Privacy Policy
Last updated: October 2, 2026
PostAll only keeps what it needs to publish the posts you write, to the accounts you pick, when you ask. Here is exactly what that is, platform by platform.
Overview
PostAll is a social media scheduling service for creators and businesses. You write a post once and publish it, right away or on a schedule, to X, Instagram, Threads, LinkedIn, TikTok and YouTube. PostAll is operated by the PostAll operator (“we”, “us”). This policy covers the PostAll website and app. It explains what data PostAll stores, what it reads from and sends to each platform, who receives it, how long it is kept, and how you can delete it.
We don't sell your data, we don't show ads, and PostAll has no analytics or advertising trackers.
What we store
Your PostAll account
- Name and email address you sign up with. Your email is used to sign in.
- Password, stored only as a salted hash by our sign-in system (Better Auth). We never store it in readable form.
- Timezone, detected from your browser the first time you open the app and editable in Settings. Every schedule uses it.
- Sessions: while you are signed in we keep a session record with its expiry time and the IP address and browser user agent your browser reported when you signed in.
Connected platform accounts
You connect an account through the platform's own official login (OAuth). You sign in on the platform's page, so PostAll never sees your platform password. For each connected account we store:
- Its public profile details: the platform's ID for the account, username or handle, display name, profile picture link and profile link.
- A few platform-specific identifiers needed to post or to show the right options, listed for each platform below.
- The access and refresh tokens the platform issues, the permissions (scopes) you granted and when the tokens expire. Tokens are encrypted with AES-256-GCM before they are saved. They are decrypted only in server memory, when PostAll needs them to publish, refresh a token or fetch posting options.
- The connection's status (working, or needs reconnecting) and the last error the platform returned.
Exactly what PostAll asks each platform for, stores and posts is listed in the TikTok, Instagram, Threads, X, YouTube & Google and LinkedIn sections.
Posts, schedules and media
- Posts: the text you write, any per-platform caption, the accounts you picked, the options you chose for each platform (for example a YouTube title, tags, privacy and “made for kids” setting, TikTok privacy, interaction and disclosure settings, or Instagram feed, Reel or Story), and the post's status and scheduled time.
- Uploaded photos and videos, with their file name, type, size, dimensions and length. Files are kept in cloud file storage, such as Cloudflare R2, at random, unguessable addresses. Those addresses have to be reachable from the internet, because Instagram, Threads and TikTok download media from a link rather than accepting an upload. Anyone who has the exact link can open the file, so only upload what you mean to publish.
- Publish results for every platform: whether it worked, the post's ID and link on that platform, any error or warning, the number of attempts and when it was published.
Server logs
The server writes short operational logs while publishing, such as which platform a post is going to and whether it succeeded or what error the platform returned. They are used only to keep PostAll running.
What we don't collect
PostAll doesn't read your feed, messages, followers, contacts or analytics on any platform. It only asks each platform for what is described in this policy.
How we use it
- To sign you in and keep you signed in.
- To show which accounts you have connected, and to preview your posts.
- To publish what you ask, only to the platforms and accounts you choose, at the time you choose, and to show you how each one went.
- To refresh platform tokens automatically so scheduled posts keep working, and to tell you when an account needs reconnecting.
- To ask a platform for posting information it requires the app to show, such as TikTok's creator info (allowed privacy levels and maximum video length) or Instagram's and Threads' publishing limits. This is read when you open the composer and isn't stored.
We don't use your data for advertising, we don't sell or rent it, and we don't use it to train AI models.
TikTok
PostAll connects to TikTok with TikTok Login Kit and publishes through TikTok's Content Posting API (Direct Post).
Permissions PostAll asks for
user.info.basic: to read your open_id, union_id, display name and avatar, so PostAll can show which TikTok account is connected.video.publish: to read your creator info and publish the videos and photo posts you create to your TikTok profile.
What PostAll reads and stores
- Your open_id and union_id, display name, username, avatar link and profile link.
- Your access token (valid for 24 hours) and refresh token (valid for up to a year), encrypted, and the permissions you granted.
Each time you open the composer, and again right before a post goes out, PostAll asks TikTok for your creator info: nickname, username, avatar, the privacy levels you can use, whether comments, Duets and Stitches are turned off for your account, and the longest video you can post. It's shown to you in the composer and used to check the post, and it isn't stored (apart from the username saved when you connect).
What PostAll posts
Only what you compose and send with Post now or Schedule: the video file (uploaded to TikTok) or your photos (which TikTok downloads from PostAll's media link), the caption, the photo title, and the settings you pick for that post: who can view it, whether comments, Duets and Stitches are allowed, the commercial content disclosure (“Your brand” or “Branded content”), the AI-generated label and, for photos, whether TikTok adds music. PostAll never picks a privacy level for you and never adds watermarks. After posting, PostAll checks the post's processing status with TikTok so it can show you the result.
Keeping and deleting it
Your tokens and profile details are deleted from PostAll the moment you disconnect the account. Your posts and their TikTok links stay in your PostAll history until you delete them or your PostAll account. Posts already published stay on TikTok until you delete them there. See Data deletion.
