1. Who we are
PostStage (“PostStage”, “we”, “us”, “our”) is a social media scheduling and publishing application available at trypoststage.com. We are based in India and our service is available to customers worldwide, without geographic restriction.
This Privacy Policy explains what personal data we collect, how we use it — including data we receive through the official APIs of Meta (Facebook, Instagram, Threads), Google (YouTube, Google Business Profile), X (formerly Twitter), TikTok, Pinterest, LinkedIn, Bluesky, Tumblr, Mastodon, Telegram, Discord, WordPress (both WordPress.com and WordPress sites you host yourself), and Dev.to, and of Canva, which we use only as a source of artwork you import — and the choices and rights you have. It applies to every visitor, registered user, and connected social account on PostStage.
If you have questions about this policy or wish to exercise any of the rights described below, contact our Privacy / Grievance Officer at info@trypoststage.com.
2. Information we collect
2.1 Information you provide directly
- Account details: name, email address, password (stored as a salted hash, never in plain text), and profile image.
- Optional profile fields: Instagram handle entered at signup (kept for reference/display only — it is not used for API authentication), and your preferred timezone.
- Content you create or upload: post captions, hashtags, hashtag groups, templates, drafts, and media files (images/videos) you schedule or publish through PostStage.
- Billing details you enter at checkout, processed directly by our payment processor (see Section 5).
- Communications you send us — support tickets (including replies you send by email), feedback, live-chat messages, demo bookings, and enquiry-form submissions.
- Text you give the AI Caption Generator or caption-fitting tools — your brief, draft caption, tone and target platform (see Section 3.2).
- Team details: the name and email address of anyone you invite to your workspace, their role, and the approvals, comments and changes they make.
2.2 Information collected automatically
- Login/session metadata: IP address and user-agent captured at signup for anti-abuse review, and session/authentication cookies needed to keep you signed in.
- Usage data: pages viewed, features used, posting activity, and error/diagnostic logs, used to operate and improve the service.
- Google reCAPTCHA signals on certain forms, used purely for bot/abuse prevention.
- Browser push subscription details, only if you turn on push notifications, so we can deliver them through your browser's push service.
- Approximate country, derived from your IP address by our hosting provider, used only to decide which cookie-consent rules apply to you. We do not store precise location.
- Advertising measurement — only with your consent (or, outside the EEA, UK and Switzerland, unless you opt out; see Section 7). We use Google Tag Manager, the Meta Pixel, the Meta Conversions API and the Google Ads tag to measure whether our own ads lead to signups. These may record the ad-click identifier you arrived with, pages you visit on our website, and your browser and device type. When you create an account, we send Meta a CompleteRegistration event containing your email address (irreversibly hashed with SHA-256 before it leaves our servers — never sent in plain text), your IP address and your browser's user-agent string. No content you create, and no data from your connected social accounts, is ever shared for advertising.
2.3 Information from connected social media accounts
When you connect a social account, PostStage uses that platform's official OAuth flow. You are shown the platform's own consent screen and you control exactly what is authorized. We request only the permissions (“scopes”) needed to schedule, publish, and report on your content — nothing more. Per platform:
| Platform | Scopes requested | What we use it for |
|---|---|---|
| Facebook Pages (Meta) | pages_show_list, pages_manage_posts, pages_read_engagement, pages_manage_engagement, business_management, public_profile | List Pages you administer (directly or via a Business Portfolio), publish posts/photos to a Page you select, and read basic engagement metrics on your own posts. |
| Instagram (Meta) | instagram_business_basic, instagram_business_content_publish, instagram_business_manage_comments | Identify your connected Instagram Business/Creator account, publish posts/Reels/carousels you schedule, and manage the auto first-comment feature (if you enable it). |
| Threads (Meta) | threads_basic, threads_content_publish | Identify your Threads profile and publish posts you schedule. |
| X (Twitter) | tweet.read, users.read, tweet.write, offline.access | Identify your X profile, publish posts you schedule, and refresh your access token in the background (offline.access) so you don't have to reconnect every two hours. |
| YouTube (Google) | youtube.upload, youtube.readonly | Upload videos/Shorts you schedule to your channel and read basic channel/video information needed to confirm a successful upload. |
| Google Business Profile | business.manage | List the business locations you manage and publish Business Profile posts/updates you schedule to a location you select. |
| boards:read, boards:write, pins:read, pins:write, user_accounts:read | List your boards, create/schedule Pins to a board you select, and read your basic Pinterest account info. | |
