# ClowdBoard: Product guide

> Self-hosted social analytics and publishing for Instagram, Facebook, YouTube and TikTok: one place to see every account, write once, and publish or schedule to all four.

Every customer-facing feature of ClowdBoard, in 21 chapters (204 features). Each entry says what the feature is, why it works the way it does, the exact steps to use it, its hard limits, and what commonly goes wrong. Owner-only tools and unfinished work are deliberately absent.

Read it in the app: https://clowdboard.com/support · Updated 2026-08-18

## Contents

- **Getting started**: 1. Signing in & account security · 2. Connecting social accounts · 3. The Accounts page
- **Measuring**: 4. Home · 5. Analytics · 6. Per-brand & per-channel analytics · 7. How the numbers stay current · 8. Exports
- **Publishing**: 9. The composer · 10. Publishing to Instagram · 11. Publishing to Facebook · 12. Publishing to YouTube · 13. Publishing to TikTok · 14. Writing assistance
- **Working at scale**: 15. Bulk upload · 16. Schedules · 17. The queue & publishing engine
- **Account & billing**: 18. Plans & billing · 19. Teammates & roles · 20. Settings & the app itself · 21. The public site
- **Answers**: Common questions · Contact

---

# Getting started

The first twenty minutes: getting in, protecting the account, and attaching the social profiles ClowdBoard will work on. Everything after this assumes these three chapters are done.

## 1. Signing in & account security

How people get into ClowdBoard, and everything that protects the account once they are in. Two-step sign-in, recovery codes, a live list of signed-in devices, and a security log are all standard, not an upsell on a higher plan.

![The sign-in screen: Google, Facebook, or username and password](https://clowdboard.com/shots/login.webp)

### Things you do

#### Sign in with a username and password

**Where:** `/login`

The standard way in. ClowdBoard identifies an account by username rather than by email: one person can hold several accounts on the same address, which matters for an agency running client workspaces.

**How to use it**

1. Go to clowdboard.com/login.
2. Type the account’s Username, not an email address, into the “Username” field.
3. Type the password into “Password”.
4. Press “Sign in”. You land on Home.

**Specifics**

- Password minimum: 8 characters
- Session length: survives closing the browser; renewed in the background
- If two-step is on: sign-in continues to the “Two-step check” screen instead of Home

> **Watch for** Wrong username and wrong password give the same message on purpose: the sign-in screen never confirms whether an account exists.

#### Sign in with Google

**Where:** `/login`

*ClowdBoard never sees the Google password. It receives an identity from Google and nothing else.*

Sign in using an existing Google account, with no ClowdBoard password to choose or remember. For an organisation this is the safer option: access follows the Google account, so removing someone from Google removes their way in here too.

**How to use it**

1. On /login, press “Continue with Google”. It sits above the “or sign in with email” divider.
2. Pick the Google account on Google’s own screen and approve.
3. You come back to ClowdBoard already signed in.

> **Watch for** This is sign-in only. It does not connect a YouTube channel: that is a separate authorisation on the Accounts page (section 2).

#### Sign in with Facebook

**Where:** `/login`

The same thing through Facebook. Worth being precise about, because it is the most common source of confusion in the product: signing in with Facebook creates a way into ClowdBoard, and connecting Facebook Pages for publishing is an entirely separate authorisation asking for entirely different permissions.

**How to use it**

1. On /login, press “Continue with Facebook”.
2. Approve on Facebook’s screen.
3. You return signed in.

> **Watch for** Also sign-in only: it does not import Pages. Connecting Pages for publishing is a second, separate authorisation with different permissions (section 2).

#### Two-step code at sign-in

**Where:** `/login`

With two-step on, the password alone is not enough: a rotating six-digit code from your phone is required as well. It is the single most effective protection available here, because a ClowdBoard account holds publishing access to every connected brand: a stolen password without the phone gets nowhere.

**How to use it**

1. Enter username and password as normal.
2. The screen becomes “Two-step check”.
3. Open the authenticator app, read the 6-digit code for ClowdBoard, and type it into “Authentication code”.
4. Press “Verify”.

**Specifics**

- Code lifetime: about 30 seconds, then it rotates
- Recovery codes: work in the same field, one use each

> **Watch for** Leave the screen sitting too long and the check expires: the form drops back to the password step. Enter the password again and a fresh code will be accepted. After a recovery code is used, the app tells you how many are left.

#### Forgot password: emailed reset link

**Where:** `/forgot-password`

Self-service recovery: a single-use link, emailed, valid for half an hour. Both limits are deliberate: a reset link is a temporary key to the account, and one that lived in an inbox indefinitely would be a standing liability.

**How to use it**

1. From /login press the forgotten-password link, or go to clowdboard.com/forgot-password.
2. Type the username or the email on the account into “Username or email”.
3. Press “Send reset link”.
4. Open the email and click the link.

**Specifics**

- Link lifetime: 30 minutes
- Uses: one: it stops working after the password is changed

> **Watch for** The success message is identical whether or not the account exists, so the page cannot be used to find out who has an account. It also means nothing arrives if no recovery email was ever saved: set one under Settings → Profile before it is needed.

#### Reset password from that link

**Where:** `/reset-password`

The second half of recovery: set a new password, and the link that got you here stops working immediately.

**How to use it**

1. Open the emailed link. It carries a single-use token in the URL.
2. Type the new password into “New password” and again into “Confirm new password”.
3. Submit. Sign in with the new password.

**Specifics**

- Password minimum: 8 characters

#### Change password while signed in

**Where:** `Settings → Profile`

Changing the password requires the current one and ends every session everywhere, including your own. That is the point: the reason to change a password is usually that a device has been lost or a credential shared, and a change that left the old sessions alive would fix nothing.

**How to use it**

1. Settings → Profile → the “Change password” panel.
2. Fill “Current password”, “New password”, “Confirm new password”.
3. Press “Update password”.

**Specifics**

- Password minimum: 8 characters
- Attempt limit: 15 per 15 minutes

> **Watch for** Changing the password signs the account out everywhere, including the tab you are in. That is deliberate: it is what makes a password change useful after a device is lost.

#### Sign out

**Where:** `Settings → Danger zone`

*Ends the session on this device only. Other devices stay signed in.*

Ends this one session. Deliberately narrow: signing out on a borrowed laptop should not sign you out on your phone. The wider options live in the device list below.

**How to use it**

1. Settings → Danger zone → “Sign out”.

#### Turn on two-step sign-in with an authenticator app

**Where:** `Settings → Security`

Setting up two-step, once. It uses TOTP, the open standard behind every authenticator app, so there is no ClowdBoard app to install and no SMS to intercept. Available on every plan, because charging for the security of an account that can publish to a company’s entire social presence would be indefensible.

**How to use it**

1. Settings → Security → “Two-step verification” → “Turn on two-step”.
2. Confirm your password when asked: turning it on is a protected action.
3. In “Set up two-step verification”, scan the QR code with any authenticator app (Google Authenticator, 1Password, Authy, Microsoft Authenticator).
4. No camera? Press “Can’t scan?” and type the key into the app by hand.
5. Type the app’s current code into “6-digit code” and confirm.
6. ClowdBoard shows “Save your recovery codes”. Save them somewhere outside ClowdBoard, then press “I have saved them”.

**Specifics**

- Standard: TOTP: works with any authenticator app
- Recovery codes issued: 10

> **Watch for** The recovery codes are shown once. If they are lost and the phone is lost too, the only way back is the recovery email.

#### Confirm or switch off two-step

**Where:** `Settings → Security`

One panel that states the current position (on or off, and how many recovery codes are left) and switches it. A security setting whose state you have to infer is a security setting people get wrong.

**How to use it**

1. Settings → Security → “Two-step verification”.
2. The panel states whether it is on, and how many recovery codes remain.
3. To switch it off, press “Turn off two-step” and confirm your password.

#### Recovery codes: issue and regenerate

**Where:** `Settings → Security`

Ten single-use codes that work in place of the authenticator app. They are what stops two-step becoming a way to lock yourself out permanently when a phone is lost or replaced, which is the reason most people give for not turning it on.

**How to use it**

1. Settings → Security → “New recovery codes”.
2. Confirm your password.
3. Save the new list, then press “I have saved them”.

**Specifics**

- Set size: 10
- Each code: works once
- Counter: reads “n of 10 left”

> **Watch for** Generating a new set immediately kills the old one. At two or fewer remaining the panel starts prompting for a new set.

#### See every device currently signed in

**Where:** `Settings → Security`

*One row per signed-in session, with the device and when it was last used. The row you are reading from is marked “This device”.*

Every session currently holding access, with its device and last-used time. This is how you find out that access exists somewhere you did not expect (an old laptop, a machine at a former agency), which you cannot discover any other way.

**How to use it**

1. Settings → Security → “Where you are signed in”.

#### Revoke one device, all others, or everything

**Where:** `Settings → Security`

Ending a session is immediate and per-device, so a single lost phone can be cut off without disturbing anything else. Revoking is separate from changing the password on purpose: it is the fast response, available before you have decided whether the password is actually compromised.

**How to use it**

1. Settings → Security → “Where you are signed in”.
2. Sign out a single device from its own row.
3. To clear every other device at once, press “Sign out everywhere else”.

> **Watch for** “Sign out everywhere else” only appears when there is more than one session: with a single device there is nothing for it to do.

#### Security activity log

**Where:** `Settings → Security`

*Sign-ins, password changes, two-step changes and account disconnects, each with a time. This is the record to check first when something looks wrong.*

A timestamped record of everything that touched access to the account. Its value is entirely in being written before anything goes wrong: when a social account is suddenly disconnected or a password changes unexpectedly, this is the only place that says when it happened and from where.

**How to use it**

1. Settings → Security → “Recent security activity”.

#### Delete the account and everything in it

**Where:** `Settings → Danger zone`

*Removes the account, connected profiles, scheduled posts and history.*

Real deletion, self-service, without emailing anyone to ask. It removes the account, the connected profiles, the scheduled posts and the history, and it cancels any active subscription first, so deleting the account cannot leave a charge running against a record that no longer exists.

**How to use it**

1. Settings → Danger zone → “Delete account”.
2. Type your password into “Your password” in the confirmation dialog.
3. Press “Delete account”.

> **Watch for** There is no undo. Any active subscription is cancelled first, so deleting the account also stops the billing: the order matters, and it is the order ClowdBoard uses.

