Security | PostAnywhere.app
    Back to Home

    Security

    Your security is our top priority. Learn how we protect your data and accounts.

    Our Security Commitment

    At PostAnywhere, we understand that you're trusting us with access to your social media presence. We take this responsibility seriously and have implemented comprehensive security measures to protect your accounts and data.

    We follow industry best practices and continuously update our security infrastructure to address emerging threats.

    Security Features

    Encryption

    All data transmitted between your device and our servers is encrypted using TLS 1.3. Sensitive data at rest is encrypted using AES-256 encryption.

    OAuth Authentication

    We never store your social media passwords. We use OAuth 2.0 tokens provided directly by each platform, which you can revoke at any time.

    Secure Infrastructure

    Our infrastructure is hosted on enterprise-grade cloud providers with SOC 2 Type II certification, redundant systems, and 24/7 monitoring.

    Access Controls

    We implement strict access controls and audit logging. Employee access to production systems requires multi-factor authentication and is logged.

    Data Protection

    What We Store

    • Your account information (email, name)
    • OAuth tokens for connected platforms (encrypted)
    • Your uploaded media (temporarily, for processing)
    • Post history and analytics data

    What We Never Store

    • Your social media passwords
    • Full payment card numbers (handled by Stripe)
    • Biometric data

    Data Retention

    Uploaded media is automatically deleted within 24 hours of successful posting. Your post history is retained for 90 days for your reference. You can request complete data deletion at any time.

    Social Media Account Security

    When you connect your social media accounts to PostAnywhere, we use OAuth 2.0 authentication. This means:

    • You authenticate directly with each platform (Instagram, TikTok, etc.)
    • We receive only a limited-scope access token, not your password
    • Tokens are encrypted and stored securely in our database
    • You can revoke access at any time from your social media platform's settings
    • We request only the minimum permissions needed for posting

    Compliance

    GDPR

    We comply with the General Data Protection Regulation for users in the European Economic Area, including data access, portability, and deletion rights.

    CCPA

    California residents have rights under the California Consumer Privacy Act, including the right to know, delete, and opt-out of data sales (we do not sell data).

    Our Security Practices

    • Regular security audits and penetration testing
    • Automated vulnerability scanning of our codebase
    • Security awareness training for all employees
    • Incident response procedures and 24/7 monitoring
    • Regular backup and disaster recovery testing
    • Dependency monitoring for known vulnerabilities

    Report a Security Vulnerability

    If you discover a security vulnerability, please report it responsibly. We appreciate security researchers who help us keep PostAnywhere safe.

    Contact us at: postanywhereapp@gmail.com

    Questions?

    If you have any questions about our security practices, we're here to help.

    Contact Us