| openid, profile, w_member_social | Identify your LinkedIn profile and publish posts you schedule as you. | |
| TikTok | user.info.basic, video.publish, video.upload | Identify your TikTok creator profile (display name and avatar) and publish videos you schedule to your TikTok account. |
| Tumblr | basic, write, offline_access | Identify your Tumblr blog and publish text, photo, and video posts you schedule to your blog. offline_access lets us refresh your token in the background so you don't need to reconnect periodically. |
| Mastodon | read, write | Identify your Mastodon account on your chosen instance and publish posts you schedule. Because Mastodon is federated, the OAuth app is registered on your specific instance at the time you connect. |
| WordPress.com | global | List the blogs on your WordPress.com account and publish the posts you schedule — title, body, featured image, categories and tags — to the blog you choose.global is the only scope WordPress.com's REST API accepts for publishing: its narrower posts scope is refused with “Required scope: global”, so asking for less is not something the API permits. WordPress.com is operated by Automattic Inc. |
| WordPress (self-hosted) | Application Password — no OAuth scopes | Publish the posts you schedule to your own WordPress site, and read the site's existing categories and tags so you can pick them in the composer. Unlike every other row in this table, no third-party company is involved — see the callout below. |
| Canva | profile:read, design:meta:read, design:content:read, design:content:write, folder:read | Canva is a content source, not a posting destination — PostStage never publishes anything to Canva. These permissions let us show your account name, list your designs so you can pick one, export a design you choose, and create a new blank design at the right size when you use “Design in Canva”. folder:read lets us list the contents of folders you can already see, because designs owned by a Canva Team don't appear in your personal design list otherwise. We read a design only when you explicitly import it; we never scan or copy your Canva library in the background, and we never create, move or delete anything in your folders. |
| Google Drive | drive.file, openid, email, profile | Google Drive is a content source, not a posting destination — PostStage never uploads to, changes or deletes anything in your Drive. drive.file is the narrowest Drive permission Google offers: it grants access only to the individual files you pick in Google's own file chooser. We cannot list, search or read the rest of your Drive, and we deliberately did not request the permission that would allow it. When you pick a file we copy it once into PostStage's own storage so it can be attached to a post; nothing is read in the background. The identity permissions are used only to show which Google account is connected. |
For each connected account we store: the platform's account/page/channel/board ID, username or display name, profile picture URL, account type, and the OAuth access token (and refresh token, where the platform issues one). Tokens are encrypted at rest and are used solely to publish the content you schedule and to display basic account status inside your PostStage dashboard. We do not read your DMs, private messages, contacts, or any content other platforms also let people see publicly unless that data is required to perform the publishing action you requested.
bsky.app/settings/app-passwords — independently of disconnecting it in PostStage. We store your handle, DID (Bluesky's permanent account identifier), the session tokens, and the post content/images you schedule — nothing more.2.4 Payment information
Subscription payments are processed by Razorpay, a PCI-DSS compliant payment gateway. PostStage does not collect or store your full card number, CVV, or UPI PIN — Razorpay handles that directly. We retain only the transaction reference, plan, billing cycle, amount, and GST details needed for invoicing and accounting under Indian tax law.
2.5 Information about other people
Using PostStage you may handle personal data about other people — comments, mentions and direct messages from your audience shown in the Inbox, team members you invite, or people who appear in your content. For that data you (or the business you work for) are the controller and PostStage processes it on your instructions, only to provide the Service. You are responsible for having a lawful basis to handle it and for telling those people about it where the law requires. Business customers who need a Data Processing Addendum can request one at info@trypoststage.com.
3. How we use your information
- To provide the core service: scheduling, queuing, and publishing your content to the platforms you connect, at the time you choose.
- To authenticate you, maintain your session, and protect your account (fraud/abuse detection, signup review).
- To process payments, issue receipts, and manage your subscription.
- To send transactional emails and in-app notifications you've opted into (post failures, channel/connection updates, post confirmations, billing) — each is individually toggleable in Settings.
- To provide customer support and respond to enquiries.
- To maintain, debug, and improve PostStage's reliability and features.
- To generate AI caption suggestions when you ask for them (Section 3.2).