### Runs on its own

#### Re-enter your password before a sensitive change

**Runs on its own**: nothing to visit, no setting to switch on.

*Asked for again at the actions that move money, keys, or access: turning two-step on or off, issuing recovery codes, disconnecting a social account, changing API keys.*

A short list of actions ask for the password again even though you are already signed in. It closes the gap a stolen session leaves: holding a live session is not the same as knowing the password, and the actions that would let an intruder take the account permanently (turning off two-step, reissuing recovery codes, disconnecting brands) sit behind that second proof.

> **Watch for** This is why a “nothing happened” click on one of those buttons is almost always an un-answered password prompt rather than a failure.

#### Sessions stay alive without re-typing a password

**Runs on its own**: nothing to visit, no setting to switch on.

*The session is renewed quietly in the background and shared correctly across browser tabs, so a long working day never ends in a surprise sign-out.*

The session renews itself while you work, and again when you come back to a laptop that has been closed. There is no idle timer. A tool that is open all day should not interrupt the day to ask who you are, and every one of the revocation controls above still ends a session instantly, so staying signed in costs nothing in control.

## 2. Connecting social accounts

Four platforms, one flow: you sign in on the platform itself and approve access. ClowdBoard never asks for a social password and never sees one. After that the connection maintains itself: the tokens behind it are encrypted at rest and renewed on a schedule.

![The connect dialog: YouTube, Instagram, Facebook and TikTok, each connected over official OAuth](https://clowdboard.com/shots/connecting.webp)

### Things you do

#### Open the connect dialog

**Where:** `Accounts`

*The dialog is titled “Connect an account” and lists YouTube, Instagram, Facebook and TikTok, each with its own “Connect” button. Threads, Bluesky and Pinterest are shown underneath marked SOON.*

One dialog, four platforms, one flow each. Every connection is made by signing in on the platform’s own site and approving there: ClowdBoard never asks for a social password and could not store one if you offered it.

**How to use it**

1. Go to Accounts.
2. Press “Connect account” at the top right. If the roster already has cards, the dashed “Connect a new account” tile at the end of the grid does the same.
3. On a completely empty account, the page shows “No accounts connected” with a “Connect accounts” button in the middle instead.

#### Connect Instagram

**Where:** `Accounts`

Attaches an Instagram Business or Creator account for both analytics and publishing. This route uses Instagram’s own login, so it works for accounts that have never been attached to a Facebook Page: the case that blocks most third-party tools.

**How to use it**

1. Accounts → “Connect account” → press “Connect” on the Instagram row.
2. Instagram’s own login screen opens. Sign in there.
3. Approve the permissions Instagram lists.
4. You are returned to the Accounts page with the profile on the roster.

**Specifics**

- Account type required: Business or Creator
- Facebook account: not required on this route
- Covers: Reels, posts and stories

> **Watch for** A personal Instagram account cannot be connected: Instagram itself blocks API access to it. Switch the account to Professional in the Instagram app first, then connect.

#### Connect Facebook Pages

**Where:** `Accounts`

*One authorisation can bring in several Pages and their linked Instagram accounts at once.*

One authorisation that brings in every Facebook Page the approving profile manages, plus any Instagram professional account linked to those Pages. For an agency holding twenty client Pages on one profile, this is twenty connections from a single approval rather than twenty separate flows.

**How to use it**

1. Accounts → “Connect account” → press “Connect” on the Facebook row.
2. Facebook asks which Facebook profile to use. It does not list Pages at this step: that surprises people, but it is Facebook’s screen, not ClowdBoard’s.
3. Approve.
4. ClowdBoard then pulls every Page that profile manages, plus any Instagram professional account linked to those Pages, whether the link was made by Business conversion or through Page → Settings → Instagram.

> **Watch for** If the Page lives on a different personal Facebook profile than the one already signed in, the browser will keep re-using the signed-in profile. Use an incognito window, or the “Different Facebook login…” button on the Facebook reconnect prompt.

#### Connect YouTube

**Where:** `Accounts`

Attaches a YouTube channel with both read and upload access, so the same connection powers the analytics and the publishing. Google asks you to approve those separately on its consent screen: approving only the read half produces a channel whose numbers appear but which cannot be posted to.

**How to use it**

1. Accounts → “Connect account” → press “Connect” on the YouTube row.
2. Choose the Google account that owns the channel and approve on Google’s screen.
3. You return to Accounts with the channel on the roster.

**Specifics**

- Grants: read access for stats, plus upload access for videos and Shorts
- Covers: channels, videos and Shorts

> **Watch for** Signing in to ClowdBoard with Google does not connect a channel. They are separate authorisations asking for different permissions.

#### Connect TikTok

**Where:** `Accounts`

Attaches a TikTok account for analytics and for publishing. TikTok grants publishing access selectively, which is why many tools can only export a file for you to upload by hand: a connected TikTok account here can be posted to directly (chapter 13).

**How to use it**

1. Accounts → “Connect account” → press “Connect” on the TikTok row.
2. TikTok’s authorisation screen opens. Approve ClowdBoard.
3. You return to Accounts with the account connected.

**Specifics**

- Account type: personal or creator profile
- Covers: videos, Reels and live

#### Reconnect an account whose access has lapsed

**Where:** `Accounts`

Repairs a connection that has stopped working: a revoked approval, a changed password on the platform, a permission withdrawn. Reconnecting repairs the existing account rather than creating a second one, so the collected history stays attached and the numbers fill back in on the next sync.

**How to use it**

1. A card whose access has lapsed shows a red “Connection expired · Reconnect” strip. Press it.
2. The right platform’s sign-in screen opens: Instagram, Facebook, YouTube or TikTok, matched to that card.
3. Approve again. The warning clears once the new access lands.

> **Watch for** Reconnect from the card, not by connecting a second time from the dialog: the card knows which account it is repairing.

#### Disconnect an account

**Where:** `Accounts`

Removes an account and the access token behind it. The normal reason is losing a client or retiring a brand, and if the account is merely dormant, hiding it from Home (chapter 4) is the reversible option that keeps the history.

**How to use it**

1. Accounts → click the card to open its drawer.
2. Scroll to the bottom of the drawer and press “Remove account”.
3. Read the confirmation: it names the account and warns that scheduled posts linked to it will not publish.
4. Press “Remove”, then confirm your password when asked.

> **Watch for** Disconnecting is password-protected because it is hard to undo. Scheduled posts pointing at that account stop publishing: clear or re-point them in the queue first.

#### Link a TikTok account to a brand profile

**Where:** `Profile workspace`

*Linking makes one brand’s Instagram/Facebook presence and its TikTok presence read as a single profile in the workspace.*

Meta hands over the relationship between a Facebook Page and its Instagram account automatically; TikTok has no equivalent, so nothing knows that a TikTok account belongs to the same brand. Linking states it by hand, and the brand’s workspace then reads as one profile across all its platforms instead of one platform sitting on its own.

**How to use it**

1. Open a connected profile’s workspace from Home or Accounts.
2. Press “Link TikTok” in the header (it reads “Change TikTok” if one is already linked).
3. Pick the TikTok account from the menu.

> **Watch for** The button only appears when there is at least one connected TikTok account available to link.

#### Paste a YouTube token by hand

**Where:** `Facebook reconnect dialog → YouTube tab`

*An escape hatch for people running their own Google Cloud project. Almost nobody needs it: the normal YouTube button is the supported route.*

A manual route for anyone running their own Google Cloud project: an organisation whose administrator will not approve third-party apps, typically. Almost nobody needs it, and the ordinary YouTube button is the supported path.

**How to use it**

1. Open the legacy “Add account” dialog (it opens from the Reconnect prompt on a Facebook card).
2. Switch to the YouTube tab.
3. Paste an “Access token”, and ideally a “Refresh token” too.
4. Optionally supply a “Channel ID fallback” beginning UC…
5. Press “Connect with tokens”.

> **Watch for** Without a refresh token the connection lapses when the access token expires and has to be pasted again.

### Runs on its own

#### Access tokens encrypted at rest

**Runs on its own**: nothing to visit, no setting to switch on.

*AES-256-GCM. They are never sent to the browser, and never visible to anyone but the platform they belong to.*

The token behind a connection is the ability to publish as that brand: the most sensitive thing ClowdBoard holds. Tokens are sealed with AES-256-GCM in storage, are never sent to the browser, and are never returned by any API response. It means a token cannot be read out of a page, a network log, or a database copy.

**Specifics**

- Cipher: AES-256-GCM
- Sent to the browser: never

#### Instagram and Facebook access renewed automatically

**Runs on its own**: nothing to visit, no setting to switch on.

*Meta expires access roughly every 60 days. ClowdBoard renews ahead of it, so a working connection stays working without anyone touching it.*

Meta expires access roughly every 60 days by design. ClowdBoard renews ahead of that deadline, so a connection that works keeps working indefinitely. Without it, every Meta account in a portfolio would need re-approving every two months, which for forty accounts is a recurring afternoon.

#### Lapsed connections detected and flagged

**Runs on its own**: nothing to visit, no setting to switch on.

*The account is marked “needs attention” on the Accounts page and in the composer, so a broken connection never fails silently: you find out before a post does.*

Renewal cannot save a connection whose approval was revoked on the platform. When that happens the account is flagged in every place it appears (the roster, the account card, the composer’s account picker) rather than only failing at publish time. A broken connection that announces itself costs a reconnect; one that does not costs a week of missing data and a post that never went out.

#### Plan connection limits enforced at connect time

**Runs on its own**: nothing to visit, no setting to switch on.

*The check happens when you connect, not when you publish, so a plan limit never turns into a failed post.*

The plan cap is checked when you connect an account, which is the only moment it can be enforced harmlessly. Checked later, at publish time or by refusing to sync, a plan limit becomes a failed post or a silently stale account, and the customer discovers their billing state through a broken feature.

#### Meta data-deletion and deauthorize callbacks

**Runs on its own**: nothing to visit, no setting to switch on.

*Required by Meta. When someone removes ClowdBoard from their Facebook settings, Facebook tells ClowdBoard and the matching data is removed here too.*

When someone removes ClowdBoard from their Facebook settings, Facebook calls ClowdBoard and the corresponding data is deleted here too. Meta requires these endpoints of every approved app; having them means revoking access on the platform actually revokes it, rather than leaving a copy behind in a tool the person has stopped using.

## 3. The Accounts page

The roster of every connected account, sorted by audience size. This is where you go when something needs fixing: a lapsed connection, a niche that steers the wrong captions, an account that should stop appearing in totals.

