Privacy Policy
Last updated: March 24, 2026
1. Introduction
PostAnywhere ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our social media posting platform and related services (collectively, the "Service").
Our Service integrates with third-party social media platforms including Meta (Instagram and Facebook), Google (YouTube), TikTok, LinkedIn, and X (Twitter). Each of these platforms has their own privacy policies and data handling practices. By using PostAnywhere, you acknowledge that your use of connected social media accounts is also subject to the privacy policies of those respective platforms.
By using PostAnywhere, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this Privacy Policy, please do not access the Service.
2. Information We Collect
2.1 Information You Provide
- •Account Information: When you create an account, we collect your name, email address, and password. If you sign in using a social login provider (Google, Facebook, or TikTok), we receive your basic profile information and email address from that provider.
- •Social Media Credentials: To enable posting to your social media accounts, we use OAuth authentication tokens provided by each platform. We do not store your social media passwords. We only store the access tokens and refresh tokens required to post on your behalf.
- •Content: Images, videos, and captions you upload for posting to social media platforms. This content is stored to provide features such as post history, allowing you to view and manage your previously created content.
- •Payment Information: If you subscribe to a paid plan, our payment processor collects payment card details. We do not store full card numbers on our servers.
2.2 Automatically Collected Information
- •Usage Data: Information about how you interact with our Service, including features used, posting frequency, and time spent on the platform.
- •Device Information: Browser type, operating system, device type, and unique device identifiers.
- •Log Data: IP address, access times, pages viewed, and referring URLs.
- •Cookies: We use cookies and similar technologies to maintain your session and remember your preferences.
3. Platform-Specific Data Collection
When you connect your social media accounts or sign in using a social login provider, we access specific data from each platform as authorized through OAuth. We collect your email address from each platform to create and manage your account. Here is exactly what we access from each platform:
Account Authentication (Social Login)
We offer social login options to create an account or sign in to PostAnywhere. When you use social login, we receive the following from each provider:
- • Google OAuth: Email address, name, and profile picture
- • Facebook OAuth: Email address, name, and profile picture
- • TikTok Login Kit: Email address (when available), username, and profile picture
This information is used solely to create and manage your PostAnywhere account. We do not post to your social media accounts through social login—that requires a separate connection through our platform integration features.
MMeta (Instagram & Facebook)
Data We Access:
- • Your Instagram Business Account username and ID
- • Your Facebook Page name, ID, and category
- • Basic profile information (as permitted by OAuth scopes)
- • Ability to publish content to your Instagram and Facebook accounts
How We Use It:
- • To display your connected account username in the app
- • To publish photos, videos, and captions you create to your accounts
- • To verify your account connection is active
OAuth Permissions (Scopes):
- • instagram_basic, instagram_content_publish
- • instagram_manage_contents, instagram_manage_insights
- • pages_show_list, pages_read_engagement, pages_manage_posts
- • read_insights, business_management
Data Deletion: You can disconnect your Meta accounts at any time through Connected Accounts settings or via Facebook Business Integrations. We will delete your Meta-related data within 48 hours of receiving a deletion callback.
YGoogle (YouTube)
Data We Access:
- • Your YouTube channel name and ID
- • Ability to upload videos to your YouTube channel
- • Ability to manage (edit and delete) your YouTube videos
- • Your channel and video analytics for performance display
- • Basic channel information for display purposes
How We Use It:
- • To display your connected channel name in the app
- • To upload videos you create through our Service
- • To delete videos when you request removal through our app
- • To display your channel and video analytics
- • To verify your account connection is active
OAuth Permissions (Scopes):
- • youtube.readonly (to read your channel information for display in the app)
- • youtube.upload (to upload videos you create through our Service)
- • youtube (to manage your videos, including editing and deletion)
- • yt-analytics.readonly (to display your channel analytics and video performance)
Google/YouTube Policies: Your use of YouTube features is subject to the YouTube Terms of Service and Google Privacy Policy. You can revoke access at any time via your Google Account permissions.
Google API Limited Use Disclosure: PostAnywhere's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained from Google APIs (including YouTube channel information, OAuth tokens, and analytics data) is used exclusively to provide core application functionality — uploading, managing, and displaying your YouTube content. This data is never transferred to, processed by, or accessible to any third-party AI service, machine learning model, or any other service beyond what is necessary to provide you the YouTube features you requested.
