Privacy Policy
Last updated 29 July 2026
xpost(“we”, “us”) runs a social media scheduling and publishing tool at xpost.to. You connect your own social accounts, you (or an AI agent you control) draft posts, and we publish them for you and report back how they did.
This policy explains what we hold, why we hold it, who else sees it, and how to make us delete it. It is written to be read, not to be survived. For anything it does not answer, email privacy@xpost.to.
We are the data controller for the information described here. Where this policy uses terms from the EU General Data Protection Regulation (GDPR), they carry their GDPR meaning.
The short version
- We collect what the product needs to work, and nothing for advertising.
- We do not sell your data, share it with data brokers, or use it to train machine-learning models.
- We never see or store your passwords for any social platform. Accounts connect through each platform’s official sign-in.
- We read only your own content on connected platforms — never anyone else’s — and only to show it back to you.
- There are no analytics scripts, advertising pixels, or third-party trackers on this site. One cookie, and it only keeps you signed in.
- Disconnect an account or delete your project and it is gone.
What we collect
Your account
- Your email address, and either a hashed password or the identifier from your Google sign-in. We never store a readable password.
- Your plan, subscription status, and customer identifiers from our payment provider. Card numbers go directly to Stripe and never touch our servers.
Social accounts you connect
- The access (and where the platform uses them, refresh) tokens issued when you authorise us, so we can post on your behalf. These are encrypted at rest with AES-256-GCM. Where a platform expires its tokens, we renew them automatically so your connection keeps working.
- Your handle, the platform’s internal ID for your account, and your profile picture, so you can see which account you are posting from.
What you create in the product
- Posts, captions, alt text, schedules, and any images or video you upload. Media files are stored on our servers so we can hand them to each platform at publish time.
- Your guardrail rules, approval decisions, and an audit log of actions taken in your project — including everything an AI agent did with your API keys. The audit log is what makes an agent accountable, so we keep it for the life of the project.
How your posts performed
For posts we published for you, we periodically ask the platform for their engagement counts — impressions, likes, replies, reposts, bookmarks and equivalents — and store those numbers so your analytics page works. We request this only for post IDs we created for you. We do not read your timeline, your followers, your direct messages, or any other account’s content.
If you join the waitlist
Your email address, an optional note about what you would use xpost for, and where you arrived from. Nothing else.
Ordinary server logs
Our servers record requests, including IP addresses and browser user agents, for security and debugging. These are kept short-term and are not used to build a profile of you.
Why we are allowed to hold it
- To perform our contract with you — your account, connected accounts, posts, media, and delivery records. Without these there is no product.
- Our legitimate interests — server logs, security measures, the audit log, and fraud and abuse prevention. We keep these minimal and to the point.
- Your consent — the waitlist, and any product announcement emails. Withdraw it at any time; every such email carries an unsubscribe link.
- Legal obligation — invoices and tax records, which we have to keep for as long as the law requires.
Who else sees it
We share data only with the services that make the product function, and only the parts they need. Each is bound by its own data-processing terms.
- The social platforms you connect— X, Bluesky, LinkedIn, Instagram, Facebook, TikTok, YouTube, Threads, and Pinterest. We send them the posts you asked us to publish. Once published, that content is governed by that platform’s own terms and privacy policy.
- bundle.social, our publishing aggregator, for platforms we have not yet connected to directly. It receives the post content and holds the authorization for the accounts connected through it.
- Stripe, for subscriptions and payments.
- Resend, for transactional email — sign-in verification, password resets, and delivery alerts.
- Cloudflare, which sits in front of the site and routes traffic to it.
We do not sell personal data, we do not share it with advertisers or data brokers, and we do not use your content or your metrics to train machine-learning models. If the business is ever sold or merged, your data may transfer with it — you would be told before that happened, and this policy would continue to apply until you were given a replacement.
A specific note about X
Our use of the X API follows the X Developer Agreement and Policy. We use it for three things: publishing posts and replies you have approved, confirming which account you connected, and reading the engagement counts on posts we published for you. We do not scrape X, we do not access accounts that have not authorised us, and we do not redistribute X content or make it — or anything derived from it — available to any third party or government entity. Your posts and their statistics are visible only to you, inside your own dashboard.
A specific note about Pinterest
Our use of the Pinterest API follows the Pinterest Developer Guidelines and the Pinterest API Terms of Service. We use it for four things: creating the pins you asked us to publish (including multi-image carousels) on the board you chose, confirming which Pinterest account you connected, listing your boards so you can pick one in the composer, and reading the engagement counts on pins we created for you.
When you connect Pinterest we ask for permission to read and write your pins and boards. Pinterest requires board-write permission in order to create a pin at all, so it appears on the consent screen — but we only ever use it to place a pin on a board you selected. We do not create, rename, or delete your boards. Your board list is fetched live when you open the picker and is not stored; the board you chose is saved alongside the post so we know where to publish it.
The consent screen mentions group boards you have joined. We list them only so you can choose one to pin to. We do not read other people’s pins, boards, or profiles, and we do not access Pinterest accounts that have not authorised us. We do not scrape Pinterest, and we do not redistribute Pinterest content — or anything derived from it — to any third party.
Your Pinterest access and refresh tokens are encrypted at rest, renewed automatically before they expire so your connection keeps working, and deleted the moment you disconnect the account. You can also revoke our access at any time from your Pinterest account settings.
How long we keep it
- Connected account credentials — deleted the moment you disconnect the account. Where the account was routed through our aggregator, we revoke it there too.
- Everything in a project — posts, media, delivery records, metrics, guardrails, audit log — deleted when you delete the project.
- Your user account — deleted on request, along with the projects you own.
- Waitlist entries — until you ask to be removed.
- Billing records — retained as long as tax and accounting law requires, even after your account is gone.
Deleted records may persist in encrypted database backups for a short rotation period before those backups expire.
Deleting something in xpost does not delete it from the social platform. A post already published to X is on X; you have to remove it there.
Security
- Platform tokens and other secrets are encrypted at rest with AES-256-GCM. Passwords are stored only as salted hashes.
- Everything travels over HTTPS.
- API keys are scoped — an agent key can be read-only, or allowed to write but not to approve — and every project is isolated from every other at the query level.
- An AI agent posting through the API lands in your approval queue by default and cannot publish around it.
No system is perfectly secure. If a breach ever affects your personal data, we will tell you and the relevant supervisory authority without undue delay, as the GDPR requires.
Cookies
One cookie, pg_session. It keeps you signed in for 30 days, is HTTP-only, and is marked Secure over HTTPS. It is strictly necessary, so it needs no consent banner. We set no analytics, advertising, or tracking cookies of any kind.
Where your data lives
Our servers and database are in Europe. Some of the services above (Stripe, Resend, Cloudflare, bundle.social, and the social platforms themselves) process data outside the EEA, including in the United States. Those transfers rely on the European Commission’s Standard Contractual Clauses or an equivalent approved mechanism.
Your rights
If you are in the EEA or the UK, you can ask us to give you a copy of your data, correct it, delete it, hand it over in a portable format, restrict what we do with it, or object to processing we base on legitimate interests. Where we rely on consent, you can withdraw it at any time without affecting what we did before.
Email privacy@xpost.to and we will answer within 30 days. There is no charge. If you think we have handled your data badly, you are entitled to complain to the data protection authority in your country — but please try us first, we would rather fix it.
Children
xpost is a business tool and is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has given us data, tell us and we will delete it.
Changes to this policy
When we change it, we update the date at the top. If a change materially affects your rights, we will email you before it takes effect rather than hope you notice.
Contact
privacy@xpost.to — for privacy questions, data requests, and anything on this page.