Privacy Policy
Draft — last updated 2026-09-27. This has not been reviewed by a lawyer; treat it as accurate-but-informal until it has been.
SocialPostAPI ("we", "the Service") is a publishing API that lets a business ("you", "the customer") connect their own social media accounts and publish content to them through our API. This policy covers what we collect and why.
What we store
- OAuth access and refresh tokens for each social account you connect, encrypted at rest (Fernet/AES-256). We never see or store your social account password — authorization happens directly on the platform's own login page.
- Basic profile info returned by the platform at connect time: account ID, display name/handle, and avatar URL.
- The content you submit for publishing (post text, media URLs) and the resulting platform post ID/permalink, for as long as your account with us is active.
- API request logs (timestamps, endpoint, status code) for reliability and abuse prevention, retained for a limited period.
What we don't do
- We don't sell, rent, or share your data with third parties for advertising.
- We don't read, analyze, or use your posts' content beyond what's needed to publish them.
- We don't post anything you didn't submit through the API.
Third-party platforms
Connecting an account authorizes SocialPostAPI to act on it only for the scopes you explicitly grant during that platform's OAuth consent screen. You can revoke that authorization at any time from the platform's own settings (e.g. Facebook's "Apps and Websites" settings, X's "Connected Apps"), which immediately invalidates the token we hold.
Data deletion
Disconnecting an account through the API (or emailing support@socialpostapi.makketing.com) deletes its stored tokens and profile info. Post history is retained for your own record-keeping unless you request full deletion.
Contact
Questions about this policy: support@socialpostapi.makketing.com.