Back to home

Privacy Policy

Effective date: July 20, 2026

The Post Engine is operated as a sole proprietorship registered in Quebec, Canada. Contact details are provided in Section 16.

This Privacy Policy explains how we collect, use, store, share, and delete information when you visit thepostengine.com or use The Post Engine.

The Post Engine is a subscription software service that helps businesses and creators generate, plan, schedule, publish, and analyze social-media content.

1. Information We Collect

Account information

When you create an account, we may collect:

  • Your name and email address.
  • Your password in hashed form.
  • Your subscription plan and account status.
  • Usage credits and feature usage.
  • Account preferences.
  • Messages and support requests.

Content

We process content you upload, create, or generate, including:

  • Images and videos.
  • Captions and written posts.
  • Brand information and instructions.
  • AI prompts.
  • Generated images and text.
  • Brand DNA profiles.
  • Competitor-analysis reports.
  • Scheduled and published content.

Technical and usage information

We may collect:

  • IP address and browser information.
  • Login and session information.
  • Device and approximate location information.
  • Publishing activity and publishing errors.
  • Usage counters.
  • Security, diagnostic, and audit logs.
  • Records of actions taken within your account.

We use essential cookies and similar technologies for authentication, security, session management, and user preferences. We do not use connected social-media information for third-party behavioural advertising.

Payments

Payments are processed by Stripe.

Stripe collects and processes payment-card and billing information directly. Full payment-card information does not pass through or remain on The Post Engine's servers.

We receive limited information from Stripe, such as your customer identifier, subscription plan, payment status, and transaction history.

2. Connected Social-Media Platforms

You may connect accounts from Facebook, Instagram, Threads, YouTube, Pinterest, TikTok, and LinkedIn.

The information we receive depends on the platform, the account type, the permissions you approve, and the access granted to The Post Engine.

We use connected-account information to identify your accounts, publish content, provide requested analytics, and operate the features described below.

2.1 Meta: Facebook Pages and Instagram

The Post Engine connects to Facebook Pages and Instagram professional accounts through Facebook Login for Business.

Depending on the permissions you approve, we may access:

  • Facebook Page and Instagram account identifiers.
  • Page or account names and usernames.
  • Profile pictures and follower counts.
  • Pages and professional accounts you are authorized to manage.
  • Posts, captions, images, videos, media types, timestamps, and permalinks.
  • Likes, comments, and other available engagement information.
  • Publishing status and error information.

We use this information to:

  • Display and identify your connected accounts.
  • Let you create, schedule, and publish content.
  • Confirm whether content was successfully published.
  • Provide analytics for accounts you manage.
  • Generate a Brand DNA analysis when you request one.
  • Provide permitted analysis of public Instagram Business or Creator accounts.

When you request Brand DNA, selected content and engagement information may be sent to Anthropic to generate your Brand Profile.

Profile pictures and selected post images may be copied to Cloudflare R2 so they can be displayed in The Post Engine.

You may disconnect Facebook or Instagram through The Post Engine's connected-account settings. You may also request deletion using the process described in Section 10.

Disconnecting your account prevents future access but does not delete posts already published on Facebook or Instagram.

2.2 Threads

The Post Engine uses the Threads API to connect Threads accounts and publish user-selected content.

We may access:

  • Your Threads account identifier.
  • Username and basic profile information.
  • Information needed to maintain the authorized connection.
  • Content and publishing instructions you submit through The Post Engine.
  • Publishing status and error information.

We use this information only to display your connected Threads account and publish content that you choose to publish immediately or schedule.

You may disconnect Threads through your connected-account settings. Disconnecting Threads does not delete content already published on Threads.

2.3 TikTok

The Post Engine uses TikTok Login Kit and the TikTok Content Posting API.

Depending on the permissions and information TikTok makes available, we may access:

  • Your TikTok account identifier.
  • Display name, username, and profile image.
  • Available publishing and privacy options.
  • Information needed to maintain the authorized connection.
  • Publishing status and error information.

When you publish or schedule TikTok content, we send TikTok the selected media, caption, privacy setting, interaction settings, commercial-content selections, and other required publishing instructions.