- To measure our own advertising campaigns, where you have allowed advertising cookies (Section 7).
- To comply with legal obligations, including tax, accounting, and law-enforcement requests.
- To establish, exercise or defend legal claims and enforce our Terms.
We do not sell your personal data for money. We do not show ads inside PostStage, and we never use your content or your connected-account data for advertising or to build advertising profiles.
3.1 Legal bases (EEA, UK and Switzerland)
- Contract — running your account, publishing your posts, billing, AI features you request, and support.
- Legitimate interests — security, fraud and abuse prevention, signup review, debugging, and improving the Service. You can object to this processing at any time.
- Consent — advertising cookies and measurement, optional notifications, and the permissions you grant each connected platform. You can withdraw consent at any time without affecting processing that happened before.
- Legal obligation — tax, accounting and invoicing records, and responding to lawful requests from authorities.
3.2 AI features
The AI Caption Generator and caption-fitting tools are powered by Anthropic (Claude models). When you use them, we send Anthropic only the text needed for that request: your brief or draft caption, the tone you chose and the target platform. We do not send your media, your password, your connected-account tokens, or data we receive from social platform APIs.
- Your inputs and the captions generated are not used to train AI models, by us or by Anthropic. Anthropic processes them under its commercial terms and may keep them only for a limited period for trust-and-safety purposes.
- AI features are optional. Nothing is sent to Anthropic unless you click a generate or fit action.
- AI output can be wrong or inappropriate. Always review it before you publish.
4. Platform API data — Limited Use & policy compliance
Where PostStage accesses data through a third-party platform's API, our use of that data is limited to providing or improving the user-facing features you request (publishing, scheduling, and basic status/analytics for your own content), and is governed by that platform's developer policy in addition to this Privacy Policy:
- Meta Platform Terms & Developer Policies (Facebook, Instagram, Threads)
- Google API Services User Data Policy, including its Limited Use requirements (YouTube, Google Business Profile)
- X Developer Agreement and Policy
- TikTok Developer Terms of Service and Platform Guidelines
- Pinterest Developer Terms
- LinkedIn API Terms of Use
- Tumblr API License Agreement
- Mastodon API terms (as set by the specific instance you connect)
- Telegram Bot API Terms of Service
- Discord Developer Terms of Service and Developer Policy
- WordPress.com REST API terms (Automattic). A WordPress site you host yourself has no third-party developer policy behind it — the software is open source and the server is yours.
- Forem / DEV Community API terms (Dev.to)
- Canva Developer Terms and Canva Connect API terms
4.1 YouTube API Services (Google)
PostStage uses YouTube API Services to provide its YouTube features (connecting your channel and uploading/scheduling videos). By using these features you also agree to the YouTube Terms of Service, and Google's handling of your information is described in the Google Privacy Policy.
What we store, and for how long. When you connect a YouTube channel we store, in our database: your channel ID, channel title, handle, and channel thumbnail URL, plus the OAuth access and refresh tokens Google issues (encrypted at rest). When you schedule a video we also store the title, description, privacy setting, and the video file until it is uploaded. Stored channel information is refreshed from the YouTube API at least every 24 hours (and in any event within 30 days) so it never goes stale, and is updated or removed if it can no longer be refreshed.
Deleting your stored YouTube data. You can delete the data PostStage has stored from the YouTube API at any time, in any of these ways:
- Disconnect the channel from the Accounts page — this immediately deletes the stored access/refresh tokens and clears the cached channel data, and we also ask Google to revoke the grant on their side.
- Delete your PostStage account (see our Data Deletion Instructions) — all connected-account data, including YouTube data, is deleted with it.
- Email info@trypoststage.com and we will delete it for you.
Revoking access on Google's side. Independently of PostStage, you can revoke PostStage's access to your YouTube/Google data at any time from the Google security settings page at myaccount.google.com/connections. Once revoked, our stored tokens stop working, and the cached channel data is removed when the next refresh fails.
4.2 TikTok API Services
PostStage uses TikTok API Services to provide its TikTok features (connecting your creator account and publishing videos you schedule). By using these features you also agree to TikTok's Terms of Service and Privacy Policy. Our use of TikTok API data is limited to: identifying your TikTok creator profile and publishing the video content you explicitly schedule through PostStage. We do not access your TikTok messages, followers list, or any data beyond what is necessary to perform the publishing action you requested.
