Privacy Policy
Last updated 10 September 2026
xpost (“we”, “us”) runs a social media scheduling and publishing tool at xpost.to. You connect your own social accounts, you (or an AI agent you control) draft posts, and we publish them for you and report back how they did.
This policy explains what we hold, why we hold it, who else sees it, and how to make us delete it. It is written to be read, not to be survived. For anything it does not answer, email privacy@xpost.to.
The data controller for the information described here is Digital Abstracts SL (company number B66760802), registered in Spain at Alaba 60, 2-2, 08005 Barcelona. Where this policy uses terms from the EU General Data Protection Regulation (GDPR), they carry their GDPR meaning.
The short version
- We collect what the product needs to work, and nothing for advertising.
- We do not sell your data, share it with data brokers, or use it to train machine-learning models.
- We never ask for your password to a social platform. Accounts connect through each platform’s own sign-in — the one exception is Bluesky, which offers no such flow, so you create a revocable app password there and paste it here, and we store it encrypted.
- We read only your own content on connected platforms — never anyone else’s — and only to show it back to you.
- There are no advertising pixels and no cross-site trackers — nothing here follows you around the web. We do count visits, and we do record which link brought you here, so we know whether anyone is finding us.
- On our public pages — the ones anyone can read without signing in — we also record how the page itself was used, so we can see where it loses people. Whatever you type is hidden from that recording, and it stops the moment you reach your own dashboard. Nothing records your screen once you are signed in. All of this is measured on our own domain, kept in the European Union, never sold, and never used for advertising.
- Disconnect an account or delete your project and it is gone.
What we collect
Your account
- Your email address, and either a hashed password or the identifier from your Google sign-in. We never store a readable password.
- Your plan, subscription status, and customer identifiers from our payment provider. Card numbers go directly to Stripe and never touch our servers.
Social accounts you connect
- The access (and where the platform uses them, refresh) tokens issued when you authorise us, so we can post on your behalf — or, for Bluesky, the app password you created there and gave us, because Bluesky has no other way in. All of it is encrypted at rest with AES-256-GCM. Where a platform expires its tokens, we renew them automatically so your connection keeps working.
- Your handle, the platform’s internal ID for your account, and your profile picture, so you can see which account you are posting from.
What you create in the product
- Posts, captions, alt text, schedules, and any images or video you upload. Media files are held in our file storage in Frankfurt so we can hand them to each platform at publish time.
- Your guardrail rules, approval decisions, and an audit log of actions taken in your project — including everything an AI agent did with your API keys. The audit log is what makes an agent accountable, so we keep it for the life of the project.
- A technical log of every call made to our API or MCP server: which tool was called, by which key, whether it worked, and what it was asked to do. The arguments are stored shortened — the first 300 characters of any text — and anything that looks like a password, token or key is replaced before it is written. This log is deleted after 30 days.
- When you connect an AI assistant, it may send context of its own along with your request — ChatGPT, for instance, tells you it may share relevant chats and memories with an app you connect. What reaches us is only ever the fields our tools ask for: the words to post, which accounts, when, and the media you attach. We never ask an assistant for your conversation, and anything it holds beyond those fields stays with it.
If you use the AI features
Writing or tailoring a caption, suggesting alt text, and the banned-topics guardrail each send the text or image in question to Anthropic, our AI provider, for that one request. They are off unless AI is switched on for your workspace, they never run in the background, and nothing sent this way is used to train a model — not by us, not by them.
How your posts performed, and what is already on your profile
For posts we published for you, we periodically ask the platform for their engagement counts — impressions, likes, replies, reposts, bookmarks and equivalents — and store those numbers so your analytics page works. We request this only for post IDs we created for you.
We also read the posts already on the profile you connected, so the Feed can show your next post against what is actually up there rather than pretending your account began the day you signed up. For accounts routed through our aggregator this is a one-off import at connect time: it copies a batch of your own recent posts into the aggregator’s system, and we read that copy.
Either way it is your own account’s public content and nothing else. We do not read your followers, your direct messages, your private timeline, or any other account’s content.
If you join the waitlist
Your email address, an optional note about what you would use xpost for, and where you arrived from. Nothing else.
Ordinary server logs, and errors
Our hosting records requests, including IP addresses and browser user agents, for security and debugging. These are kept short-term and are not used to build a profile of you.