![The Accounts roster: one card per connected account, sorted by audience](https://clowdboard.com/shots/accounts.webp)

### Things you do

#### Account roster, sorted by audience

**Where:** `Accounts`

*The line under the title reads “Connected · n accounts · n platforms · updated 4m ago”, and the counter above the grid reads “n SHOWN · SORTED BY AUDIENCE”.*

Every connected account as a card, ordered biggest audience first. The ordering is the design decision: connection order is an accident of history, while audience order puts the accounts that carry the business at the top of the page every time you open it.

**How to use it**

1. Open Accounts from the sidebar.
2. Every connected account is a card in one grid, biggest audience first.
3. Each card carries the platform mark, the name and handle, the headline numbers for that platform, the niche, and when it was last updated.

> **Watch for** Sorting is by audience, not by when you connected. On a large roster that is the difference between finding the 12,500-follower Page immediately and scrolling past a dozen 13-follower ones.

#### Filter by platform

**Where:** `Accounts`

Narrows the roster to one platform, with a live count per tab. Tabs exist only for platforms you actually use, so the rail describes your portfolio rather than the product’s feature list.

**How to use it**

1. Use the tab rail under the page title: “All platforms”, then one tab per platform you actually use.
2. Each tab shows its own count.
3. Click a tab to filter the grid in place. Click “All platforms” to clear it.

> **Watch for** Tabs only exist for platforms with at least one connected account: an unused platform is not a dead tab.

#### Filter to “needs attention” only

**Where:** `Accounts`

Shows only the accounts that need a person: lapsed connections, mostly. On a roster of forty this converts the weekly maintenance pass from scanning every card into pressing one button and fixing what it lists.

**How to use it**

1. When any account has lapsed, a red “n needs attention” button appears next to the status line.
2. Press it to show only those accounts.
3. Press it again to go back to everything.

> **Watch for** The button is absent when nothing is wrong. That is the intended read: no button, nothing to fix.

#### Search by name, handle, channel, or niche

**Where:** `Accounts`

*Search runs across the display name, the @handle, the channel name and the niche, so “true crime” finds every account set to that niche.*

One box searching across display names, handles, channel names and niches. Searching the niche as well as the name is what makes it more than a finder: typing a niche returns every account in that vertical, which is how you review a whole content lane at once.

**How to use it**

1. Type into the search box above the grid: “Search name, @handle, channel…”.
2. The grid narrows as you type and the counter switches to “3 OF 47 SHOWN”.
3. Press the × in the box to clear.

#### Refresh every account, with live progress

**Where:** `Accounts`

Forces an immediate re-read of every account rather than waiting for the next scheduled pass. The case it exists for is a meeting in five minutes: the collection pipeline (chapter 7) already keeps the numbers current, and this is the override for when “current to within a few hours” is not current enough.

**How to use it**

1. Press “Refresh all” at the top right.
2. The status dot turns to “Syncing” and the button reads “Refreshing”.
3. When it finishes, the “updated …” stamp resets and keeps counting up on its own.

> **Watch for** Platforms rate-limit how often stats can be pulled. Refresh all is for when you need numbers right now: the scheduled collection (section 7) already keeps them current without anyone pressing anything.

#### Refresh one account

**Where:** `Accounts → account drawer`

Re-reads a single account. Two buttons, doing two different things: one refreshes only the drawer in front of you, the other writes the new numbers into ClowdBoard so Home and Analytics see them. Refreshing one account rather than forty is also how you avoid spending a rate-limit allowance you do not need to spend.

**How to use it**

1. Click the card to open its drawer.
2. “Reload live” re-reads the platform and updates what the drawer is showing.
3. “Refresh saved” pulls fresh numbers and writes them into ClowdBoard, so Home and Analytics see them too.

> **Watch for** The two buttons are not the same. “Reload live” only refreshes the drawer in front of you; “Refresh saved” is the one that updates the rest of the app.

#### Edit an account’s niche

**Where:** `Accounts`

*The niche drives caption generation, post generation and template voice for that account.*

A short description of what this account posts, and the highest-leverage field on the page. It is what steers every caption, title and template generated for the account (chapter 14): the same clip on a true-crime account and a pet account should not produce the same caption, and the niche is the only thing that knows the difference.

**How to use it**

1. On the card, click the “Niche” line: it reads “Set a niche” in italics when empty.
2. Describe what the account posts. Be specific: “true crime and killer psychology, real serial killers, their crimes, and the psychology behind them” beats “true crime”.
3. Press “Save niche”.

**Specifics**

- Length limit: 280 characters

> **Watch for** This is the single highest-leverage field on the page. A vague niche produces generic captions, and no amount of prompting downstream fixes it.

#### Account detail drawer

**Where:** `Accounts`

Everything about one account in a panel that slides in over the roster: live profile details read straight from the platform, a link out to the profile itself, and the connection’s real state including when access expires. The connection block is the important half: it is the one place that will tell you an account has stopped syncing and why.

**How to use it**

1. Click any card to slide the drawer in from the right.
2. “Overview (live)” reads straight from the platform: bio, website and counts for Instagram; about, website, fans and category for Facebook; description, subscribers, views and video count for YouTube; followers, following and likes for TikTok.
3. A link opens the profile on the platform itself: “Open in Instagram”, “Open Facebook Page”, “Open on TikTok”, “YouTube Studio”.
4. “Connection” shows the account id and whether access is still valid, with the expiry date when there is one.

> **Watch for** If the drawer says “Connection expired. Reconnect this account to resume syncing”, nothing downstream is being updated for that account until it is reconnected.

#### Edit a Facebook Page’s profile from ClowdBoard

**Where:** `Accounts → account drawer`

*Writes straight to the Page on Facebook: this is the real Page profile, not a ClowdBoard-side copy.*

Edits the real Page on Facebook (the About text, the website, the contact emails) without opening Facebook. For an agency updating a detail across a dozen client Pages, it removes a dozen trips through Facebook’s Page settings, which is the slowest interface any of these platforms has.

**How to use it**

1. Open a Facebook Page’s drawer.
2. Scroll to “Edit page (API)”.
3. Change “About”, “Website”, or “Contact emails (comma-separated)”.
4. Press “Save to Facebook”.

> **Watch for** Facebook only allows this on Pages, and only where the connected profile has permission to edit them. Instagram, YouTube and TikTok profiles are read-only from here.

---

# Measuring

What is happening across every account you manage, and how it is changing. Home is the current state, Analytics is the trend, the profile workspaces are the depth, and the collection pipeline underneath is why all three are already right when you open them.

## 4. Home

The current state of everything you manage, in one screen: four headline numbers and the account roster behind them. Home answers "what do I have and how is it doing right now": it deliberately carries no charts, because trends live on Analytics.

![Home: the KPI rail across the top and the account roster below it](https://clowdboard.com/shots/overview.webp)

### Things you do

#### Total audience

**Where:** `Home`

Every follower, subscriber and fan across every connected account, added up into one number. For someone running one brand it is a vanity metric; for someone running forty accounts across four platforms it is the only number that exists: there is nowhere else, including the platforms themselves, that will tell them how big their whole operation is.

#### Views over the last 30 days

**Where:** `Home`

Total content views across all accounts for the trailing 30 days. Audience size is what you have accumulated; views are what you reached this month. Read together, they say whether the audience is actually being served: a large audience with falling views is the earliest warning a portfolio gives you.

#### Net followers today

**Where:** `Home`

Followers gained minus followers lost since midnight, pooled across accounts. This is a real subtraction, not a gain count: it is measured against a baseline recorded automatically at midnight (chapter 7), which is why it can be negative and why it resets cleanly each day.

#### Posts this month

**Where:** `Home`

How much you have actually published this calendar month, across every account. It exists to be read next to the other three: output is the input you control, and it is the first thing to check when views fall.

#### Every headline number deep-links into the matching chart

**Where:** `Home`

Each of the four stat cards is a link. Clicking one opens Analytics scrolled to the chart that explains it: audience, net followers, views, cadence. The split between the two pages is deliberate: Home tells you the state, Analytics tells you the shape of the change, and the cards are the seam between them so you never have to remember which page holds what.

#### Account roster with platform badges

**Where:** `Home`

Every connected account as a row, each carrying its platform mark and its own numbers. The roster is what makes the totals above it trustworthy: a total nobody can decompose is a number nobody believes.

#### Filter the whole page by platform

**Where:** `Home`

Narrows the page to one platform: the totals recompute and the roster drops to that platform only. Useful when a client or a stakeholder only owns one channel, and when you want to know whether a bad month is everywhere or on one platform.

#### Onboarding checklist

**Where:** `Home`

*Three steps; can be collapsed, dismissed, and brought back.*

A short setup list for a new account: connect a profile, set a niche, publish something. It collapses out of the way and can be dismissed permanently, and it can be re-opened later from Settings → Preferences, so dismissing it is never a decision you are stuck with.

#### Hide an account from Home, or restore it

**Where:** `Home → account roster`

*Hiding is undoable for five seconds. Hidden accounts move to an “Inactive accounts” list underneath.*

Takes a dormant or retired account out of the roster and out of the totals, without disconnecting it. Anyone running a real portfolio has accounts they no longer post to; leaving them in quietly poisons every average on the page. Hiding is reversible at any time and the account keeps collecting data while hidden.

> **Watch for** Hiding changes the totals above the roster. If a number moves the moment you hide something, that is why.

#### Roster of hidden accounts

**Where:** `Home → Inactive accounts`

*Hidden from Home: restore anytime.*

The list of everything currently hidden, kept visible underneath the main roster rather than buried in a menu. Hidden accounts are excluded from the page, not from the product: this list is the proof, so nothing you own can quietly disappear.

## 5. Analytics

Trends over time, pooled across every connected account. Where Home shows the current state, Analytics shows the shape of the change: audience, daily net follower movement, views, posting cadence, biggest movers, and the best recent content.

![Analytics: audience and views charted over the selected window, with the movers list](https://clowdboard.com/shots/analytics.webp)

### Things you do

#### Switch between 7, 30, and 90 days

**Where:** `Analytics`

One control that re-scales every chart on the page at once. The three windows answer different questions: 7 days is “did that post work”, 30 is “is this month better than last”, 90 is “is the strategy working”. Because they all move together, you never end up comparing a 7-day chart against a 90-day one by accident.

#### Audience over time

**Where:** `Analytics`

The accumulated follower count plotted day by day, pooled across accounts. A line that keeps climbing is the easiest thing in the product to show a client, and a flat stretch in the middle of it is the most useful, because it dates the moment something changed.

#### Daily follower change

**Where:** `Analytics`

The same data differentiated: how many followers were gained or lost each day, as bars above and below zero. The audience line always looks like success because it barely moves down; this chart is where losses are actually visible, which makes it the honest half of the pair.