Revoking access
In the TikTok app: Settings and privacy → Security & permissions → Apps and services permissions, then remove PostAll. Revoking stops PostAll from using its tokens. To also delete what PostAll stored, disconnect the account on the Accounts page.
PostAll connects to Instagram professional accounts (Business or Creator) with Instagram Login and publishes through Meta's Instagram API.
Permissions PostAll asks for
instagram_business_basic: to read your account's ID, username, name, account type and profile picture, and your current publishing limit.instagram_business_content_publish: to publish the feed posts, carousels, Reels and Stories you create.
What PostAll reads and stores
- Your Instagram user ID and app-scoped ID, username, name, account type, profile picture link and profile link.
- Your long-lived access token, encrypted, and the permissions you granted. PostAll renews it before it expires so scheduled posts keep working.
Before you post, PostAll asks Instagram how many posts you've published in the last 24 hours, so the composer can warn you before you reach Instagram's limit. This isn't stored.
What PostAll posts
Only what you compose and send: your photos or videos (Instagram downloads them from PostAll's media links), the caption, and the format you pick (feed post, Reel or Story).
Keeping and deleting it
Your tokens and profile details are deleted from PostAll the moment you disconnect the account. Your posts and their Instagram links stay in your PostAll history until you delete them or your PostAll account. Posts already published stay on Instagram until you delete them there. See Data deletion.
Revoking access
In Instagram: Settings → Website permissions → Apps and websites, then remove PostAll. Revoking stops PostAll from using its tokens. To also delete what PostAll stored, disconnect the account on the Accounts page.
Threads
PostAll connects to Threads with Threads Login and publishes through Meta's Threads API.
Permissions PostAll asks for
threads_basic: to read your Threads ID, username, name and profile picture, and your current publishing limit.threads_content_publish: to publish the posts, photos, videos and carousels you create.
What PostAll reads and stores
- Your Threads user ID, username, name, profile picture link and profile link.
- Your long-lived access token, encrypted, and the permissions you granted. PostAll renews it before it expires.
Before you post, PostAll asks Threads how much of your daily publishing limit is left, so the composer can warn you. This isn't stored.
What PostAll posts
Only what you compose and send: the text, and any photos or videos (Threads downloads them from PostAll's media links).
Keeping and deleting it
Your tokens and profile details are deleted from PostAll the moment you disconnect the account. Your posts and their Threads links stay in your PostAll history until you delete them or your PostAll account. Posts already published stay on Threads until you delete them there. See Data deletion.
Revoking access
In the Threads app: Settings → Account → Website permissions (apps and websites), then remove PostAll. Revoking stops PostAll from using its tokens. To also delete what PostAll stored, disconnect the account on the Accounts page.
X
PostAll connects to X with OAuth 2.0 and publishes through the X API.
Permissions PostAll asks for
tweet.read: required by X, together with users.read, to look up the account you connected.users.read: to read your X user ID, username, name, profile picture, and verified status and subscription type as X reports them.tweet.write: to publish the posts you write.media.write: to upload the photos, GIFs and videos you attach.offline.access: to receive a refresh token, so scheduled posts still go out while you're away.
What PostAll reads and stores
- Your X user ID, username, name, profile picture link and profile link, and your verified status, verification type and subscription type.
- Your access token and refresh token, encrypted, and the permissions you granted.
What PostAll posts
Only what you compose and send: the text, any photos, GIF or video (uploaded to X), and the labels you choose (“made with AI” or “paid partnership”).
Keeping and deleting it
Your tokens and profile details are deleted from PostAll the moment you disconnect the account. Your posts and their X links stay in your PostAll history until you delete them or your PostAll account. Posts already published stay on X until you delete them there. See Data deletion.
Revoking access
On X: Settings → Security and account access → Apps and sessions → Connected apps, then revoke PostAll. Revoking stops PostAll from using its tokens. To also delete what PostAll stored, disconnect the account on the Accounts page.
YouTube & Google
PostAll uses YouTube API Services. It connects your channel with Google's OAuth sign-in and uploads videos through the YouTube Data API. By connecting a YouTube channel you agree to the YouTube Terms of Service. Google's handling of your data is described in the Google Privacy Policy.
Google API Services: Limited Use
PostAll's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In practice:
- Google user data is used only to upload your videos and show your channel in PostAll.
- It isn't transferred to anyone else, except as needed to provide that feature, to comply with the law, or to keep PostAll secure.
- It is never used for advertising, never sold, and never used to train AI or machine-learning models.
- Nobody reads it unless you ask us to, it's needed for security, or the law requires it.
Permissions PostAll asks for
youtube.upload: to upload the videos you choose to publish, with the title, description, tags and settings you pick.youtube.readonly: to look up which channel you connected (its ID, name, handle and picture) and to check the processing status of videos PostAll uploaded for you.
What PostAll reads and stores
- Your channel ID, name, handle, picture link and channel link.
- Your access token and refresh token, encrypted, and the permissions you granted.
- The ID and link of each video PostAll uploads for you.
PostAll doesn't read your other videos, comments, subscribers, playlists or analytics.
