This Privacy Policy describes how FB Postiz ("we", "us", or "our") collects, uses, and protects your information when you use our social media automation platform.
1. Information We Collect
We collect information that you provide directly to us, including:
Account Information: Email address, name, and password when you create an account
Social Media Credentials: API keys, access tokens, and integration credentials for connected platforms (Facebook, Instagram, Twitter, LinkedIn, etc.)
Content Data: Posts, media files, captions, scheduling information, and analytics data you create or generate through our platform
Usage Data: Device information, IP address, browser type, operating system, and interaction logs with our services
9Drive Storage Data: Files, folders, and metadata stored through our integrated 9Drive self-hosted storage system
2. How We Use Your Information
We use the collected information to:
Provide, maintain, and improve our social media automation services
Process scheduled posts and automate content publishing across connected platforms
Generate AI-powered captions, images, and content recommendations
Analyze usage patterns to enhance platform performance and user experience
Communicate with you about service updates, features, and support
Ensure platform security, prevent fraud, and protect against unauthorized access
Comply with legal obligations and enforce our Terms of Service
3. Data Storage and Security
Your data is stored using industry-standard security measures:
Encryption: All data in transit is encrypted using TLS 1.3. Sensitive credentials (API keys, passwords) are encrypted at rest using AES-256
Authentication: Password-based authentication with HMAC-SHA256 cookie verification and device-based session management
Infrastructure: Hosted on Cloudflare Pages with edge protection, PostgreSQL database with automatic backups, Redis caching, and Temporal workflow orchestration
Access Control: Strict role-based access controls (RBAC) and zero-trust architecture for internal systems
Self-Hosted Storage: Media files are stored on your self-hosted 9Drive instance with optional zero-password SSO handoff via SHA-256 tickets
4. Third-Party Integrations
Our platform integrates with third-party social media platforms (Facebook, Instagram, Twitter, LinkedIn, TikTok, YouTube, Pinterest, Reddit, etc.). When you connect these services:
We request only the minimum necessary permissions to perform scheduled posting, analytics retrieval, and content management
Your social media credentials are never stored in plaintext and are encrypted using platform-provided OAuth 2.0 tokens
We do NOT sell, rent, or share your social media credentials with any third parties
Each platform's own Privacy Policy governs data collected directly by them
5. Data Retention and Deletion
We retain your information as long as your account is active or as needed to provide services. You may request account deletion at any time, which will:
Permanently delete your account data, scheduled posts, and media files within 30 days
Revoke all connected social media integrations and delete stored API tokens
Remove analytics history and usage logs after a 90-day retention period for legal compliance
Retain minimal transaction records for accounting and legal purposes as required by law
6. Cookies and Tracking
We use cookies and similar technologies to:
Maintain secure authentication sessions via HMAC-signed cookies with 1-year expiration
Store user preferences, UI settings, and language preferences
Analyze platform usage via anonymized analytics (we do NOT use third-party advertising trackers)
Enable Cloudflare edge protection and DDoS mitigation
You can disable cookies in your browser settings, but this may limit platform functionality.
7. Your Privacy Rights
Depending on your jurisdiction (GDPR, CCPA, etc.), you may have the following rights:
Access: Request a copy of all personal data we hold about you
Correction: Update or correct inaccurate account information
Deletion: Request permanent deletion of your account and associated data
Data Portability: Export your scheduled posts, media files, and analytics in machine-readable formats (JSON, CSV)
Objection: Opt out of automated decision-making and AI-powered content generation
Withdrawal of Consent: Revoke social media integration permissions at any time
To exercise any of these rights, contact us at the email below.
8. Children's Privacy (COPPA/GDPR Compliance)
Our platform is NOT intended for users under 18 years of age. We do not knowingly collect, store, or process personal information from children under 13 (COPPA) or 16 (GDPR).
Age Verification: Account registration requires users to confirm they are 18+ or have parental/guardian consent
Immediate Deletion: If we discover an account belongs to a minor, we will suspend it immediately and delete all associated data within 72 hours
Parental Rights: If you believe a child has provided us with personal information without consent, contact us at shaytaanfreefire@gmail.com with proof of guardianship, and we will investigate and delete the data
9. International Data Transfers
Your data may be transferred to and processed in countries outside your residence. We ensure adequate safeguards through:
Standard Contractual Clauses (SCCs): Approved by the European Commission for GDPR compliance
Data Processing Agreements (DPAs): Signed with all service providers handling EU/EEA user data
Cloudflare Global Network: GDPR-compliant edge infrastructure with ISO 27001 certification
Cross-Border Data Protection: Adherence to Privacy Shield successor frameworks and local data protection laws
10. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
Right to Know: Request disclosure of categories and specific pieces of personal information collected in the past 12 months
Right to Delete: Request deletion of personal information collected from you
Right to Opt-Out: Opt out of the "sale" of personal information (note: we do NOT sell user data)
Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights
How to Exercise CCPA Rights: Email shaytaanfreefire@gmail.com with "CCPA Request" in the subject line. We will respond within 45 days.
11. European Users (GDPR)
If you are located in the European Economic Area (EEA), UK, or Switzerland, you have rights under the General Data Protection Regulation (GDPR):
Legal Basis for Processing: We process your data based on consent (social media integrations), contract fulfillment (service provision), and legitimate interests (platform security, fraud prevention)
Supervisory Authority: You have the right to lodge a complaint with your local data protection authority if you believe your rights have been violated
Automated Decision-Making: Our AI content generation features are NOT used for profiling or automated decisions that significantly affect you
12. Data Breach Notification
In the event of a data breach affecting your personal information, we will:
Notify affected users via email within 72 hours of discovery (GDPR requirement)
Provide details on the nature of the breach, data affected, and steps we are taking to mitigate harm
Report to relevant data protection authorities as required by law
Offer credit monitoring services if financial or identity theft risk exists
13. Do Not Track (DNT) Signals
Our platform does NOT respond to "Do Not Track" browser signals. However, we do NOT use third-party advertising trackers or sell user data to data brokers.
14. Changes to This Policy
We may update this Privacy Policy to reflect changes in legal requirements, business practices, or platform features. Changes will be posted on this page with an updated "Last Updated" date. Material changes will be communicated via email notification. Continued use of our services after changes constitutes acceptance of the revised policy.