#### Content views

**Where:** `Analytics`

Views your posts collected per day across the window. This is reach, not audience: it responds to what you published this week rather than to everything you have ever published, so it moves first and it moves hardest.

#### Posting activity and cadence

**Where:** `Analytics`

How much you published, per day, over the window. Placed on the same page as the views chart on purpose: the pair answers whether a quiet month was the algorithm or was you. It is also the reality check on a posting schedule: the cadence you intended (chapter 16) versus the cadence that actually happened.

#### Top movers

**Where:** `Analytics`

The accounts that changed most over the window, up and down. With forty accounts nobody scans forty rows looking for the interesting one; this is the product doing that scan. The downward movers matter more than the upward ones: a falling account is the thing you would otherwise notice a month late.

#### Top content, ranked by engagement

**Where:** `Analytics`

*Ranked by engagement rather than raw views, so a small account’s hit is not buried by a large account’s ordinary post.*

The best recent posts pooled across every account. The ranking is engagement relative to reach, not raw views, and that choice is the whole feature: sorted by views, a 300k-follower account’s routine post outranks a 2k-follower account’s genuine breakout every time, and the list stops telling you anything you did not already know.

#### Filter by platform

**Where:** `Analytics`

Restricts every chart to one platform. Platforms do not behave alike: a Reel and a Short with identical content produce different curves, so a pooled chart can hide a platform that is quietly dying inside a healthy total.

#### Instagram audience breakdowns

**Where:** `Profile → Instagram`

*Age, gender, country, city: as far as Instagram will report them.*

Who the followers actually are, as Instagram reports them: age bands, gender split, top countries and cities. This is the demographic slide in a pitch, and the sanity check before a campaign: an audience that turns out to be in the wrong country is worth knowing before the media spend, not after.

> **Watch for** Instagram withholds these breakdowns for accounts under roughly 100 followers, and reports them in bands rather than exact figures. A missing breakdown is usually the platform, not the connection.

#### Instagram mentions

**Where:** `Profile → Instagram`

Posts and comments where the account was tagged. For a brand this is the raw material of social listening: the conversation happening about you rather than by you, collected without anyone monitoring a notification tab.

#### Instagram hashtag search

**Where:** `Profile → Instagram`

Looks up a hashtag and shows what is performing under it right now. Used before publishing, to choose tags on evidence rather than habit.

> **Watch for** Instagram limits how many distinct hashtags an account may look up in a rolling seven-day window. Searching widely for the sake of it spends an allowance you will want later.

## 6. Per-brand & per-channel analytics

One brand at a time, with a pane per platform. This is the depth view: custom date ranges, drill-in dialogs behind every tile, per-post insights, and a heatmap of when the account actually posts.

![One brand: audience split across its platforms, headline tiles, and its top posts](https://clowdboard.com/shots/profile.webp)

### Things you do

#### Profile overview tab

**Where:** `Profile`

The landing tab of a brand’s workspace: that brand’s headline numbers with its platforms side by side. A brand is usually several accounts (an Instagram, a Facebook Page, a TikTok), and this is the only place they are treated as one thing rather than three rows on a roster.

#### Instagram pane

**Where:** `Profile → Instagram`

Everything Instagram reports for this account in one pane: reach and views over the range, the post list with per-post numbers, audience demographics, mentions and the posting heatmap. It is the depth view: the pane you open when Analytics has told you something moved and you need to know which post did it.

#### Facebook pane

**Where:** `Profile → Facebook`

The same treatment for a Facebook Page: fans, views, post-level performance and reactions. Facebook reports a different metric set from Instagram: the pane shows what the Page API actually returns rather than inventing parity with the Instagram pane.

#### YouTube pane

**Where:** `Profile → YouTube`

Channel-level numbers and the video list: subscribers, views, and per-video performance. YouTube is the platform where a single upload keeps earning for months, so the video list here is ordered by performance rather than by upload date.

#### TikTok pane

**Where:** `Profile → TikTok`

Followers, likes and recent video performance for a connected TikTok account, alongside the other platforms rather than in a separate app.

#### 7, 14, 30, 90 day and all-time ranges

**Where:** `Profile`

Five preset windows, including all-time. All-time is the one that matters at this level: it is how you show a brand’s entire history in one chart during a pitch, without exporting anything.

#### Custom date range, up to 365 days

**Where:** `Profile`

Any start and end date within the last year. Presets answer recurring questions; a custom range answers a specific one: a campaign flight, a quarter, the six weeks either side of a rebrand.

**Specifics**

- Maximum span: 365 days

#### Views, Posts, Average engagement and Engagement-rate tiles

**Where:** `Profile`

*Each opens a drill-in dialog rather than being a dead number.*

Four summary tiles, each of which opens rather than just sits there. Clicking one shows the working behind it: the posts and days that produced the figure. A dashboard number you cannot decompose is a number nobody trusts in a meeting, and this is the answer to “where does that come from”.

#### Top posts and recent posts

**Where:** `Profile`

Two lists side by side: what performed best over the range, and what went out most recently. Best posts tell you what to make more of; recent posts tell you whether the last thing you made is tracking or dying.

#### Per-post insights

**Where:** `Profile`

The numbers for one individual post: reach, engagement, and the platform-specific metrics behind it. This is the level at which content decisions are actually made, and it is pulled from the platform rather than estimated.

#### YouTube channel analytics

**Where:** `Channel page`

A dedicated page for a YouTube channel, with the channel-level series and the video catalogue. YouTube carries more per-video metadata than the other platforms, and this page has the room to show it.

#### Posting-activity heatmap by day and hour

**Where:** `Profile → Instagram`

A grid of day-of-week against hour-of-day, shaded by how much this account has published in each cell. It shows the posting habit as it really is rather than as intended, and read next to the best-time recommendations (chapter 14), it is where you see that an account has been publishing into its own quietest hours for months.

**How to use it**

1. Open a brand’s workspace → the Instagram pane.
2. Find the Content card and its day/hour bars.
3. Click any bar to open the full heatmap dialog.

## 7. How the numbers stay current

Nothing in this section has a button. It is the machinery that means the dashboard is already right when you open it, instead of spending thirty seconds fetching. Worth understanding because it is the difference between a report and a dashboard.

### Runs on its own

#### Every account fully refreshed every 4 hours

**Runs on its own**: nothing to visit, no setting to switch on.

On a schedule, ClowdBoard walks every connected account and re-reads it from the platform. This is why the dashboard is already populated when you open it. The alternative, fetching on demand, is what makes most social tools feel like a loading screen with a logo, and it is also what gets an app rate-limited the moment several people open it at once.

**Specifics**

- Interval: every 4 hours

#### Warm pass shortly after the server starts

**Runs on its own**: nothing to visit, no setting to switch on.

*So the first person to sign in after a restart does not pay for the cold cache.*

After a restart the caches are empty, and whoever signs in first would otherwise wait for every fetch. A warm pass runs on startup and fills them before anyone arrives. It is a small thing that decides whether a deploy is invisible or is a bad first impression.

#### Instagram and Facebook analytics cached for 6 hours

**Runs on its own**: nothing to visit, no setting to switch on.

Meta’s insight numbers update slowly at their end, so re-fetching them more often than every few hours returns the same values while spending an allowance that is not unlimited. Six hours is set to match how fast the underlying data actually changes.

**Specifics**

- Cache lifetime: 6 hours

#### YouTube video lists cached for 30 minutes

**Runs on its own**: nothing to visit, no setting to switch on.

A shorter window than Meta’s, because a channel’s video list changes the moment you upload and you expect to see it. Different platforms get different cache lifetimes deliberately: a single global setting would be either stale on YouTube or wasteful on Meta.

**Specifics**

- Cache lifetime: 30 minutes

#### Background warmer over a 90-day window

**Runs on its own**: nothing to visit, no setting to switch on.

Historical data is fetched ahead of being asked for, across a rolling 90-day window, so switching Analytics to the 90-day range is instant rather than a fetch. It is the reason the range selector feels like a filter instead of a query.

#### Rate governor and credential parking

**Runs on its own**: nothing to visit, no setting to switch on.

*When a platform starts rate-limiting, ClowdBoard backs off and parks that credential rather than hammering it and getting the whole app throttled.*

Every platform will throttle an app that asks too often, and the penalty usually lands on the whole app rather than the one account that caused it. When a credential starts being rate-limited, ClowdBoard stops using that one, backs off, and carries on with the others. One misbehaving account never takes the rest of a portfolio down with it.

#### Daily follower baseline recorded at midnight

**Runs on its own**: nothing to visit, no setting to switch on.

*This is what makes "net followers today" a real number instead of a guess.*

Platforms report a current follower count, not a change. Without a stored reading from a known moment there is nothing to subtract from, and “net followers today” would be an estimate. A baseline written at local midnight each day is what turns it into arithmetic, and it is also what lets the daily-change chart show losses at all.

#### Nightly database backup, 14 kept

**Runs on its own**: nothing to visit, no setting to switch on.

A complete backup runs each night and the last fourteen are retained, so there is always a fortnight of recoverable history. Years of collected analytics cannot be re-fetched from the platforms, most of which only serve a recent window. That makes the backup the difference between an incident and a permanent loss.

**Specifics**

- Frequency: nightly
- Copies kept: 14

## 8. Exports

Getting data out, as CSV. Large exports run as background jobs with progress and a retry, so a big pull does not tie up the browser.

### Things you do

#### Account roster CSV

**Where:** `Home`

Every connected account with its current numbers, as a spreadsheet. The usual destination is a client report or a board deck: the point of the export is that ClowdBoard does not have to be the last stop for the data it collects.

#### Follower history CSV

**Where:** `Home, Analytics`

The day-by-day follower series, per account. This is the export that matters most, because it is the one thing the platforms will not give back: Instagram and Facebook only serve a recent window, so history that was not recorded as it happened cannot be recovered. Exporting it puts a copy somewhere you control.

#### Recent posts CSV

**Where:** `Analytics`

Recent posts with their performance figures, for analysis somewhere else: a pivot table, a BI tool, a model. Content analysis quickly outgrows any fixed set of charts, and this is the escape hatch for when it does.

### Runs on its own

#### Background export jobs with progress, download and retry

**Runs on its own**: nothing to visit, no setting to switch on.

A large export runs on the server as a job rather than in the browser: you see progress, the download appears when it is finished, and a failure can be retried without starting over. It is the difference between exporting a year of history for forty accounts and watching a tab hang until it is killed.

---

# Publishing

Posting to Instagram, Facebook, YouTube and TikTok from one screen. The composer is shared, so the four platform chapters cover only what is genuinely different about each one: the formats, the limits, and the platform rules ClowdBoard enforces for you.

## 9. The composer

Every publishing screen is built from the same parts: pick accounts, drop media, see a real preview of how it will look on the platform, then publish now or pick a time. Learn it once and all four platforms are familiar.

![The composer: account picker and caption on the left, live phone preview on the right](https://clowdboard.com/shots/composer.webp)

### Things you do

#### Account picker showing connection health

**Where:** `All publishing screens`

*A dot per account, so you find out a connection has lapsed before you write the post, not after you hit publish.*

The list of accounts you can post to, each carrying a live status dot. The dot is the feature: a lapsed connection is visible while you are choosing where to post, rather than surfacing as a failure after you have written the caption, attached the video and pressed publish.

#### Drag-and-drop media, or browse

**Where:** `All publishing screens`

Drop files onto the composer or pick them from a file dialog. Video is validated as it lands: format, size and duration are checked against the target platform’s rules before anything is uploaded, so an unusable file is rejected in a second rather than after a long upload.

#### Live preview in the platform’s own chrome

**Where:** `All publishing screens`

The post rendered as it will appear on the platform: the real frame, the real caption truncation point, the real aspect crop. Every platform crops and truncates differently, and a preview that does not model that is decoration. This one exists so you find out that your first line is cut off before the audience does.

#### Publish now

**Where:** `All publishing screens`

Sends the post immediately. The composer stays in place while it works and reports the outcome, including the platform’s own error text when something is rejected: a rejection you cannot read is a rejection you cannot fix.

#### Pick a time

**Where:** `All publishing screens`

Choose a date and time instead of publishing now; the post joins the queue (chapter 17) and ClowdBoard publishes it. It does not depend on your browser, your laptop being open, or the platform’s own scheduler, which several of them do not offer at all for the formats ClowdBoard supports.

#### Auto-schedule into the next open slot

**Where:** `Instagram composer`

Instead of choosing a time, drops the post into the next free slot in that account’s cadence (chapter 16). It is the shortcut for the common case: you know it should go out soon and on-pattern, and you do not want to open a calendar to work out when that is.

### Runs on its own

#### Media upload pipeline

**Runs on its own**: nothing to visit, no setting to switch on.

Handles moving the file from the browser to the platform: chunked for large videos, resumable, and validated on arrival. Every platform has different rules about how a file must be delivered (some want a URL to fetch, some want a multi-stage upload session), and this is the layer that hides that difference from the composer.

#### Media compose and transform

**Runs on its own**: nothing to visit, no setting to switch on.

Adjusts media to fit a platform’s requirements where it can: aspect and format handling that would otherwise be a rejection, or a trip through a separate editor before you could post at all.

## 10. Publishing to Instagram

Every Instagram surface: feed, Reels, Stories and carousels, with caption tooling built around how people actually post, saved templates, and hashtags moved into a first comment so the caption stays readable.

![The Instagram composer: post, reel, story and carousel modes with the post-details rail](https://clowdboard.com/shots/instagram.webp)

### Things you do

#### Feed post

**Where:** `Instagram composer`

A standard image or video post to the grid: the permanent, profile-defining format. Published straight to Instagram through the official API, so it behaves exactly as a post made in the app does.

#### Reel

**Where:** `Instagram composer`

Short-form vertical video, the format Instagram currently pushes hardest to non-followers. Reels are how accounts grow on Instagram in practice, which makes this the most-used publish path in the product.

**Specifics**

- Aspect: 9:16 vertical
- Also appears: in the profile grid unless excluded

#### Story

**Where:** `Instagram composer`

A 24-hour post to the Stories tray. Stories are the format that talks to people who already follow you: the daily contact that keeps an audience warm between grid posts.

**Specifics**

- Lifetime: 24 hours

#### Carousel, up to 10 slides

**Where:** `Instagram composer`

A multi-image or mixed-media post that swipes. Carousels earn more engagement per post than single images because each swipe is another interaction, which is why educational and listicle content lives in this format.

**Specifics**

- Maximum slides: 10

#### Caption editor: 2,200 characters, 30 hashtags

**Where:** `Instagram composer`

The caption field, with Instagram’s real limits counted as you type rather than discovered on rejection. Both numbers are Instagram’s, not ClowdBoard’s.

**Specifics**

- Caption limit: 2,200 characters
- Hashtag limit: 30

> **Watch for** Instagram counts the hashtags in the caption and in the first comment together against the same 30.

#### Saved caption templates, up to 10

**Where:** `Instagram composer`

Reusable caption skeletons (a call to action, a sign-off, a standing hashtag block) saved once and applied to any post. Anyone publishing daily is retyping the same closing lines; templates are where that repetition goes.

**Specifics**

- Templates kept: 10

#### Cross-post to Facebook

**Where:** `Instagram composer`

Publishes the same post to a linked Facebook Page in the same action. Most brands maintain both and post identical content to each; this turns two publishing sessions into one, and keeps the two timelines genuinely in step.

#### Cross-post to TikTok

**Where:** `Instagram composer`

Sends the same vertical video to a connected TikTok account. Reels and TikToks are usually the same asset, and this is the toggle that stops that being two uploads of the same file.

#### Hashtags posted as the first comment

**Where:** `Instagram composer`

Moves the hashtag block out of the caption and posts it as the first comment automatically, a moment after the post goes live. It is a well-established practice: the tags still work, and the caption stays readable instead of ending in a wall of blue text. Doing it by hand means going back to the app after every post.

#### Best-time-to-post card

**Where:** `Instagram composer`

A recommended posting time for this specific account, shown while you are composing. It is derived from that account’s own history rather than a published list of “best times to post”, which is the difference between advice and a general-interest article.

### Runs on its own

#### Product tagging

**Runs on its own**: nothing to visit, no setting to switch on.

Attaches catalogue products to a post so they are shoppable in-app. Available where the connected Instagram account has an approved Shop.

## 11. Publishing to Facebook

Full Page publishing (text, links, photos, video and Reels) plus the Page-specific things that matter to a business: a call-to-action button, link attachments, and audience targeting.

![The Facebook studio: post, video and reel modes beside a live feed preview](https://clowdboard.com/shots/facebook.webp)

### Things you do

#### Text or link post

**Where:** `Facebook composer`

A plain status or a shared link. Facebook is the only one of the four platforms where a text-only post is still a normal thing to publish, and the only one where a link reliably carries traffic off-platform, which is why it stays the channel businesses use to send people somewhere.

#### Single photo

**Where:** `Facebook composer`

One image with a caption, published to the Page.

#### Multi-photo, up to 10

**Where:** `Facebook composer`

Several images in one post, as a real Facebook multi-photo post rather than ten separate ones. Each image is uploaded and then attached to a single published post: the same thing the Facebook app does, which is why it looks native in the feed.

**Specifics**

- Maximum photos: 10

#### Video

**Where:** `Facebook composer`

Standard video upload to the Page: landscape or square, the long-form half of Facebook video.

#### Reel

**Where:** `Facebook composer`

Vertical short-form video to Facebook Reels, which Facebook distributes to non-followers the way Instagram does. Publishing a Reel takes three separate calls to Facebook (start the session, upload the file, then finish it), and ClowdBoard runs all three; a partial sequence produces a video that exists but never appears.

#### Scheduled Page post

**Where:** `Facebook composer`

A time chosen for a Page post. Facebook can hold the post itself, which means it is Facebook publishing at the appointed moment rather than ClowdBoard: one less system that has to be awake.

#### Call-to-action button

**Where:** `Facebook composer`

Attaches a Facebook CTA button (Shop Now, Learn More, Sign Up) to the post. This is one of the features that makes Facebook a commercial channel rather than a broadcast one, and it is not available on the other three platforms at all.

#### Link attachment

**Where:** `Facebook composer`

Attaches a URL so Facebook renders its link preview card: the image, title and description pulled from the page. The preview card is what makes a link clickable in practice; a bare URL in the text gets a fraction of the traffic.

#### Audience targeting

**Where:** `Facebook composer`

Restricts an organic Page post to a slice of the Page’s audience: by location, language, age. Useful for a Page with a genuinely split audience, where a regional announcement would otherwise be noise to everyone else. This is organic targeting, not paid: no budget is involved.

## 12. Publishing to YouTube

Long-form and Shorts, with the full metadata set YouTube ranks on (title, description, tags, category, visibility) and a live SEO score while you type.

### Things you do

#### Video upload, up to 350MB

**Where:** `YouTube composer`

Long-form video to the channel, uploaded with its full metadata in one action rather than uploaded first and edited afterwards in YouTube Studio.

**Specifics**

- Maximum size: 350MB

#### Shorts

**Where:** `YouTube composer`

Vertical short-form video. YouTube decides a video is a Short from its shape and length rather than from a switch, so the same upload path produces one: the composer just makes the requirements visible so you know which you are publishing.

#### Custom thumbnail

**Where:** `YouTube composer`

*16:9, under 10MB.*

Replaces YouTube’s auto-generated frame with your own image. On YouTube the thumbnail is the single largest lever on click-through, and the auto-generated frame is almost always a bad frame, which makes this a required field in practice, not an optional one.

**Specifics**

- Aspect: 16:9
- Maximum size: 10MB

#### Title, 100 characters, with regenerate

**Where:** `YouTube composer`

The title field with YouTube’s real limit, and a regenerate control that proposes alternatives (chapter 14). Titles are ranked on and searched against, so this is the field that decides whether a video is ever found.

**Specifics**

- Limit: 100 characters

#### Description, 5,000 characters

**Where:** `YouTube composer`

The description body: links, chapters, credits. YouTube indexes it for search, and it is where the outbound links live, so it does real work beyond being a caption.

**Specifics**

- Limit: 5,000 characters

#### Visibility and "made for kids"

**Where:** `YouTube composer`

Public, unlisted or private, plus the audience declaration YouTube requires on every upload. “Made for kids” is a legal obligation under COPPA, not a preference, and getting it wrong carries real consequences, so the composer asks rather than assuming a default.

#### Scheduled premiere

**Where:** `YouTube composer`

Uploads the video as private with a public release time, so it goes live at a set moment with a countdown. Premieres let an audience gather before the video starts, which is why launches and series episodes use them.

#### Tags, category, and a live SEO score

**Where:** `YouTube composer`

The ranking metadata, with a score that updates as you type. The score is a checklist made visible (title length, description depth, tags present, thumbnail set), so the fields that get skipped under time pressure are the ones the page keeps pointing at.

