Postcast

Privacy Policy

Postcast is operated by Inaxxe. This policy explains what we collect and why.

How we protect your data

All traffic to and from Postcast is encrypted in transit over HTTPS/TLS. Sensitive data at rest is protected in multiple ways: account passwords are never stored in plain text - they're hashed with industry-standard, one-way hashing that cannot be reversed - and access tokens for connected social accounts (including YouTube) are encrypted at rest using an encryption key that is kept separate from the database itself, so database access alone is not enough to obtain a usable token. Access to production systems and stored data is restricted to authorized Inaxxe personnel. Disconnecting a social account deletes its stored credentials immediately, and stored tokens are only ever used for the specific publishing/metrics actions described below.

Account data

Your email address and password (stored as a one-way hash, never in plain text) to operate your account, plus billing details handled entirely by Stripe - we never see or store your card number ourselves.

Connected social media accounts & data protection

When you connect a platform (Facebook, Instagram, YouTube, TikTok), we store an encrypted access token that lets us publish content on your behalf, as you configure it. These tokens are encrypted at rest using a key kept separate from the database itself. We do not access your followers' data, your private messages, or anything beyond what's needed to publish the content you've queued.

Facebook & Instagram specifically

When you connect a Facebook Page, we request pages_show_list to let you pick which Page to connect, pages_manage_posts to publish the text, photo, and video posts you've scheduled to that Page, and business_management, which Facebook's own API requires for a Page with a linked Instagram professional account to even appear in your account list. If you also connect that linked Instagram account, we request instagram_basic to read its basic account details and instagram_content_publish to publish the photos and Reels you've scheduled. We request pages_read_engagement and read_insights to show performance metrics (likes, comments, reach) for the Facebook posts you've published through Postcast, and instagram_manage_insights for the same on Instagram media. Postcast never accesses your Page's or Instagram account's followers, private messages, or ad data.

YouTube specifically

Postcast uses YouTube API Services. By connecting a YouTube channel to Postcast, you agree to be bound by the YouTube Terms of Service.

When you connect a YouTube channel, we request two Google API scopes: youtube.readonly, used exactly once immediately after connecting to read your channel's display name so it can be shown in your Postcast connections list, and youtube.upload, used to publish the videos you've uploaded and scheduled inside Postcast, either immediately or at your chosen time. We also periodically (about once an hour) fetch view, like, and comment counts for videos you've published through Postcast, so you can see their performance in your dashboard. In total, the YouTube API Data we access, collect, and store is: your channel's display name, the video files and captions you upload, and view/like/comment counts for videos published through Postcast. Postcast never uploads a video without your own explicit action, and never accesses any other YouTube data - not your subscriptions, your other videos, your comments on other channels, or anything belonging to your viewers.

Revoking access: you can disconnect your YouTube channel at any time from Postcast's Connections page, which immediately deletes the stored access token from our systems. You can also revoke Postcast's access directly from Google's own account settings, at myaccount.google.com/connections.

Content you upload

Video and image files you upload are stored on our servers until published (and for a period after, so you can reuse them), and are never shared with anyone other than the platforms you've explicitly chosen to publish to.

What we don't do

We don't sell your data. We don't use your content for anything other than publishing it where you've asked us to. We don't access data belonging to your followers or the people who interact with your posts.

Cookies

Postcast places a single first-party session cookie to keep you signed in - nothing else. We don't use tracking, advertising, or analytics cookies, and we don't allow any third party to place cookies or similar technology through Postcast.

Data deletion & revoking access

Disconnecting a social account (from the Connections page, at any time) deletes its stored access credentials from our systems immediately, and stops any further access to that account's data. For platforms with their own account-level permissions manager, you can also revoke access directly there - for Google/YouTube, at myaccount.google.com/connections. Closing your Postcast account deletes your uploaded content and account data - contact us if you need this done on a specific timeline.

Third parties

We use Stripe for payment processing and the social platforms' own APIs (Meta, Google, TikTok) to publish content - each of those has its own privacy policy governing how they handle the interaction: Meta, Google, TikTok.

Postcast's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Contact: hello@inaxxe.com