Skip to content
Privacy & Compliance

Privacy Policy

LAST MODIFIED: AUGUST 12, 2026|EFFECTIVE: AUGUST 12, 2026|VERSION 2.0.0

1. Overview & Scope

PostMCP AI (“PostMCP AI”, “we”, “us”) provides a social media scheduling and publishing platform, available at postmcpai.com, together with its API and Model Context Protocol (MCP) server, which lets you connect social accounts and publish content to them — directly or through an AI assistant.

This policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and how you can review, export or delete it. It applies to the PostMCP AI website, dashboard, API and MCP server. It does not apply to the social platforms themselves (Facebook, Instagram, Threads, LinkedIn, X, Bluesky, YouTube), which handle your data under their own policies.

For the purposes of the EU/UK GDPR, PostMCP AI is the data controller for account data and the content you submit to our service. Where you connect a social account, we act on your instructions to transmit your content to that platform.

2. Information We Collect

We limit collection to what is required to operate scheduling and publishing workflows. We collect:

  • Account data: your name, email address, avatar URL, and either a hashed password or the provider identifier from the sign-in service you used (Google, GitHub, LinkedIn or X). We never store your social sign-in password.
  • Access credentials for connected platforms: OAuth access tokens and refresh tokens issued by the platform you connect — including Google/YouTube (see §5) — and (for Bluesky) the app password and server URL you supply. These are stored encrypted — see §7.
  • Connected profile metadata: platform account IDs, usernames/handles, display names, Page or organization names, profile picture URLs, and token expiry dates — used to show you which accounts are connected and to target the right destination for a post.
  • Content you submit: post drafts, captions, links, images and video you upload or generate for publishing, and scheduling times.
  • AI assistant data: your chat messages with the AI assistant, the assistant’s responses, tool-call logs, proposed actions and token usage counts.
  • Workspace data: project names, members and their roles, and the email addresses you enter to invite collaborators.
  • Publishing and diagnostic logs: API request and response statuses, published post identifiers, and error messages, used to confirm delivery and troubleshoot failures.
  • Billing data: your plan, subscription status and validity, billing email, and a subscription identifier from our payment processor. We do not receive or store card numbers.
  • Usage and device data: product analytics events, pages viewed, browser and device type, approximate location derived from IP address, and session cookies — see §12.

We do not knowingly collect special-category data (health, biometrics, religion, political opinions, precise location) and ask that you do not submit it.

3. How & Why We Use Data

We process your information only to deliver, secure and support the service:

PurposeLegal basis (GDPR)
Create and authenticate your account and sessionsPerformance of a contract
Connect social accounts and display connection statusPerformance of a contract
Publish and schedule the posts you create, and report delivery status back to youPerformance of a contract
Generate or refine content with the AI assistant when you use itPerformance of a contract
Process subscriptions, credits and invoicesPerformance of a contract; legal obligation
Send transactional email (welcome, invites, deletion confirmations)Performance of a contract
Diagnose failures, prevent abuse, and keep the service secureLegitimate interests
Understand aggregate product usage to improve featuresLegitimate interests (consent where required)
Comply with legal obligations and platform termsLegal obligation
WE DO NOT use Platform Data or your content for advertising or ad targeting, to build user profiles, to train our own or any third party’s AI models, or for any purpose other than delivering the features you asked for.

4. Meta Permissions We Request

When you connect a Facebook Page, Instagram professional account or Threads profile, Meta asks you to grant specific permissions. We request only the permissions needed for the features below, and you can decline any of them (some publishing features will then be unavailable).