#### Import a Reel from a linked Instagram account

**Where:** `YouTube composer`

Pulls an existing Instagram Reel into the YouTube composer as the source video, ready to publish as a Short. It closes the most common repurposing loop in short-form without a download, a re-encode, and a re-upload.

## 13. Publishing to TikTok

Direct posting and drafts, with TikTok’s own account settings read before you publish, so the options shown are the ones that account is actually allowed to use.

### Things you do

#### Account settings checked before publishing

**Where:** `TikTok composer`

*TikTok is asked what this account may do, and the form matches the answer.*

Before the form is drawn, ClowdBoard asks TikTok what this specific account is permitted to do, which privacy levels are allowed, whether duet and stitch are available, how long a video may be. TikTok’s rules differ per account and change without notice, so the composer reads them rather than assuming. It is the reason the options you are shown are options that will actually be accepted.

#### Direct video post, up to 500MB

**Where:** `TikTok composer`

Publishes straight to the account’s feed. Direct posting is a capability TikTok grants selectively, and most third-party tools can only push a draft, so this is the difference between scheduling TikTok and being reminded to open TikTok.

**Specifics**

- Maximum size: 500MB

#### Save to drafts

**Where:** `TikTok composer`

Sends the video to the account’s TikTok drafts instead of publishing, ready to be finished in the app. The route to take when you want TikTok’s own editor (sounds, effects, on-platform text) but do not want to move the file to a phone by hand.

#### Comment, duet and stitch toggles

**Where:** `TikTok composer`

Per-post control over whether people can comment, duet or stitch. On TikTok these are distribution decisions as much as moderation ones: duet and stitch are how a video spreads through other creators, and turning them off on a video meant to travel is a real cost.

#### Cover-frame picker

**Where:** `TikTok composer`

Choose which frame of the video becomes the cover in the profile grid. The default is the first frame, which on a video that opens on a cut or a black frame is the worst possible choice.

#### Commercial, branded and AI disclosure

**Where:** `TikTok composer`

TikTok’s required declarations: whether the video promotes your own brand, whether it is a paid partnership, and whether the content is AI-generated. These are compliance obligations with penalties attached, not preferences, and TikTok validates the combination: some pairings are not permitted, and the composer will not let you submit one.

## 14. Writing assistance

Caption and title generation, steered by the account’s niche. Generation runs on your own API key (set one in Settings → API keys), so nothing is written by a model you did not choose and did not pay for.

### Things you do

#### Caption generation

**Where:** `Instagram composer, Bulk`

Writes a caption for the post in front of you, steered by the account’s niche (chapter 3) rather than by a generic prompt. The niche is what makes the output usable: the same clip on a true-crime account and on a pet account should not produce the same caption, and without a specific niche it will.

> **Watch for** Generation needs an API key of your own, set in Settings → API keys. A vague niche produces generic captions, and no amount of re-generating fixes that: fix the niche instead.

#### Long or short caption style

**Where:** `Instagram composer, Bulk`

Two lengths, because two things are being written. Short is a hook that survives Instagram’s truncation point; long is a caption meant to be expanded and read. Choosing between them is a format decision, not a preference.

#### Generate captions for a whole batch

**Where:** `Bulk`

*Runs five at a time and can be stopped part-way.*

Runs caption generation across every row of a bulk upload. Captioning forty clips by hand is the part of a batch that actually takes the afternoon; this reduces it to reviewing and editing. It runs five at a time so a large batch does not hammer your API key, and it can be stopped mid-run: what has been generated is kept.

#### YouTube title generation

**Where:** `YouTube composer, Instagram cross-post`

Proposes titles for a video. YouTube titles do a different job from captions: they are searched against and ranked on, and they carry the click, so they are generated against title-writing conventions rather than treated as a short caption.

#### Best-time recommendations

**Where:** `Instagram composer, Schedules`

*Built from the account’s own posting and engagement history.*

Suggested posting times for a specific account, computed from when that account’s own posts have actually performed. Published “best time to post” tables are averages across millions of accounts and describe none of them; this describes yours. It feeds the composer’s best-time card and the slot generator in Schedules.

> **Watch for** A new account with little history has little to compute from: the recommendations get sharper as posting history accumulates.

---

# Working at scale

The difference between running three accounts and running forty. A week of content goes in as a batch, a cadence decides when each piece goes out, and the queue publishes it without anyone watching.

## 15. Bulk upload

The reason someone with forty accounts uses ClowdBoard instead of the native apps. Drop a folder of clips, let filenames route them to the right accounts, caption them in a pass, and spread them across the week’s open slots.

![Bulk upload: drop up to forty videos, filenames routing each one to an account](https://clowdboard.com/shots/bulk.webp)

### Things you do

#### Drop up to 40 videos at once

**Where:** `Bulk`

*Up to 350MB each.*

Drag a folder of clips onto the page and each becomes a row in a grid. Forty is a week of content for a large portfolio; the ceiling exists so a single submission stays reviewable rather than becoming a wall nobody checks.

**Specifics**

- Files per batch: 40
- Maximum per file: 350MB

#### Filenames route clips to accounts

**Where:** `Bulk`

*Name a file @handle-title.mp4 and it lands on that account.*

If a filename starts with an @handle, the clip is assigned to that account automatically on drop. This is the feature that makes bulk upload viable at forty accounts: the alternative is choosing an account from a dropdown forty times, and the routing decision has usually already been made in the editing folder anyway.

> **Watch for** A handle that does not match a connected account leaves the row unassigned rather than guessing: check the rows before submitting.

#### Drag to reorder

**Where:** `Bulk`

Rows can be dragged into a different order. Order matters because the auto-schedule assigns slots top to bottom, so reordering the grid is how you decide what goes out first.

#### Per-row account and platform

**Where:** `Bulk`

Every row keeps its own destination: a different account, a different platform, or several. A batch is rarely for one account, and forcing one destination per batch would mean running the same process five times.

#### Per-row caption, with generate

**Where:** `Bulk`

Each row has its own caption field, editable inline, with generation available per row as well as across the whole batch. Generated captions are a starting point that you edit in place: you never leave the grid to fix one.

#### Per-row cross-post toggles

**Where:** `Bulk`

Cross-posting decided per clip, not per batch. Some clips belong on every platform and some are made for one; a batch-level setting would force the wrong answer onto half the rows.

#### Per-row publish now or schedule

**Where:** `Bulk`

Rows can be mixed: some published immediately, others given a time. A real batch usually contains one thing that is time-sensitive and thirty-nine that are not.

#### Bulk actions

**Where:** `Bulk`

*Copy a caption to every row, set all, clear cross-posts.*

Operations that apply to the whole grid at once: push one caption to every row, set every destination, clear every cross-post toggle. They exist for the case where the batch is genuinely uniform, which turns forty edits into one.

#### Set a time for all, with spacing presets

**Where:** `Bulk`

Assigns times across the whole batch with a fixed gap between them. Publishing forty clips at once to the same account is throttled by the platform and reads as spam to the audience; spacing is how a batch becomes a week of posting rather than one minute of it.

#### Preview an auto-schedule before applying it

**Where:** `Bulk`

Shows the times each row would receive, worked out against each account’s cadence and open slots, before anything is committed. Auto-scheduling forty posts is exactly the kind of action nobody wants to discover the results of afterwards, so the preview is a real step rather than a confirmation dialog.

#### Submit everything, with a daily-quota warning

**Where:** `Bulk`

*Instagram caps daily publishes; you are told before you exceed it, not after.*

Commits the batch. Instagram enforces a hard daily publishing limit per account, and posts beyond it are simply refused. ClowdBoard counts what is already scheduled against that limit and warns before submission, so an over-quota batch is caught while it can still be re-spaced, rather than at 3am when the queue tries to publish it.

> **Watch for** The quota is per Instagram account per rolling 24 hours, and scheduled posts already in the queue count towards it.

## 16. Schedules

A posting cadence per account: how often, which days, and at what times. Once a schedule exists, everything else can fill it: bulk upload, auto-schedule, and the queue all draw from these slots.

![Schedules: a cadence per account, with its weekly slots laid out](https://clowdboard.com/shots/schedules.webp)

### Things you do

#### Cadence per account

**Where:** `Schedules`

*One to six times a day.*

How many times a day this account should publish. Set per account rather than globally, because a daily-Reels account and a twice-a-week Page are not running the same operation. This one number is what every slot below it is derived from.

**Specifics**

- Range: 1–6 posts per day

#### Active-day toggles

**Where:** `Schedules`

Which days of the week the account posts at all. Most business Pages go quiet at the weekend and most entertainment accounts do their best numbers there: the schedule should encode which of those you are, rather than treating all seven days the same.

#### Weekly slot editor

**Where:** `Schedules`

The actual times, laid out as a week, each one editable. The cadence decides how many slots exist; this is where you say when. Everything that fills a queue automatically (bulk auto-schedule, the composer’s next-open-slot) draws from exactly these times.

#### Lock a slot

**Where:** `Schedules`

Pins one time so regenerating the schedule leaves it alone. There is usually one slot that is not negotiable (a standing weekly feature, a time that has been trained into the audience), and locking it means you can regenerate everything else without losing it.

#### Minimum gap between posts

**Where:** `Schedules`

*30 to 90 minutes.*

The floor on how close together two slots may sit. Posts stacked too tightly compete with each other for the same impressions, and platforms throttle rapid repeat publishing. The gap is the guard that stops a generated schedule producing six posts in an evening.

**Specifics**

- Range: 30–90 minutes

#### Choose what the times are based on

**Where:** `Schedules`

*When the audience is online, the account’s own history, or general best practice.*

Three sources for generated times, in descending order of how specific they are to you: when this account’s audience is actually online, when this account’s own posts have performed, or general best practice. Named explicitly so you always know which one produced the times in front of you: the third is a fallback for a new account, not an equal option.

#### Generate a set of times

**Where:** `Schedules`

Fills the whole week from the cadence, the active days, the minimum gap and the chosen source: in one action, respecting any locked slots. Hand-placing eighteen weekly times across forty accounts is not work anyone does twice.

#### Copy one schedule to other accounts

**Where:** `Schedules`

Applies a schedule you have tuned to any number of other accounts at once. Portfolios cluster: a dozen accounts in the same niche and timezone want the same cadence, and this is how one good schedule becomes twelve without twelve editing sessions.

## 17. The queue & publishing engine

Everything scheduled, in one list, updating live. Behind it is the part nobody sees until it matters: a scheduler that will not double-publish, spaces posts to the same account apart, and retries failures differently depending on why they failed.

![The queue: every scheduled post in one list, filtered by status](https://clowdboard.com/shots/queue.webp)

### Things you do

#### Every scheduled post in one list

**Where:** `Queue`

Everything waiting to publish, across every account and platform, in one table. This is the answer to “what is going out this week”: a question that otherwise requires opening four apps and forty accounts, and that nobody can answer confidently without it.

#### Filter by status

**Where:** `Queue`

*Pending, overdue, publishing, draft, published, failed.*

The status filter is the queue’s primary control, and the vocabulary is deliberate. Pending is waiting; overdue is late and needs a look; publishing is in flight right now; failed needs a decision. Opening the page and pressing Failed is the whole daily check for most operators.

#### Search by caption or handle

**Where:** `Queue`

Free-text search across captions and account handles. The realistic way to find one post in several hundred is to remember a phrase from it.

#### Filter by account

**Where:** `Queue`

Narrows the queue to one account: what you do before a client call, or when one account needs re-planning without touching the rest.

#### Filter by date range

**Where:** `Queue`

Restricts the list to a window. Combined with the account filter it answers the question a client actually asks: what is going out for me, next week.

#### Edit a queued post

**Where:** `Queue`

Change the caption, the media or the destination of a post that has not gone out yet. A scheduled post is a draft until the moment it publishes, and it should stay editable that whole time: the alternative is deleting and rebuilding it.

#### Reschedule with presets

**Where:** `Queue`

Move a post with one click (later today, tomorrow, next week) rather than opening a date picker. Rescheduling is the most frequent action taken in a queue, and presets cover almost all of it.

#### Publish something now

**Where:** `Queue`

Jumps a scheduled post to the front and publishes it immediately. For the moment something becomes newsworthy early, or an overdue post needs to go out without waiting for the next cycle.

#### Retry a failed post

**Where:** `Queue`

Re-attempts a post that failed, after you have fixed whatever caused it: usually a reconnect. The post keeps its content and destination, so a retry is one click rather than a rebuild.

#### Delete one, several, or clear the queue

**Where:** `Queue`

Remove a single post, a selection, or everything. Clearing exists because a genuinely wrong batch (the wrong folder, the wrong account) is a real event, and the fix should not be four hundred individual deletions.

> **Watch for** Deleting from the queue is permanent and there is no undo. It only affects unpublished posts; anything already live stays live on the platform.

#### Live updates without refreshing

**Where:** `Queue`

Rows change state on screen as the scheduler works: pending becomes publishing becomes published. During a large batch this is the difference between watching it work and reloading a page to find out whether it did.

### Runs on its own

#### Scheduler runs every 60 seconds

**Runs on its own**: nothing to visit, no setting to switch on.

A cycle every minute picks up everything now due and publishes it. A minute is the resolution of the whole scheduling system: it is fine enough that a chosen time is honoured in practice, and coarse enough that the machinery is not spending its life waking up.

**Specifics**

- Cycle: every 60 seconds

#### Posts to the same account are spaced apart

**Runs on its own**: nothing to visit, no setting to switch on.

*Eight seconds for video, four for images: enough that the platform treats them as separate posts.*

When several posts to one account come due together, they are published a few seconds apart rather than simultaneously. Platforms treat simultaneous posts from one account as automated behaviour and may drop or throttle them; the gap is small enough to be invisible and large enough to avoid that.

**Specifics**

- Video: 8 seconds apart
- Images: 4 seconds apart

#### Three retry tracks, by failure type

**Runs on its own**: nothing to visit, no setting to switch on.

*A rate-limit is retried patiently; a bad token is not retried at all, it is surfaced.*

Failures are not all the same and are not treated the same. A rate-limit is temporary, so it is retried after a wait. A malformed post will fail identically forever, so it is not retried at all. A lapsed connection needs a person, so it is surfaced immediately rather than retried into the ground. Undifferentiated retries either give up on recoverable failures or hammer unrecoverable ones: both produce a queue nobody trusts.

#### Never publishes the same post twice

**Runs on its own**: nothing to visit, no setting to switch on.

*Enforced by design, not by hope: only one scheduler may run against a database.*

Duplicate publishing is the worst failure a scheduling tool has, because it is public and cannot be taken back. ClowdBoard guarantees against it structurally: exactly one scheduler process may run against a database, and a post is claimed before it is sent. It is a design constraint that is enforced rather than a check that might be skipped.

---

# Account & billing

Plans, teammates, preferences, and the parts of the product that are not a feature so much as a promise: what it costs, who else can get in, what happens if you stop paying, and what the app tells us about you when something breaks.

## 18. Plans & billing

Four tiers, priced on how many social connections you need and how many people need their own login. Billing runs through Stripe, which means ClowdBoard never handles a card number, and entitlement is enforced server-side, so a lapsed subscription becomes read-only rather than a locked door in front of your own data.

### Things you do

#### Four plans, by connection count and seat count

**Where:** `Billing`

*8, 25, 100, or unlimited connections; 1, 3, 10, or unlimited seats.*

Pricing scales on two things only: how many social connections you need, and how many teammates need their own login. Every plan has every feature. The connection number counts connections, not brands: a brand with an Instagram, a Facebook Page and a TikTok is three connections. Metering on capacity rather than on features means the product never withholds something you need to do the job, and a growing customer pays more only when they are genuinely running more.

**Specifics**

- Connection caps: 8 · 25 · 100 · unlimited
- Seat caps: 1 · 3 · 10 · unlimited

#### Monthly or annual

**Where:** `Billing`

*Annual saves 20%.*

Both billing periods on every tier, with a fifth of the year free for paying annually. Switching between them is done in Stripe’s portal and takes effect at the next renewal.

**Specifics**

- Annual discount: 20%

#### Manage the subscription in Stripe’s portal

**Where:** `Billing`

Card changes, invoices, receipts, plan changes and cancellation all happen on Stripe’s own hosted pages. ClowdBoard never sees or stores a card number: that is the security posture, and it is also why the billing screens look like Stripe rather than like ClowdBoard.

### Runs on its own

#### Subscription status synced automatically

**Runs on its own**: nothing to visit, no setting to switch on.

Stripe notifies ClowdBoard when a payment succeeds, fails, or a subscription changes, and access updates immediately. Nobody has to reconcile a payment by hand, and a successful payment never leaves an account locked out waiting for someone to notice.

#### Existing subscribers keep their price

**Runs on its own**: nothing to visit, no setting to switch on.

*When pricing changes, an old plan keeps resolving to the tier it was sold as.*

When list prices change, existing subscriptions keep resolving to the tier they were sold as, at the price they were sold at. Price rises never reach back to people who already bought, which is what makes a long-term customer safe to become one.

#### Entitlement enforced server-side

**Runs on its own**: nothing to visit, no setting to switch on.

*A lapsed account goes read-only. The data stays.*

What a plan permits is decided on the server, not in the browser, so entitlement cannot be bypassed by editing a page. Just as importantly, a lapsed subscription makes the account read-only rather than locked: publishing and connecting stop, but the analytics history is still yours to read and export. Years of collected data are not a hostage.

## 19. Teammates & roles

A workspace can hold more than one person. Each seat is a separate account with its own password, its own two-step sign-in and its own sessions: what they share is the workspace they act on, not a set of credentials. Three roles decide what each seat can do, and the server decides, not the browser.

### Things you do

#### Invite a teammate

**Where:** `Settings → Team`

*Owners and admins can invite. The link is single-use and expires in seven days.*

Adds a person to the workspace without handing over your password. They receive a link, choose their own username and password on it, and land in the same workspace you are in: the same connected accounts, the same queue, the same analytics. This is the answer to the question every organisation asks first: how do four marketers use this without sharing one login.

**How to use it**

1. Open Settings → Team.
2. Type their email into the “Email address” field.
3. Choose “Member” or “Admin” with the two-button role picker beside it.
4. Press “Send invitation”. Confirm the step-up prompt if it appears.
5. They appear under “Pending invitations” until they accept.

**Specifics**

- Invitation lifetime: 7 days
- Uses per link: one
- Invitations per hour: 20 per workspace
- Roles you can grant: Member, Admin: Owner is not grantable

> **Watch for** A pending invitation occupies a seat. If the plan is full, revoke an unaccepted invitation before sending another one.

#### Three roles

**Where:** `Settings → Team`

*Owner, Admin, Member.*

An owner holds billing and seat management. An admin can invite people and disconnect connected accounts. A member can publish, schedule and read analytics. Roles are resolved on the server from the account record on every single request: the interface hides what a role cannot do, but hiding is not the control, and a member cannot reach an owner action by typing a URL.

**Specifics**

- Owner: billing, seats, and everything below
- Admin: invite people, disconnect connected accounts
- Member: publish, schedule, read analytics

#### Accept an invitation

**Where:** `/invite/… (the link in the email)`

The invitee opens the link and chooses a username and password on the spot. There is no pre-existing account to sign in to and nothing to configure: the workspace and role are already decided by the invitation, so the page asks for the two things only they should know.

**How to use it**

1. Open the link from the invitation email.
2. Choose a “Username”: letters, numbers and underscores, 3 to 32 characters.
3. Choose a password of at least 8 characters and type it again to confirm.
4. Press “Join workspace”. You land on Home, already signed in.

> **Watch for** The link is the only copy of the invitation: ClowdBoard stores a hash of it and nothing else, the same treatment a password reset gets. A lost link is re-sent as a new invitation, never recovered.

#### Change a teammate’s role

**Where:** `Settings → Team`

*Owner only, and behind a step-up confirmation.*

Promote a member to admin or demote an admin to member. Only the owner can do it, and only after re-confirming who they are: a privilege change made from a walked-away laptop is exactly the kind of thing step-up exists to stop.

**How to use it**

1. Settings → Team.
2. Find the person under “Teammates”.
3. Press the other half of the role picker on their row.
4. Confirm the step-up prompt.

> **Watch for** Ownership cannot be handed over from this screen. There is exactly one owner and it is the account that holds the subscription.

#### Remove a teammate

**Where:** `Settings → Team`

*Owner only. Takes effect on their next request, not at token expiry.*

Ends someone’s access to the workspace and invalidates every session they hold, immediately, not whenever their current sign-in happens to lapse. They keep their own login and their own security log: the record of what they did while they had access is not erased along with their access, which is the difference between offboarding and a cover-up.

**How to use it**

1. Settings → Team.
2. Press “Remove” on their row.
3. Confirm the step-up prompt.

> **Watch for** Removing someone frees their seat straight away. It does not delete anything they published or scheduled: that work belongs to the workspace.

