Pickpost is a social media scheduler. It is a product and trading brand of Auvyx LLC ("we", "us"), not a separate company. This page explains what we store about you, why, who else handles it, and how to remove it. Questions: [email protected].
What we collect
- Your account. Your email address, a name if you give one, and what is needed to sign you in. Passwords are stored only in a form that cannot be read back. With Google or another sign-in provider, we receive your name and verified email from it.
- Connected social accounts. For each account you connect (on X, Threads, Facebook, Instagram, TikTok, YouTube, LinkedIn, Pinterest, Bluesky, Mastodon, Pixelfed or Google Business Profile): its name, username, profile picture and the access tokens the network gives us. Tokens are encrypted and never sent to your browser.
- What you create. Posts, their versions for each network, schedules, publishing results and the images you upload. Images are re-encoded when uploaded, which removes EXIF data such as GPS location. Videos are stored as you upload them, with any metadata they carry (for example a location your camera recorded): remove it before uploading if it matters to you.
- Statistics of your published posts. After a post goes out, we ask the network for its numbers a few times over the following 30 days (1 hour, 6 hours, 1 day, 3 days, 7 days and 30 days after publishing) and store what it reports: views, reach, likes, comments, shares, quotes, saves and clicks, depending on the network, with the time we read them. These are totals the network computes. We do not receive who liked, commented or viewed.
- Workspaces and teams. The workspaces you belong to and your role in each. People in the same workspace see each other's name and email. When you invite someone, we store their email address until the invitation is accepted, cancelled or expires (after 7 days), and send them one email.
- Plans and payments. Your workspace's plan, its status and renewal date, and the identifier of the customer and subscription at our payment processor. Card details are entered on the processor's page and never reach us.
- Assistant conversations. When you use the built-in assistant, your messages and the posts it works on are stored with the conversation.
- Webhooks. The addresses that owners and admins of a workspace enter to receive events, and a record of what we sent to each one and how it answered, kept for 30 days.
- Apps you connect. When you connect an AI tool over MCP, we record which app it is and the permissions you granted.
- Technical data. Request logs (time, path without its query string, status, a request identifier) to run and debug the service. Logs never contain passwords, tokens or the text of your posts. Rate limiting uses hashed IP addresses and emails.
Cookies
The app uses one session cookie to keep you signed in, and a short-lived cookie during sign-in. They are necessary for the service. We use no advertising or analytics cookies, and this website sets none.
Why we use it
- To run your account and show you your posts, calendar and media.
- To publish to the networks you connected, at the times you scheduled, and only after you approved.
- To show you how your published posts did, and which days and hours worked best, in the app and to the assistant or apps you connected.
- To answer you in the assistant, when you use it.
- To send the emails the service needs: sign-up and password reset links, and invitations you ask us to send.
- To bill paid plans and apply what each plan includes.
- To keep the service secure and working.
We do not sell your data, and we do not use your posts to train AI models.
Who processes it
We share data only with service providers that help us run Pickpost, and only what each one needs:
- Infrastructure providers host the application, the database and the private storage for your images, and deliver our emails.
- Stripe processes payments for paid plans, under its own privacy policy, and handles your card details itself.
- AI model providers (such as Anthropic) receive your messages and the posts they are about when you use the built-in assistant, to generate its replies. We do not allow them to use this data to train their models.
- Google receives your sign-in request only if you choose to sign in with Google.
They act on our instructions and are bound to protect the data. We may also disclose information where the law requires it, or to protect the rights, safety and security of our users, the public or Pickpost.
If an owner or admin of your workspace adds a webhook, we also send the events it asks for to the address they entered: a post that was published or failed, including its text, or the name of an account that needs reconnecting. Your workspace chooses that address and what happens to the data there.
The social networks you connect
When you connect an account and publish, the network receives your posts and images and handles your sign-in with it. Afterwards we read the statistics of those posts from it, with the permission you gave when connecting. If you remove Pickpost in Facebook, Instagram or Threads, the network tells us and we disconnect the accounts you connected from there and delete their access tokens; if you ask it to have your data deleted, we also delete those accounts and the statistics of their posts, and give you a code to check the request (see Data deletion). Each is a separate company that acts under its own terms and privacy policy, not on our behalf:
- X is provided by X Corp., Austin, Texas, USA.
- Facebook, Instagram and Threads are provided by Meta Platforms, Inc., Menlo Park, California, USA.
- YouTube and Google Business Profile are provided by Google LLC, Mountain View, California, USA.
- LinkedIn is provided by LinkedIn Corporation, Sunnyvale, California, USA.
- Pinterest is provided by Pinterest, Inc., San Francisco, California, USA.
- TikTok is provided by the TikTok company that serves your country, as named in TikTok's terms.
- Bluesky is provided by Bluesky Social, PBC, or by the server that hosts your account.
- Mastodon and Pixelfed accounts live on independent servers (instances); each is run by its own operator under its own rules.
Pickpost is not affiliated with, endorsed or sponsored by any of these companies or operators.
How long we keep it
We keep your data while your account exists. Statistics stay with the post they belong to; we stop reading them 30 days after publishing, or as soon as you disconnect the account. When you delete your account, your posts and their statistics, schedules, conversations, connected accounts and their tokens are deleted from the database, and your images are deleted from storage. See Data deletion.
Your rights
You can see, correct and delete your data in the app, and ask us for a copy of it or for anything the app does not cover. Write to [email protected]; we answer within 30 days.
Security
Access tokens are encrypted, each account's data is kept apart from every other account's, images are private and reach the networks only through short-lived links, and every connection is encrypted in transit.
Children
Pickpost is not meant for children under 16, and we do not knowingly collect their data.
Changes
If we change this policy in a way that matters, we will say so in the app or by email before it applies.