kept in a small relay at auth.x13labs.com (a Cloudflare Worker). The relay is used only for the moment an authorization code is exchanged for a token, when a token is refreshed or checked, and when access is revoked. It adds the app secret, forwards that single request to the platform's official token address, and returns the platform's answer to the user's computer. It stores nothing and logs nothing: no tokens, no account data, no statistics, no posts. People who register their own developer apps in Basira's settings do not use the relay at all.

Platform connections and the permissions requested

Basira connects to a platform only after the account owner (or a person the platform authorizes to grant access) signs in on that platform's official authorization screen. Each permission below is requested only when the user turns on the feature that needs it.

PlatformPermissionWhy
YouTube (Google) youtube.readonly, yt-analytics.readonly, openid, email Channel and video information and YouTube Analytics reports; the email only records which Google account granted access.
youtube.upload Upload a video, and set its thumbnail, that the user selected and approved in Basira's publishing window. Nothing is uploaded otherwise.
Facebook Pages and Instagram professional accounts (Meta) pages_show_list, pages_read_engagement, read_insights, instagram_basic, instagram_manage_insights, business_management List the Pages the person manages to pick the client's Page; read Page and Instagram posts and their statistics. business_management only where Meta requires it to read a Page owned by a business portfolio.
pages_manage_posts, instagram_content_publish Publish a video post or Reel, with the cover the user chose, that the user approved in Basira. Basira does not edit or delete existing posts.
TikTok user.info.basic, user.info.profile, user.info.stats, video.list Account identity, follower/like/video counts, and the public videos with their view, like, comment and share counts.
Meta Ads ads_read, ads_management Read the results of the ad account's campaigns. ads_management is requested separately and used only to create a campaign the user approved, within the spending limit the user set; campaigns are created paused unless the user chooses otherwise.
Google Ads adwords Read campaign results and the account's image assets (to pick an ad logo), and create a campaign the user approved, within the user's spending limit.

Basira never manages comments or direct messages, never reads revenue data, never deletes content, and never publishes or spends money without the user's explicit approval of that specific post or campaign.

Optional services the user may turn on

How the data is used

Data is used only to show performance, write reports and recommendations, publish the posts and create the campaigns the user approves, all for the connected account and its manager. It is not used for any other advertising, not sold, and not shared with anyone except as described above. Each client's data is kept separate and is never combined with another client's.

Basira's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Where the data is stored

Revoking access and deletion

An account owner can revoke Basira's access at any time: Google — myaccount.google.com/connections; Facebook — Settings → Business integrations; Instagram — Settings → Apps and websites; TikTok — Settings → Security → Manage app permissions. After revocation, or on request by email, the authorized data for that account is deleted from Basira within 7 days. Uninstalling Basira does not delete the data folder; the user can delete it themselves.

Platform terms

Basira uses YouTube API Services: by authorizing Basira for YouTube, account owners also agree to the YouTube Terms of Service, and Google's handling of data is described in the Google Privacy Policy. Meta data is used in accordance with the Meta Platform Terms; TikTok data in accordance with the TikTok Developer Terms.

Children

Basira is a professional tool and is not directed at children.

Changes

Any change to this policy, including before a new permission is requested, is published on this page with a new date.

سياسة الخصوصية — بصيرة

آخر تحديث: 27/9/2026 — أُضيف النشر وإدارة الإعلانات والخدمات الاختيارية.