Legal
Privacy Notice
Last updated:
This notice explains how the Prepost beta service handles personal data across prepost.social, the dashboard, email, API, MCP tools, and social-platform connections.
We use data to run the account and the publishing workflow you request. We do not sell personal data or use customer content for advertising. Social access can be disconnected, API keys can be revoked, and deletion can be requested at any time.
01Who is responsible
Prepost is the public name of the beta social-media scheduling service available at prepost.social. The operator of Prepost is the data controller for account, product, support, and first-party website data. The full statutory operator identity and address must be added before paid production service and external provider review begin.
Privacy questions and rights requests can be sent to privacy@prepost.social. Prepost has not appointed a data protection officer.
02Data we use
- Account and authentication data: email address, password hash when password sign-in is used, email-verification status, Google account subject and email when Google sign-in is used, and hashed session, verification, and login-code records.
- Workspace data: workspace name, membership, role, invitations, account groups, plan entitlement, and the user who created or changed a record.
- Social connections: platform, account identifier and display name, connection metadata, encrypted access and refresh tokens, token expiry, and disconnect status.
- Content and publishing data: captions, platform-specific edits, media files and metadata, schedules, time zone, selected accounts, publishing status, provider post ID or URL, and error details.
- API and MCP data: API-key name and prefix, a one-way key hash, requested operations, and the minimum inputs and outputs needed to perform them. Prepost does not receive an AI assistant's full conversation unless the user or assistant sends it to a Prepost tool.
- Email and support data: verification and login delivery status, messages you send, and the information needed to answer a request.
- Website and beta-list data: email, locale, referral and campaign values, page path, referrer, browser user agent, and limited first-party events such as a page view, button click, or free-tool use.
- Security and operations data: IP address and request or error details may appear in short-lived server and security logs. Secrets, passwords, raw session tokens, and full OAuth tokens are not intended to be logged.
- Billing data: billing is not active in the current beta. If activated, Stripe will process payment details; Prepost will keep customer, subscription, invoice, plan, and entitlement identifiers but not full card numbers.
03Where data comes from
Most data comes directly from you, your browser, a workspace administrator who invites you, Google account sign-in, or a social platform you choose to connect. Publishing results come from the selected platform. Prepost does not connect a social account or publish without an authorization or command from the relevant workspace.
04Why we use it
- To create and secure accounts, workspaces, sessions, invitations, and API access, and to provide the service requested by the user.
- To store, prepare, schedule, transmit, and report the result of content sent to selected social platforms.
- To deliver essential account email and answer support or privacy requests.
- To prevent abuse, diagnose failures, protect workspaces, and improve reliability based on Prepost's legitimate interests, balanced against user rights.
- To record a requested beta-list subscription or optional marketing update based on consent, which can be withdrawn at any time.
- To meet legal, tax, accounting, fraud-prevention, and dispute requirements if paid billing is activated.
07International processing
Some social platforms and service providers may process data outside the European Economic Area. Where Prepost selects a processor for such processing, it will use an applicable transfer mechanism and safeguards. Data sent to a social platform at your direction is also handled under that platform's terms, privacy notice, and transfer arrangements.
08How long we keep data
- Account, workspace, content, social-connection, and publishing history are kept while the account or workspace is active and while needed to provide the requested service.
- A normal authenticated session is valid for up to 30 days. Login codes are valid for 10 minutes, Google authorization state for 10 minutes, and email-verification links normally for 30 minutes. Expired security records are removed during maintenance when no longer needed for abuse prevention.
- Deleted media is removed from the product database and queued for deletion from object storage. Deleted posts are removed from Prepost, but content already published on a social platform must also be managed on that platform.
- Beta-list and optional update data are kept until unsubscribe, withdrawal, or a deletion request, unless a shorter campaign period is adopted.
- Operational logs and backups are kept only for security, recovery, and incident investigation, then rotated. Data already in a protected backup is isolated from normal use and expires through the backup cycle.
- Where payment becomes active, required invoices, tax records, fraud evidence, and legal-claim records may be retained for the period required by applicable law.
09Your choices and rights
We may need to verify control of the account before acting. We normally respond within one month, subject to permitted extensions and legal exceptions. There is no solely automated decision that produces a legal or similarly significant effect on users.
- Access, correct, export, restrict, object to, or request deletion of personal data where applicable.
- Withdraw consent for optional updates without affecting earlier lawful processing.
- Disconnect a social account, revoke access in the platform itself, delete posts or media, revoke API keys, and log out of a session.
- Complain to the data-protection authority in the EEA country where you live or work, or where you believe an infringement occurred.
10Google and YouTube data
If YouTube or another Google API is enabled, its data is used only to provide the user-facing connection and publishing function requested by the user. Use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including its Limited Use requirements. Access can be revoked in Google Account permissions.
11Security, children, and changes
Prepost uses access controls, workspace isolation, encrypted social tokens, one-way hashes for passwords and API keys, private media storage, secure cookies in deployed environments, and restricted operational access. No system can promise absolute security, so confirmed incidents are handled under the applicable notification rules.
Prepost is a business and creator tool for people aged 18 or older. We do not knowingly offer accounts to children.
Material changes to this notice will be shown in the product or sent by email where appropriate. The date at the top identifies the current version.