#### Revoke a pending invitation

**Where:** `Settings → Team`

Cancels an invitation that has not been accepted yet and returns the seat. Owners and admins can do it. Useful when an address was mistyped, or when a hire fell through and the link is still live in someone’s inbox.

### Runs on its own

#### Seat count enforced server-side

**Runs on its own**: nothing to visit, no setting to switch on.

*The plan’s cap is checked when the invitation is sent and again when it is accepted.*

The seat limit is applied on the server twice: once when an invitation goes out, and again when someone accepts it. The second check is the one that matters: between sending and accepting, a plan can downgrade, and without it a workspace could quietly exceed the tier it pays for.

**Specifics**

- Seats by plan: Creator 1 · Studio 3 · Agency 10 · Enterprise unlimited

#### Every team change lands in the security log

**Runs on its own**: nothing to visit, no setting to switch on.

Invitations sent, invitations revoked, invitations accepted, roles changed, teammates removed: each is written to the security log under the account that performed it, not under the workspace it affected. Who did it and whose data it touched are recorded as two different things, because an audit trail that confuses them is not an audit trail.

> **Watch for** Read it at Settings → Security. It is the same log that records sign-ins and session revocations.

## 20. Settings & the app itself

Preferences, your own API keys, and the things that make the app an app: a changelog, an installable version, and error reporting that tells us something broke without telling us who you are or what you were looking at.

### Things you do

#### Recovery email

**Where:** `Settings → Profile`

The address a password reset is sent to. ClowdBoard signs in on a username rather than an email, so this is the only route back into an account whose password and two-step device are both gone. It is worth setting on day one, because the day it is needed is too late.

#### Comfort mode

**Where:** `Settings → Preferences`

*A warmer, lower-contrast palette for long sessions.*

A warmer, softer palette for people who have the dashboard open all day. Not a novelty theme: the interface is a work surface for anyone managing a portfolio, and a work surface should be tolerable for eight hours.

#### Maintenance panel

**Where:** `Settings → Preferences`

*Refresh everything, test the connection, re-open the setup guide.*

Three deliberate manual actions: force a full refresh of every account, test that the app can reach the server, and bring the onboarding checklist back. This is the panel to reach for before contacting support: a connection test that succeeds tells you the problem is data, and one that fails tells you it is the network.

#### Bring your own API key

**Where:** `Settings → API keys`

*Gemini, OpenAI or Anthropic. Write-only: a saved key is never shown again.*

Caption and title generation run on your own key with your own provider. That means your content is never sent to a model chosen for you, the usage appears on your own bill at cost, and there is no per-generation markup. The field is write-only: once saved, the key is never displayed again, not even to you.

**Specifics**

- Providers: Google Gemini · OpenAI · Anthropic
- Storage: encrypted, never returned to the browser

> **Watch for** Without a key, generation is the only thing that stops working: analytics, publishing and scheduling do not need one.

#### What’s new

**Where:** `Changelog`

*Built from the actual release history.*

The changelog is generated from the real release history rather than written by hand, so it cannot drift from what actually shipped. An unread marker sits on your avatar until you have looked.

#### Your profile

**Where:** `Profile`

Your own account details: username, recovery email, and the settings that belong to you rather than to a connected social account.

#### Install as an app

**Where:** `Anywhere`

*Works offline for what it can, and updates itself.*

ClowdBoard installs to a desktop or phone home screen and runs in its own window with no browser chrome. It keeps working offline for anything already loaded, and it updates itself in the background, so there is nothing to download, no version to manage, and no IT ticket to raise.

### Runs on its own

#### Sidebar navigation and routing

**Runs on its own**: nothing to visit, no setting to switch on.

Every screen has a real URL that can be bookmarked, shared with a colleague, and opened directly. The back button works. This sounds unremarkable and is the thing single-page apps most often get wrong.

#### Old links keep working

**Runs on its own**: nothing to visit, no setting to switch on.

When a page moves, the old path redirects to the new one rather than 404ing. Bookmarks and links in old emails survive product changes.

#### Errors surfaced rather than swallowed

**Runs on its own**: nothing to visit, no setting to switch on.

When something fails, the app says so: including the platform’s own message where there is one. The failure mode this rules out is the worst one a publishing tool has: a post that silently did not go out and a screen that looks fine.

#### Crash reporting, stripped of anything identifying

**Runs on its own**: nothing to visit, no setting to switch on.

*The page that broke is recorded. Everything after the "?", which can carry a reset or download token, is dropped before it reaches any log.*

When the interface throws an error, the page it happened on is reported so it can be fixed. Everything after the “?” in the address is removed first, at the source, before the report reaches any log or any third party, because that part of a URL can carry a password-reset token or a signed download link. Reporting a crash must never be the thing that leaks the credential.

#### Image proxy for avatars and media

**Runs on its own**: nothing to visit, no setting to switch on.

Profile pictures and thumbnails are fetched through ClowdBoard rather than loaded straight from the platform. Platform image URLs expire, and loading them directly would also expose your browsing of the dashboard to the platform.

#### Signing in stays consistent across tabs

**Runs on its own**: nothing to visit, no setting to switch on.

Sign in once and every open tab is signed in; sign out and they all end. Sessions renew in the background as you work, so a long day never ends in an unexpected sign-out, and a renewal in one tab never invalidates another.

## 21. The public site

What a visitor sees before they have an account: the landing page, the FAQ, the legal pages, and the two trust pages a procurement review is sent to. The analytics behind it are first-party and cookieless: the same standard we hold the product to.

![The landing page: the headline, the waitlist form, and a live screenshot of the dashboard](https://clowdboard.com/shots/landing.webp)

### Things you do

#### Landing page

**Where:** `/`

The signed-out home page: what ClowdBoard is, what it costs, and real screenshots of the actual product rather than illustrations of it.

#### Light and dark switcher for visitors

**Where:** `/`

The public pages open light and can be switched to dark by the visitor. The choice is remembered on their device and applies to the public site only: it does not follow them into the app.

#### Waitlist

**Where:** `/`

An email address and nothing else. Submitting twice is silently accepted rather than answered with “already registered”, because an error that distinguishes the two turns the form into a way of testing whether a given address has signed up.

#### FAQ

**Where:** `/faq`

The pre-purchase questions: what it connects to, what it costs, what happens to the data. The public counterpart to this guide.

#### Terms of service

**Where:** `/tos`

The agreement covering use of the product.

#### Privacy policy

**Where:** `/privacy`

What is collected, why, and for how long. It describes the collector ClowdBoard actually runs rather than a generic template: including the first-party site analytics below and the waitlist email.

#### Security page

**Where:** `/security`

*Written to be checked, not taken on trust: including a list of what ClowdBoard does not have.*

The vendor-review page: how sign-in is protected, how connected-account credentials are sealed, how customers are separated, what the application surface enforces, who the sub-processors are, and what is deleted when. Every claim on it describes a control that is in the shipped code, and the last-but-one section lists the gaps (no SOC 2, no SSO, single-region) because procurement asks what you do not have and the answer they can verify is the one that earns the rest.

> **Watch for** Send this to a prospect before the security questionnaire arrives. Most questionnaires are answerable from it verbatim.

#### Data Processing Addendum

**Where:** `/dpa`

*Accepting the Terms accepts it. Nothing needs signing unless the customer wants it countersigned.*

The contractual counterpart to the Security page. It sets out that the customer is the controller and ClowdBoard the processor, the categories of personal data processed and why, the named sub-processors with thirty days’ notice before that list changes, 72-hour breach notification, retention and deletion, and the Standard Contractual Clauses and UK IDTA covering transfers to the United States. Technical measures are incorporated from the Security page by reference rather than restated, so the two cannot drift apart.

> **Watch for** It has not been through outside counsel, and the page says so. If a customer’s legal team wants their own paper instead, that is expected: email the address on the page.

### Runs on its own

#### First-party, cookieless visitor analytics

**Runs on its own**: nothing to visit, no setting to switch on.

*No third-party tracker, no cross-site identifier, nothing sold on.*

Visits to the public pages are counted by ClowdBoard itself. There is no Google Analytics, no Meta pixel, no third-party script, and no cookie: returning visitors are recognised by a rotating daily identifier that cannot be linked backwards across days or across sites. It is a deliberately harder way to build visitor analytics, and it is the standard the product claims to hold, so the marketing site holds it too.

#### Rate limiting on every public endpoint

**Runs on its own**: nothing to visit, no setting to switch on.

Every endpoint reachable without signing in (sign-in, password reset, the waitlist, the image proxy) has its own request budget. Separate budgets matter: one shared limit means a busy public page can exhaust the allowance that sign-in needs, and lock out real customers.

---

# Answers

The questions people actually send in, and how to reach a person.

## Common questions

### How do I connect my Instagram account?

Accounts → Connect account → Instagram. Instagram hands you to Facebook to sign in and approve access, because Business and Creator accounts are managed through a Facebook Page. Approve the permissions and you land back on your dashboard. Data starts syncing straight away and refreshes on its own every few hours.

### Why does an account show 0 followers, or no data?

Almost always a lapsed connection. Instagram and Facebook expire access roughly every 60 days; ClowdBoard renews it automatically, but it cannot once the connection is broken. Go to Accounts, look for "needs attention", and reconnect. Your history stays intact and the numbers fill back in on the next sync.

### How do I turn on two-step sign-in?

Settings → Security. Scan the QR code with any authenticator app, enter the six-digit code to confirm, and save the recovery codes somewhere safe. The same page lists every device currently signed in, and you can revoke any of them.

### Do I need my own API key?

Only for caption and title generation. Add a Gemini, OpenAI or Anthropic key in Settings → API keys and generation uses it. Everything else (analytics, publishing, scheduling) works without one.

### How do Schedules work?

A schedule is a posting cadence for one account: how often, which days, at what times. Set it up in Schedules, and everything else fills it: bulk upload, auto-schedule and the queue all draw from those slots.

### Google blocked my YouTube connection. What now?

Google refuses when the sign-in is cancelled, when the Google account you picked does not manage a YouTube channel, or when a Workspace administrator restricts third-party apps. Try again from Accounts → Connect account → YouTube, choose the account that owns the channel, and approve every permission. If it is a work or school account, ask your administrator to allow ClowdBoard.

### Is my data shared with anyone?

No. Your analytics stay private to your account, and the tokens behind your connections are encrypted at rest and never exposed to your browser or to anyone else using ClowdBoard. Nothing is sold or shared with advertisers. The Privacy Policy has the full detail.

## Contact

Email contact@clowdboard.com. For a bug, say what you did, what happened, and what you expected instead. We normally reply within one business day.