When something breaks, an error report goes to our error tracker: what failed, where in the code, and which page you were on. Web addresses are stripped of anything that acts as a credential before the report leaves us, your cookies and IP address are not attached, and the error tracker records no screen and no session.
Why we are allowed to hold it
- To perform our contract with you — your account, connected accounts, posts, media, and delivery records. Without these there is no product.
- Our legitimate interests — server logs, security measures, the audit log, and fraud and abuse prevention. We keep these minimal and to the point.
- Your consent — the waitlist, and any product announcement emails. Withdraw it at any time; every such email carries an unsubscribe link.
- Legal obligation — invoices and tax records, which we have to keep for as long as the law requires.
Who else sees it
We share data only with the services that make the product function, and only the parts they need. Each is bound by its own data-processing terms.
- The social platforms you connect — X, Bluesky, LinkedIn, Instagram, Facebook, TikTok, YouTube, Threads, and Pinterest. We send them the posts you asked us to publish. Once published, that content is governed by that platform’s own terms and privacy policy.
- bundle.social, our publishing aggregator, for platforms we have not yet connected to directly. It receives the post content and holds the authorization for the accounts connected through it.
- Stripe, for subscriptions and payments.
- Resend, for transactional email — sign-in verification, password resets, approval requests, and delivery alerts.
- Vercel, which hosts the site and stores your media, and Neon, which runs the database. Both hold the data in Frankfurt.
- Amazon Web Services, which holds our encrypted backups, also in Frankfurt.
- Sentry, for error reports when something breaks. Credentials that appear in a web address are stripped out before the report leaves us.
- PostHog, for counting visits and use of the product, on their European servers. It sees which pages were opened, which link or campaign brought someone to the site, and — once you have an account — which of a short list of things happened: you signed up, confirmed your address, connected an account, published a post, or changed your plan. It never sees your posts, your media, your messages, or anyone you publish to. The same stripping Sentry gets is applied here, so an approval or unsubscribe link never leaves with the rest.
- PostHog session recording, on our public pages only. This keeps a replay of the page as you used it — where you moved, what you clicked, how far you scrolled — so we can tell a page that reads well from one that does not. It is switched on for the pages anyone can read without signing in, including the sign-in and sign-up forms, and it is switched off for everything behind them: your dashboard, your posts, your media, and every link sent to you by email. Anything typed into a form is masked before it leaves your browser, passwords included, so the replay shows that a field was filled in and never what was put in it. Recordings are kept on PostHog’s European servers, deleted after 30 days, and a browser sending “Do Not Track” is never recorded at all.
- Anthropic, but only if you switch the AI features on — writing or tailoring a caption, suggesting alt text, and the classifier behind the banned-topics guardrail. It sees the text or image in that one request and does not train on it.
- The AI assistant you connect, if you connect one. Linking xpost to ChatGPT, Claude, Cursor or any other MCP client means that whatever you ask it for comes back through that assistant — your connected accounts, your posts and their captions, delivery links, analytics. So the operator of the assistant you chose sees it too: OpenAI for ChatGPT, Anthropic for Claude, whoever runs the one you picked. That happens only for the assistants you connect yourself, only for what you ask them, and you can revoke the connection at any time from Dashboard → AI agent.
- Cloudflare, for the domain’s DNS and for delivering mail sent to our published addresses.
If you use xpost on behalf of clients, the same list appears — with each company’s legal name and location — as Annex C of our Data Processing Agreement, alongside what we commit to as your processor. It applies automatically; nothing to sign.
We do not sell personal data, we do not share it with advertisers or data brokers, and we do not use your content or your metrics to train machine-learning models. If the business is ever sold or merged, your data may transfer with it — you would be told before that happened, and this policy would continue to apply until you were given a replacement.
A specific note about X
Our use of the X API follows the X Developer Agreement and Policy. We use it for three things: publishing posts and replies you have approved, confirming which account you connected, and reading the engagement counts on posts we published for you. We do not scrape X, we do not access accounts that have not authorised us, and we do not redistribute X content or make it — or anything derived from it — available to any third party or government entity. Your posts and their statistics are visible only to you, inside your own dashboard.