TTikTok
Data We Access:
- • Your TikTok username and unique user ID (open_id)
- • Your email address (when available through Login Kit)
- • Your profile display name and avatar URL
- • Ability to upload videos to your TikTok account
How We Use It:
- • To authenticate your account using TikTok Login Kit
- • To display your connected account in the app
- • To upload videos to your TikTok account
- • To verify your account connection is active
OAuth Permissions (Scopes):
- • user.info.basic (basic profile information)
- • user.info.profile (profile details)
- • video.upload (upload videos)
- • video.publish (direct publish capability)
TikTok Privacy Policy: Your use of TikTok features is also subject to TikTok's Privacy Policy and Terms of Service.
inLinkedIn
Data We Access:
- • Your LinkedIn profile name and ID
- • Basic profile information for display
- • Ability to share posts on your LinkedIn profile
How We Use It:
- • To display your connected LinkedIn profile in the app
- • To share content you create to your LinkedIn feed
- • To verify your account connection is active
LinkedIn Privacy: Your use is also subject to LinkedIn's Privacy Policy. You can revoke access via LinkedIn Permitted Services.
𝕏X (formerly Twitter)
Data We Access:
- • Your X username and user ID
- • Ability to post tweets on your behalf
How We Use It:
- • To display your connected X account in the app
- • To post content you create to your X feed
X Privacy Policy: Your use is also subject to X's Privacy Policy. You can revoke access via X Connected Apps settings.
📊Telemetry & Analytics Data
What We Collect:
- • Feature usage patterns (which features you use and how often)
- • Performance metrics (page load times, error rates)
- • Device and browser information
- • Session duration and navigation paths
- • Posting activity statistics (number of posts, platforms used)
How We Use It:
- • To provide you with analytics about your posting activity
- • To improve our Service and user experience
- • To identify and fix technical issues
- • To understand which features are most valuable to users
Important: This telemetry data is used solely for internal analytics and to provide you with insights about your usage. We do not sell, share, or provide this data to any third parties for their marketing or advertising purposes.
4. How We Use Your Information
We use the information we collect to:
- •Provide, maintain, and improve our Service
- •Process your posts to connected social media platforms
- •Generate AI-powered captions for your content
- •Process payments and manage subscriptions
- •Send service-related communications and updates
- •Respond to your inquiries and support requests
- •Detect, prevent, and address technical issues and fraud
- •Analyze usage patterns to improve user experience
- •Comply with legal obligations and platform requirements
Important: We do not use your data for advertising purposes, we do not sell your data to third parties, and we do not use your content to train AI models. Our AI caption generation feature uses Anthropic's Claude API, which does not train on commercial API data. Data obtained from Google APIs is never sent to or processed by any AI service — the AI caption feature only receives the image you uploaded and text you typed, with no Google account data, tokens, or identifiers included.
6. Data Security
We implement industry-standard security measures to protect your information, including:
- •Encryption of data in transit using TLS/SSL
- •Encryption of sensitive data at rest (including OAuth tokens)
- •Secure OAuth token storage in isolated database tables
- •Row-level security policies to prevent unauthorized data access
- •Access controls and authentication requirements
- •Regular security assessments
Security Incident Reporting: If you discover a security vulnerability, please report it immediately to postanywhereapp@gmail.com. We will investigate and respond promptly.
While we strive to protect your information, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.
7. Data Retention
We retain your information for as long as your account is active or as needed to provide services. Specifically:
- •Account data is retained until you delete your account
- •Posted content is retained for 90 days after posting for your reference
- •OAuth tokens are retained while your social accounts are connected
- •Usage logs are retained for 12 months
- •Payment records are retained as required by tax and accounting laws
When you disconnect a social media account or delete your PostAnywhere account, we delete the associated OAuth tokens and connection data according to the timelines specified in Section 8.
8. Data Deletion
How to Request Data Deletion
You have the right to request deletion of your personal data at any time. Here are the ways you can delete your data:
Option 1: Delete Your Account (Recommended)
Go to Settings → Profile → Danger Zone and click "Delete Account". This will permanently delete all your data including:
- • Your account and profile information
- • All uploaded media and posts
- • All connected social media account tokens
- • Usage history and analytics data
Option 2: Disconnect Individual Platforms
Go to Connected Accounts in the app and click the disconnect button for any platform. This removes your OAuth tokens and connection data for that specific platform.
Option 3: Email Request
Send a data deletion request to postanywhereapp@gmail.com with the subject line "Data Deletion Request". Include the email address associated with your account. We will process your request within 30 days.
Option 4: Platform-Specific Disconnection
You can also revoke PostAnywhere's access directly from each platform:
- • Meta (Facebook/Instagram): Facebook Business Integrations
- • Google (YouTube): Google Connected Apps
- • TikTok: TikTok App → Settings → Security → Manage App Permissions
- • LinkedIn: LinkedIn Permitted Services
- • X: X Connected Apps
When you revoke access from a platform, we receive a callback notification and will delete your associated data within 48 hours.
