Privacy Policy
Last updated: 16 September 2026
What we collect
When you sign in to Simplepostr we store your email address, display name, and a Simplepostr account identifier. When you connect a social account, we store an encrypted access token issued by that provider, the list of channels (Pages, professional accounts) you administer, and metadata describing each channel. When you upload media we store the file and its content type, dimensions, duration, and checksum. When you publish, we store the caption, provider settings, scheduled time, provider identifiers for the resulting post, and the outcome of each publication attempt.
Why we collect it
Each piece of data supports the feature that produced it. Access tokens allow us to publish to the channels you connect. Media and captions allow us to prepare and dispatch posts. Publication outcomes drive retries, status reporting, and quota accounting. We do not sell or share your personal data with third parties for advertising.
Google user data
When you connect a Google account (for YouTube or Google Drive), Simplepostr requests only the scopes needed for the features you use, and uses the data solely to provide those features:
- YouTube — upload videos (
youtube.upload): when you compose a video post and click Publish, we upload that video to your own YouTube channel on your behalf. Nothing is uploaded without an explicit Publish action by you. - YouTube — read account (
youtube.readonly): after an upload we read back only the resulting video’s status and identifier, so we can show you the published result and a link to it inside Simplepostr. - Google Drive — app files (
drive.file): if you enable Drive archiving, we save copies of your own posts (caption and media) into a folder we create in your Google Drive. Thedrive.filescope limits us to only the files Simplepostr creates — we never read, access, or manage any of your other Drive files. - Sign-in (
userinfo.email,userinfo.profile,openid): to identify your account and show which Google account is connected.
We use Google user data only to provide the publishing and archiving features you request. We do not use it for advertising, we do not sell it, and we do not transfer it to others except as needed to carry out your request (for example, uploading your video to YouTube) or as required by law. Simplepostr’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How we protect your data
We protect your data — including sensitive data such as the OAuth access and refresh tokens issued by connected providers — with the following mechanisms:
- Encryption in transit: all traffic to and from Simplepostr is encrypted using HTTPS/TLS.
- Encryption at rest: provider access and refresh tokens, and other secrets, are encrypted before storage using AES-256-GCM authenticated (envelope) encryption. They are never stored in plaintext.
- Access control and isolation: data is scoped to your workspace and isolated from other customers; internal access follows the principle of least privilege, and every mutation is recorded in an audit log.
- Token lifecycle: encrypted provider tokens are deleted immediately when you disconnect a connection or the provider revokes access.
Providers we send data to
We call the platform APIs of the providers you connect (Meta, TikTok, and others as we add support) to fulfil your requests to schedule and publish content. We call Stripe for subscription billing and Resend for transactional email. Media is hosted on Vercel Blob storage. Postgres hosting is on Neon.
How long we keep it
Account and workspace records are retained for as long as the account is active. On account deletion we delete personal data within 30 days, except for records required to satisfy legal, tax, or provider-mandated retention. Encrypted provider tokens are deleted immediately on disconnection or revocation. Audit records may be retained for up to 24 months for security and abuse review.
Your rights
You may export your data or request deletion by emailing the address below. Provider-initiated deletion requests (Meta data-deletion callback, etc.) are honoured through automated endpoints and result in the same deletion path as a user-initiated request.
Contact
Privacy questions: privacy@simplepostr.com