The Post Engine publishes to TikTok only after you select or schedule the content and choose the required TikTok publishing settings.

We do not sell TikTok information or use it for cross-context behavioural advertising.

You may disconnect TikTok through your connected-account settings. We will delete stored TikTok access information when it is no longer necessary, when you disconnect the account, or when you request deletion, subject to legal requirements.

Disconnecting TikTok does not delete content already published on TikTok. Our access to and use of TikTok information complies with the TikTok Terms of Service and the TikTok Privacy Policy.

2.4 YouTube

The Post Engine uses YouTube API Services, including the YouTube Data API.

Depending on the features you use, we may access:

  • YouTube channel identifiers.
  • Channel name, profile image, description, and subscriber count.
  • Videos, titles, descriptions, tags, thumbnails, and publication dates.
  • Public view, like, and comment counts.
  • Information needed to upload content to an authorized channel.
  • Publishing status and error information.

We use authorized YouTube information to:

  • Display and identify your connected channel.
  • Upload content that you choose to publish or schedule.
  • Display permitted channel and content information.
  • Provide features you request that are permitted by YouTube's policies and our approved API access.

A user may submit a public YouTube channel for competitor analysis. Where permitted, public channel and video information may be sent to Anthropic to generate the requested report.

We do not use YouTube API data for advertising.

Information received through YouTube API Services may be shared with our hosting and AI service providers only as necessary to provide the requested feature and subject to applicable YouTube requirements.

Stored YouTube API data is refreshed or deleted within the periods required by YouTube, generally within 30 calendar days unless longer storage is expressly permitted.

When you request deletion, delete your The Post Engine account, or revoke YouTube authorization through The Post Engine, applicable authorized YouTube data will be deleted as soon as reasonably possible and no later than seven calendar days.

You may also revoke The Post Engine's access through Google's security permissions page. Revocation through Google may take up to 30 calendar days to be detected and fully reflected in stored YouTube API data.

Deleting information from The Post Engine does not delete videos or other content stored directly on YouTube. Content hosted on YouTube must be deleted through YouTube or another authorized application that supports deletion.

Your use of YouTube features is also subject to the YouTube Terms of Service. Google processes information according to the Google Privacy Policy.

2.5 Pinterest

The Post Engine uses the Pinterest API to connect authorized Pinterest accounts, publish user-selected Pins, and provide analytics on your own account.

Depending on the permissions you approve, we may access:

  • Your Pinterest account identifier.
  • Basic account and profile information, including follower count.
  • Boards available for publishing.
  • Your own Pins, including titles, descriptions, images, and creation dates.
  • Information needed to maintain the authorized connection.
  • Pin publishing status and error information.

We use Pinterest information only to provide services to the person whose account supplied the information. This includes displaying your connected account, publishing Pins you select, and generating a Brand DNA analysis of your own Pins when you request one.

Every Pin published or scheduled through The Post Engine must be individually selected by the user.

We do not use Pinterest API information to analyze accounts you do not own, and we do not sell Pinterest API information or combine it with information from unrelated accounts for advertising purposes.

Pinterest API information is stored only where and for as long as Pinterest permits. You may disconnect Pinterest through your connected-account settings.

Disconnecting Pinterest does not delete Pins already published on Pinterest.

2.6 LinkedIn

The Post Engine uses Sign In with LinkedIn and Share on LinkedIn.

Depending on the permissions you approve, we may access:

  • Your LinkedIn member identifier.
  • Name and basic profile information.
  • Profile picture.
  • Information needed to maintain the authorized connection.
  • Publishing status and error information.

We collect this information when you connect LinkedIn and use it to identify your account and publish content you choose to publish or schedule.

We do not publish to LinkedIn without your direction.

You may withdraw authorization by disconnecting LinkedIn. We delete stored LinkedIn access tokens and applicable LinkedIn API information when you disconnect the account, request deletion, or close your The Post Engine account, except where retention is legally required.

Disconnecting LinkedIn does not delete content already published on LinkedIn.

