Privacy Policy

Last updated 29 July 2026

xpost(“we”, “us”) runs a social media scheduling and publishing tool at xpost.to. You connect your own social accounts, you (or an AI agent you control) draft posts, and we publish them for you and report back how they did.

This policy explains what we hold, why we hold it, who else sees it, and how to make us delete it. It is written to be read, not to be survived. For anything it does not answer, email privacy@xpost.to.

We are the data controller for the information described here. Where this policy uses terms from the EU General Data Protection Regulation (GDPR), they carry their GDPR meaning.

The short version

What we collect

Your account

Social accounts you connect

What you create in the product

How your posts performed

For posts we published for you, we periodically ask the platform for their engagement counts — impressions, likes, replies, reposts, bookmarks and equivalents — and store those numbers so your analytics page works. We request this only for post IDs we created for you. We do not read your timeline, your followers, your direct messages, or any other account’s content.

If you join the waitlist

Your email address, an optional note about what you would use xpost for, and where you arrived from. Nothing else.

Ordinary server logs

Our servers record requests, including IP addresses and browser user agents, for security and debugging. These are kept short-term and are not used to build a profile of you.

Why we are allowed to hold it

Who else sees it

We share data only with the services that make the product function, and only the parts they need. Each is bound by its own data-processing terms.

We do not sell personal data, we do not share it with advertisers or data brokers, and we do not use your content or your metrics to train machine-learning models. If the business is ever sold or merged, your data may transfer with it — you would be told before that happened, and this policy would continue to apply until you were given a replacement.

A specific note about X

Our use of the X API follows the X Developer Agreement and Policy. We use it for three things: publishing posts and replies you have approved, confirming which account you connected, and reading the engagement counts on posts we published for you. We do not scrape X, we do not access accounts that have not authorised us, and we do not redistribute X content or make it — or anything derived from it — available to any third party or government entity. Your posts and their statistics are visible only to you, inside your own dashboard.

A specific note about Pinterest

Our use of the Pinterest API follows the Pinterest Developer Guidelines and the Pinterest API Terms of Service. We use it for four things: creating the pins you asked us to publish (including multi-image carousels) on the board you chose, confirming which Pinterest account you connected, listing your boards so you can pick one in the composer, and reading the engagement counts on pins we created for you.

When you connect Pinterest we ask for permission to read and write your pins and boards. Pinterest requires board-write permission in order to create a pin at all, so it appears on the consent screen — but we only ever use it to place a pin on a board you selected. We do not create, rename, or delete your boards. Your board list is fetched live when you open the picker and is not stored; the board you chose is saved alongside the post so we know where to publish it.

The consent screen mentions group boards you have joined. We list them only so you can choose one to pin to. We do not read other people’s pins, boards, or profiles, and we do not access Pinterest accounts that have not authorised us. We do not scrape Pinterest, and we do not redistribute Pinterest content — or anything derived from it — to any third party.

Your Pinterest access and refresh tokens are encrypted at rest, renewed automatically before they expire so your connection keeps working, and deleted the moment you disconnect the account. You can also revoke our access at any time from your Pinterest account settings.

How long we keep it

Deleted records may persist in encrypted database backups for a short rotation period before those backups expire.

Deleting something in xpost does not delete it from the social platform. A post already published to X is on X; you have to remove it there.

Security

No system is perfectly secure. If a breach ever affects your personal data, we will tell you and the relevant supervisory authority without undue delay, as the GDPR requires.

Cookies

One cookie, pg_session. It keeps you signed in for 30 days, is HTTP-only, and is marked Secure over HTTPS. It is strictly necessary, so it needs no consent banner. We set no analytics, advertising, or tracking cookies of any kind.

Where your data lives

Our servers and database are in Europe. Some of the services above (Stripe, Resend, Cloudflare, bundle.social, and the social platforms themselves) process data outside the EEA, including in the United States. Those transfers rely on the European Commission’s Standard Contractual Clauses or an equivalent approved mechanism.

Your rights

If you are in the EEA or the UK, you can ask us to give you a copy of your data, correct it, delete it, hand it over in a portable format, restrict what we do with it, or object to processing we base on legitimate interests. Where we rely on consent, you can withdraw it at any time without affecting what we did before.

Email privacy@xpost.to and we will answer within 30 days. There is no charge. If you think we have handled your data badly, you are entitled to complain to the data protection authority in your country — but please try us first, we would rather fix it.

Children

xpost is a business tool and is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has given us data, tell us and we will delete it.

Changes to this policy

When we change it, we update the date at the top. If a change materially affects your rights, we will email you before it takes effect rather than hope you notice.

Contact

privacy@xpost.to — for privacy questions, data requests, and anything on this page.