Privacy policy

Last updated: 8 October 2026

This policy covers Victim or villain uploader (Meta app ID 557426723952816), operated by Aidan Jones in the United Kingdom. The app prepares, schedules and publishes fictional literary discussion posts to the operator’s Facebook Page and linked Instagram professional account.

The current app is an internal publishing tool. It does not offer public registration or ask Page visitors to connect their own Facebook or Instagram accounts.

Information the app uses

  • Meta account, Page and Instagram identifiers, names or usernames, and account-link information returned during authorised account setup and connection checks.
  • Access tokens and permissions supplied by the operator to authorise publishing.
  • Post text, images, schedules, platform post and media identifiers, timestamps, and publication or removal records.
  • Information you choose to send when contacting the operator about privacy or deletion, such as your name, message and the account or content concerned.

Account information comes from Meta’s APIs following the operator’s authorisation. The app does not currently retrieve audience profiles, follower lists, comments or private messages through those APIs. A message sent directly to the Page is handled separately through Meta’s messaging tools.

How information is used

Information is used to connect the operator’s accounts, publish and manage posts, confirm delivery, avoid duplicate publication, investigate failures, and respond to privacy requests. It is not sold or used by this app to profile Page visitors.

Where these activities involve personal data, the operator relies on legitimate interests in securely managing their own publishing accounts and responding to enquiries. Providing data to this app is not a statutory obligation. Account authorisation is necessary for its publishing functions. The app does not make automated decisions about individuals with legal or similarly significant effects.

Storage, sharing and services

The operator runs the app from their own computer or configured hosting environment. Credentials are held in local configuration or environment variables and excluded from the project’s Git history. Publishing content and operational records are stored in project files and may be kept in Git history or backups.

Meta receives the account authorisation and content necessary to publish on Facebook and Instagram. When public image hosting is configured, that hosting provider stores the images so Meta can fetch them. Published captions and images are intended to be public.

The operator may use a coding assistant or an optional MiniMax or OpenAI API to help write fictional book posts. The publishing workflow does not send audience profiles, messages, Meta access tokens or other audience personal data to these generation APIs.

The standalone policy files do not add analytics scripts, embedded media, forms or tracking cookies. If this policy is published on the operator’s WordPress site, the site’s theme and hosting may provide their own cookies or services. The hosting provider may process ordinary request information, including IP addresses and browser details, to deliver and secure the site. For WordPress.com hosting, see Automattic’s privacy policy. For GitHub Pages hosting, see GitHub’s privacy statement.

Meta and other services may process information internationally under their own privacy terms. See Meta’s privacy policy for its processing, transfers and safeguards. Contact the operator if you need information about a provider used for your data.

Affiliate links

Posts and our Books & editions page include disclosed Amazon UK and Bookshop.org UK affiliate links. These links contain a retailer affiliate identifier, not a visitor’s personal identifier. If you follow a link, the retailer handles your visit and any purchase under its own privacy notice: Amazon or Bookshop.org UK. We may earn a commission on qualifying purchases. The publishing app does not receive your payment details or order contents.

Retention

Account identifiers and credentials are kept while needed to operate the connected accounts. Expired or revoked credentials can be replaced or removed by the operator. Content and delivery history may be retained for the life of the project to prevent duplicates and document publication. Privacy correspondence is kept only as needed to resolve the request and any related dispute or legal obligation.

Personal information that is no longer needed can be removed on request, subject to applicable obligations. Removing a live post does not automatically erase historical backups or Git copies, or copies held independently by Meta or other people; those require separate consideration.

Your rights and contact

Where applicable, you may request access, correction, deletion or restriction of your personal data. You may object to processing based on legitimate interests. Other rights, including portability, depend on the circumstances and the applicable legal basis.

For questions or requests, send a private message to the Victim or Villain? Facebook Page, addressed to Aidan Jones, and say that it concerns the uploader app. Do not send passwords or access tokens. The operator may ask for limited information to verify the account or request.

See the data-deletion instructions for disconnecting the app and requesting deletion. You can also raise a concern with the UK’s Information Commissioner’s Office.

Changes

This page will be updated if the app’s data handling changes. The date above identifies the latest revision.