Skip to content
WePost
  • Features
  • Pricing
  • Developers
Log in Request early access
  • Features
  • Pricing
  • Developers
  • Log in
Request early access
Legal

Privacy Policy

This policy explains what information WePost collects, why, how we protect it, how long we keep it, and the choices you have. It includes the specific data we access from each social platform you connect.

Last updated: September 27, 2026

Contents

  1. Who we are
  2. Scope of this policy
  3. Information we collect
  4. How we use information
  5. Connected platforms
  6. YouTube and Google
  7. Instagram, Facebook and Threads
  8. TikTok
  9. LinkedIn, Pinterest, X and Bluesky
  10. How we share information
  11. Service providers
  12. Cookies and tracking
  13. How we protect information
  14. Data retention
  15. International transfers
  16. Your rights and choices
  17. Children
  18. Changes to this policy
  19. Contact us

1. Who we are

WePost (“WePost”, “we”, “us” or “our”) provides the WePost social media publishing and scheduling service at wepo.st and its subdomains (the “Service”).

WePost lets creators, brands, agencies and teams connect their social media accounts, compose posts, schedule them, and publish them to those accounts through each platform’s official application programming interface (API). For questions about this policy or your data, email privacy@wepo.st.

2. Scope of this policy

This policy applies to:

  • our website at wepo.st;
  • the WePost web application at app.wepo.st;
  • connect links, which let an account owner connect a social account to a workspace without creating a WePost login;
  • the WePost API, webhooks and MCP server; and
  • emails and other communications between you and us.

For information about you and your WePost account, we act as the data controller. When a customer uses WePost to manage content or accounts on behalf of someone else (for example, an agency managing a client’s accounts), the customer decides what content is uploaded and published, and we process that content on the customer’s behalf and according to their instructions. If your account was connected to a customer’s workspace through a connect link, you can also contact that customer directly about how they use it.

Social platforms you connect (such as Instagram, TikTok or YouTube) have their own privacy policies, which govern how they handle your information. We link to them below.

3. Information we collect

3.1 Account information

When you create a WePost account or are invited to a workspace, we collect your name, email address, password (stored only as a salted hash) or sign-in method, passkey and two-factor authentication settings, time zone, and your role in each workspace. If you sign in with Google, we receive your name, email address and profile picture from Google for sign-in only.

3.2 Workspace content

Content you create in the Service: workspaces and their settings, posts, captions, per-platform settings, schedules and posting slots, drafts, approvals, account groups, comments on drafts, API keys (stored only as hashes), webhook endpoints and an audit log of actions taken in the workspace.

3.3 Connected social accounts

When you or an account owner connects a social account, the platform asks for permission on its own sign-in page. We never see or store your social media passwords. With your permission, we receive and store:

  • Basic profile information needed to identify the account in your workspace, such as the account ID, username or handle, display name, profile picture and account type;
  • OAuth access and refresh tokens that let us publish on your behalf, together with the permissions (scopes) you granted and their expiry dates;
  • Publishing settings the platform provides, such as the privacy options available to a TikTok creator, your Pinterest boards, or the Facebook Pages you manage; and
  • Records of posts published through WePost: the platform’s post or media ID, its permalink, its publishing status, and any error the platform returned.

We do not access or store your private or direct messages, your followers’ or subscribers’ personal information, your contacts, or content you did not publish through WePost. The exact data for each platform is described in section 5.

3.4 Media you upload

Images and videos you upload or import from a URL, along with technical metadata we read from the files (such as format, dimensions, duration and codecs), thumbnails we generate, tags you add, and whether you marked the media as AI-generated. To publish, we may create platform-compatible copies of your media (“renditions”) and make them available at an unguessable address on media.wepo.st so that the platform can download them.

3.5 Usage and log data

When you use the Service, our systems record technical information such as IP address, browser and device type, pages and API endpoints requested, timestamps, request identifiers, and error details. We use it to operate, secure and debug the Service and to enforce rate limits. We also count usage (such as posts per account per day) to respect each platform’s limits.

3.6 Communications

When you email us, request early access or contact support, we keep your message, your email address and any details you choose to share, so we can respond and keep a record of the conversation.

3.7 Payment information

WePost is free during early access and we do not collect payment information. If paid plans launch, payments will be handled by a payment processor, and we will update this policy before collecting any billing details.

4. How we use information

We use information only to provide and improve the Service, specifically to:

  • create and secure your account and workspaces, and authenticate you and your API keys;
  • connect your social accounts and keep those connections working, including refreshing tokens and checking account health;
  • validate, schedule and publish the posts you create, to the accounts you choose, at the times you choose;
  • show you the status of each post, and notify you about failures, approvals and accounts that need reconnecting;
  • prepare your media in the formats each platform accepts;
  • apply the platform disclosure labels you request, such as labels for AI-generated content;
  • respond to support requests and send service messages (such as security alerts or changes to these terms);
  • detect, prevent and investigate abuse, fraud, spam and security incidents, and enforce our Terms of Service; and
  • comply with legal obligations and platform policies.

We do not sell your personal information, use it or data obtained from platform APIs for advertising, build advertising profiles, or use your content or platform data to train artificial intelligence or machine-learning models. Our staff do not read your content or platform data, except when you ask us to help with a specific issue, when needed to investigate security incidents or abuse, or when required by law.

