Privacy Policy

Last updated 10 September 2026

xpost (“we”, “us”) runs a social media scheduling and publishing tool at xpost.to. You connect your own social accounts, you (or an AI agent you control) draft posts, and we publish them for you and report back how they did.

This policy explains what we hold, why we hold it, who else sees it, and how to make us delete it. It is written to be read, not to be survived. For anything it does not answer, email privacy@xpost.to.

The data controller for the information described here is Digital Abstracts SL (company number B66760802), registered in Spain at Alaba 60, 2-2, 08005 Barcelona. Where this policy uses terms from the EU General Data Protection Regulation (GDPR), they carry their GDPR meaning.

The short version

What we collect

Your account

Social accounts you connect

What you create in the product

If you use the AI features

Writing or tailoring a caption, suggesting alt text, and the banned-topics guardrail each send the text or image in question to Anthropic, our AI provider, for that one request. They are off unless AI is switched on for your workspace, they never run in the background, and nothing sent this way is used to train a model — not by us, not by them.

How your posts performed, and what is already on your profile

For posts we published for you, we periodically ask the platform for their engagement counts — impressions, likes, replies, reposts, bookmarks and equivalents — and store those numbers so your analytics page works. We request this only for post IDs we created for you.

We also read the posts already on the profile you connected, so the Feed can show your next post against what is actually up there rather than pretending your account began the day you signed up. For accounts routed through our aggregator this is a one-off import at connect time: it copies a batch of your own recent posts into the aggregator’s system, and we read that copy.

Either way it is your own account’s public content and nothing else. We do not read your followers, your direct messages, your private timeline, or any other account’s content.

If you join the waitlist

Your email address, an optional note about what you would use xpost for, and where you arrived from. Nothing else.

Ordinary server logs, and errors

Our hosting records requests, including IP addresses and browser user agents, for security and debugging. These are kept short-term and are not used to build a profile of you.

When something breaks, an error report goes to our error tracker: what failed, where in the code, and which page you were on. Web addresses are stripped of anything that acts as a credential before the report leaves us, your cookies and IP address are not attached, and the error tracker records no screen and no session.

Why we are allowed to hold it

Who else sees it

We share data only with the services that make the product function, and only the parts they need. Each is bound by its own data-processing terms.

If you use xpost on behalf of clients, the same list appears — with each company’s legal name and location — as Annex C of our Data Processing Agreement, alongside what we commit to as your processor. It applies automatically; nothing to sign.

We do not sell personal data, we do not share it with advertisers or data brokers, and we do not use your content or your metrics to train machine-learning models. If the business is ever sold or merged, your data may transfer with it — you would be told before that happened, and this policy would continue to apply until you were given a replacement.

A specific note about X

Our use of the X API follows the X Developer Agreement and Policy. We use it for three things: publishing posts and replies you have approved, confirming which account you connected, and reading the engagement counts on posts we published for you. We do not scrape X, we do not access accounts that have not authorised us, and we do not redistribute X content or make it — or anything derived from it — available to any third party or government entity. Your posts and their statistics are visible only to you, inside your own dashboard.

A specific note about Pinterest

Our use of the Pinterest API follows the Pinterest Developer Guidelines and the Pinterest API Terms of Service. We use it for four things: creating the pins you asked us to publish (including multi-image carousels) on the board you chose, confirming which Pinterest account you connected, listing your boards so you can pick one in the composer, and reading the engagement counts on pins we created for you.

When you connect Pinterest we ask for permission to read and write your pins and boards. Pinterest requires board-write permission in order to create a pin at all, so it appears on the consent screen — but we only ever use it to place a pin on a board you selected. We do not create, rename, or delete your boards. Your board list is fetched live when you open the picker and is not stored; the board you chose is saved alongside the post so we know where to publish it.

The consent screen mentions group boards you have joined. We list them only so you can choose one to pin to. We do not read other people’s pins, boards, or profiles, and we do not access Pinterest accounts that have not authorised us. We do not scrape Pinterest, and we do not redistribute Pinterest content — or anything derived from it — to any third party.

Your Pinterest access and refresh tokens are encrypted at rest, renewed automatically before they expire so your connection keeps working, and deleted the moment you disconnect the account. You can also revoke our access at any time from your Pinterest account settings.

How long we keep it

Deleted records may persist in encrypted database backups for a short rotation period before those backups expire.

Deleting something in xpost does not delete it from the social platform. A post already published to X is on X; you have to remove it there.

Security

No system is perfectly secure. If a breach ever affects your personal data, we will tell you and the relevant supervisory authority without undue delay, as the GDPR requires.

Cookies

All of ours, all functional, none of them tracking. The important one is pg_session: it keeps you signed in for 30 days, is HTTP-only, and is marked Secure over HTTPS. The rest are small conveniences — your time zone, which workspace you were last in, how you left a list sorted or filtered, a one-shot note to show you a message after a redirect, and a short-lived value that keeps a connect-an-account popup honest.

Two more come from counting visits. One remembers which link or campaign brought you here the first time, so that when somebody signs up we can tell what actually works; it holds a referring site and any campaign tags that were already in the address you clicked, nothing about you, and it expires after 90 days. The others belong to PostHog and tell one visit from the next. They are served from this domain, they are not shared with advertisers, and they are not used to follow you anywhere else.

There are no advertising or cross-site tracking cookies, and nobody else sets cookies here. If your browser sends a “Do Not Track” signal, none of this happens: no cookie is written and no visit is counted. That is the opt-out, and it works without asking us. It is also why there is no consent banner — the rest are what the site needs to work, and what is left is a visit count on our own domain rather than an advertising profile.

Where your data lives

Your database records, your media, and our backups are all stored in Frankfurt, in the European Union. Several of the companies above are United States companies and may process data outside the EEA, as do the social platforms themselves. Those transfers rely on the European Commission’s Standard Contractual Clauses or an equivalent approved mechanism.

Your rights

If you are in the EEA or the UK, you can ask us to give you a copy of your data, correct it, delete it, hand it over in a portable format, restrict what we do with it, or object to processing we base on legitimate interests. Where we rely on consent, you can withdraw it at any time without affecting what we did before.

Email privacy@xpost.to and we will answer within 30 days. There is no charge. If you think we have handled your data badly, you are entitled to complain to the data protection authority in your country — but please try us first, we would rather fix it.

Children

xpost is a business tool and is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has given us data, tell us and we will delete it.

Changes to this policy

When we change it, we update the date at the top. If a change materially affects your rights, we will email you before it takes effect rather than hope you notice.

Contact

privacy@xpost.to — for privacy questions, data requests, and anything on this page.

Digital Abstracts SL
Alaba 60, 2-2, 08005 Barcelona
Spain