This Privacy Policy explains how Octopost.ai ("Octopost," "we," "our," or "us") collects, uses, stores, and shares information when you use our website, social media management platform, public API, OAuth authorization features, AI assist features, and related services (collectively, the "Services").
This Policy is a privacy notice, not a contract. Your use of the Services is governed by our Terms of Service.
1. Contact and Controller
For privacy questions, data requests, or legal notices related to privacy, contact Octopost.ai at [email protected].
If you are in the EU or UK, Octopost.ai acts as the controller for personal data processed through the Services unless another party is clearly identified as the controller.
2. Information We Collect
2.1 Account and Workspace Information
- Name, email address, avatar, and account settings
- Authentication credentials, stored in hashed form where applicable
- Workspace names, members, roles, invitations, and billing plan details
- Support requests, email preferences, and service communications
2.2 Social Account and Publishing Information
- Connected social account identifiers, profile/page metadata, permissions, and platform tokens
- OAuth access tokens and refresh tokens needed to publish, sync, and maintain connected accounts
- Posts, captions, comments, approvals, scheduled times, publishing status, and related workflow activity
- Uploaded or imported media, including images, videos, filenames, file metadata, and generated thumbnails
- Analytics data such as impressions, reach, engagement, audience insights, and post performance where available from connected platforms
- Inbox data for supported Facebook workflows, including comments, direct messages, sender/page metadata, read status, and reply context where available through platform APIs
2.3 API, OAuth, and Developer Information
- API key metadata, OAuth client information, OAuth authorization records, scopes, token metadata, and request logs
- IP address, user agent, timestamps, rate-limit metadata, error logs, and security audit information
2.4 Billing Information
Paid subscriptions are processed by Polar. We may receive billing status, plan, invoice, subscription, and payment event metadata. We do not intentionally store full payment card numbers.
2.5 Automatically Collected Information
- IP address, browser type, device information, operating system, approximate location derived from IP, and referring pages
- Login timestamps, page views, feature usage, errors, and security events
- Cookies and similar technologies used for sessions, security, preferences, and product functionality
3. How We Use Information
We use information to:
- Provide, maintain, secure, and improve the Services
- Authenticate users and protect accounts, workspaces, API keys, and OAuth flows
- Connect social accounts, publish scheduled content, sync analytics, and support Facebook inbox workflows
- Process uploads, store media, generate previews, and manage publishing workflows
- Provide AI-assisted drafting, rewriting, caption generation, and related features when you choose to use them
- Process subscriptions, trials, billing events, and plan limits
- Send transactional emails, service notices, security alerts, and support responses
- Detect abuse, spam, fraud, security incidents, and violations of our Terms or platform policies
- Comply with legal obligations and enforce our rights
If you are in the EU or UK, our legal bases may include performance of a contract, legitimate interests, consent where required, and compliance with legal obligations.
4. AI Features
When you use AI features, the text, prompts, URLs, brand context, media context, and instructions you provide may be sent to AI providers such as OpenAI and Anthropic to generate or refine outputs.
Do not submit sensitive personal data, confidential information, regulated data, or content you do not have permission to process through AI features. We do not use your content to train our own AI models.
5. How We Share Information
We do not sell your personal information. We may share information with:
- Social platforms: Facebook and other connected platforms, as needed to publish, sync account data, retrieve analytics, and support approved workflows.
- Infrastructure and storage providers: including Cloudflare R2 for media storage and related infrastructure.
- Email providers: including Brevo for transactional and service email.
- Payment providers: including Polar for subscriptions, trials, invoices, and payment events.
- AI providers: including OpenAI and Anthropic when you use AI features.
- Realtime providers: including Pusher for realtime app updates and notifications.
- Professional, legal, or compliance recipients: where necessary to comply with law, enforce terms, protect rights, or respond to lawful requests.
- Business transfer recipients: if the Services are transferred, sold, merged, or reorganized.
Service providers may process information only as needed to provide their services to us, subject to their own terms and data protection obligations.
6. Connecting Social Accounts
When you connect a social account, you authorize Octopost to access the permissions you approve through the platform OAuth flow. These permissions may allow us to publish content, retrieve account metadata, sync analytics, refresh tokens, and, for supported Facebook workflows, sync comments, direct messages, and related inbox data.
We do not ask for or store your social platform passwords. You can revoke Octopost access through the relevant social platform settings, though doing so may stop publishing, analytics, inbox, or automation features from working.
We do not post content unless you, a workspace member with permission, an approved automation, or an authorized API/OAuth client instructs the Services to do so.
7. Data Storage and Security
We use technical and organizational safeguards intended to protect information, including access controls, encrypted connections, hashed credentials, secure token handling, and operational monitoring. Media files may be stored in Cloudflare R2.
No method of transmission or storage is completely secure. You are responsible for keeping account credentials, API keys, OAuth clients, and workspace permissions secure.
8. Data Retention
We keep information for as long as needed to provide the Services, comply with legal obligations, resolve disputes, prevent abuse, enforce agreements, and maintain security. Retention periods may vary by data type.
When an account or workspace is deleted, we will delete or anonymize associated information within a reasonable timeframe unless we need to retain it for legal, security, billing, backup, or abuse-prevention purposes. Backups and logs may persist for a limited period before being overwritten or deleted.
9. Your Rights
Depending on your location, you may have rights to request access, correction, deletion, portability, restriction, objection, or withdrawal of consent where processing is based on consent.
If you are in the EU or UK, you may also have the right to lodge a complaint with your local data protection authority.
If you are in California or another jurisdiction with privacy rights, you may have rights to know, access, delete, correct, or opt out of certain sharing depending on applicable law. We do not sell personal information.
To exercise privacy rights, contact [email protected]. We may need to verify your identity before responding.
10. Cookies and Similar Technologies
We use cookies and similar technologies for sessions, authentication, security, preferences, product functionality, and usage analysis. You can manage cookies through your browser settings, but disabling some cookies may prevent parts of the Services from working.
11. International Data Transfers
Your information may be processed in countries other than where you live, including the United States and locations where our providers operate. Where required, we rely on appropriate safeguards for international transfers, such as provider data processing terms, contractual protections, and other lawful transfer mechanisms.
12. Children and Age Restrictions
The Services are intended for users who are at least 18 years old. We do not knowingly collect personal data from anyone under 18. If you believe someone under 18 has provided data to us, contact us at [email protected].
13. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. If changes are material, we may provide additional notice where appropriate.
14. Contact
If you have questions or concerns about this Privacy Policy, contact us at:
- Email: [email protected]
- Website: https://octopost.ai