Security
Your security is our top priority. Learn how we protect your data and accounts.
Our Security Commitment
At PostAnywhere, we understand that you're trusting us with access to your social media presence. We take this responsibility seriously and have implemented comprehensive security measures to protect your accounts and data.
We follow industry best practices and continuously update our security infrastructure to address emerging threats.
Security Features
Encryption
All data transmitted between your device and our servers is encrypted using TLS 1.3. Sensitive data at rest is encrypted using AES-256 encryption.
OAuth Authentication
We never store your social media passwords. We use OAuth 2.0 tokens provided directly by each platform, which you can revoke at any time.
Secure Infrastructure
Our infrastructure is hosted on enterprise-grade cloud providers with SOC 2 Type II certification, redundant systems, and 24/7 monitoring.
Access Controls
We implement strict access controls and audit logging. Employee access to production systems requires multi-factor authentication and is logged.
Data Protection
What We Store
- Your account information (email, name)
- OAuth tokens for connected platforms (encrypted)
- Your uploaded media (temporarily, for processing)
- Post history and analytics data
What We Never Store
- Your social media passwords
- Full payment card numbers (handled by Stripe)
- Biometric data
Data Retention
Uploaded media is automatically deleted within 24 hours of successful posting. Your post history is retained for 90 days for your reference. You can request complete data deletion at any time.
Social Media Account Security
When you connect your social media accounts to PostAnywhere, we use OAuth 2.0 authentication. This means:
- You authenticate directly with each platform (Instagram, TikTok, etc.)
- We receive only a limited-scope access token, not your password
- Tokens are encrypted and stored securely in our database
- You can revoke access at any time from your social media platform's settings
- We request only the minimum permissions needed for posting
Compliance
GDPR
We comply with the General Data Protection Regulation for users in the European Economic Area, including data access, portability, and deletion rights.
CCPA
California residents have rights under the California Consumer Privacy Act, including the right to know, delete, and opt-out of data sales (we do not sell data).
Our Security Practices
- ✓Regular security audits and penetration testing
- ✓Automated vulnerability scanning of our codebase
- ✓Security awareness training for all employees
- ✓Incident response procedures and 24/7 monitoring
- ✓Regular backup and disaster recovery testing
- ✓Dependency monitoring for known vulnerabilities
Report a Security Vulnerability
If you discover a security vulnerability, please report it responsibly. We appreciate security researchers who help us keep PostAnywhere safe.
Contact us at: postanywhereapp@gmail.com
Questions?
If you have any questions about our security practices, we're here to help.
Contact Us