Skip to content
Back to Support

The Social Queue

Connecting an account and publishing quotes

The social queue publishes extracts of your own manuscript to accounts you connect, per pen name. Nothing is published that you have not approved. This page covers connecting an account, how the credential is stored, what accompanies a post, and how access is ended.

The social queue publishes text taken from your own manuscript to social accounts you connect. It publishes nothing on its own initiative, does not read your timeline, followers, messages or engagement figures, and never posts as Calamus.

Connecting an account

Connection is made per pen name, in Settings under Social, and is performed in the browser. Bluesky is operative. Threads is implemented against the same interface but is not enabled and cannot be connected pending approval by Meta.

For Bluesky you generate an app password in Bluesky’s own settings and supply it to Calamus. An app password is not your account password: it permits posting and reading on your behalf, and it can be revoked in Bluesky at any time without changing your account password or signing you out anywhere else.

How the credential is stored

Calamus verifies the credential against the platform before storing it, then encrypts it with AES-256-GCM. Each record has its own initialization vector and an authentication tag, so a tampered value fails on decryption rather than being transmitted. The key is stored in a server environment variable and not in the database.

The credential is decrypted only on the server, and only inside the scheduled process that publishes. No screen you can open handles it: interfaces receive the handle, the display name and the connection status, and nothing else.

What is published

Text you captured from your own manuscript, edited if you chose to, and expressly approved. A post can include a buy link, attribution to the book title, and an image. Attribution is drawn from the book rather than typed, and a buy link cannot be selected until the book has one.

When a post fails

Publication depends on the platform being available and on the stored credential remaining valid. Transient failures are retried. Where a platform rejects the credential, the account is marked as requiring reconnection and you are notified by email. A failed post remains in the queue with the error the platform returned, so nothing disappears without explanation.

The platform’s own terms apply to you in addition to ours, and a platform may restrict or suspend an account for reasons Calamus has no visibility into.

Disconnecting, and revoking

These are two different actions and both are worth taking. Disconnect in Settings under Social: the record is deleted outright, together with the encrypted credential and its initialization vector, and no further post is sent. That makes Calamus forget the credential but does not cancel it.

Revoking the app password in Bluesky’s own settings, under Privacy and security, then App passwords, is what actually ends the access. The steps may be performed in either order. Posts already queued are separate from the credential and should be canceled in the queue if they are not wanted. Both routes are set out in the data deletion notice.