Legal
Privacy Policy
How PostEngine collects, uses, and protects your information.
Last updated: June 1, 2025
Welcome to PostEngine ("we", "us", or "our"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered social media automation platform. By accessing or using PostEngine, you agree to this Privacy Policy.
1. Information We Collect
- Account Information: Name, email address, phone number, and profile information provided during registration.
- Business Profile Data: Business name, category, address, services, brand colors, Google Places data, and product/offer details.
- Facebook & Instagram Data: Pages, profiles, and permissions you explicitly grant through Meta's OAuth system.
- Content Data: AI-generated posters, captions, scheduled posts, and content plan data.
- Usage Data: Log data, IP addresses, device info, and platform interactions.
- Payment Data: Billing details processed via PhonePe — we do not store full card or UPI credentials.
2. Facebook & Instagram Login Permissions
PostEngine uses Meta's official Login API to connect your accounts. During the OAuth flow, we request only the permissions necessary for posting:
pages_manage_posts – Create and publish posts on your Facebook Pages.
pages_read_engagement – Read basic engagement metrics.
instagram_basic – Access your Instagram Business account.
instagram_content_publish – Publish photos, videos, and carousels to Instagram.
pages_show_list – List which Facebook Pages you manage.
You can revoke permissions anytime via Facebook App Settings .
3. OAuth Authentication
- We never see or store your Facebook or Instagram password.
- You authorize PostEngine through Meta's secure login dialog using OAuth 2.0.
- Meta issues a time-limited access token we use to publish on your behalf.
- You can revoke access at any time through your Meta account settings or via our Data Deletion page.
4. Access Token Storage
- All access tokens encrypted with AES-256 at rest.
- Transmitted exclusively over HTTPS (TLS 1.2+).
- Stored in isolated, role-based access-controlled environments.
- Tokens are deleted immediately upon disconnection or account deletion.
5. Scheduled Posting & AI Generation
By using PostEngine's automation features, you authorize us to:
- Store your business profile, offers, and content plan data to generate AI posters and captions.
- Pass anonymized business data to OpenAI (GPT-4o-mini, DALL-E) for content generation.
- Auto-publish to your connected social accounts at the scheduled time.
- Retry failed publications up to 5 times with exponential backoff.
You retain full ownership of all content. We never use it for advertising.
6. User Privacy Protection
- End-to-end HTTPS encryption for all data in transit.
- AES-256 encryption for all sensitive data at rest.
- Role-based access controls — only authorized personnel can access user data.
- JWT access tokens + device-based refresh tokens with account lockout after 5 failed attempts.
- We do not sell your data. No third-party advertising integrations.
7. Data Deletion Rights
You have the right to request permanent deletion of all your data at any time. Visit our dedicated page for full instructions:
Go to Data Deletion Page
We will process your request within 30 days and confirm deletion via email.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or in-app notification. Continued use of PostEngine after the effective date constitutes acceptance.
Contact Us
Questions about this Privacy Policy or your data?