A specific note about Pinterest
Our use of the Pinterest API follows the Pinterest Developer Guidelines and the Pinterest API Terms of Service. We use it for four things: creating the pins you asked us to publish (including multi-image carousels) on the board you chose, confirming which Pinterest account you connected, listing your boards so you can pick one in the composer, and reading the engagement counts on pins we created for you.
When you connect Pinterest we ask for permission to read and write your pins and boards. Pinterest requires board-write permission in order to create a pin at all, so it appears on the consent screen — but we only ever use it to place a pin on a board you selected. We do not create, rename, or delete your boards. Your board list is fetched live when you open the picker and is not stored; the board you chose is saved alongside the post so we know where to publish it.
The consent screen mentions group boards you have joined. We list them only so you can choose one to pin to. We do not read other people’s pins, boards, or profiles, and we do not access Pinterest accounts that have not authorised us. We do not scrape Pinterest, and we do not redistribute Pinterest content — or anything derived from it — to any third party.
Your Pinterest access and refresh tokens are encrypted at rest, renewed automatically before they expire so your connection keeps working, and deleted the moment you disconnect the account. You can also revoke our access at any time from your Pinterest account settings.
How long we keep it
- Connected account credentials — deleted the moment you disconnect the account. Where the account was routed through our aggregator, we revoke it there too.
- Everything in a project — posts, media, delivery records, metrics, guardrails, audit log — deleted when you delete the project.
- Your user account — deleted on request, along with the projects you own.
- Waitlist entries — until you ask to be removed.
- Billing records — retained as long as tax and accounting law requires, even after your account is gone.
Deleted records may persist in encrypted database backups for a short rotation period before those backups expire.
Deleting something in xpost does not delete it from the social platform. A post already published to X is on X; you have to remove it there.
Security
- Platform tokens and other secrets are encrypted at rest with AES-256-GCM. Passwords are stored only as salted hashes.
- Everything travels over HTTPS.
- API keys are scoped — an agent key can be read-only, or allowed to write but not to approve — and every project is isolated from every other at the query level.
- An AI agent posting through the API lands in your approval queue by default and cannot publish around it.
No system is perfectly secure. If a breach ever affects your personal data, we will tell you and the relevant supervisory authority without undue delay, as the GDPR requires.
Cookies
All of ours, all functional, none of them tracking. The important one is pg_session: it keeps you signed in for 30 days, is HTTP-only, and is marked Secure over HTTPS. The rest are small conveniences — your time zone, which workspace you were last in, how you left a list sorted or filtered, a one-shot note to show you a message after a redirect, and a short-lived value that keeps a connect-an-account popup honest.
Two more come from counting visits. One remembers which link or campaign brought you here the first time, so that when somebody signs up we can tell what actually works; it holds a referring site and any campaign tags that were already in the address you clicked, nothing about you, and it expires after 90 days. The others belong to PostHog and tell one visit from the next. They are served from this domain, they are not shared with advertisers, and they are not used to follow you anywhere else.
There are no advertising or cross-site tracking cookies, and nobody else sets cookies here. If your browser sends a “Do Not Track” signal, none of this happens: no cookie is written and no visit is counted. That is the opt-out, and it works without asking us. It is also why there is no consent banner — the rest are what the site needs to work, and what is left is a visit count on our own domain rather than an advertising profile.
Where your data lives
Your database records, your media, and our backups are all stored in Frankfurt, in the European Union. Several of the companies above are United States companies and may process data outside the EEA, as do the social platforms themselves. Those transfers rely on the European Commission’s Standard Contractual Clauses or an equivalent approved mechanism.
Your rights
If you are in the EEA or the UK, you can ask us to give you a copy of your data, correct it, delete it, hand it over in a portable format, restrict what we do with it, or object to processing we base on legitimate interests. Where we rely on consent, you can withdraw it at any time without affecting what we did before.
Email privacy@xpost.to and we will answer within 30 days. There is no charge. If you think we have handled your data badly, you are entitled to complain to the data protection authority in your country — but please try us first, we would rather fix it.
Children
xpost is a business tool and is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has given us data, tell us and we will delete it.
Changes to this policy
When we change it, we update the date at the top. If a change materially affects your rights, we will email you before it takes effect rather than hope you notice.
Contact
privacy@xpost.to — for privacy questions, data requests, and anything on this page.
Digital Abstracts SL
Alaba 60, 2-2, 08005 Barcelona
Spain