Trust
What we store, and what we never touch
You hand us the keys to your accounts. Here is exactly what we do with them, in plain words.
What we store
- Your email address and a one-way hash of your password — never the password itself.
- The name and picture of each connected account, so you can tell them apart.
- Your posts, pictures and videos, until you delete them.
- The access tokens the networks give us, so we can publish on your behalf.
- One record per delivery: where it went, when, and the link to the live post.
Access tokens are encrypted at rest
Accounts connect through each network's own sign-in page, so we never see a password. The access tokens we do hold are encrypted in the database with a key kept outside it. Disconnect an account and our access ends at once.
API keys are scoped
A key belongs to one project and can only reach that project's accounts. A key held by an AI agent can create posts, but every one of them waits for your approval — a key can never approve.
What xpost can and cannot do with your accounts
We can
- Publish the posts you or your approved agent asked us to publish.
- Read your own profile name and picture.
- Read views, likes and comments on the posts we published for you.
We never
- Post anything you did not set in motion.
- Read messages, follow anyone or read other people's content.
- Sell your data, share it with data brokers, or train models on it.
Where your data lives
The database, your media and the backups are all in the EU, in Frankfurt, Germany. The Privacy Policy names every company that processes data for us.
Backups every 6 hours
An encrypted copy of the database is taken every six hours and kept in a separate store. The key that writes the backups cannot delete them, so a stolen key cannot destroy them.
Delete your account and data
Open Settings and choose “Delete my account”. It removes your account, your projects, every post and picture, and ends our access to every connected account. You can also write to us and we will do it for you.
Report a security issue
Found something? Write to us before telling anyone else, and we will answer within two working days. We do not pursue researchers who report in good faith.privacy@xpost.to
What we do not claim
xpost does not hold a SOC 2 or ISO 27001 certificate. We would rather say so than show a badge we have not earned. If your company needs one, write to us and we will tell you where we are.
Who is responsible
xpost is operated by Digital Abstracts SL, registered in Spain under number B66760802, at Alaba 60, 2-2, 08005 Barcelona. Every security and privacy email reaches a person.Privacy PolicyTerms of ServiceData Processing Agreement
Questions people ask
No. Every account connects through the network's own sign-in page. We receive an access token, never a password, and the token is encrypted in the database with a key kept outside it.
Still got questions?
Contact us