Privacy Policy

Effective July 21, 2026 · Updated August 4, 2026

What we collect

We collect the information you provide (name, email, workspace details) and the data required to publish on your behalf, including OAuth tokens, account handles, profile avatars, post content, media files, and publishing logs.

How connected-platform data is handled

TikTok, Instagram, Facebook, Threads, and YouTube provide only the data and permissions you approve on their consent screens. Post Social does not receive your social-network password. Access and refresh tokens are encrypted and kept on the server; they are never returned to the browser. We share post data with a connected platform only when needed to perform the publishing action you requested or approved.

Platform data categories

  • Identity: platform user ID, display name, handle, avatar URL.
  • Tokens: OAuth access and refresh tokens, encrypted server-side.
  • Content: captions, media files, scheduled times, and publishing settings.
  • Results: status updates, live post URLs, and sanitized error details.
  • Developer access: API key hashes and prefixes, webhook URLs, encrypted webhook signing secrets, delivery attempts, and request identifiers.

Google user data and YouTube API Services

Post Social uses YouTube API Services to publish videos to your YouTube channel. When you connect YouTube, we request a single Google permission (the youtube.upload scope), which allows uploading videos you compose to your own channel. We do not read your channel, subscriber, or viewing data. The only Google user data we store are your OAuth access and refresh tokens, encrypted at rest (AES-256-GCM) on the server and never exposed to the browser, plus the video ID and public watch link of posts you publish. Google user data is shared only with YouTube itself to perform the upload you requested; it is never sold, used for advertising, or shared with other third parties.

By using the YouTube connection you also agree to the YouTube Terms of Service. Google's handling of your data is described in the Google Privacy Policy. You can disconnect YouTube in Post Social at any time — we revoke our access with Google and delete the stored tokens — or revoke Post Social's access yourself from your Google security settings.

Service providers and security

We use service providers, including Convex for application data, scheduled functions, and file storage, only to operate Post Social. We limit stored permissions to the product features in use, encrypt platform credentials at rest, and keep a time-stamped security and publishing record. No internet service can guarantee absolute security.

How we use data

We use your data only to operate the service: authenticating you, publishing posts, refreshing tokens, showing status, and maintaining an audit trail. If you configure a webhook, we send the selected publishing event and its safe result details to the URL you provide. We do not sell personal data.

Data retention and deletion

We keep account data and posts until you delete them or close your workspace. You can disconnect individual accounts or delete your workspace to remove associated data. When a workspace is deleted, we attempt to revoke connected-platform access before removing locally stored encrypted credentials. Already-published content remains on the social platform and must be deleted there directly.

Deletion-request receipts contain a one-way hash and a confirmation status and are retained for no more than 30 days. Expired OAuth state and rate-limit records are routinely purged. See the data deletion page for details.

Your choices

You may disconnect a social account at any time, delete an unpublished post and its unused media, delete a workspace, or delete your Post Social sign-in identity after all workspaces are removed. Disconnecting Post Social does not delete content already published on a third-party platform.

Contact

For privacy questions, contact aki.b@pentridgemedia.com.