Privacy Policy
Effective July 21, 2026
What we collect
We collect the information you provide (name, email, workspace details) and the data required to publish on your behalf, including OAuth tokens, account handles, profile avatars, post content, media files, and publishing logs.
How connected-platform data is handled
TikTok, Instagram, and Facebook provide only the data and permissions you approve on their consent screens. Post Social does not receive your social-network password. Access and refresh tokens are encrypted and kept on the server; they are never returned to the browser. We share post data with a connected platform only when needed to perform the publishing action you requested or approved.
Platform data categories
- Identity: platform user ID, display name, handle, avatar URL.
- Tokens: OAuth access and refresh tokens, encrypted server-side.
- Content: captions, media files, scheduled times, and publishing settings.
- Results: status updates, live post URLs, and sanitized error details.
- Developer access: API key hashes and prefixes, webhook URLs, encrypted webhook signing secrets, delivery attempts, and request identifiers.
Service providers and security
We use service providers, including Convex for application data, scheduled functions, and file storage, only to operate Post Social. We limit stored permissions to the product features in use, encrypt platform credentials at rest, and keep a time-stamped security and publishing record. No internet service can guarantee absolute security.
How we use data
We use your data only to operate the service: authenticating you, publishing posts, refreshing tokens, showing status, and maintaining an audit trail. If you configure a webhook, we send the selected publishing event and its safe result details to the URL you provide. We do not sell personal data.
Data retention and deletion
We keep account data and posts until you delete them or close your workspace. You can disconnect individual accounts or delete your workspace to remove associated data. See the data deletion page for details.
Your choices
You may disconnect a social account at any time, delete an unpublished post and its unused media, delete a workspace, or delete your Post Social sign-in identity after all workspaces are removed. Disconnecting Post Social does not delete content already published on a third-party platform.
Contact
For privacy questions, contact aki.b@pentridgemedia.com.