Skip to content

Whataripoff · Legal

Privacy Policy

Last updated: 24 September 2026

Whataripoff (whataripoff.apx-digital.co.uk) is a marketing reporting and social media management platform operated by APX Digital Ltd ("APX", "we", "us"), a company registered in the United Kingdom. This policy explains what data Whataripoff accesses, why, how we protect it, and the rights you have under UK data protection law, including the UK GDPR and the Data Protection Act 2018.

This policy covers the Whataripoff platform only. Our general website is covered by the APX Digital privacy policy.

Who uses Whataripoff

Whataripoff is used by APX Digital staff and by APX's business clients, who are given their own logins. It is not a consumer app and is not open to public sign-up.

Who is responsible for your data

APX Digital Ltd is responsible for the personal data processed in Whataripoff. For anything to do with this policy or your data, email privacy@apx-digital.co.uk.

Platforms we connect to

With the account owner's permission, Whataripoff connects to third-party platforms through their official APIs. Access is read-only reporting access, except for content publishing described below. Supported platforms are:

  • Meta: Facebook Pages, Instagram Business accounts and Meta Ads
  • Google: Google Ads, Google Analytics 4, Google Search Console and Google Sheets
  • TikTok: TikTok accounts, through Login Kit, the Display API and the Content Posting API

We may add other advertising platforms in future (such as TikTok Ads, LinkedIn Ads and Microsoft Advertising). If we do, this policy will be updated before they are made available.

What data we access

  • Ad and campaign performance metrics, such as spend, impressions, clicks and conversions
  • Facebook Page and Instagram insights, such as followers, reach, views and engagement
  • TikTok profile information (display name, avatar and profile details) and video statistics, such as views, likes, comments and shares
  • Post and video content and thumbnails
  • Account and page names and IDs
  • Basic profile information (name and email address) of the person who connects an account, which we use to label the connection
  • For Whataripoff users: your name, email address and login details

What we do not access

Whataripoff does not read private messages, friends lists, or personal data about the people in a connected account's audience. Demographic breakdowns (such as age, gender and region) are received only in the aggregated form the platforms supply. They do not identify individuals.

How we use the data

We use this data only to:

  • show reports and dashboards to the client who owns the connected account, and to APX Digital staff working on that account;
  • send scheduled email reports that the client has set up;
  • publish posts to connected Facebook Pages, Instagram accounts and TikTok accounts, where the account owner has given permission and approved the content.

We do not sell data, use it for advertising, or share it with third parties except the service providers listed below.

Our lawful basis is performing our contract with the client, and our legitimate interest in providing and securing the service.

Google user data

Whataripoff's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular:

  • Google user data is used only to provide the reporting features the user has asked for in Whataripoff.
  • Google user data is not used for advertising, and is not sold or transferred to third parties for any other purpose.
  • People do not read Google user data unless the user has given consent, it is needed for security purposes (such as investigating abuse), or it is required by law.

Where data is stored and how it is protected

  • Whataripoff is hosted by Hostinger in EU data centres, in a MySQL database.
  • OAuth access and refresh tokens are encrypted at rest using AES-256-GCM.
  • Photos and videos uploaded for social posts are stored on the same hosting.
  • Reporting data is cached temporarily (for about an hour) and kept in report snapshots.
  • You must log in to access Whataripoff. Client users can see only their own organisation's data.

Service providers

We use these providers to run Whataripoff. They process data on our instructions:

  • Hostinger: hosting and database
  • Anthropic: optional AI-written report summaries. When this feature is used, aggregated metrics are sent to Anthropic's API to write the summary. Anthropic does not use this data to train its models.
  • An email delivery provider: sending scheduled report emails

We may also disclose data where the law requires it.

How long we keep data

  • We keep data while the client relationship and the platform connection are active.
  • Disconnecting a platform in Whataripoff deletes the stored access tokens for that platform.
  • All data is deleted on request, or within 90 days of the account closing.

See Data deletion for how to ask us to delete your data.

Your rights

Under UK GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data deleted;
  • object to or restrict how we use your data;
  • complain to the Information Commissioner's Office (ICO) at ico.org.uk.

To use any of these rights, email privacy@apx-digital.co.uk. We will reply within one month.

Changes to this policy

We may update this policy from time to time. The date at the top of this page shows when it last changed. If we make significant changes, we will tell Whataripoff users.