3. Publishing and Scheduling

When you schedule a post, The Post Engine stores the selected content, destination accounts, publishing time, and required platform settings.

A background service attempts to publish the content at the scheduled time. Failed publishing jobs may be retried automatically. If publishing ultimately fails, we may send you a transactional email.

The Post Engine does not publish content unless you choose to publish it immediately or schedule it.

You remain responsible for:

  • The content you publish.
  • The accounts you select.
  • Visibility and privacy settings.
  • Commercial-content disclosures.
  • Your right to use uploaded or generated content.
  • Compliance with each platform's rules.

4. Brand DNA

Brand DNA analyzes past content from social-media accounts you own or are authorized to manage.

When you request an analysis, we may process up to 100 recent posts, including:

  • Captions.
  • Images and media types.
  • Publication dates and times.
  • Likes, comments, views, and other available engagement figures.
  • Hashtags and permalinks.

This information is sent to Anthropic's Claude API to generate a written analysis that may include:

  • Content pillars.
  • Tone and writing patterns.
  • Posting-time patterns.
  • Caption and hashtag patterns.
  • High- and low-performing content.
  • Suggested future content.

The resulting Brand Profile is stored in your account. Up to ten selected post images may also be stored in Cloudflare R2.

Brand DNA is provided only where the applicable platform permits this processing and where The Post Engine has the necessary authorization.

5. Public Competitor and Non-User Information

A user may request an analysis of a publicly available business, creator, professional account, channel, or website that the user does not own.

Depending on the requested feature and our approved access, we may process:

Public YouTube information

  • Channel name, description, and statistics.
  • Video titles and descriptions.
  • Tags and publication dates.
  • Public view, like, and comment counts.

Public Instagram information

Through Instagram Business Discovery, where approved, we may process:

  • Public Business or Creator account usernames.
  • Follower and media counts.
  • Public captions and recent posts.
  • Public engagement figures.

Public website information

When a user submits a website URL, we may retrieve and analyze publicly available webpage content, including:

  • Page text.
  • Product or service descriptions.
  • Public pricing information.
  • Links.
  • Publicly observable website technologies.

This information may relate to people who do not use The Post Engine.

We process this information to provide a limited competitive report specifically requested by a user. Where applicable, we rely on our legitimate interest in providing business and content-strategy analysis based on publicly presented professional or commercial information.

Public competitor information may be sent to Anthropic to generate the requested report. The completed report is stored in the requesting user's account.

We do not use competitor analysis to:

  • Access private accounts or restricted information.
  • Determine sensitive personal characteristics.
  • Conduct personal surveillance.
  • Create reports about children.
  • Sell personal profiles or public-platform datasets.

We process platform information only where the applicable platform's terms and our approved API access permit it.

A person whose information appears in a competitor report may request access, correction, removal, or objection to future processing by contacting us. The request should identify the relevant username, profile, channel, website, or URL.

6. AI Services

The Post Engine uses:

  • Anthropic Claude for captions, written content, Brand DNA analysis, and competitor reports.
  • OpenAI for image generation and image editing.

When you use an AI feature, the information needed to complete your request may be sent to the relevant provider. This may include:

  • Prompts.
  • Brand instructions.
  • Captions and written content.
  • Uploaded images.
  • Public competitor content.
  • Selected post and engagement information.

Under our current commercial API arrangements, Anthropic and OpenAI state that API inputs and outputs are not used to train their general-purpose models by default unless the customer opts in or another agreement applies.

These providers may temporarily retain limited information for service operation, safety, abuse prevention, or legal compliance.

We do not authorize AI providers to use connected-platform data for independent advertising or marketing.

7. How We Use Information

We use information to:

  • Create and manage accounts.
  • Authenticate users.
  • Connect authorized social-media accounts.
  • Generate, schedule, and publish content.
  • Provide Brand DNA and competitor reports.
  • Process subscriptions and usage credits.
  • Store and deliver uploaded and generated content.
  • Send billing, account, security, and publishing notifications.
  • Diagnose technical problems.
  • Prevent fraud, misuse, and security incidents.
  • Comply with legal obligations.
  • Enforce our agreements.
  • Improve the Service using aggregated or de-identified information.