Data Deletion Timeline
- • Immediate: Account access revoked and all active sessions ended
- • Within 24 hours: Profile data and uploaded media queued for deletion
- • Within 48 hours: OAuth tokens and platform connections permanently deleted
- • Within 30 days: All backup systems purged of your data
9. GDPR Compliance
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) applies to how we process your personal data.
9.1 Data Controller
PostSocial, LLC is the data controller responsible for your personal data. For GDPR inquiries, contact our Data Protection representative at postanywhereapp@gmail.com.
9.2 Legal Basis for Processing
We process your personal data under the following legal bases:
- •Contractual Necessity (Article 6(1)(b)): Processing necessary to provide you with our Service, including account management, content posting, and connected account functionality.
- •Consent (Article 6(1)(a)): When you explicitly consent to specific processing activities, such as connecting social media accounts via OAuth authorization.
- •Legitimate Interests (Article 6(1)(f)): For fraud prevention, security, service improvement, and analytics, where our interests do not override your rights.
- •Legal Obligation (Article 6(1)(c)): To comply with applicable laws, regulations, and legal processes.
9.3 Your GDPR Rights
Under GDPR, you have the following rights:
- •Right of Access (Article 15): Request a copy of your personal data and information about how we process it
- •Right to Rectification (Article 16): Request correction of inaccurate or incomplete personal data
- •Right to Erasure (Article 17): Request deletion of your personal data ('right to be forgotten')
- •Right to Restriction (Article 18): Request restriction of processing in certain circumstances
- •Right to Data Portability (Article 20): Receive your data in a structured, machine-readable format
- •Right to Object (Article 21): Object to processing based on legitimate interests or direct marketing
- •Right to Withdraw Consent (Article 7): Withdraw consent at any time where processing is based on consent
- •Right to Lodge a Complaint: File a complaint with your local Data Protection Authority
Exercising Your Rights
To exercise any GDPR right, email postanywhereapp@gmail.com with the subject line "GDPR Request". We will respond within 30 days. We may request identity verification before processing your request. There is no fee for most requests, but we may charge a reasonable fee for manifestly unfounded or excessive requests.
9.4 Data Protection Authority
If you believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local Data Protection Authority. A list of EU Data Protection Authorities is available at EDPB Members.
10. Additional Privacy Rights (CCPA & Others)
California Residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with additional rights:
- •Right to Know: What personal information we collect, use, disclose, and sell
- •Right to Delete: Request deletion of your personal information
- •Right to Correct: Request correction of inaccurate personal information
- •Right to Opt-Out: Opt out of the sale or sharing of personal information (Note: We do not sell personal information)
- •Right to Non-Discrimination: We will not discriminate against you for exercising your rights
Response Time: We will respond to verifiable CCPA requests within 45 days. If we need more time (up to an additional 45 days), we will notify you in writing.
To exercise these rights, please contact us at postanywhereapp@gmail.com
11. Third-Party Platform Policies
When you connect your social media accounts, you are also subject to the terms and privacy policies of those platforms. We encourage you to review these policies:
12. Children's Privacy
PostAnywhere is not intended for users under the age of 16. This age limit complies with the minimum age requirements under the EU General Data Protection Regulation (GDPR) and represents the strictest global standard for social media usage.
We do not knowingly collect personal information from children under 16 years of age. If we become aware that we have collected personal information from a child under 16, we will take steps to delete that information as quickly as possible.
If you are a parent or guardian and believe your child has provided us with personal information without your consent, please contact us immediately at postanywhereapp@gmail.com. We will promptly investigate and delete any such information.
Note: The connected social media platforms may have their own age requirements (typically 13-16 years). Users must also meet the age requirements of each platform they connect to PostAnywhere.
13. International Data Transfers
PostSocial, LLC is based in Miami, Florida, United States. Your information may be transferred to and processed in the United States and other countries where our servers and service providers are located.
For users in the European Economic Area (EEA), United Kingdom, or Switzerland, we ensure appropriate safeguards are in place for such transfers in compliance with GDPR, including:
- •Standard Contractual Clauses (SCCs): EU-approved contractual terms that ensure adequate protection
- •Adequacy Decisions: Where transfers are to countries with an adequacy decision from the EU Commission
- •Supplementary Measures: Additional technical and organizational measures as required
By using our Service, you acknowledge that your data may be transferred internationally and you consent to such transfers, subject to the safeguards described in this policy.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. For significant changes, we will also send an email notification to registered users. Your continued use of the Service after changes constitutes acceptance of the updated policy.
15. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us: