Back to home

Data Deletion Instructions

Last updated: [DATE]

This page is a template prepared for OmniPost. It has not yet been reviewed by a lawyer, and the bracketed placeholders below (legal entity name, address, jurisdiction, contact emails, dates) are not filled in. It must be reviewed by qualified legal counsel and completed with OmniPost's actual details before being relied on in production.

This page explains how to remove OmniPost's access to your connected Instagram, Facebook, TikTok, or X account, and how to request that OmniPost delete the data associated with your account.

Purpose of this page

Meta's Platform Terms require every app on the Instagram and Threads platforms to provide either (a) an automated Data Deletion Callback URL, or (b) a public Data Deletion Instructions page like this one. OmniPost implements both: an automated callback at /api/meta/data-deletion that Meta calls automatically when you remove OmniPost from your Facebook/Instagram App settings, and this page for anyone who wants to request deletion directly, or whose platform does not support an automated callback.

Step 1 — Revoke OmniPost's access from the platform

The fastest way to stop OmniPost from being able to publish to your account is to revoke its access directly in the platform's own settings. This takes effect immediately on the platform's side.

Instagram / Facebook

  1. Open the Instagram app or facebook.com and go to Settings.
  2. Go to "Apps and Websites" (or, in the Instagram app, "Apps and Websites" under "Website Permissions").
  3. Find "OmniPost" in the list of connected apps.
  4. Select "Remove" / "Remove Access".

Removing OmniPost here triggers Meta's deauthorization webhook and, where supported, Meta's Data Deletion Callback, which automatically notifies OmniPost to delete your stored token and connection data (see "How we comply with Meta Platform Terms" in our Privacy Policy).

Threads

Threads uses the same Meta Accounts Center as Instagram/Facebook. Go to Accounts Center → Apps and websites, find "OmniPost", and remove access.

TikTok

  1. Open the TikTok app and go to Profile → Settings and privacy.
  2. Go to "Security and permissions" → "Manage apps" (or "Apps and login activity").
  3. Find "OmniPost" and tap "Remove" / "Revoke Access".

X (Twitter)

  1. Go to X Settings → Security and account access → Apps and sessions → Connected apps.
  2. Find "OmniPost" and select "Revoke app permissions".

Revoking access on the platform stops OmniPost from being able to make further API calls for that account immediately. It does not, by itself, guarantee our systems have deleted the now-invalid token — for that, also complete Step 2.

Step 2 — Request deletion of your OmniPost data

To request that OmniPost delete the data associated with your account or workspace — including connected-account tokens, stored profile information, and post history — you can either:

  • Delete your workspace directly from the OmniPost dashboard (Settings → Danger Zone → Delete Workspace), which immediately deletes stored OAuth tokens and schedules the remaining workspace data for deletion; or
  • Email [Data Deletion Contact Email] from the email address associated with your OmniPost account, with the subject line "Data Deletion Request", and tell us which connected account(s) or workspace you'd like deleted; or
  • Submit the request via [Data Deletion Request Form Placeholder URL].

We will confirm receipt of your request and complete deletion within [X] days (and, in any case, within any shorter window required by the platform in question — for example, X's Developer Agreement requires deletion within 10 business days of API access termination, and actioning end-user deletion requests within 24 hours). Some data may be retained for a limited period where required for legal, security, or fraud-prevention purposes, as described in our Privacy Policy.

Automated Data Deletion Callback (Meta)

In addition to this instructions page, OmniPost's Meta app is configured with an automated Data Deletion Request Callback URL at /api/meta/data-deletion. When Meta forwards a signed deletion request to that endpoint (triggered when a user removes OmniPost from their Facebook or Instagram app settings), OmniPost verifies the request signature, deletes the associated stored tokens and connection record, and returns a confirmation URL and code, satisfying Meta Platform Terms' data deletion requirement without the user needing to take the manual steps above. This page exists both as the required public "Data Deletion Instructions" URL referenced in our Meta App Dashboard configuration, and as a manual path for users on platforms without an equivalent automated callback (TikTok, X).

Contact

Contact information (placeholder)

Data deletion requests: [Data Deletion Contact Email]
General privacy inquiries: [DPO/Privacy Contact Email]