Legal

Privacy Policy

What we collect, why we collect it, and who we share it with.

Last updated: September 8, 2026

1. Who we are

This Privacy Policy explains how PostWing ("we", "us") handles personal data when you use the website at postwing.io, the PostWing dashboard, and the PostWing MCP server (collectively, the "Service"). It applies alongside our Terms of Use.

2. Data we collect

  • Account data — your name, email address, and profile image, received from Google when you sign in. We never receive or store your Google password.
  • Connected social accounts — the platform, handle, display name, and access credentials for each social account you connect, so we can publish on your behalf.
  • Content you create — captions, images, videos, scheduled times, target accounts, and the publish status of each post.
  • Billing data — subscription plan, status, and billing identifiers. Card details are handled by our payment provider and never reach our servers.
  • Integration credentials — API keys and OAuth tokens you issue to connect AI assistants, stored in hashed or encrypted form.
  • Usage and technical data — log records of actions taken in your account, including actions taken through the MCP server, plus basic aggregate analytics about site visits.

We do not ask for and do not want sensitive personal data such as government identifiers, health information, payment card numbers, or biometric data. Please do not send it to us.

3. How we use your data

  • To operate the Service, including scheduling and publishing the posts you create.
  • To authenticate you and secure your account and connected integrations.
  • To process subscriptions, enforce plan limits, and handle refunds.
  • To maintain an audit log of account activity for security and support.
  • To respond to your support requests and send essential service notices.
  • To detect, prevent, and investigate abuse, fraud, and technical problems.

We do not sell your personal data, and we do not use your content to train machine learning or AI models.

4. AI assistant connections, MCP, and the Agent API

PostWing lets you connect an AI assistant such as ChatGPT, Claude, or Muse to your account through an MCP server and/or a REST Agent API. This section describes exactly what those connections can access.

How access is granted. You authorize the connection yourself through OAuth, on a PostWing consent screen that lists the permissions being requested, or by creating an API key in your dashboard. You may grant read access to your connected accounts, read access to your posts, and permission to schedule, edit, and cancel posts. Access requires an active subscription, and you can revoke OAuth connections or API keys at any time from your PostWing dashboard, which immediately stops further access.

What the assistant can see. Only data covered by the permissions you granted: your connected social account handles and platforms, your account timezone, and the captions, media, times, targets, and status of your posts. The MCP server and Agent API never expose your Google credentials, your social platform access tokens, your billing details, or any other user's data.

Confirmation before changes. Scheduling and editing posts require a two-step flow: the assistant must first request a preview, then submit a short-lived signed confirmation token to apply the change. Cancelling a post requires an explicit confirmation flag. This is designed so that no post is created, changed, or removed without you seeing and approving it first.

Media. Agent endpoints do not accept arbitrary private-network URLs. Media is imported only from HTTPS links you provide, and links that resolve to private or internal network addresses are refused.

Logging. We record which agent actions were taken and when, so you have an audit trail of anything an assistant did in your account.

When you use an AI assistant with PostWing, your prompts and the data returned to the assistant are also handled by that assistant's provider under their own privacy policy. We do not control how OpenAI, Anthropic, Meta, or any other provider processes that data.

5. Who we share data with

We share data only with service providers that help us run the Service:

  • postforme.dev — connects your social accounts, stores your media, and publishes your scheduled content on your behalf.
  • Supabase — database, authentication, and storage infrastructure.
  • Our hosting and payment providers — to serve the application and process subscription billing.
  • Google — to authenticate you when you sign in.
  • The social networks you connect — to publish the content you schedule. Each platform then handles that content under its own policies.

We may also disclose data if required by law, or in connection with a merger, acquisition, or sale of assets, in which case we will notify you.

6. Retention

We keep your account data, posts, and audit logs for as long as your account is active. When you delete your account, we delete or anonymize your personal data and disconnect your social accounts, except where we must retain records for legal, tax, or fraud-prevention reasons. Expired integration tokens and authorization codes are removed automatically.

7. Security

Data is encrypted in transit. Integration credentials are stored hashed or encrypted rather than in plain text, MCP requests are rate limited, and access to your data is scoped to your own account and workspace. No system is perfectly secure, so we cannot guarantee absolute security.

8. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. You can disconnect social accounts, revoke AI assistant access, and delete your account from your dashboard, or email us and we will help.

9. International transfers

We and our service providers may process your data in countries other than your own, including the United States. Where required, we rely on appropriate safeguards for those transfers.

10. Children

PostWing is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us data, contact us and we will delete it.

11. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will post the updated policy on this page and update the "Last updated" date.

12. Contact

Questions about this policy or your data? Email us at mejed@templyo.io.