appost.io
Product For agencies Comparisons Guides About Pricing
IT Request access
LEGAL

Privacy Policy.

What data we process, why, where, with which providers, for how long, and how you delete it — including data from the social platforms you connect. Readable, but complete and substantive. GDPR-compliant.

Contents

  • 1. Controller and DPO
  • 2. What data we process
  • 3. Why, and legal basis
  • 4. Social platform data
  • 5. Providers and transfers
  • 6. How long we keep it
  • 7. Your rights
  • 8. Deleting social data
  • 9. Security
  • 10. Minors
  • 11. Cookies and tracking
  • 12. Changes
Last revised: 30 June 2026 · Version 5.0 · DPO: dpo@appost.io

This policy covers appost.io, the social content planning and publishing platform (https://app.appost.io), and the processing of early-access waitlist data collected on this website. Where a processing activity is specific to the product platform or to the waitlist, we say so.

1. Data controller and DPO

The data controller is Francesco Checchia, based in Biccari (FG), Italia, VAT no. 04429140710 (sole proprietorship under Italian law).

For any request about your personal data and to exercise your rights, contact our data protection point of contact: dpo@appost.io.

2. What data we process

We process only the data needed to run the service, grouped by category.

2.1 Account data

  • Email address.
  • Password, stored only as a cryptographic hash (bcrypt) — we never see your plaintext password.
  • First and last name, if you provide them.
  • If you sign in with Google: your Google account identifier (an opaque code Google provides) and the associated email. We never receive your Google password.
  • Technical sign-in data: last sign-in time, email verification status.

2.2 Brand and content data

  • Brand name, website, documents and any materials you upload.
  • Text and images of the content you create or import.
  • "Voice examples": short texts representative of the brand's tone (added by you or imported from social — see §4).
  • Vector representations (embeddings) of your brand content, used so the AI matches your style. They are derived from your content and used only within your workspace.

2.3 Social platform data

When you connect a social account, we process the data described in detail in section 4: access tokens (encrypted), Page/account identifiers, display name, the content of a few recent imported posts, and engagement metrics.

2.4 Data generated by the service

  • AI-generated posts, editorial plans, drafts.
  • Technical logs of AI processing: truncated and stripped of personal data, retained for a limited time (see §6).
  • An audit log of operations relevant to security and traceability.
  • A transactions ledger (credits/usage): during the preview phase it involves no real payments (see §6).

2.5 Website and waitlist technical data

  • Early-access waitlist: the email you voluntarily provide, plus minimal technical metadata (IP address, user-agent, timestamp, source parameter) collected for anti-abuse and as proof of consent; the consent text and timestamp, kept under Art. 7 GDPR.
  • Website access logs (IP, user-agent, timestamp), handled by the content delivery network (Cloudflare).

3. Why we process data, and legal basis

Each processing activity has a specific purpose and legal basis:

  • Provide the service (create and manage the account, generate content, schedule and publish, show you analytics) — legal basis: performance of a contract (Art. 6(1)(b) GDPR).
  • Publish on your behalf to the social accounts you connect and import your recent content for tone-of-voice analysis, when you enable it — legal basis: performance of a contract (Art. 6(1)(b)).
  • Security, abuse prevention, technical continuity (logs, audit, anti-abuse protection) — legal basis: legitimate interest (Art. 6(1)(f)).
  • Tax and accounting obligations once payments exist (retention of the billing skeleton) — legal basis: legal obligation (Art. 6(1)(c); Art. 2220 of the Italian Civil Code).
  • Transactional emails (confirmations, password resets, service notices) — legal basis: performance of a contract (Art. 6(1)(b)).
  • Early-access waitlist (collecting your email to contact you when access opens) — legal basis: consent (Art. 6(1)(a)), withdrawable at any time.

appost.io does not sell your data and does not reuse it for purposes other than those stated here.

4. Social platform data (Meta, LinkedIn, WordPress)

You connect your social accounts to appost.io through official authorization (OAuth) so you can publish and analyze your brand's content. We process this data only for the purposes you enable. Transparently, here is what we read, why, what we store, and for how long.