What PostAll posts
Only the video you choose, as a regular video or a Short, with the title, description (your post text), tags, privacy setting (public, unlisted or private) and “made for kids” setting you pick.
Keeping and deleting it
Your tokens and profile details are deleted from PostAll the moment you disconnect the account. Your posts and their YouTube links stay in your PostAll history until you delete them or your PostAll account. Posts already published stay on YouTube until you delete them there. See Data deletion.
Revoking access
In addition to disconnecting in PostAll, you can revoke PostAll's access to your Google data at any time from the Google security settings page. Revoking stops PostAll from using its tokens. To also delete what PostAll stored, disconnect the account on the Accounts page.
PostAll connects to LinkedIn with Sign In with LinkedIn (OpenID Connect) and publishes with LinkedIn's Share on LinkedIn API.
Permissions PostAll asks for
openid, profile, email: to identify your LinkedIn member account: member ID, name and profile photo. LinkedIn includes your email address with these permissions. PostAll stores it with the connection and doesn't use it for anything else.w_member_social: to publish the posts you create to your LinkedIn profile.
What PostAll reads and stores
- Your LinkedIn member ID, name, profile photo link and email address.
- Your access token, encrypted, and the permissions you granted.
What PostAll posts
Only what you compose and send: the text, any photos or video, and who can see it (anyone, or your connections only).
Keeping and deleting it
Your tokens and profile details are deleted from PostAll the moment you disconnect the account. Your posts and their LinkedIn links stay in your PostAll history until you delete them or your PostAll account. Posts already published stay on LinkedIn until you delete them there. See Data deletion.
Revoking access
On LinkedIn: Settings → Data privacy → Permitted services, then remove PostAll. Revoking stops PostAll from using its tokens. To also delete what PostAll stored, disconnect the account on the Accounts page.
Security
- Platform tokens are encrypted at rest with AES-256-GCM, using a key that stays on the server.
- Passwords are stored only as salted hashes.
- Connecting an account uses OAuth with a state check and, where the platform supports it, PKCE. PostAll only requests the permissions it uses.
No system is perfectly secure, but we work to protect your data and fix problems quickly.
Retention
- Your PostAll profile is kept while you have a PostAll account.
- A connected account, including its encrypted tokens, is kept until you disconnect it or delete your PostAll account. If a platform stops accepting the tokens, the account is marked “needs reconnect” but stays stored until you disconnect it.
- Posts, schedules and publish results are kept until you delete the post or your PostAll account.
- Uploaded media stays in storage while your PostAll account exists, even after the post that used it is deleted. It is erased when your PostAll account is deleted.
- Information a platform shares only for the composer (TikTok creator info, Instagram and Threads publishing limits) isn't stored at all.
- Sessions end when you sign out or after 30 days.
- Posts already published live on the platform. Deleting a post in PostAll doesn't remove it from the platform. Delete it there if you want it gone.
Data deletion
You can remove your data from PostAll at any time.
Disconnect a platform account
- Open the Accounts page while signed in.
- Find the account and choose Disconnect, then confirm.
This immediately and permanently deletes that connection from PostAll's database: its encrypted access and refresh tokens and the profile details stored with it. PostAll can no longer post to that account. Your post history keeps the record of what was already published (including its link) until you delete those posts.
Delete a post
Open the post from the Posts page and choose Delete. This removes its text, schedule, platform settings and publish results from PostAll. A post can't be deleted while it is publishing.
Delete your whole PostAll account
PostAll doesn't have a self-serve “delete account” button yet. To delete your account, email support@your-domain.com from (or mentioning) the email address you use for PostAll. We will delete your account and everything linked to it: your profile and sign-in details, sessions, connected accounts and their tokens, posts, schedules, publish results and uploaded media files. We do this within 30 days and confirm when it is done.
Revoke access on the platform too
Disconnecting in PostAll deletes the tokens PostAll holds, but it doesn't remove PostAll from the platform's list of apps you have authorized. You can revoke PostAll's access there at any time:
- TikTok: Settings and privacy → Security & permissions → Apps and services permissions
- Instagram: Settings → Website permissions → Apps and websites
- Threads: Settings → Account → Website permissions (apps and websites)
- X: Settings → Security and account access → Apps and sessions → Connected apps
- YouTube / Google: Google security settings page
- LinkedIn: Settings → Data privacy → Permitted services
Revoking on the platform stops PostAll from using the tokens. To also delete what PostAll stored, disconnect the account in PostAll as well.
Instagram and Threads are the exception: removing PostAll there tells PostAll to delete the connected account automatically, and you can check on a deletion request on the data deletion page.
Your choices
- Change your name and timezone any time in Settings.
- Choose, for every post, which accounts it goes to, or connect no accounts at all.
- Ask us for a copy of your data, a correction or deletion at support@your-domain.com.
Children
PostAll is not meant for children. You must be old enough to hold an account on the platforms you connect, and at least 13.
Changes to this policy
If PostAll starts handling data differently, we will update this page and the “Last updated” date above before the change takes effect.
Contact
PostAll is operated by the PostAll operator. For privacy questions or requests, including account deletion, email support@your-domain.com. See also our Terms of Service.