Post Pilot ("we", "our", "the app") helps you schedule and publish posts to your own social media accounts. This page explains what information we access, why we access it, and how you stay in control of it.
1. What we access
When you connect an account, we only request the minimum information needed to schedule and publish posts on your behalf:
Facebook: your Page name, Page ID, and permission to publish posts to that Page.
Instagram: your Instagram professional account name and ID (linked to your Facebook Page), and permission to publish content to it.
YouTube: your channel name and ID, and permission to upload videos on your behalf.
We do not access your personal messages, contacts, private photos, or any data unrelated to publishing the content you create inside Post Pilot.
2. How we use this information
To show you which accounts are connected inside the app.
To publish or schedule the posts, reels, or videos you create, at the time you choose.
To display basic account details (name, profile picture) so you can confirm the right account is connected.
3. How we store your information
We store your account access tokens and basic profile details securely in our database, only for as long as your account stays connected. We do not sell, rent, or share your data with third parties for advertising or any other purpose.
4. Data protection & security
Your Facebook, Instagram, and YouTube access tokens are sensitive data because they grant permission to publish on your behalf. We protect this data using the following mechanisms:
Encryption in transit: All communication between your browser, our servers, and Facebook/Instagram/YouTube APIs is encrypted using HTTPS/TLS. We never transmit access tokens or account data over unencrypted connections.
Encryption at rest: Access tokens and account credentials are stored in our database in encrypted form. They are not stored in plain text at any point.
Restricted access: Only backend services required to publish your scheduled content can read stored tokens. No Post Pilot employee has standing access to your access tokens outside of debugging a specific issue you report.
Minimal retention: We retain your access token only for as long as the account remains connected. When you disconnect an account, its token is permanently deleted from our database immediately — not just deactivated.
Scoped permissions: We request only the specific OAuth scopes needed to publish content (e.g. page/account name and publishing permission) — never scopes that would let us read your messages, contacts, or private data.
Secure hosting: Our database and backend run on reputable managed cloud infrastructure with access-controlled, authenticated administrative access.
5. Your control over your data
You can disconnect any account at any time from the Accounts page inside Post Pilot — this immediately removes our access and deletes the stored access token for that account.
You can also revoke access directly from Facebook, Instagram, or Google account settings at any time.
You may request full deletion of your data by contacting us (see below).
6. Data sharing
We do not share your data with any third party except the platforms you explicitly connect (Facebook, Instagram, YouTube) — and only to carry out the publishing actions you request.
7. Children's privacy
Post Pilot is not intended for use by anyone under 13 years of age. We do not knowingly collect data from children.
8. Changes to this policy
We may update this policy occasionally. Any changes will be posted on this page with an updated date at the top.
9. Contact us
If you have any questions about this Privacy Policy or how your data is handled, contact us at: