Privacy Policy

Last updated September 2026

This policy explains what MultiPost Studio (“we”, “the app”) collects when you use it to schedule and publish social media content, why we collect it, and how you can get it back or have it deleted. It covers the app at app.multipoststudio.online and every account created on it.

Who we are

MultiPost Studio is a social media management tool. You connect your own social accounts, create and schedule posts, and we publish them on your behalf at the times you choose. We are the data controller for your account data and the processor for the content you publish through us.

What we collect

  • Account details. Your name, email address, password hash (or Google sign-in identifier), timezone and profile photo if you set one.
  • Content you create. Posts, drafts, captions, media you upload, comments, campaigns, approval decisions and any notes you add.
  • Connected social accounts. Access and refresh tokens for the accounts you connect, your handle and profile identifiers on those platforms, and the metrics those platforms report about the posts we published for you.
  • Billing information. Your plan, billing contact details and invoices. Card and bank details are handled entirely by our payment provider and never reach our servers.
  • Usage and diagnostics. Sign-in times, device and browser information, IP address, and error logs, used to keep the service running and to detect abuse.

Google user data

If you sign in with Google or connect a Google service, the app requests only the scopes it needs for the feature you asked for. It requests no Google data beyond these:

  • Sign-in (email, profile) — to create and identify your MultiPost Studio account. We store your email address, name and profile photo URL.
  • YouTube upload (youtube.upload) — to publish the videos you schedule in MultiPost Studio to the YouTube channel you connected. Used only when a scheduled post reaches its publish time.
  • YouTube channel data (youtube.readonly, youtube.force-ssl) — to show your channel, list the posts we published, and read and reply to comments inside the app.
  • YouTube analytics (yt-analytics.readonly) — to show the views and engagement of your posts in your MultiPost Studio analytics.

We do not use Google user data to train any machine learning model, our own or anyone else’s. We do not sell it and we do not transfer it to third parties for advertising, market research or credit assessment.

Limited Use

MultiPost Studio’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

How we use your data

  • To operate the service: scheduling, publishing to the accounts you connected, and analytics.
  • To show you your own performance data retrieved from the platforms you connected.
  • To generate content when you ask for it. AI features send the text of your prompt and your workspace’s brand context to our AI provider to produce a draft. Your connected-account tokens and Google user data are never sent to an AI provider.
  • To notify you about approvals, failures and account activity.
  • To bill you, to support you, and to detect and prevent abuse.

How your data is stored and protected

  • Social account tokens are encrypted at rest with AES-256-GCM under a dedicated encryption key, separate from the database.
  • Passwords are stored only as salted hashes; we never store them in a readable form.
  • All traffic to and from the app is served over HTTPS.
  • Your data is isolated per workspace, and every request is checked against your role and workspace membership before any record is returned.
  • You can see and revoke your active sessions and devices at any time from Settings → Devices.

Who we share it with

We do not sell personal data. We share it only with the service providers needed to run the product, each acting on our instructions:

  • Hosting and database — our application host and managed Postgres provider, who store your account and content data.
  • Object storage — for the media files you upload.
  • The social platforms you connect — we send them the posts you schedule. Their own privacy policies govern what they do with that content once published.
  • AI provider — receives prompt text and brand context when you use an AI feature.
  • Payment provider — handles card details directly and returns only the subscription status and invoices.
  • Email provider — delivers transactional email such as invitations and alerts.

We may also disclose data where required by law, or to protect the rights and safety of users.

Retention and deletion

We keep your content while your account is active. When you delete your account, your workspaces, posts, media and connected-account tokens are deleted within 30 days, after which they persist only in encrypted backups until those rotate out. Disconnecting a social account deletes its stored tokens immediately.

You can request deletion at any time — see our data deletion instructions.

Your rights

You can access, export, correct or delete your data. Most of this is available directly in the app under Settings; for anything else, email us and we will action it within 30 days. Depending on where you live you may also have the right to object to processing, to restrict it, or to complain to your local data protection authority.

Cookies

We use cookies that are necessary to keep you signed in and to remember your active workspace. See our cookie policy for details.

Children

MultiPost Studio is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.

Changes to this policy

If we change how we use your data we will update this page and change the date at the top. Material changes will also be sent to the email address on your account.

Contact

Questions about this policy, or any request about your data: multipoststudio@gmail.com.