Last updated 26 September 2026
Privacy Policy
notoriouspiginc.com is the portfolio and blog of Samuel Piggott (Notorious P.I.G. Inc.). This page explains what the site collects, and what its private publishing tool does with Facebook, Threads and LinkedIn data.
Visiting the site
- There are no visitor accounts, comments or forms. The site uses no analytics, advertising or tracking, and its public pages don't set cookies.
- The site is hosted on Google Cloud, which logs each request: your IP address, browser user agent, the page requested, the referring page and the time. The site owner can see these logs, and Google Cloud deletes them after 30 days.
- Pages load the Bootstrap stylesheet and script from the jsDelivr CDN, so your browser also requests those files from cdn.jsdelivr.net.
- Emails sent to the addresses on the Contact page go to the site owner's email inbox. The site itself doesn't store them.
Social publishing
The site has a private admin area that only the site owner can sign in to. From there, the owner shares their own blog posts to:
- the site's Facebook Page, using Meta's Facebook Login for Business and Pages API
- the owner's Threads account, using Meta's Threads API
- the owner's LinkedIn profile, using LinkedIn's API
Connecting an account requires being signed in to the admin area, so the only accounts and Pages connected are the owner's own. The tool doesn't read other people's data from Facebook, Threads or LinkedIn: no posts, comments, followers or profiles.
What the publishing tool stores
- Facebook: Meta returns the Pages the owner's account manages, with each Page's ID, name, category and Page access token. The tool keeps only the chosen Page's ID, name and access token, and the permissions granted (
pages_show_list,pages_read_engagement,pages_manage_posts). The user access token used while signing in is never saved. If the account manages several Pages, the list is held for up to 10 minutes in an encrypted cookie in the owner's browser until one is chosen. - Threads: the account's Threads user ID and username, an access token and its expiry date, and the permissions granted (
threads_basic,threads_content_publish). - LinkedIn: the member ID and name, an access token (and a refresh token, if LinkedIn issues one) and its expiry date, and the permissions granted (
openid,profile,w_member_social). - Each shared post: the text drafted or sent, its status, the post ID and link the platform returns, when it was published, and any error message.
How it is used
This data is used only to show which account is connected, to publish posts the owner has reviewed and approved (nothing is posted until the owner clicks Publish), and to keep a record of what was published where. It isn't sold, used for advertising, or shared with anyone else.
It's stored in the site's database, hosted by Neon; the site itself runs on Google Cloud. Access tokens are encrypted (AES-256-GCM) before they're stored, are decrypted only on the server when publishing, and are never shown in the admin area or returned by the site's API.
The owner can optionally ask Google's Gemini API to draft a social post. Gemini receives only the blog post itself (its title, summary, link and text) and the owner's drafting instructions. It never receives Facebook, Threads or LinkedIn data or access tokens.
How long it is kept
A connected account's details are kept until the owner deletes that connection in the admin area; reconnecting replaces the stored token. Records of shared posts are kept as the site's publishing history until they're deleted.
Deleting your data
To ask for data this site holds about you to be deleted, including anything it received from Facebook or Threads, get in touch using the details on the Contact page. The site owner can delete stored connections and publishing records from the admin area. You can also remove the site's access at any time in your Facebook, Threads or LinkedIn settings.