Last Updated: August 2026

Privacy Policy

We believe in complete transparency. Here is a clear, human-readable breakdown of exactly what data PostaGrid collects, why we need it, and how we protect it in compliance with global privacy standards.

1️⃣

Data Categories & Exact Purpose

We strictly collect only what is necessary to operate our scheduling service. Here is the exact breakdown:

Data Category Exact Purpose
Name & Email Account creation, login authentication, and system notifications.
OAuth Access Tokens To securely authenticate with social platforms and publish your scheduled posts.
Social Account ID & Username To identify the correct destination for your posts and display it in your dashboard.
Uploaded Media (Images/Videos) Temporarily stored to schedule and publish to your selected social platforms.
Log & Device Data (IP Address) For security monitoring, preventing unauthorized access, and troubleshooting.

🔒 Security Note: We NEVER ask for, see, or store your social media passwords.

2️⃣

Cookies & Authentication

PostaGrid uses essential cookies strictly for operational security. We use:

  • Session Cookies: To keep you securely logged into your dashboard.
  • CSRF Cookies: To protect your account from Cross-Site Request Forgery attacks.
3️⃣

Third-Party Services

We never sell your data. We only interact with actual services required to run PostaGrid:

  • Social APIs: Meta (Facebook/Instagram), TikTok, Google (YouTube), LinkedIn, Pinterest, Tumblr, and X APIs are utilized strictly for publishing.
  • Generative AI APIs: Google Gemini API is used strictly when you request AI-generated captions.
  • Infrastructure: Secure Cloud Hosting and database providers for server operations.
4️⃣

Security Measures & Encryption

Your data security is implemented at the code level. Our actual security measures include:

  • In-Transit Encryption: All traffic is forced through HTTPS/TLS.
  • Password Hashing: User passwords are mathematically hashed using modern algorithms (bcrypt) before reaching the database.
  • Database Protection: We utilize PDO Prepared Statements to prevent SQL injection attacks.
5️⃣

Data Retention Timeline

  • Account Data & Tokens: Retained only while your account is active. If you initiate account deletion, your data and OAuth tokens are wiped from our active databases immediately.
  • Uploaded Media: Media files used for posts are deleted from our temporary storage after the post is successfully published.
  • Server Logs: Retained for a maximum of 30 days for security auditing, then automatically purged.
6️⃣

Your Legal Rights (UK/EU GDPR)

We operate under the legal basis of Contractual Necessity, Consent, and Legitimate Interests. You have complete control over your personal data:

Access & Export: Request a structured copy of your data.
Erasure: Request full deletion of your account.
Withdraw Consent: Revoke API access anytime.
Rectification: Correct inaccurate data.

If you believe your privacy rights have been violated, you may lodge a complaint with your local data protection authority (e.g., ICO in the UK).

Data Controller & Compliance

Bilal (Independent Developer) — Operating from London, United Kingdom
compliance@postagrid.xyz

View Data Deletion Policy ➔