Privacy Policy
We believe in complete transparency. Here is a clear, human-readable breakdown of exactly what data PostaGrid collects, why we need it, and how we protect it in compliance with global privacy standards.
Data Categories & Exact Purpose
We strictly collect only what is necessary to operate our scheduling service. Here is the exact breakdown:
| Data Category | Exact Purpose |
|---|---|
| Name & Email | Account creation, login authentication, and system notifications. |
| OAuth Access Tokens | To securely authenticate with social platforms and publish your scheduled posts. |
| Social Account ID & Username | To identify the correct destination for your posts and display it in your dashboard. |
| Uploaded Media (Images/Videos) | Temporarily stored to schedule and publish to your selected social platforms. |
| Log & Device Data (IP Address) | For security monitoring, preventing unauthorized access, and troubleshooting. |
🔒 Security Note: We NEVER ask for, see, or store your social media passwords.
Cookies & Authentication
PostaGrid uses essential cookies strictly for operational security. We use:
- ✓ Session Cookies: To keep you securely logged into your dashboard.
- ✓ CSRF Cookies: To protect your account from Cross-Site Request Forgery attacks.
Third-Party Services
We never sell your data. We only interact with actual services required to run PostaGrid:
- ✓ Social APIs: Meta (Facebook/Instagram), TikTok, Google (YouTube), LinkedIn, Pinterest, Tumblr, and X APIs are utilized strictly for publishing.
- ✓ Generative AI APIs: Google Gemini API is used strictly when you request AI-generated captions.
- ✓ Infrastructure: Secure Cloud Hosting and database providers for server operations.
Security Measures & Encryption
Your data security is implemented at the code level. Our actual security measures include:
- ✓ In-Transit Encryption: All traffic is forced through HTTPS/TLS.
- ✓ Password Hashing: User passwords are mathematically hashed using modern algorithms (bcrypt) before reaching the database.
- ✓ Database Protection: We utilize PDO Prepared Statements to prevent SQL injection attacks.
Data Retention Timeline
- ✓ Account Data & Tokens: Retained only while your account is active. If you initiate account deletion, your data and OAuth tokens are wiped from our active databases immediately.
- ✓ Uploaded Media: Media files used for posts are deleted from our temporary storage after the post is successfully published.
- ✓ Server Logs: Retained for a maximum of 30 days for security auditing, then automatically purged.
Your Legal Rights (UK/EU GDPR)
We operate under the legal basis of Contractual Necessity, Consent, and Legitimate Interests. You have complete control over your personal data:
If you believe your privacy rights have been violated, you may lodge a complaint with your local data protection authority (e.g., ICO in the UK).
Data Controller & Compliance
Bilal (Independent Developer) — Operating from London, United Kingdom
compliance@postagrid.xyz