Privacy Policy
Last updated: [DATE]
This page is a template prepared for OmniPost. It has not yet been reviewed by a lawyer, and the bracketed placeholders below (legal entity name, address, jurisdiction, contact emails, dates) are not filled in. It must be reviewed by qualified legal counsel and completed with OmniPost's actual details before being relied on in production.
OmniPost ("OmniPost", "we", "us", or "our") operates a developer API and dashboard that lets business customers connect their own Instagram, Threads, TikTok, and X accounts and publish content to those accounts programmatically. This Privacy Policy explains what data we collect to provide that service, why we collect it, who we share it with, and the choices and rights available to you.
This policy applies to workspace owners and members who use the OmniPost dashboard and API ("Customers"), and, where relevant, to the end users whose Instagram, Threads, TikTok, or X accounts a Customer connects to OmniPost. It is a template and must be reviewed and completed by [Legal Entity Name] before publication.
1. Who we are
OmniPost is operated by [Legal Entity Name], a company registered at [Company Address] ("OmniPost"). For the purposes of GDPR and similar data protection laws, OmniPost acts as a data controller for account and workspace data described below, and as a data processor for content and media that Customers submit to the API for publishing on their own connected social accounts.
2. Data we collect
We collect the following categories of data:
- Account and workspace data — name, email address, hashed password (or SSO identifier), workspace name, billing plan, and team membership/role information when you create an OmniPost account and workspace.
- Connected social account tokens — when you connect an Instagram, Threads, TikTok, or X account through OAuth, we store the resulting access token and (where issued) refresh token, the connected account's platform user ID, username, display name, and the OAuth scopes granted. Tokens are encrypted at rest using AES-256-GCM and are only decrypted in memory at the moment they are needed to call a platform's API on your behalf.
- Content and uploaded media — post captions, scheduling metadata, and media URLs you submit through the API or dashboard for publishing. Media itself must be reachable at a public HTTPS URL you provide (or is uploaded via a platform's binary upload path where supported); OmniPost does not require you to host permanent copies of media with us beyond what is needed to complete a publish.
- API keys and request logs — API keys are stored as a hash, never in plaintext. We log API requests (method, path, status code, duration, timestamp, and the associated workspace/API key) to operate, secure, rate-limit, and debug the service.
- Technical and usage data — IP address, user agent, and session identifiers collected via cookies, described further in our Cookie Policy.
- Billing data — plan, subscription status, and invoice history. Card and payment details are handled directly by our payment processor ([Payment Processor Placeholder]) and are not stored on OmniPost servers.
3. Why we collect it
We use the data described above to:
- Provide the core OmniPost service: authenticating you, storing your connected social accounts, and using the associated OAuth tokens to call Instagram's, Threads', TikTok's, and X's APIs to publish content you submit, on your behalf and at your direction.
- Operate, secure, monitor, and rate-limit the API and dashboard.
- Provide customer support, respond to inquiries, and send service-related notices (for example, a token that has expired and needs to be reconnected).
- Bill for paid plans and enforce plan-based usage limits.
- Comply with legal obligations and the platform terms of the social networks OmniPost integrates with, including data deletion and deauthorization requirements described below.
We do not sell personal data, and we do not use connected social account tokens or your content for advertising, profiling, or any purpose other than performing the publishing actions you request.
4. Third-party data sharing
Because OmniPost's function is to call third-party platform APIs on your behalf, your connected account tokens and the content you submit are necessarily sent to the platform(s) you target for a given post. Specifically:
- Meta Platforms, Inc. — for Instagram and Threads accounts you connect, we use your OAuth token to call the Instagram Platform API and the Threads API (graph.instagram.com / graph.threads.net) to publish the content you submit and to read basic profile/account information needed to operate the connection.
- TikTok Inc. / ByteDance Ltd. — for TikTok accounts you connect, we use your OAuth token to call the TikTok Content Posting API to publish or upload content you submit.