Revoking access. You can disconnect your TikTok account at any time from the Accounts page in PostStage, which immediately deletes the stored access token on our side. You can also revoke PostStage's access directly from your TikTok account settings under “Manage app permissions”.
5. Who we share information with
We use a small number of trusted service providers (“subprocessors”) to run PostStage. They process data only on our instructions and are not permitted to use it for their own purposes.
- Vercel — application hosting and object/blob storage for uploaded media.
- Neon / Vercel Postgres — primary database (account, post, and scheduling data).
- Razorpay — payment processing (India).
- Zoho ZeptoMail — transactional email delivery (account, billing, and post notifications).
- Upstash (QStash) — background job scheduling that triggers your posts to publish at the exact time you set.
- Google reCAPTCHA — bot/abuse protection on public forms.
- tawk.to — live chat support. Receives the messages you send us in the chat window, and — when you are signed in — your name and email address, so we can identify your account and answer you properly.
- Anthropic — AI caption generation, only for text you submit to the AI tools (Section 3.2).
- Mailgun — receives email replies you send to support tickets so they can be attached to the ticket.
- Browser push services (operated by your browser vendor, e.g. Google, Mozilla, Apple, Microsoft) — deliver push notifications, only if you turn them on.
- The social platforms themselves — when you schedule a post, the content you authored is sent to that platform's API at publish time, exactly as if you had posted it yourself.
- Your own WordPress server, for a self-hosted site you connect — your post is sent directly to the address you gave us. This is listed for completeness, not as a subprocessor: that server is operated by you, not by a provider we have engaged.
Advertising partners. Where advertising cookies are allowed (Section 7), Google (Tag Manager and Google Ads) and Meta (Pixel and Conversions API) receive the measurement data described in Section 2.2. They act as independent controllers under their own privacy policies, and may use it to measure and improve ad delivery. They receive nothing if you reject advertising cookies or your browser sends a Global Privacy Control signal.
We may also disclose information if required by law, to enforce our Terms of Service, to protect the rights/safety of PostStage or our users, or in connection with a merger, acquisition, or sale of assets (with notice to you).
6. Data storage, security & retention
- All traffic to PostStage is encrypted in transit (HTTPS/TLS).
- Social platform access and refresh tokens are encrypted at rest.
- A WordPress Application Password is encrypted a second time, with AES-256-GCM at the application layer, because unlike an OAuth token the credential itself has to be stored and replayed on every publish.
- Passwords are stored as salted hashes — we never store or have access to your plaintext password.
- Access to production data is restricted to authorized PostStage personnel on a need-to-know basis.
- When you disconnect a social account, its access tokens are deleted from our systems immediately; historical post records for that account are kept for your own reference unless you request their deletion.
- We retain account data for as long as your account is active. If you delete your account (Section 8 and our Data Deletion page), we delete your personal data and connected-account tokens, except billing/invoice records, which Indian tax law requires us to retain for up to 8 years.
- Backups are rotated and purged on a routine schedule; deleted data is removed from backups within a reasonable period as part of that cycle.
How long we keep each kind of data:
- Account, content, team and connected-account data — while your account exists. Deleted within 30 days of a verified account-deletion request.
- Support tickets, chat and feedback — while your account exists, so we can see the history of an issue. Deleted with your account.
- Signup IP address and user-agent — while your account exists, for abuse prevention.
- Billing and invoice records — up to 8 years, as required by Indian tax law, even after account deletion.
- Your cookie-consent choice — about 6 months in your browser, after which we ask again.
- Data needed for a legal claim or investigation — for as long as that claim or investigation lasts.
Media retention (images and videos)
- Published media is kept for 3 months. The image and video files you upload are stored for 3 months after the post they belong to is published, then deleted automatically from our storage. This is a storage-cost measure and applies to all plans.
- Your published posts are unaffected. Once a post is published, the destination platform (Instagram, Facebook, LinkedIn, X, and so on) holds its own copy of the media, and that copy governs what your audience sees. Deleting our copy does not remove, alter or unpublish anything on the platform.
- Your post records are kept. Captions, hashtags, scheduling history, publish status, platform links and engagement metrics are retained for as long as your account is active. Only the stored media file is removed; where it was displayed in PostStage, we show a note saying it was removed under this policy.
