Privacy Policy

Last updated: June 24, 2026

Overview

PostPilot ("we", "us") helps you generate and publish social media content on your behalf. This policy explains what information we collect, how we use it, and the choices you have.

Information we collect

Account information — your name, email address, and authentication details when you sign up or log in, including via Google OAuth.

Brand and content data — brand profiles, logos, product details, and the posts, images, and captions you generate or schedule.

Connected social accounts — when you connect Instagram, Facebook, Twitter/X, LinkedIn, or Reddit, we store the access tokens needed to publish on your behalf. Tokens are encrypted (AES-256) before storage.

Usage data — basic activity logs (e.g. login times, audit events for team actions) used to operate and secure the product.

How we use your information

We use your information to generate content with AI providers, publish posts to the social accounts you connect, manage your workspace and team access, send account and security-related notifications, and improve the reliability of the product.

Third-party services

We share data with the providers necessary to deliver the service: AI content generation providers, Cloudinary for image storage, and the social platforms you explicitly connect (Meta, X, LinkedIn, Reddit). We do not sell your personal information.

Data retention

We retain your account and brand data for as long as your account is active. Social account tokens are deleted immediately when you disconnect a platform. You can request deletion of your account and associated data at any time.

Your choices

You can disconnect any social account at any time from Settings → Connected Accounts. You can edit or delete brands, products, and scheduled posts you own. Workspace owners and admins control team member access within a workspace.

Contact

Questions about this policy? Reach us at support@postpilot.app.