Privacy Policy
1. Overview & Scope
PostMCP AI (“PostMCP AI”, “we”, “us”) provides a social media scheduling and publishing platform, available at postmcpai.com, together with its API and Model Context Protocol (MCP) server, which lets you connect social accounts and publish content to them — directly or through an AI assistant.
This policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and how you can review, export or delete it. It applies to the PostMCP AI website, dashboard, API and MCP server. It does not apply to the social platforms themselves (Facebook, Instagram, Threads, LinkedIn, X, Bluesky, YouTube), which handle your data under their own policies.
For the purposes of the EU/UK GDPR, PostMCP AI is the data controller for account data and the content you submit to our service. Where you connect a social account, we act on your instructions to transmit your content to that platform.
2. Information We Collect
We limit collection to what is required to operate scheduling and publishing workflows. We collect:
- Account data: your name, email address, avatar URL, and either a hashed password or the provider identifier from the sign-in service you used (Google, GitHub, LinkedIn or X). We never store your social sign-in password.
- Access credentials for connected platforms: OAuth access tokens and refresh tokens issued by the platform you connect — including Google/YouTube (see §5) — and (for Bluesky) the app password and server URL you supply. These are stored encrypted — see §7.
- Connected profile metadata: platform account IDs, usernames/handles, display names, Page or organization names, profile picture URLs, and token expiry dates — used to show you which accounts are connected and to target the right destination for a post.
- Content you submit: post drafts, captions, links, images and video you upload or generate for publishing, and scheduling times.
- AI assistant data: your chat messages with the AI assistant, the assistant’s responses, tool-call logs, proposed actions and token usage counts.
- Workspace data: project names, members and their roles, and the email addresses you enter to invite collaborators.
- Publishing and diagnostic logs: API request and response statuses, published post identifiers, and error messages, used to confirm delivery and troubleshoot failures.
- Billing data: your plan, subscription status and validity, billing email, and a subscription identifier from our payment processor. We do not receive or store card numbers.
- Usage and device data: product analytics events, pages viewed, browser and device type, approximate location derived from IP address, and session cookies — see §12.
We do not knowingly collect special-category data (health, biometrics, religion, political opinions, precise location) and ask that you do not submit it.
3. How & Why We Use Data
We process your information only to deliver, secure and support the service:
| Purpose | Legal basis (GDPR) |
|---|---|
| Create and authenticate your account and sessions | Performance of a contract |
| Connect social accounts and display connection status | Performance of a contract |
| Publish and schedule the posts you create, and report delivery status back to you | Performance of a contract |
| Generate or refine content with the AI assistant when you use it | Performance of a contract |
| Process subscriptions, credits and invoices | Performance of a contract; legal obligation |
| Send transactional email (welcome, invites, deletion confirmations) | Performance of a contract |
| Diagnose failures, prevent abuse, and keep the service secure | Legitimate interests |
| Understand aggregate product usage to improve features | Legitimate interests (consent where required) |
| Comply with legal obligations and platform terms | Legal obligation |
4. Meta Permissions We Request
When you connect a Facebook Page, Instagram professional account or Threads profile, Meta asks you to grant specific permissions. We request only the permissions needed for the features below, and you can decline any of them (some publishing features will then be unavailable).
