Privacy policy
Last updated 27 August 2026
Pushapost schedules social media posts on behalf of the brands you manage. This policy describes what we collect, why we hold it, who else sees it, and how to have it removed. It is written to describe what the software actually does.
What we collect
Your account. Your email address and a hashed password, or the identifier from whichever provider you sign in with. We never store your password in a form we can read.
Your content. The brands you create, the posts you write or approve, any images and video you upload, and the schedule you set.
Social account references. When you connect a social profile, the authorisation is handled by our integration provider and we store only a reference to the connected account, plus the handle and its status. We do not receive or store your social platform passwords, and we do not hold long-lived access tokens ourselves.
Performance data. Figures the social platforms report about your posts and profiles — impressions, engagements, follower counts — collected on a schedule so your reporting stays current.
Activity records. Who created, approved or rejected a post, and which AI assistant queued it, if any. This exists so an agency can answer "who signed this off" about work done for a client.
What we do not do
We do not sell your data. We do not use the content of your posts to train machine learning models. We do not read your social inbox or messages — the access we request is for publishing and for reading performance figures about your own profiles.
Who else sees it
Running the service means sharing some data with the companies that host and power it: our cloud host, our database provider, our social integration provider, and the social platforms themselves when you publish to them. Each receives only what that job needs.
If you connect a social account, that platform's own privacy policy governs what it does with the post once we hand it over.
How long we keep it
Your content stays until you delete it or close your workspace. Activity records are kept for as long as the workspace exists, because their value is in being a complete history. When a workspace is deleted, everything belonging to it is removed.
Your choices
You can disconnect a social account at any time from the Accounts page, which also revokes the connection at our integration provider. You can delete posts, media and brands from within the app.
You can request a copy of your data, or its deletion, by writing to privacy@pushapost.com. See the data deletion page for how that works and how long it takes.
Children
Pushapost is a business tool and is not directed at anyone under 16.
Changes
If this policy changes in a way that affects how we handle your data, we will tell account owners by email before it takes effect.