PermissionHow PostMCP AI uses it
pages_show_listRetrieve the list of Facebook Pages you administer so you can choose which Page to connect in the Integration Manager. We store only the Page ID, name and picture URL of the Pages you explicitly connect.
pages_manage_postsPublish the text, image and video posts you create or schedule in PostMCP AI to the Facebook Page you connected, and delete a post we published when you ask us to.
pages_read_engagementRead the delivery status and basic engagement counts of posts published through PostMCP AI, so the dashboard can confirm a scheduled post went live and show its performance back to you.
pages_read_user_contentRead the reaction and comment counts on posts published through PostMCP AI, when you ask the dashboard for a post’s performance. We read totals only; we never read, store or display the comments themselves, the people who left them, or any other content on your Page.
read_insightsRead Page Insights — views and clicks on posts published through PostMCP AI, and your Page’s follower count and 28-day page views — only when you ask the dashboard for a post’s or Page’s performance. Nothing is read in the background.
instagram_business_basicIdentify the Instagram professional account linked to your connected Page (account ID, username, profile picture) so it can be displayed and selected as a publishing target.
instagram_business_content_publishPublish the images, videos, reels and captions you create or schedule in PostMCP AI to your connected Instagram professional account.
instagram_business_manage_insightsRead the views, reach, likes, comments, saves and shares of posts published through PostMCP AI, and your account’s follower count, only when you ask the dashboard for that post’s or account’s performance.
threads_basicIdentify your Threads profile (Threads user ID and username) so it can be displayed and selected as a publishing target.
threads_content_publishPublish the Threads posts and threads you create or schedule in PostMCP AI to your connected Threads profile.
threads_manage_insightsRead the views, likes, replies, reposts and quotes of posts published through PostMCP AI, and your profile’s follower count, only when you ask the dashboard for that post’s or profile’s performance.

Data obtained through these permissions (“Platform Data”) is used solely to provide the publishing and reporting features you requested. We do not sell, license or transfer Platform Data to data brokers, advertising networks, or any other third party, and we do not use it to train AI models. Our use of information received from Meta APIs adheres to the Meta Platform Terms and Developer Policies, including the Limited Use requirements.

5. YouTube API Services

PostMCP AI uses YouTube API Services to publish videos and Shorts to a YouTube channel you connect. By connecting a channel you are also agreeing to the YouTube Terms of Service, and the data Google receives and provides in that exchange is handled under the Google Privacy Policy.

Permissions we request, and why

OAuth scopeHow PostMCP AI uses it
https://www.googleapis.com/auth/youtube.uploadUpload the videos and Shorts you create or schedule in PostMCP AI to the YouTube channel you connected, with the title, description and visibility (public, unlisted or private) you set for that upload. This scope is used only to perform an upload you explicitly requested or scheduled. It is never used to read, modify or delete videos already on your channel, and never to change the visibility of anything already published.
https://www.googleapis.com/auth/youtube.readonlyRead the identity of the channel you are connecting — channel ID, channel title, handle and avatar — so the dashboard can name the destination on a post and so you can tell two connected channels apart. We do not read your videos, playlists, subscribers, comments or analytics.

YouTube data we collect and store

DataPurpose
Channel identifiersThe channel ID, title, @handle and avatar URL of the channel you connect. Stored so the dashboard can display and target it.
OAuth tokensThe Google access token and refresh token issued when you grant access. Stored encrypted (see §7) and used only to publish on your instruction and to keep the connection alive.
Token expiry and connection healthWhen the access token expires, whether it could be renewed, and the last renewal error. Used to warn you before a scheduled post fails on a dead connection.
Video metadata you authoredThe title, description and visibility (public, unlisted or private) you set for the upload — or, where you left them blank, the title and description derived from your post copy — plus the tags taken from its hashtags and the video file you attached. Stored with the post so you can review and edit them before it goes out.
Upload outcomeThe resulting YouTube video ID, its public URL, and any error YouTube returned. Used to show you the published Short and to let you retry a failed upload.

How we store it

Google access and refresh tokens are encrypted with AES-256-CBC before being written to the database, using a key held in our server environment’s secret configuration and never stored alongside the ciphertext (see §7). Tokens are decrypted in memory only for the moment an upload or a token renewal requires them. Channel identifiers and upload results are stored in plain form because they are not credentials.

How often we refresh, update and delete YouTube data

DataRefreshed or updatedDeleted
Google access & refresh tokensAccess-token expiry is checked hourly in the background and before publishing or refreshing channel data. Tokens within 10 minutes of expiry are renewed. The refresh token is replaced only when Google returns a new one.Erased when you disconnect the channel in the Integration Manager, or when revoked access is detected by channel maintenance. YouTube data-deletion requests are handled within 7 days.
Channel identifiers (ID, title, handle, avatar)Read when you connect or reconnect, then refreshed daily by an hourly maintenance job. Failed refreshes are retried hourly. Channel snapshots displayed on posts are updated by the same job.Deleted when you disconnect the channel or revoked access is detected. If refresh keeps failing, channel data is removed after 29 days without a successful refresh. YouTube data-deletion requests are handled within 7 days.
Upload metadata you set (title, description, visibility, tags)Written when you create or schedule the post and updated whenever you edit it; sent to YouTube once, at upload time, and never modified on YouTube afterwards.Deleted when you delete the post. YouTube-related user-data deletion requests are handled within 7 days.
Attached video fileStored once when you attach it; read once, at upload time, to send to YouTube.Kept in our media storage for as long as your account exists, so a failed upload can be retried; removed within 7 days of a verified YouTube-related account-deletion request, or earlier on request.
Upload outcome (video ID, URL, any error)Written once when the upload finishes or fails, and again if you retry a failed post. Not read back from YouTube afterwards.API video IDs, URLs and errors are cleared after 29 days by hourly maintenance, or earlier when you disconnect or delete the post. Your own post copy and media are retained separately. YouTube data-deletion requests are handled within 7 days.

Channel metadata is refreshed daily, with hourly retries and expiry checks. Upload results are not read back from YouTube and are cleared after 29 days. If you revoke access in your Google Account, renewal detects the invalid grant and hourly channel maintenance removes the connection and its stored API data. You can also disconnect a channel or submit a deletion request; YouTube user-data deletion requests are completed as soon as possible and within 7 calendar days.

What we never do with it

  • We do not change the visibility of any video after it is uploaded. The privacy status you choose in the composer (public, unlisted or private) is applied to that new upload only, and shown to you before the post is confirmed. To change it later, use YouTube Studio.
  • We do not sell, rent, license or transfer YouTube data to data brokers, advertising networks, or any other third party.
  • We do not use YouTube data to train, fine-tune or evaluate AI models. The AI drafting described in §6 writes post copy from your own prompt; it is not given your YouTube tokens or channel data.
  • We do not use YouTube data for advertising, profiling or any purpose other than performing the publishing actions you requested.
  • We do not read, alter or delete videos on your channel that were not published through PostMCP AI.
  • We do not upload anything to your channel that you did not create or schedule in PostMCP AI.

PostMCP AI’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Your control over this connection

  1. In PostMCP AI: remove the YouTube card in the Integration Manager. This deletes the stored channel identifiers and permanently erases the encrypted access and refresh tokens from our database immediately.
  2. In your Google Account: revoke PostMCP AI at myaccount.google.com/permissions — the Google security settings page for third-party application access. Revoking there invalidates our tokens instantly, whether or not you have also disconnected inside PostMCP AI.
  3. Formal deletion request: use the Data Deletion Request Form to have every trace of the connection erased on a verified request (see §11).

Videos already published to your channel remain on YouTube after you disconnect — delete them in YouTube Studio if you no longer want them.

6. AI Processing

PostMCP AI includes optional AI drafting and image generation, used from the composer, the API and the MCP tools on your instruction. When — and only when — you use them:

  • Your prompt and the names of the social networks you selected are sent to a large language model through OpenRouter, which routes the request to the model provider selected for your account. An image prompt, and any reference image URL you supply, is sent to an image model the same way.
  • You may supply your own OpenRouter API key; if you do, it is stored encrypted and used only to bill your own AI usage to your key.
  • We instruct our AI providers not to train on data submitted through our integration. We do not use your content to train any model of our own.
  • Post content is never sent to a model unless you ask for an AI draft. Drafts you write yourself are transmitted only to the social platform you publish to.
  • AI drafting never publishes anything. The copy and image land in the composer for you to review, and go out only when you schedule or publish them.

Meta Platform Data is not sent to AI model providers. The model is told which networks a draft is for, never which accounts.

7. Storage, Encryption & Security

  • Encryption in transit: all traffic between your browser, our API, and platform APIs uses TLS (HTTPS).
  • Encryption at rest: OAuth access tokens (including Google/YouTube), refresh tokens, Bluesky app passwords, MCP API keys and any OpenRouter key you provide are encrypted with AES-256-CBC before being written to the database. The encryption key is held in our server environment’s secret configuration and is never stored in the database alongside the ciphertext.
  • Decryption on use: credentials are decrypted in memory only at the moment a publishing or account request is executed, and are not written to application logs.
  • Passwords: account passwords are stored only as salted one-way hashes; we cannot read them.
  • Access control: tokens are scoped to the owning user and project; database and infrastructure access is restricted to authorized personnel who need it to operate the service.
  • Storage location: data is stored in managed cloud infrastructure (see §8) with provider-level disk encryption and access logging.
No system is perfectly secure. We use commercially reasonable safeguards but cannot guarantee absolute security. Keep your account password and MCP API key confidential, and revoke a key immediately if you believe it has been exposed.

