
Last updated: June 2026
Account information: Name, email address, and profile photo when you sign up.
Content data: Posts, media, schedules, and analytics you create within the Service.
Usage data: Pages visited, features used, device type, browser, IP address, and referral source.
Payment data: Billing information processed securely by our payment provider (Stripe). We do not store full card numbers.
Connected accounts: OAuth tokens and profile data from social platforms you connect.
We use collected information to:
We use cookies and similar technologies to keep you signed in, remember preferences, and understand how you use PostPilot.Help. See our Cookie Policy for details.
We may share limited data with trusted third parties including:
For the full list of the third-party companies that process data on our behalf, see our Sub-processors page.
We never sell your personal data to third parties.
PostPilot lets you connect your own social media accounts — including TikTok, YouTube, Instagram, Facebook, Threads, LinkedIn, X (Twitter), Pinterest, Reddit, and Tumblr, as well as open, federated, and self-hosted platforms such as Bluesky, Mastodon (and Mastodon-compatible servers), Nostr, Lemmy, Discord, Telegram, Slack, Matrix, LINE, Dev.to, Micro.blog, WordPress, Ghost, and WriteFreely — so you can create, schedule, and publish content to them from one place. The full, current list of recipient platforms is maintained on our Sub-processors page.
What we access: When you connect an account, that platform asks for your permission and issues us a secure access token. We use it only to (a) identify which account is connected (your handle or display name) and (b) publish or schedule the specific posts you create in PostPilot. We request the minimum permissions needed to publish on your behalf and nothing more.
What we do not do: We never post anything without an action you take (publishing now or scheduling a post), we never read your private messages, and we never sell, rent, or share your connected-account data or content with advertisers or other third parties.
How we store it: Access tokens are held securely on our backend and used only to carry out the publishing requests you initiate.
How to revoke access: You can disconnect any platform at any time on the Connections page in PostPilot — this immediately stops our access and deletes the stored token. Deleting your PostPilot account removes all connected-account tokens. You may also revoke PostPilot's access directly in each platform's own settings.
Your use of each connected platform also remains subject to that platform's own terms and privacy policy — for example, TikTok's Privacy Policy.
We retain your data for as long as your account is active or as needed to provide the Service. Upon account deletion, we remove your personal data within 30 days, except where retention is required by law or legitimate business interest (e.g., billing records).
Depending on your location, you may have the right to:
You can export all of your data or permanently delete your account yourself at any time in Settings → Your Data. Deleting your account also cancels any active subscription. For anything else, contact us at smithappsupport@gmail.com.
California residents have additional rights under the California Consumer Privacy Act, including the right to know what personal information is collected, request deletion, and opt out of the sale of personal information. We do not sell personal information.
If you are in the EU/EEA, we process your data based on consent, contractual necessity, or legitimate interest. You may lodge a complaint with your local data protection authority. Our data processing complies with GDPR requirements.
PostPilot.Help is not directed at children under 18. We do not knowingly collect personal information from minors. If we learn that a child has provided us with personal data, we will delete it promptly.
For questions about this Privacy Policy, contact us at smithappsupport@gmail.com.