Privacy Policy

This policy describes what data Hashipost collects, why we collect it, and the controls you have over it. We've written it to be readable — not just legally compliant.

Last updated: May 20, 2025

01

Overview

Hashipost ("we," "our," or "us") operates hashipost.com — a social media scheduling platform that lets you plan and publish content to YouTube, Instagram, and TikTok from one dashboard.

This Privacy Policy explains how we handle personal data when you use our service. By creating an account, you agree to the collection and use of your information as described here.

Key points at a glance

  • We collect only what is necessary to operate the service.
  • We never sell your personal data or your social media content to third parties.
  • Social media access tokens are encrypted at rest and only used to publish on your behalf.
  • You can delete your account and all associated data at any time.
  • We use a small number of trusted sub-processors (Clerk, Stripe, Cloudflare, Sentry) to run the service.
02

Information We Collect

Account information

When you sign up we collect your name, email address, and — if you use Google Sign-In — your Google profile picture. This information is managed by Clerk, our authentication provider.

Profile information

You can create named profiles inside your account (e.g., "Pizza Hut" or "ViralToys"). For each profile you may optionally upload a profile image.

Social media account tokens

When you connect a YouTube, Instagram, or TikTok account, we receive and store OAuth 2.0 access and refresh tokens. These tokens are:

  • Encrypted at rest using AES-256-GCM before being written to our database.
  • Only decrypted in memory at the moment they are needed to publish a post.
  • Never shared with third parties or exposed in any API response.
  • Automatically refreshed in the background before expiry.
  • Permanently deleted from our systems when you disconnect an account.

Content you create

We store the captions, hashtags, scheduled times, and media files (images and videos) you upload while composing posts. Orphaned uploads are automatically deleted after 24 hours.

Billing information

Payment processing is handled entirely by Stripe. We do not store your credit card number, CVV, or bank details. We retain your Stripe Customer ID and subscription status to manage your tier.

Usage and technical data

  • Browser type, operating system, and device type.
  • IP address (used for rate limiting and security monitoring).
  • Pages visited and actions taken within the app (via privacy-friendly analytics tools).
  • Error reports and performance traces via Sentry.
03

How We Use Your Information

  • To create and manage your account and authenticate your identity.
  • To connect your social media accounts and publish content on your behalf at your chosen scheduled time.
  • To send you transactional emails — post publish confirmations, failure alerts, and billing receipts.
  • To enforce subscription tier limits and process payments.
  • To respond to support requests you submit through the app.
  • To detect, prevent, and investigate fraud, abuse, and security incidents.
  • To monitor service health, diagnose errors, and improve reliability.
  • To comply with applicable laws and respond to lawful requests from public authorities.

We do not use your content, captions, or social media account data for advertising, machine learning training, or any purpose beyond operating the service as described.

04

Social Platform Data & OAuth

Hashipost integrates with YouTube (Google), Instagram (Meta), and TikTok via their official OAuth 2.0 APIs.

Permissions we request

YouTube (Google)

youtube.upload to upload videos to your channel as Shorts. We do not access your private videos, watch history, subscriptions, or any other YouTube data.

Instagram (Meta)

instagram_basic, instagram_content_publish, pages_show_list to publish Posts, Reels, and Stories. We do not read your messages, followers, or personal feed.

TikTok

video.upload, video.publish, user.info.basic to upload and publish videos. We do not access your messages, followers, or TikTok analytics.

How we use platform data

  • Platform data (your handle, display name, and profile picture) is fetched at connection time and stored to display in the app interface.
  • Access tokens are used only to execute scheduled publishing actions you have explicitly created.
  • We do not scrape, analyze, or resell your social media data.

Revoking access

You can disconnect any social account at any time from your account settings. When disconnected, we revoke the token at the platform level and permanently delete all stored tokens for that account.

YouTube API Services

Hashipost's use of YouTube API Services is subject to the YouTube Terms of Service and Google Privacy Policy. You can manage or revoke access at Google Security Settings.

05

Data Sharing & Third Parties

We do not sell, rent, or trade your personal data. We share limited data with the following sub-processors solely to operate the service:

ProcessorPurposeData shared
ClerkAuthentication & user managementEmail, name, profile picture
StripePayment processingEmail, billing address, subscription status
Cloudflare R2 / S3Media file storageUploaded images and videos
Upstash (Redis)Job queue for schedulingPost IDs and scheduling metadata
Neon (PostgreSQL)Primary databaseAll structured app data
SentryError monitoringError traces, browser type, page URL
Railway / RenderWorker process hostingProcessing environment only
Resend / PostmarkTransactional emailEmail address and notification content

We may also disclose your data where required by law or to protect the rights, property, or safety of Hashipost, our users, or the public.

06

Data Retention

  • Account data is retained for as long as your account is active.
  • If you delete your account, all personal data is permanently deleted within 30 days.
  • Media files are deleted when the associated post is deleted, or when your account is deleted.
  • Orphaned uploads (never attached to a post) are deleted after 24 hours.
  • Billing records are retained for up to 7 years where required by financial regulations.
  • Anonymized aggregate analytics data may be retained indefinitely.
  • Audit logs for admin actions are retained for 2 years.
07

Security

  • All data in transit is encrypted via TLS 1.2+.
  • OAuth tokens are encrypted at rest using AES-256-GCM with keys stored separately from the database.
  • Access to production systems is restricted by role and requires two-factor authentication.
  • Dependencies are scanned for known vulnerabilities on every deployment.
  • Rate limiting is applied to all API endpoints to prevent brute force and abuse.

To report a security vulnerability, please email security@hashipost.com.

08

Your Rights

Depending on your location, you may have the following rights. To exercise any of them, contact us at privacy@hashipost.com.

Access

Request a copy of the personal data we hold about you.

Rectification

Ask us to correct inaccurate or incomplete data.

Erasure

Request deletion of your account and all associated data.

Portability

Receive your data in a machine-readable format.

Restriction

Ask us to pause processing of your data in certain circumstances.

Objection

Object to processing based on legitimate interests.

Withdraw consent

Disconnect any connected social account at any time.

Complaints

Lodge a complaint with your local data protection authority.

We will respond to all requests within 30 days.

09

Children's Privacy

Hashipost is not directed at children under the age of 13 (or 16 in the European Economic Area). If you believe a child has provided us with personal data, please contact us at privacy@hashipost.com and we will delete it promptly.

10

International Transfers

Hashipost is operated globally and your data may be processed in countries other than your own — including the United States — where data protection laws may differ.

Where we transfer personal data from the EEA, UK, or Switzerland to countries without an adequacy decision, we rely on Standard Contractual Clauses or equivalent mechanisms.