| Permission | How PostMCP AI uses it |
|---|---|
| pages_show_list | Retrieve the list of Facebook Pages you administer so you can choose which Page to connect in the Integration Manager. We store only the Page ID, name and picture URL of the Pages you explicitly connect. |
| pages_manage_posts | Publish the text, image and video posts you create or schedule in PostMCP AI to the Facebook Page you connected, and delete a post we published when you ask us to. |
| pages_read_engagement | Read the delivery status and basic engagement counts of posts published through PostMCP AI, so the dashboard can confirm a scheduled post went live and show its performance back to you. |
| pages_read_user_content | Read the reaction and comment counts on posts published through PostMCP AI, when you ask the dashboard for a post’s performance. We read totals only; we never read, store or display the comments themselves, the people who left them, or any other content on your Page. |
| read_insights | Read Page Insights — views and clicks on posts published through PostMCP AI, and your Page’s follower count and 28-day page views — only when you ask the dashboard for a post’s or Page’s performance. Nothing is read in the background. |
| instagram_business_basic | Identify the Instagram professional account linked to your connected Page (account ID, username, profile picture) so it can be displayed and selected as a publishing target. |
| instagram_business_content_publish | Publish the images, videos, reels and captions you create or schedule in PostMCP AI to your connected Instagram professional account. |
| instagram_business_manage_insights | Read the views, reach, likes, comments, saves and shares of posts published through PostMCP AI, and your account’s follower count, only when you ask the dashboard for that post’s or account’s performance. |
| threads_basic | Identify your Threads profile (Threads user ID and username) so it can be displayed and selected as a publishing target. |
| threads_content_publish | Publish the Threads posts and threads you create or schedule in PostMCP AI to your connected Threads profile. |
| threads_manage_insights | Read the views, likes, replies, reposts and quotes of posts published through PostMCP AI, and your profile’s follower count, only when you ask the dashboard for that post’s or profile’s performance. |
Data obtained through these permissions (“Platform Data”) is used solely to provide the publishing and reporting features you requested. We do not sell, license or transfer Platform Data to data brokers, advertising networks, or any other third party, and we do not use it to train AI models. Our use of information received from Meta APIs adheres to the Meta Platform Terms and Developer Policies, including the Limited Use requirements.
5. YouTube API Services
PostMCP AI uses YouTube API Services to publish videos and Shorts to a YouTube channel you connect. By connecting a channel you are also agreeing to the YouTube Terms of Service, and the data Google receives and provides in that exchange is handled under the Google Privacy Policy.
Permissions we request, and why
| OAuth scope | How PostMCP AI uses it |
|---|---|
| https://www.googleapis.com/auth/youtube.upload | Upload the videos and Shorts you create or schedule in PostMCP AI to the YouTube channel you connected, with the title, description and visibility (public, unlisted or private) you set for that upload. This scope is used only to perform an upload you explicitly requested or scheduled. It is never used to read, modify or delete videos already on your channel, and never to change the visibility of anything already published. |
| https://www.googleapis.com/auth/youtube.readonly | Read the identity of the channel you are connecting — channel ID, channel title, handle and avatar — so the dashboard can name the destination on a post and so you can tell two connected channels apart. We do not read your videos, playlists, subscribers, comments or analytics. |
YouTube data we collect and store
| Data | Purpose |
|---|---|
| Channel identifiers | The channel ID, title, @handle and avatar URL of the channel you connect. Stored so the dashboard can display and target it. |
| OAuth tokens | The Google access token and refresh token issued when you grant access. Stored encrypted (see §7) and used only to publish on your instruction and to keep the connection alive. |
| Token expiry and connection health | When the access token expires, whether it could be renewed, and the last renewal error. Used to warn you before a scheduled post fails on a dead connection. |
| Video metadata you authored | The title, description and visibility (public, unlisted or private) you set for the upload — or, where you left them blank, the title and description derived from your post copy — plus the tags taken from its hashtags and the video file you attached. Stored with the post so you can review and edit them before it goes out. |
| Upload outcome | The resulting YouTube video ID, its public URL, and any error YouTube returned. Used to show you the published Short and to let you retry a failed upload. |
How we store it
Google access and refresh tokens are encrypted with AES-256-CBC before being written to the database, using a key held in our server environment’s secret configuration and never stored alongside the ciphertext (see §7). Tokens are decrypted in memory only for the moment an upload or a token renewal requires them. Channel identifiers and upload results are stored in plain form because they are not credentials.
How often we refresh, update and delete YouTube data
| Data | Refreshed or updated | Deleted |
|---|---|---|
| Google access & refresh tokens | Access-token expiry is checked hourly in the background and before publishing or refreshing channel data. Tokens within 10 minutes of expiry are renewed. The refresh token is replaced only when Google returns a new one. | Erased when you disconnect the channel in the Integration Manager, or when revoked access is detected by channel maintenance. YouTube data-deletion requests are handled within 7 days. |
| Channel identifiers (ID, title, handle, avatar) | Read when you connect or reconnect, then refreshed daily by an hourly maintenance job. Failed refreshes are retried hourly. Channel snapshots displayed on posts are updated by the same job. | Deleted when you disconnect the channel or revoked access is detected. If refresh keeps failing, channel data is removed after 29 days without a successful refresh. YouTube data-deletion requests are handled within 7 days. |
| Upload metadata you set (title, description, visibility, tags) | Written when you create or schedule the post and updated whenever you edit it; sent to YouTube once, at upload time, and never modified on YouTube afterwards. | Deleted when you delete the post. YouTube-related user-data deletion requests are handled within 7 days. |
| Attached video file | Stored once when you attach it; read once, at upload time, to send to YouTube. | Kept in our media storage for as long as your account exists, so a failed upload can be retried; removed within 7 days of a verified YouTube-related account-deletion request, or earlier on request. |
| Upload outcome (video ID, URL, any error) | Written once when the upload finishes or fails, and again if you retry a failed post. Not read back from YouTube afterwards. | API video IDs, URLs and errors are cleared after 29 days by hourly maintenance, or earlier when you disconnect or delete the post. Your own post copy and media are retained separately. YouTube data-deletion requests are handled within 7 days. |
Channel metadata is refreshed daily, with hourly retries and expiry checks. Upload results are not read back from YouTube and are cleared after 29 days. If you revoke access in your Google Account, renewal detects the invalid grant and hourly channel maintenance removes the connection and its stored API data. You can also disconnect a channel or submit a deletion request; YouTube user-data deletion requests are completed as soon as possible and within 7 calendar days.
What we never do with it
- We do not change the visibility of any video after it is uploaded. The privacy status you choose in the composer (public, unlisted or private) is applied to that new upload only, and shown to you before the post is confirmed. To change it later, use YouTube Studio.
- We do not sell, rent, license or transfer YouTube data to data brokers, advertising networks, or any other third party.
- We do not use YouTube data to train, fine-tune or evaluate AI models. The AI drafting described in §6 writes post copy from your own prompt; it is not given your YouTube tokens or channel data.
- We do not use YouTube data for advertising, profiling or any purpose other than performing the publishing actions you requested.
- We do not read, alter or delete videos on your channel that were not published through PostMCP AI.
- We do not upload anything to your channel that you did not create or schedule in PostMCP AI.
PostMCP AI’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Your control over this connection
- In PostMCP AI: remove the YouTube card in the Integration Manager. This deletes the stored channel identifiers and permanently erases the encrypted access and refresh tokens from our database immediately.
- In your Google Account: revoke PostMCP AI at myaccount.google.com/permissions — the Google security settings page for third-party application access. Revoking there invalidates our tokens instantly, whether or not you have also disconnected inside PostMCP AI.
- Formal deletion request: use the Data Deletion Request Form to have every trace of the connection erased on a verified request (see §11).
Videos already published to your channel remain on YouTube after you disconnect — delete them in YouTube Studio if you no longer want them.
6. AI Processing
PostMCP AI includes optional AI drafting and image generation, used from the composer, the API and the MCP tools on your instruction. When — and only when — you use them:
- Your prompt and the names of the social networks you selected are sent to a large language model through OpenRouter, which routes the request to the model provider selected for your account. An image prompt, and any reference image URL you supply, is sent to an image model the same way.
- You may supply your own OpenRouter API key; if you do, it is stored encrypted and used only to bill your own AI usage to your key.
- We instruct our AI providers not to train on data submitted through our integration. We do not use your content to train any model of our own.
