DES UL
BUILDING IN THE OPEN

Privacy

Last updated 27 August 2026. This covers desoul.dev, its subdomains, and every Desoul application listed below.

None of these are offered as a service. They are tools the owner runs for himself, each with one user, and no other person's account is ever read or written. Nothing is sold, shared, transferred, used for advertising, or used to train any model.

The public site

desoul.dev collects nothing. No analytics, no cookies, no tracking, and no third-party requests: the fonts and images are served from this domain, so loading a page here tells nobody anything. Standard server logs kept by the host (Cloudflare) may record an IP address and a request line briefly, for security and abuse prevention. Nothing is passed on.

The portfolio at portfolio.desoul.dev is static and served the same way. Where a page there embeds a demo video, that video is loaded from YouTube in privacy-enhanced mode (youtube-nocookie.com), which is a request to Google and is the one exception to the paragraph above.

Signing in to the internal apps

The applications below are reachable on subdomains of this site but are not open to the public. Sign-in is handled by Cloudflare Access, which authenticates against the owner's own Cloudflare account and, in doing so, processes the email address of whoever signs in. Only accounts the owner has named can get in.

Desoul Production

Produces and publishes the videos on @desoul.dev1412.

Stored: an OAuth token, on the owner's own computer, in a file that is not committed to source control and is not transmitted anywhere except to Google when refreshing access; and the connected channel's name and handle, cached beside it so the tool can show which channel it is about to publish to.

Desoul Posting

Reads public news sources, drafts posts from them, and publishes to Facebook Pages the owner administers. It requests pages_manage_posts and pages_read_engagement through the Facebook Graph API, which let it publish to those Pages and read their own post statistics. It never reads a personal profile, a friend list, or anyone else's Page.

Stored: a long-lived Page access token for each connected Page, together with that Page's name and id, held in the owner's own hosted Postgres database (Supabase) so the tool can post without re-authenticating. Article text and links gathered from public news sources are stored in the same place. No personal data about readers is collected, because there are no readers: the app has no public surface.

Desoul Traveling

Builds the owner's own travel itineraries as static pages. There are no accounts and no visitor tracking. Place details come from public map data; an itinerary contains only what the owner typed into it.

Platform integrations

Every platform this account connects to, what it is allowed to do, and where the credential lives. A platform that is not on this list is not connected.

Google Limited Use

This application's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Revoking access, and deletion

Google: disconnect from inside the tool, which deletes the stored token, or revoke directly at myaccount.google.com/permissions. Deleting the local token file has the same effect.

Facebook: remove the app at facebook.com/settings, which invalidates the Page tokens, or delete them from the database directly.

To ask for anything held about you to be deleted, write to the address below. Given that these tools hold no third-party accounts, the answer is usually that there is nothing to delete, and you will get that answer in writing.

Contact

Questions about any of this: hello@desoul.dev.