8. Service Providers (Sub-processors)

We rely on a small number of vetted providers to run the service. Each is bound by contract to process data only on our instructions and to maintain appropriate safeguards:

ProviderPurpose
MongoDB AtlasPrimary application database (accounts, projects, posts, encrypted tokens, sessions).
Cloudflare R2Object storage for images and video you upload or generate for publishing.
OpenRouterRoutes AI assistant requests to the model provider you or we select. See §6.
PostHogProduct analytics and error reporting for the web dashboard. See §12.
Dodo PaymentsSubscription billing and payment processing. Card details are entered on the processor’s systems and are never received or stored by PostMCP AI.
Google (Gmail SMTP)Transactional email delivery (welcome, invitation, deletion confirmation emails).
Cloud hosting providersCompute and networking for the PostMCP AI web app, API and scheduler.

We do not transfer Meta Platform Data to any of these providers except the infrastructure required to store it securely (database and object storage) and operate the service you requested.

9. Data Sharing & Sale

We do not sell, rent, lease or share your personal data, platform metadata or access tokens for money or for cross-context behavioural advertising. Your data leaves our systems only in these situations:

  • To the platforms you authorize — content and tokens are sent to the Meta Graph API, LinkedIn API, X API, Bluesky ATProto API or YouTube Data API to execute the publishing action you requested.
  • To the service providers listed in §8, strictly to operate the service.
  • To collaborators you invite — members of a project workspace can see that project’s connected accounts, drafts and scheduled posts.
  • For legal reasons — where required by law, valid legal process, or to protect the rights, safety or property of PostMCP AI, our users or the public.
  • In a business transfer — if PostMCP AI is involved in a merger, acquisition or asset sale, data may transfer to the successor, subject to this policy. We will notify you before your data becomes subject to a different policy.

10. Data Retention

DataRetention period
Access tokens & connected-account metadataUntil you disconnect the account or delete your account — deleted immediately on disconnect
Account profile & workspace dataFor the life of your account, then deleted within 30 days of a deletion request
Posts, drafts & mediaUntil you delete them, or within 30 days of account deletion
AI assistant conversationsUntil you delete the session, or within 30 days of account deletion
Publishing & diagnostic logsUp to 90 days
Billing & transaction recordsUp to 7 years, where required by tax and accounting law
Analytics eventsUp to 12 months
Deletion request recordsRetained as proof of compliance; reduced to the request ID, date and outcome

Encrypted backups may retain deleted data for a short additional period and are overwritten on the normal backup rotation.

11. Revoking Access & Deleting Data

You can disconnect any account at any time from the Integration Manager in your dashboard. Disconnecting immediately deletes that platform’s stored access tokens, refresh tokens and cached profile identifiers from our database. You can also revoke our access from the platform itself, and you can ask us to erase everything we hold.

Meta (Facebook Pages, Instagram, Threads)

  1. In PostMCP AI: open the Integration Manager and click the disconnect (trash) icon on the Meta account card. All Meta tokens and cached identifiers for that account are purged from our active database immediately.
  2. In Facebook: go to Settings & Privacy → Settings → Apps and Websites, select PostMCP AI, and click Remove. For Instagram and Threads, remove the connection from Business Integrations or the linked account’s settings.
  3. Formal deletion request: submit the Data Deletion Request Form, or email [email protected] with the subject “Meta Data Deletion Request”. We confirm receipt by email and complete deletion within 30 days.

LinkedIn

  1. In PostMCP AI: disconnect the member profile or organization page from the Integration Manager. This deletes the LinkedIn member/page ID, tokens and cached avatar from our servers.
  2. In LinkedIn: Settings & Privacy → Data Privacy → Other applications → Permitted services → select PostMCP AI → Remove.
  3. Formal deletion request: use the Data Deletion Request Form.

X (Twitter)

  1. In PostMCP AI: remove the account card in the Integration Manager to purge X tokens and cached profile data.
  2. In X: Settings and privacy → Security and account access → Apps and sessions → Connected apps → select PostMCP AI → Revoke app permissions.
  3. Formal deletion request: use the Data Deletion Request Form.

YouTube

  1. In PostMCP AI: remove the YouTube card in the Integration Manager to erase the stored channel identifiers and the encrypted Google access and refresh tokens.
  2. In Google: myaccount.google.com/permissions → select PostMCP AI → Remove access. This invalidates our tokens immediately.
  3. Formal deletion request: use the Data Deletion Request Form.

Bluesky

  1. In PostMCP AI: remove the Bluesky card in the Integration Manager to delete the stored handle, DID, server URL and app password.
  2. In Bluesky: Settings → App passwords → delete the password you generated for PostMCP AI to invalidate it instantly.
  3. Formal deletion request: use the Data Deletion Request Form.

Full account deletion. On a verified deletion request we erase your account record, projects, connected-account metadata, encrypted credentials, drafts, scheduled posts, uploaded media, AI conversations and analytics identifiers. Credentials and tokens are removed immediately; YouTube-related user data is erased within 7 days and other remaining records within 30 days, except billing records we must retain by law (§10). Content already published to a social platform stays on that platform — delete it there.

12. Cookies & Analytics

  • Strictly necessary cookies: session and authentication cookies that keep you signed in and protect against cross-site request forgery. These cannot be disabled without breaking the service.
  • Preference storage: local storage for settings such as theme and active project.
  • Product analytics: we use PostHog to record feature-usage events (for example, a post being scheduled or an account connected), page views, device/browser type and error reports, keyed to your account ID once you sign in. We use this only to understand and improve the product.

We do not use advertising cookies, third-party ad pixels or cross-site tracking. You can block cookies in your browser, and where required by law we ask for your consent before setting non-essential analytics cookies.

13. Your Privacy Rights

Depending on where you live (including under the EU/UK GDPR, the California CCPA/CPRA, and India’s DPDP Act), you have the right to:

  • Access the personal data we hold about you and receive a copy in a portable format.
  • Correct inaccurate or incomplete data.
  • Delete your data — see §11.
  • Restrict or object to processing based on legitimate interests.
  • Withdraw consent at any time, without affecting processing already carried out.
  • Not be discriminated against for exercising these rights; we do not sell personal information, so there is nothing to opt out of.
  • Complain to your local data protection authority (in the EU/UK, your national supervisory authority).

To exercise any right, email [email protected] or use the Data Deletion Request Form. We verify requests against the email on the account and respond within 30 days. An authorized agent may act on your behalf with written proof.

14. International Transfers

PostMCP AI and its service providers operate globally, so your data may be processed in countries other than your own, including the United States and the European Union. Where data leaves the EEA or UK, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses and equivalent UK provisions, together with our providers’ own transfer frameworks. Contact us for details of the safeguards applied to a specific transfer.

15. Children’s Privacy

PostMCP AI is a business tool intended for users aged 18 and over, and is not directed to children. We do not knowingly collect personal data from anyone under 13 (or the minimum age of digital consent in your country). If we learn that we have collected such data, we delete it promptly. If you believe a child has provided us data, contact [email protected].

16. Security Incidents

If we become aware of a breach affecting your personal data or Platform Data, we will investigate immediately, take steps to contain it, and notify affected users and the relevant supervisory authorities — and, where Platform Data is involved, the relevant platform operator — without undue delay and within the timeframes required by applicable law and platform terms. Report a suspected vulnerability or incident to [email protected].

17. Changes to This Policy

We may update this policy as the service evolves. The version number and “last modified” date at the top of this page always reflect the current version. For material changes — for example a new category of data, a new purpose, or a new sub-processor handling your content — we will notify you by email or an in-app notice before the change takes effect. Continued use after the effective date means you accept the updated policy.

18. Contact Us

For any privacy question, data request, or to reach our data protection contact:

Data controller: PostMCPAI Technologies Private Limited (“PostMCP AI”)
Email: [email protected]
Website: www.postmcpai.com
Deletion requests: postmcpai.com/deletion-request
Terms of Service: postmcpai.com/terms