- Post content is never sent to a model unless you ask for an AI draft. Drafts you write yourself are transmitted only to the social platform you publish to.
- AI drafting never publishes anything. The copy and image land in the composer for you to review, and go out only when you schedule or publish them.
Meta Platform Data is not sent to AI model providers. The model is told which networks a draft is for, never which accounts.
7. Storage, Encryption & Security
- Encryption in transit: all traffic between your browser, our API, and platform APIs uses TLS (HTTPS).
- Encryption at rest: OAuth access tokens (including Google/YouTube), refresh tokens, Bluesky app passwords, MCP API keys and any OpenRouter key you provide are encrypted with AES-256-CBC before being written to the database. The encryption key is held in our server environment’s secret configuration and is never stored in the database alongside the ciphertext.
- Decryption on use: credentials are decrypted in memory only at the moment a publishing or account request is executed, and are not written to application logs.
- Passwords: account passwords are stored only as salted one-way hashes; we cannot read them.
- Access control: tokens are scoped to the owning user and project; database and infrastructure access is restricted to authorized personnel who need it to operate the service.
- Storage location: data is stored in managed cloud infrastructure (see §8) with provider-level disk encryption and access logging.
8. Service Providers (Sub-processors)
We rely on a small number of vetted providers to run the service. Each is bound by contract to process data only on our instructions and to maintain appropriate safeguards:
| Provider | Purpose |
|---|---|
| MongoDB Atlas | Primary application database (accounts, projects, posts, encrypted tokens, sessions). |
| Cloudflare R2 | Object storage for images and video you upload or generate for publishing. |
| OpenRouter | Routes AI assistant requests to the model provider you or we select. See §6. |
| PostHog | Product analytics and error reporting for the web dashboard. See §12. |
| Dodo Payments | Subscription billing and payment processing. Card details are entered on the processor’s systems and are never received or stored by PostMCP AI. |
| Google (Gmail SMTP) | Transactional email delivery (welcome, invitation, deletion confirmation emails). |
| Cloud hosting providers | Compute and networking for the PostMCP AI web app, API and scheduler. |
We do not transfer Meta Platform Data to any of these providers except the infrastructure required to store it securely (database and object storage) and operate the service you requested.
10. Data Retention
| Data | Retention period |
|---|---|
| Access tokens & connected-account metadata | Until you disconnect the account or delete your account — deleted immediately on disconnect |
| Account profile & workspace data | For the life of your account, then deleted within 30 days of a deletion request |
| Posts, drafts & media | Until you delete them, or within 30 days of account deletion |
| AI assistant conversations | Until you delete the session, or within 30 days of account deletion |
| Publishing & diagnostic logs | Up to 90 days |
| Billing & transaction records | Up to 7 years, where required by tax and accounting law |
| Analytics events | Up to 12 months |
| Deletion request records | Retained as proof of compliance; reduced to the request ID, date and outcome |
Encrypted backups may retain deleted data for a short additional period and are overwritten on the normal backup rotation.
11. Revoking Access & Deleting Data
You can disconnect any account at any time from the Integration Manager in your dashboard. Disconnecting immediately deletes that platform’s stored access tokens, refresh tokens and cached profile identifiers from our database. You can also revoke our access from the platform itself, and you can ask us to erase everything we hold.
Meta (Facebook Pages, Instagram, Threads)
- In PostMCP AI: open the Integration Manager and click the disconnect (trash) icon on the Meta account card. All Meta tokens and cached identifiers for that account are purged from our active database immediately.
- In Facebook: go to Settings & Privacy → Settings → Apps and Websites, select PostMCP AI, and click Remove. For Instagram and Threads, remove the connection from Business Integrations or the linked account’s settings.
- Formal deletion request: submit the Data Deletion Request Form, or email [email protected] with the subject “Meta Data Deletion Request”. We confirm receipt by email and complete deletion within 30 days.