- Unpublished media is never removed on this schedule. Media attached to drafts, scheduled posts, posts awaiting approval, and posts that failed to publish is retained regardless of the age of the upload, because you may still need it to publish.
- Uploads never attached to a post (for example, a file selected in the composer and then abandoned) may be deleted after 7 days, since they are not reachable in the app.
- Direct-message attachments received in the engagement Inbox are re-hosted by us so the thread history remains readable, and are deleted on the same 3-month schedule. The message text and thread history are kept.
- Keep your own originals. PostStage is a scheduling and publishing tool, not a media archive or backup service. If you need long-term access to your source files, retain your own copies.
No system is 100% secure. If we become aware of a data breach affecting your personal data, we will notify you and the relevant authorities as required by applicable law, including the Data Protection Board of India and CERT-In under Indian law.
8. Your rights & choices
Regardless of where you live, you can at any time:
- Access, correct, or update your account information from Settings.
- Disconnect any connected social account from the Accounts page — this immediately revokes and deletes the stored token.
- Export or request a copy of the personal data we hold about you.
- Request deletion of your account and associated personal data — see our Data Deletion Instructions.
- Opt in or out of individual notification types from Settings → Notifications.
- Withdraw consent for a connected platform at any time by disconnecting it or revoking access directly on that platform's app-permissions page.
- Turn advertising cookies off from Cookie Preferences.
We will not charge you, or treat you differently, for exercising any of these rights.
8.1 India — Digital Personal Data Protection Act, 2023
As an Indian entity, we process personal data consistent with the DPDP Act, 2023. You have the right to a summary of the personal data we process and who we share it with, to correct, complete, update and erase it, to withdraw consent at any time (as easily as you gave it), and to nominate another person to exercise your rights if you die or become incapacitated. Our Grievance Officer for DPDP Act purposes is reachable at info@trypoststage.com; we aim to acknowledge grievances within 7 days and resolve them within 30 days. If you are not satisfied with our response, you may complain to the Data Protection Board of India.
8.2 EEA, UK and Switzerland — GDPR
If you are in the EEA, UK or Switzerland, you have the right to access your personal data, to rectify it, to have it erased, to restrict its processing, to data portability, to object to processing based on legitimate interests (including any direct marketing, which you can always stop), to withdraw consent at any time, and to lodge a complaint with your local data protection authority. Our legal bases are listed in Section 3.1. We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.
8.3 California — CCPA/CPRA
In the last 12 months we have collected these categories of personal information: identifiers (name, email, IP address, account IDs), commercial information (plan and payment records), internet activity (pages and features used), approximate location (country from IP address), and the content you create. Sources, purposes and recipients are described in Sections 2 to 5. We do not collect sensitive personal information for the purpose of inferring characteristics about you.
We do not sell personal information for money. Our advertising cookies and the Meta Conversions API may count as “sharing” for cross-context behavioural advertising under the CPRA. You can opt out at any time from Cookie Preferences, and we honour Global Privacy Control signals as an opt-out. We do not knowingly sell or share the personal information of anyone under 16.
You have the right to know, access, correct and delete your personal information, to opt out of sharing, and not to be discriminated against for using these rights. You may use an authorised agent, who must show us your signed permission. Residents of other US states with similar privacy laws have the same rights, which we honour in the same way.
To exercise any of these rights, email info@trypoststage.com. We may need to verify your identity before fulfilling a request.
9. International data transfers
PostStage is operated from India and uses service providers (including Vercel, Neon, Upstash and Anthropic) that may process data on servers located outside India, including in the United States. By using PostStage, you understand your data may be transferred to and processed in countries with different data protection laws than your own. For personal data from the EEA, UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum and Swiss amendments where needed), adequacy decisions, or our providers' certifications under the EU-US Data Privacy Framework. We do not transfer personal data to any country the Government of India has restricted under the DPDP Act. You can ask us for details of the safeguard that applies.
10. Children's privacy
PostStage is not directed at, and is not intended for use by, anyone under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us personal data, contact us at info@trypoststage.com and we will delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal/regulatory reasons. We will post the revised policy here with an updated effective date, and for material changes we will notify you by email or an in-app notice.
12. Contact us
Questions, requests, or complaints about this Privacy Policy or our data practices can be sent to info@trypoststage.com. We aim to respond within 5 business days.