We do not sell personal information or connected social-platform data.

8. Service Providers

We use the following service providers:

  • Anthropic — AI text generation and analysis.
  • OpenAI — AI image generation and editing.
  • Stripe — payment and subscription processing.
  • Cloudflare R2 — media and file storage.
  • Neon — PostgreSQL database hosting.
  • Upstash — Redis, caching, and job queues.
  • Resend — transactional email delivery.
  • Vercel — application hosting and delivery.
  • Railway — background workers and supporting services.

These providers process information only as necessary to provide their services to us, subject to their contractual and legal obligations.

We may also disclose information:

  • When required by law or a valid legal request.
  • To investigate fraud, abuse, or security incidents.
  • To protect our users, rights, property, or safety.
  • As part of a merger, financing, acquisition, restructuring, or sale of the business.
  • At your direction, including when you publish content to a connected platform.

Each connected social-media platform separately processes information according to its own privacy policy and terms.

9. Legal Bases

Where the GDPR, UK GDPR, or similar laws apply, we rely on one or more of the following legal bases:

  • Contract — to create your account and provide requested services.
  • Consent — when you authorize connected platforms or where consent is otherwise required.
  • Legitimate interests — to operate and secure the Service, prevent misuse, and provide limited analysis of publicly available professional or commercial information.
  • Legal obligations — to comply with tax, accounting, regulatory, and legal requirements.

You may withdraw consent by disconnecting a platform or contacting us. Withdrawal does not affect processing that occurred before consent was withdrawn.

10. Retention, Disconnection, and Deletion

We retain account information while your account remains active and for as long as necessary to provide the Service.

Uploaded media, generated content, Brand Profiles, and competitor reports remain in your account until you delete them, close your account, or a shorter platform-specific retention period applies.

Access tokens are retained only while necessary to maintain an authorized connection. When you disconnect an account or delete your The Post Engine account, we revoke or delete applicable access tokens and platform data as required by the relevant platform.

Billing and transaction records may be retained for tax, accounting, fraud-prevention, and legal purposes.

Security and audit logs may be retained for a limited period to protect the Service and investigate misuse.

Deleted information may remain temporarily in encrypted backups until those backups are overwritten. We may retain limited information where required by law, necessary to resolve disputes, or needed to prevent fraud.

You may request deletion by:

Deleting your The Post Engine account does not automatically delete content already published on a third-party platform.

We may need to verify your identity before completing a request.

11. Your Rights

Depending on where you live, you may have the right to:

  • Access your personal information.
  • Correct inaccurate information.
  • Request deletion.
  • Request restriction of processing.
  • Object to processing based on legitimate interests.
  • Withdraw consent.
  • Request a portable copy of certain information.
  • Make a complaint to a privacy regulator.

To exercise these rights, contact support@thepostengine.com.

If your request concerns public non-user information, identify the relevant username, account, channel, website, or URL.

12. Security

We use reasonable administrative and technical safeguards designed to protect information, including:

  • AES-256-GCM encryption for stored platform access tokens.
  • Bcrypt hashing for passwords.
  • JWT-based session management.
  • Encryption during transmission.
  • Restricted access to production systems.
  • Security and audit logging.
  • Payment processing through Stripe.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

13. International Transfers

The Post Engine and its service providers may process information in Canada, the United States, and other countries.

Where required, we use contractual safeguards and other lawful transfer mechanisms intended to protect personal information transferred outside its country of origin.

14. Children

The Post Engine is intended for businesses and creators. It is not directed to children under 13 or the minimum age required by the applicable platform.

We do not knowingly collect personal information from children. Contact us if you believe a child has provided information to us.

15. Changes to This Policy

We may update this Privacy Policy when our services, integrations, legal obligations, or information practices change.

We will update the effective date and provide additional notice where legally required or where a change materially affects how personal information is used.

16. Contact

Questions, complaints, privacy requests, deletion requests, and non-user removal requests may be sent to:

The Post Engine
Operated as a sole proprietorship registered in Quebec, Canada
Email: support@thepostengine.com
Website: thepostengine.com