Trust

What we store, and what we never touch

You hand us the keys to your accounts. Here is exactly what we do with them, in plain words.

What we store

  • Your email address and a one-way hash of your password — never the password itself.
  • The name and picture of each connected account, so you can tell them apart.
  • Your posts, pictures and videos, until you delete them.
  • The access tokens the networks give us, so we can publish on your behalf.
  • One record per delivery: where it went, when, and the link to the live post.

Access tokens are encrypted at rest

Accounts connect through each network's own sign-in page, so we never see a password. The access tokens we do hold are encrypted in the database with a key kept outside it. Disconnect an account and our access ends at once.

API keys are scoped

A key belongs to one project and can only reach that project's accounts. A key held by an AI agent can create posts, but every one of them waits for your approval — a key can never approve.

What xpost can and cannot do with your accounts

We can

  • Publish the posts you or your approved agent asked us to publish.
  • Read your own profile name and picture.
  • Read views, likes and comments on the posts we published for you.

We never

  • Post anything you did not set in motion.
  • Read messages, follow anyone or read other people's content.
  • Sell your data, share it with data brokers, or train models on it.

Where your data lives

The database, your media and the backups are all in the EU, in Frankfurt, Germany. The Privacy Policy names every company that processes data for us.

Backups every 6 hours

An encrypted copy of the database is taken every six hours and kept in a separate store. The key that writes the backups cannot delete them, so a stolen key cannot destroy them.

Delete your account and data

Open Settings and choose “Delete my account”. It removes your account, your projects, every post and picture, and ends our access to every connected account. You can also write to us and we will do it for you.

Report a security issue

Found something? Write to us before telling anyone else, and we will answer within two working days. We do not pursue researchers who report in good faith.privacy@xpost.to

What we do not claim

xpost does not hold a SOC 2 or ISO 27001 certificate. We would rather say so than show a badge we have not earned. If your company needs one, write to us and we will tell you where we are.

Who is responsible

xpost is operated by Digital Abstracts SL, registered in Spain under number B66760802, at Alaba 60, 2-2, 08005 Barcelona. Every security and privacy email reaches a person.Privacy PolicyTerms of ServiceData Processing Agreement

Questions people ask

  • No. Every account connects through the network's own sign-in page. We receive an access token, never a password, and the token is encrypted in the database with a key kept outside it.

Still got questions?

Contact us

Your next month of posts, planned this afternoon.

Try it for free

No credit card · Cancel any time