- X Corp. — for X (Twitter) accounts you connect, we use your OAuth token to call the X API v2 to publish posts and upload media you submit.
We also share data with service providers who process data on our behalf under contract, such as our hosting provider, database provider, and payment processor (see subprocessor placeholders in our Security page). We do not otherwise share personal data with third parties except: to comply with law, respond to a valid legal request, protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets (with notice to affected Customers where required by law).
5. Data retention
- OAuth tokens are retained for as long as the connection remains active. When you disconnect a social account in OmniPost, or delete your workspace, the associated access and refresh tokens are deleted from our database. Deletion is completed within [X] days of the disconnect or deletion request, consistent with the per-platform obligations summarized below.
- For X (Twitter), the X Developer Agreement requires that content deletions requested by X or by the end user be actioned within 24 hours, and that all retained data be deleted within 10 business days of API access being terminated. OmniPost's deletion process is designed to meet or beat both windows.
- For Meta (Instagram and Threads), see "How we comply with Meta Platform Terms" below — deletion requests are handled through Meta's Data Deletion Callback mechanism as well as directly by OmniPost.
- API request logs and other operational data are retained for a limited period for security and debugging purposes and then deleted or anonymized on a rolling basis (see Security).
How we comply with Meta Platform Terms
Meta's Platform Terms require every app that integrates with Instagram or Threads to provide a way for a person to have their data deleted from the app, and to respond automatically when a person removes the app's access from their Facebook or Instagram account settings.
OmniPost implements this in two ways:
- Automated Data Deletion Callback. Our Meta app is registered with a Data Deletion Request Callback URL. When a user removes OmniPost from their Instagram/Facebook app settings, Meta signs and sends a deletion request to that endpoint. OmniPost verifies the signed request, deletes the stored access/refresh tokens and connected-account record for that user, and returns a confirmation URL and code that the user can use to check the status of their deletion, exactly as required by Meta's Platform Terms.
- Manual instructions. For users who prefer to request deletion directly, or as a fallback if the automated callback cannot run, we publish a human-readable Data Deletion Instructions page describing how to revoke access and request deletion by email.
We also honor Meta's deauthorization webhook: when a connected Instagram or Threads account is deauthorized, OmniPost marks the corresponding connection as revoked and stops using the associated token.
6. Your rights
Depending on where you are located, you may have rights under the EU/UK General Data Protection Regulation (GDPR) or the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), including the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion of your personal data, subject to legal retention requirements.
- Portability — receive your data in a structured, commonly used, machine readable format.
- Objection — object to certain processing of your data.
- Under CCPA/CPRA, California residents additionally have the right to know what personal information is collected, to opt out of any sale or sharing of personal information (OmniPost does not sell personal information), and to non-discrimination for exercising these rights.
To exercise any of these rights, contact us at [DPO/Privacy Contact Email]. We may need to verify your identity before actioning a request. See also our dedicated Data Deletion Instructions page for platform-connection-specific deletion.
7. Cookies
OmniPost uses a minimal set of cookies required to keep you signed in and to remember your theme preference. We do not use third-party advertising or tracking cookies. See our Cookie Policy for details.
8. Children's privacy
OmniPost is a business/developer tool and is not directed at, or knowingly offered to, individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at [DPO/Privacy Contact Email] and we will delete it.
9. International data transfers
OmniPost may process and store data in countries other than your own, including [Hosting Region Placeholder]. Where we transfer personal data out of the EU/UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs) or an equivalent lawful transfer mechanism [SCC Reference Placeholder].
10. Security
We encrypt OAuth tokens at rest using AES-256-GCM, encrypt data in transit using TLS, hash API keys and passwords, and apply least-privilege access controls to production systems. See our Security page for more detail. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
11. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date above and, where appropriate, notify workspace owners by email or in-app notice.
12. Contact
Contact information (placeholder)
[Legal Entity Name]
[Company Address]
Privacy inquiries: [DPO/Privacy Contact Email]
Governing jurisdiction: [Jurisdiction]