Privacy Policy
This policy describes what data Hashipost collects, why we collect it, and the controls you have over it. We've written it to be readable — not just legally compliant.
Last updated: May 20, 2025
Overview
Hashipost ("we," "our," or "us") operates hashipost.com — a social media scheduling platform that lets you plan and publish content to YouTube, Instagram, and TikTok from one dashboard.
This Privacy Policy explains how we handle personal data when you use our service. By creating an account, you agree to the collection and use of your information as described here.
Key points at a glance
- We collect only what is necessary to operate the service.
- We never sell your personal data or your social media content to third parties.
- Social media access tokens are encrypted at rest and only used to publish on your behalf.
- You can delete your account and all associated data at any time.
- We use a small number of trusted sub-processors (Clerk, Stripe, Cloudflare, Sentry) to run the service.
Information We Collect
Account information
When you sign up we collect your name, email address, and — if you use Google Sign-In — your Google profile picture. This information is managed by Clerk, our authentication provider.
Profile information
You can create named profiles inside your account (e.g., "Pizza Hut" or "ViralToys"). For each profile you may optionally upload a profile image.
Social media account tokens
When you connect a YouTube, Instagram, or TikTok account, we receive and store OAuth 2.0 access and refresh tokens. These tokens are:
- Encrypted at rest using AES-256-GCM before being written to our database.
- Only decrypted in memory at the moment they are needed to publish a post.
- Never shared with third parties or exposed in any API response.
- Automatically refreshed in the background before expiry.
- Permanently deleted from our systems when you disconnect an account.
Content you create
We store the captions, hashtags, scheduled times, and media files (images and videos) you upload while composing posts. Orphaned uploads are automatically deleted after 24 hours.
Billing information
Payment processing is handled entirely by Stripe. We do not store your credit card number, CVV, or bank details. We retain your Stripe Customer ID and subscription status to manage your tier.
Usage and technical data
- Browser type, operating system, and device type.
- IP address (used for rate limiting and security monitoring).
- Pages visited and actions taken within the app (via privacy-friendly analytics tools).
- Error reports and performance traces via Sentry.
How We Use Your Information
- To create and manage your account and authenticate your identity.
- To connect your social media accounts and publish content on your behalf at your chosen scheduled time.
- To send you transactional emails — post publish confirmations, failure alerts, and billing receipts.
- To enforce subscription tier limits and process payments.
- To respond to support requests you submit through the app.
- To detect, prevent, and investigate fraud, abuse, and security incidents.
- To monitor service health, diagnose errors, and improve reliability.
- To comply with applicable laws and respond to lawful requests from public authorities.
We do not use your content, captions, or social media account data for advertising, machine learning training, or any purpose beyond operating the service as described.
Data Retention
- Account data is retained for as long as your account is active.
- If you delete your account, all personal data is permanently deleted within 30 days.
- Media files are deleted when the associated post is deleted, or when your account is deleted.
- Orphaned uploads (never attached to a post) are deleted after 24 hours.
- Billing records are retained for up to 7 years where required by financial regulations.
- Anonymized aggregate analytics data may be retained indefinitely.
- Audit logs for admin actions are retained for 2 years.
Security
- All data in transit is encrypted via TLS 1.2+.
- OAuth tokens are encrypted at rest using AES-256-GCM with keys stored separately from the database.
- Access to production systems is restricted by role and requires two-factor authentication.
- Dependencies are scanned for known vulnerabilities on every deployment.
- Rate limiting is applied to all API endpoints to prevent brute force and abuse.
To report a security vulnerability, please email security@hashipost.com.
Your Rights
Depending on your location, you may have the following rights. To exercise any of them, contact us at privacy@hashipost.com.
Access
Request a copy of the personal data we hold about you.
Rectification
Ask us to correct inaccurate or incomplete data.
Erasure
Request deletion of your account and all associated data.
Portability
Receive your data in a machine-readable format.
Restriction
Ask us to pause processing of your data in certain circumstances.
Objection
Object to processing based on legitimate interests.
Withdraw consent
Disconnect any connected social account at any time.
Complaints
Lodge a complaint with your local data protection authority.
We will respond to all requests within 30 days.
Children's Privacy
Hashipost is not directed at children under the age of 13 (or 16 in the European Economic Area). If you believe a child has provided us with personal data, please contact us at privacy@hashipost.com and we will delete it promptly.
International Transfers
Hashipost is operated globally and your data may be processed in countries other than your own — including the United States — where data protection laws may differ.
Where we transfer personal data from the EEA, UK, or Switzerland to countries without an adequacy decision, we rely on Standard Contractual Clauses or equivalent mechanisms.
Social Platform Data & OAuth
Hashipost integrates with YouTube (Google), Instagram (Meta), and TikTok via their official OAuth 2.0 APIs.
Permissions we request
YouTube (Google)
youtube.upload— to upload videos to your channel as Shorts. We do not access your private videos, watch history, subscriptions, or any other YouTube data.Instagram (Meta)
instagram_basic, instagram_content_publish, pages_show_list— to publish Posts, Reels, and Stories. We do not read your messages, followers, or personal feed.TikTok
video.upload, video.publish, user.info.basic— to upload and publish videos. We do not access your messages, followers, or TikTok analytics.How we use platform data
Revoking access
You can disconnect any social account at any time from your account settings. When disconnected, we revoke the token at the platform level and permanently delete all stored tokens for that account.
YouTube API Services
Hashipost's use of YouTube API Services is subject to the YouTube Terms of Service and Google Privacy Policy. You can manage or revoke access at Google Security Settings.