Privacy Policy
Last updated: July 15, 2026
SocialPilot ("SocialPilot," "we," "us," or "our") is a tool that lets you connect your own social and publishing accounts — such as Facebook Pages, YouTube channels, and WordPress sites — and create, schedule, and publish content to them from one place. This policy explains what we collect, why, and the choices you have. It applies to our web application and related services (the "Service").
1. Information we collect
We collect only what we need to run the Service:
- Account information. Your email address, name, a securely hashed password, and — if you enable it — two-factor authentication data. We never store your password in plain text.
- Connected-account credentials. When you connect a third-party account (e.g. a Facebook Page, a Google/YouTube channel, or a WordPress site), we store the access tokens that platform issues so we can publish on your behalf. These tokens are encrypted at rest and are only ever used server-side to perform actions you request. We do not receive or store your passwords for those platforms.
- Content you create. The posts, captions, links, images, videos, schedules, and related metadata you submit for publishing or scheduling.
- Basic profile data from connected platforms. For example, the name and picture of a Facebook Page you connect, or the name of a YouTube channel — used to show you which accounts are connected.
- Usage and activity logs.Records of actions taken in the Service (such as "post scheduled") for security, troubleshooting, and audit purposes.
2. How we use your information
- To provide the Service — connecting your accounts and creating, scheduling, and publishing the content you ask us to.
- To authenticate you and keep your account secure (including two-factor authentication).
- To operate, maintain, debug, and improve the Service.
- To communicate with you about your account or important service changes.
- To comply with legal obligations and enforce our terms.
We do not sell your personal information, and we do not use the content of your connected accounts for advertising.
3. Facebook / Meta Platform data
When you connect a Facebook Page, we request only the permissions needed to list your Pages and to publish and schedule posts on Pages you manage. We use Meta's native scheduling: the posts you schedule are submitted to Facebook and held in that Page's own content calendar until their scheduled time. Our use of information received from Meta APIs follows Meta's Platform Terms and Developer Policies. You can revoke our access at any time from your Facebook Business Integrations settings, or by disconnecting the Page inside SocialPilot.
4. How we share information
We share information only with the service providers that make the Service work, and only as needed:
- Publishing platforms you connect (Meta/Facebook, Google/YouTube, WordPress) — to publish the content you direct us to.
- Infrastructure providers — our database host, object storage for media, and application hosting — who process data on our behalf under their own security and privacy commitments.
- Legal and safety — when required by law, or to protect the rights, safety, and security of our users or the Service.
We do not sell or rent your personal information to third parties.
5. Data retention
We keep your information for as long as your account is active or as needed to provide the Service. When you disconnect a platform we delete the stored credentials for it. When you delete your account, we delete or de-identify your personal data and connected-account tokens, except where we must retain limited records to meet legal obligations.
6. Security
We protect your data with industry-standard measures, including encryption in transit (HTTPS) and encryption at rest for sensitive credentials such as OAuth tokens and two-factor secrets. Access to production systems is restricted. No method of transmission or storage is completely secure, but we work to protect your information and to respond promptly to any incident.
7. Your rights and data deletion
You can access, update, or delete your information at any time. Specifically:
- Disconnect a platform. In SocialPilot, open the relevant integration (e.g. Facebook → Pages) and disconnect the account. This removes the stored tokens for it.
- Delete your account. Deleting your account removes your personal data and all connected-account credentials from our systems.
- Request deletion by email. You may also email us at privacy@example.comwith the subject "Data deletion request." We will delete your personal data and connected-account tokens and confirm once complete. There is no charge for this.
Deleting data in SocialPilot does not delete content already published to a third-party platform; you can remove that from within the platform itself. Depending on where you live, you may have additional rights (such as access, correction, portability, or objection) — email us to exercise them.
8. Children's privacy
The Service is not directed to children under 13 (or the minimum age required in your jurisdiction), and we do not knowingly collect their personal information.
9. Changes to this policy
We may update this policy from time to time. When we do, we'll revise the "Last updated" date above and, for significant changes, provide a more prominent notice.
10. Contact us
Questions about this policy or your data? Email us at privacy@example.com.