4.1 Facebook and Instagram (Meta)

We use the official "Instagram API with Facebook Login" flow. The permissions we request and their actual use:

  • List of Pages (pages_show_list) — we read the list of Facebook Pages you manage so you can choose which one to publish to. We store: the id and name of the Page you select. For how long: while the connection is active.
  • Publish to the Page (pages_manage_posts) — we publish to your Facebook Page the posts you approve from the content calendar. We store: the published posts and their publishing outcome.
  • Page metadata (pages_read_engagement) — we read Page metadata to confirm the connection and resolve the linked Instagram Business account. We store: the Page name and the link to the Instagram account.
  • Recent Page content (pages_read_user_content) — when you run "enrich from social", we import recently published posts to learn the brand's tone of voice and avoid repeating topics. We store: a few of those posts (up to about 6 per workspace) are saved as "voice examples", with the text and a link to the original post, so the AI matches your real style. They are visible in the app, individually deletable by you, and erased on a data-deletion request (see §8). The total number of voice examples per workspace is capped (at most 20, manual and social combined).
  • Instagram profile and media (instagram_basic) — we read the linked Instagram Business account's profile and media to set up publishing and tone analysis. We store: the account id and display name.
  • Publish to Instagram (instagram_content_publish) — we publish generated images and captions to your Instagram Business account. We store: the published posts.
  • Instagram insights (instagram_manage_insights) — after publishing, we show you reach, likes and comments for your Instagram posts in a dashboard. We store: the engagement metrics of your posts.
  • Page insights (read_insights) — we show you engagement metrics (clicks, reactions) for your Facebook Page posts. We store: the metrics of your Page posts.
  • Pages in a Business Portfolio (business_management) — if a Page belongs to a Business Portfolio and would not appear in the normal list, we enumerate it so you can connect and publish. We store: nothing beyond the Page you select.

For each connection we also store, in encrypted form, the access tokens issued by Meta (AES-256-GCM encryption, never exposed by our interfaces) and the Meta app-scoped user identifier (ASID) of whoever authorized the connection: it is the key the Meta data-deletion request relies on (see §8).

4.2 LinkedIn

If you connect LinkedIn, we publish on your behalf to the profiles or Pages you authorize and read the profile data strictly needed to publish. We store the encrypted access tokens and required identifiers for the duration of the connection. LinkedIn offers no automatic data-deletion mechanism: to request deletion, de-authorize and/or write to dpo@appost.io (see §8).

4.3 WordPress

If you connect a WordPress site, we publish content to your site using the credentials you authorize. This is an outbound flow to a platform you control; we store the connection credentials in encrypted form for the duration of the connection.

Social platforms, LinkedIn and WordPress are not our sub-processors: they are destinations you choose, on your own accounts, to which we send content on your instruction.

5. Providers and transfers outside the European Union

Where the product runs. The platform infrastructure consists of servers operated by the controller in Germany (European Union): the database, file and content storage, queues and cache reside in the EU. Encrypted offsite backups are kept on Backblaze B2 (USA), encrypted on the controller's side, so the provider cannot access the data in clear. Product transactional emails are sent through a self-hosted mail server in the EU.

Waitlist and website. Early-access waitlist and website data are processed on Cloudflare (EU) and Resend (EU), with EU data residency.

Transfers outside the EU. To generate content and enrich the brand profile, some data (the text and images you submit for processing, and the public content read at your request) is transmitted to providers located in third countries, in particular the United States. These transfers are covered by the EU Standard Contractual Clauses (SCC) 2021/914. Content is transmitted to these providers solely to produce the result you request; their processing is governed by their respective contractual terms.

The providers that process data on our behalf, declared by category (an up-to-date named list is available on request to dpo@appost.io, Art. 28 GDPR):

  • AI model providers — text generation, content embeddings, image generation and moderation. Content is routed through an AI model gateway. Country: USA (third country). Safeguard: EU SCC 2021/914 + data minimization.
  • Web search and reading providers — market research and reading of the brand's website to enrich the editorial profile (on your action). Country: USA and other third countries. Safeguard: EU SCC 2021/914.
  • CDN, DNS and perimeter protection — content delivery, anti-abuse and DDoS protection, DNS resolution. Country: global network with an EU point of presence. Safeguard: EU SCC 2021/914.
  • Encrypted offsite backup — storage of encrypted backup copies outside the primary cluster. Country: USA (third country). Safeguard: EU SCC + controller-side encryption (the provider cannot access the data in clear).
  • Website delivery and analytics — Cloudflare (network with an EU point of presence) for static hosting, protection and cookieless aggregate statistics on the marketing site.
  • Waitlist email delivery — Resend (EU data region) for waitlist confirmation emails.

Payments. During the preview no payments are active: we use no payment provider and process no card data. When we introduce subscriptions, we will update this policy to name the payment provider (a processor) and the relevant safeguards.

6. How long we keep data

  • Account and working data — for the duration of the relationship. On account closure a 7-day grace period opens, during which you can regain access; after it, working data is permanently deleted.
  • Anonymized billing skeleton — once payments exist, the data needed for accounting obligations is kept for 10 years (Art. 2220 of the Italian Civil Code) in anonymized form (name, email and direct identifiers removed).
  • Voice examples imported from social — while the connection stays active or until you delete them; erased on a social data-deletion request (see §8).
  • AI processing logs — truncated and stripped of personal data, automatically deleted after 90 days.
  • Deleted files and images — permanently removed within 7 days of deletion (soft-delete + scheduled cleanup).
  • Audit log — immutable, kept for as long as needed for traceability and security; removed on full account deletion.
  • Backups — encrypted copies kept for a limited period, then overwritten on the rotation cycle.
  • Early-access waitlist — until the preview phase ends or at your deletion request; proof of consent kept under Art. 7 GDPR. Website technical logs: 90 days.

7. Your rights

You can exercise your GDPR rights at any time:

  • Access (Art. 15) — obtain a copy of the data concerning you.
  • Rectification (Art. 16) — correct inaccurate or incomplete data.
  • Erasure (Art. 17) — delete your data, within the limits of retention obligations (e.g. the tax skeleton).
  • Restriction (Art. 18) and objection (Art. 21) — restrict or object to certain processing.
  • Portability (Art. 20) — receive your data in a structured, machine-readable format. Today portability is exercised by requesting it from the DPO, who prepares the export.
  • Withdraw consent (Art. 7(3)) — for consent-based processing (the waitlist), at any time, without affecting the lawfulness of prior processing.
  • Complaint to the supervisory authority — you may contact the Italian Data Protection Authority (www.garanteprivacy.it).

To exercise a right, write to dpo@appost.io. We respond within 30 days (usually much sooner).

8. Deleting social platform data

You have two distinct routes, with different effects:

  • De-authorization (revoking access). You can disconnect a social account in the app or remove the app from the platform's settings. The connection becomes invalid and we immediately stop accessing your data. This revokes access; it does not delete data already imported.
  • Data-deletion request. When you remove appost.io from Facebook, Meta sends a deletion request to our dedicated endpoint: https://api.appost.io/oauth/meta/data-deletion. This procedure permanently deletes the affected social connections, the imported historical posts, and the social-derived voice examples together with their vector representations. You receive a confirmation code and a public status page (https://api.appost.io/meta/data-deletion/status/<code>) to check progress.

You can also delete individual voice examples directly in the app at any time.

For LinkedIn, which offers no equivalent automatic mechanism, de-authorize and, to delete imported data, write to dpo@appost.io: we act within 30 days.

9. Security

  • Encryption of data in transit (TLS) and at rest (AES-256).
  • Social platform access tokens encrypted separately (AES-256-GCM) and never returned by the app's interfaces.
  • Passwords protected with a strong hashing function (bcrypt); we never store the plaintext password.
  • Per-customer (tenant) data isolation and an audit log of relevant operations.
  • Staff access on a least-privilege basis.

10. Minors

appost.io is a professional tool intended for people aged 18 or over who can enter into contracts (see Terms). We do not direct the service to minors and do not knowingly collect their personal data. If you believe a minor has provided us data, write to dpo@appost.io and we will remove it.

11. Cookies and tracking

  • App (app.appost.io) — we use only technical cookies necessary to operate: a session cookie (HttpOnly) to keep you signed in, a technical anti-CSRF cookie, and a language preference. No analytics cookies, no advertising pixels, no third-party trackers.
  • Marketing site (appost.io) — cookieless aggregate statistics (Cloudflare Web Analytics). No Google Analytics, no Meta Pixel, no third-party trackers.

12. Changes to this policy

We may update this policy. For material changes we will give notice. The version and date at the top always indicate the edition in force.

For any privacy question, write to dpo@appost.io. Complaints to the supervisory authority: www.garanteprivacy.it.

© 2026 APPOST.IO · DATA STORED IN THE EU · GDPR · EU AI ACT · NO-COOKIE ANALYTICS
For agencies Comparisons Guides About Contact Privacy Terms DPA