This Privacy Policy describes how PostToSocial ("we", "us", "our") collects, uses, and protects information when you use our service at posttosocial.com (the "Service"). By using the Service, you agree to the practices described below.
1. Information We Collect
1.1 Account information
- Email address, name, and securely-hashed password (bcrypt) when you register
- Optional profile information (organization name, role) you provide
- Subscription tier, billing status, and payment history (processed by Stripe; we never store full card numbers)
1.2 Connected social platform data
When you connect a social account (LinkedIn, Facebook, Instagram, YouTube, TikTok, or X), we receive and store:
- OAuth access tokens and refresh tokens issued by the platform — used solely to publish content you create on your behalf
- Account display name (for example, your LinkedIn name or Facebook Page name) so we can show you which accounts are connected
- Token expiration timestamp so we can refresh proactively
We do not read your social inbox, friend list, follower data, or private messages. We do not sell or share your tokens with third parties.
1.3 Content you create
- Topics, audiences, brand voice, and other inputs you provide to our generators
- Generated text, images, and videos
- Files you upload (images, videos) for use in posts
- Scheduling metadata (when, where, status of each post)
1.4 Usage data
- API request logs (endpoint, timestamp, response status — no personal content)
- Aggregated usage metrics (number of posts generated, platforms used) for product improvement
2. How We Use Your Information
- Provide the Service — generate content, publish to your connected platforms, schedule posts
- Authenticate you and keep your account secure
- Process payments via Stripe and manage subscriptions
- Send transactional emails (account verification, password resets, organization invitations) via SendGrid
- Improve the Service through aggregated, de-identified analytics
- Comply with legal obligations (tax records, fraud prevention, lawful requests)
3. Third-Party Services
To deliver the Service we share specific data with these vetted providers:
- OpenAI — your generation prompts (topic, audience, tone). OpenAI does not train on data sent via API as of March 2023.
- Stripe — billing email + subscription metadata for payment processing
- SendGrid — your email address for transactional messages
- MongoDB Atlas — encrypted database storage
- Social platforms (LinkedIn / Meta / Google / TikTok / X) — only the content you explicitly publish, plus the OAuth handshake
We do not sell your personal information or generated content to data brokers, advertisers, or AI training datasets.
4. Platform-Specific Disclosures
4.1 Meta (Facebook + Instagram)
Our Meta integration uses the Instagram Graph API and Facebook Pages API in compliance with the Meta Platform Terms. We request only the permissions necessary to publish posts to Pages and Instagram Business accounts you administer (pages_manage_posts, instagram_content_publish, and supporting read scopes). We do not access your personal Facebook profile, friends list, or private messages.
4.2 LinkedIn
Our LinkedIn integration uses the w_member_social scope solely to publish posts you author to your own LinkedIn feed. We do not read your network, messages, or job activity.
4.3 Other platforms (YouTube, TikTok, X)
Each integration uses the minimum scopes required to publish the content you create. Tokens are stored encrypted and used only on your behalf.
5. Data Retention
- Account and connection data: retained for as long as your account is active
- Generated content: retained until you delete it or close your account
- Backups: deleted within 30 days of account closure
- Billing records: retained 7 years to satisfy tax obligations
6. Your Rights
You can at any time:
- Access your personal data via your account settings
- Correct inaccurate data via account settings
- Delete your account and all associated data — see our Data Deletion page
- Disconnect social platforms at any time from /connections; we immediately revoke their use
- Export your generated content as CSV from the Export page
- Object to processing by emailing us at privacy@posttosocial.com
EU/EEA, UK, and California residents have additional rights under GDPR / UK GDPR / CCPA including the right to lodge a complaint with a supervisory authority.
7. Security
We use industry-standard practices: bcrypt password hashing, HTTPS-only transport, encrypted database storage, JWT-based session tokens, role-based access control, and least-privilege OAuth scopes. No system is 100% secure — if you discover a vulnerability, please email support@posttosocial.com.
8. Children's Privacy
The Service is not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact us and we will delete it.
9. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email and a banner on the Service at least 14 days before taking effect. Continued use after the effective date constitutes acceptance.
10. Contact
Questions, concerns, or requests:
PostToSocial
Email: privacy@posttosocial.com
Support: support@posttosocial.com