- In PostMCP AI: disconnect the member profile or organization page from the Integration Manager. This deletes the LinkedIn member/page ID, tokens and cached avatar from our servers.
- In LinkedIn: Settings & Privacy → Data Privacy → Other applications → Permitted services → select PostMCP AI → Remove.
- Formal deletion request: use the Data Deletion Request Form.
X (Twitter)
- In PostMCP AI: remove the account card in the Integration Manager to purge X tokens and cached profile data.
- In X: Settings and privacy → Security and account access → Apps and sessions → Connected apps → select PostMCP AI → Revoke app permissions.
- Formal deletion request: use the Data Deletion Request Form.
YouTube
- In PostMCP AI: remove the YouTube card in the Integration Manager to erase the stored channel identifiers and the encrypted Google access and refresh tokens.
- In Google: myaccount.google.com/permissions → select PostMCP AI → Remove access. This invalidates our tokens immediately.
- Formal deletion request: use the Data Deletion Request Form.
Bluesky
- In PostMCP AI: remove the Bluesky card in the Integration Manager to delete the stored handle, DID, server URL and app password.
- In Bluesky: Settings → App passwords → delete the password you generated for PostMCP AI to invalidate it instantly.
- Formal deletion request: use the Data Deletion Request Form.
Full account deletion. On a verified deletion request we erase your account record, projects, connected-account metadata, encrypted credentials, drafts, scheduled posts, uploaded media, AI conversations and analytics identifiers. Credentials and tokens are removed immediately; YouTube-related user data is erased within 7 days and other remaining records within 30 days, except billing records we must retain by law (§10). Content already published to a social platform stays on that platform — delete it there.
13. Your Privacy Rights
Depending on where you live (including under the EU/UK GDPR, the California CCPA/CPRA, and India’s DPDP Act), you have the right to:
- Access the personal data we hold about you and receive a copy in a portable format.
- Correct inaccurate or incomplete data.
- Delete your data — see §11.
- Restrict or object to processing based on legitimate interests.
- Withdraw consent at any time, without affecting processing already carried out.
- Not be discriminated against for exercising these rights; we do not sell personal information, so there is nothing to opt out of.
- Complain to your local data protection authority (in the EU/UK, your national supervisory authority).
To exercise any right, email [email protected] or use the Data Deletion Request Form. We verify requests against the email on the account and respond within 30 days. An authorized agent may act on your behalf with written proof.
14. International Transfers
PostMCP AI and its service providers operate globally, so your data may be processed in countries other than your own, including the United States and the European Union. Where data leaves the EEA or UK, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses and equivalent UK provisions, together with our providers’ own transfer frameworks. Contact us for details of the safeguards applied to a specific transfer.
15. Children’s Privacy
PostMCP AI is a business tool intended for users aged 18 and over, and is not directed to children. We do not knowingly collect personal data from anyone under 13 (or the minimum age of digital consent in your country). If we learn that we have collected such data, we delete it promptly. If you believe a child has provided us data, contact [email protected].
16. Security Incidents
If we become aware of a breach affecting your personal data or Platform Data, we will investigate immediately, take steps to contain it, and notify affected users and the relevant supervisory authorities — and, where Platform Data is involved, the relevant platform operator — without undue delay and within the timeframes required by applicable law and platform terms. Report a suspected vulnerability or incident to [email protected].
17. Changes to This Policy
We may update this policy as the service evolves. The version number and “last modified” date at the top of this page always reflect the current version. For material changes — for example a new category of data, a new purpose, or a new sub-processor handling your content — we will notify you by email or an in-app notice before the change takes effect. Continued use after the effective date means you accept the updated policy.
18. Contact Us
For any privacy question, data request, or to reach our data protection contact:
Data controller: PostMCPAI Technologies Private Limited (“PostMCP AI”)
Email: [email protected]
Website: www.postmcpai.com
Deletion requests: postmcpai.com/deletion-request
Terms of Service: postmcpai.com/terms