Legal bases (EEA, UK and similar laws)

  • Contract: to provide the Service you asked for, including publishing to your connected accounts.
  • Consent: when you connect a social account and grant permissions. You can withdraw consent at any time by disconnecting the account or revoking access at the platform.
  • Legitimate interests: to secure and improve the Service, prevent abuse, and answer enquiries, balanced against your rights.
  • Legal obligation: where we must keep or disclose information by law.

5. Connected platforms: what we access and why

WePost connects to each platform only through its official API and sign-in (OAuth). We request only the permissions needed for the publishing features you use. We use the data below solely to publish your content, show you its status, and keep your connection working. Disconnecting an account in WePost deletes its stored tokens and, where the platform supports it, revokes our access at the platform. You can also revoke access directly in each platform’s settings.

6. YouTube and Google

WePost uses YouTube API Services. By connecting a YouTube channel to WePost, you agree to be bound by the YouTube Terms of Service. Google’s handling of your information is described in the Google Privacy Policy.

  • What we access: your channel ID, channel title and thumbnail (so you can see which channel a post will go to), and the ability to upload videos and set their title, description, visibility, made-for-kids status, altered or synthetic content disclosure and scheduled publish time. We also read the processing and publishing status of videos uploaded through WePost.
  • What we do not access: your watch history, subscriptions, comments, private messages, or videos you did not upload through WePost (other than confirming the status of our own uploads).
  • How we use and share it: only to upload and publish the videos you schedule, show you their status and link, and keep your connection working. We do not sell YouTube data or share it with third parties, except the service providers in section 11 that host our systems for us.
  • Storage and refresh: stored YouTube API data (such as channel details) is refreshed or deleted at least every 30 days.
  • Deletion: we delete your YouTube data within 7 days of your deletion request, and within 30 days after you revoke WePost’s access or disconnect the channel.
  • Revoking access: disconnect the channel in WePost, which revokes our token at Google, or revoke WePost’s access at any time from your Google Account’s security settings at https://security.google.com/settings/security/permissions.

WePost’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. If you use Google sign-in, we use your Google name, email address and profile picture only to sign you in.

7. Instagram, Facebook Pages and Threads (Meta)

Instagram

For Instagram professional (business or creator) accounts, we access your Instagram account ID, username, profile picture and account type, and the permission to publish content (feed posts, Reels, Stories and carousels) to your account. We read the status, ID and permalink of media we publish, and your current publishing limit usage, so we can confirm publication and warn you before you reach Instagram’s daily limit. When you mark content as AI-generated, we pass Instagram’s AI label with the post.

Facebook Pages

We access the list of Facebook Pages you choose to grant us, their IDs, names and pictures, and a Page access token, so you can publish posts, videos, Reels and Stories to those Pages. We read the status and permalink of posts we publish. Where Meta requires it for Pages owned by a business portfolio, we access the related business so that we can reach those Pages.

Threads

We access your Threads user ID, username and profile picture, and the permission to publish posts to your profile. We read your publishing limit usage and the status and permalink of posts we publish.

Removing access and deleting data

You can disconnect an account in WePost at any time, or remove WePost from your Facebook, Instagram or Threads settings (Apps and Websites / Business Integrations). When Meta tells us that you removed WePost or requested deletion, we delete the related tokens and data. Instructions and the status of deletion requests are at https://wepo.st/data-deletion. See also the Meta Privacy Policy.

8. TikTok

WePost uses TikTok’s Login Kit and Content Posting API to post to your TikTok account. With your permission we access your TikTok open ID, display name and avatar, and, each time you prepare a post, your current creator settings (such as which privacy options you can choose, whether comments, duets and stitches are available, and your maximum video length) so the composer shows only valid options. We upload the video or photos you choose, with the caption, privacy level, interaction settings and disclosures you select, either directly to your profile or to your TikTok inbox as a draft. We store the publish ID and status TikTok returns. We do not access your messages, followers, likes or viewing activity. WePost never adds watermarks or its own branding to your content. See the TikTok Privacy Policy. You can remove WePost’s access in the TikTok app under Settings and privacy, Security, Apps and services permissions.

9. LinkedIn, Pinterest, X and Bluesky

LinkedIn

We access your LinkedIn member ID, name and profile picture (and your email address if LinkedIn provides it, used only to identify the connection), and the permission to create posts on your profile. If you connect a company page, we access the pages you administer (their IDs, names and logos) and the permission to post on their behalf. We read the status of posts and media we publish. We do not access your connections, messages or feed. See the LinkedIn Privacy Policy.

Pinterest

We access your Pinterest username, profile image and account type, and the list of your boards so you can choose where a Pin goes, plus the permission to create Pins. We store the IDs and links of Pins we create. See the Pinterest Privacy Policy.

X

We access your X user ID, username, display name and profile image, and the permissions to upload media and create posts on your behalf. We read the posts we create to confirm they were published. We do not access your direct messages, likes, bookmarks or followers. See the X Privacy Policy.

Bluesky

We connect through the AT Protocol’s OAuth sign-in. We access your decentralized identifier (DID), handle, display name and avatar, and the permission to create posts and upload images and video to your account. Posts on Bluesky are public by design. See the Bluesky Privacy Policy.

10. How we share information

We share information only in these situations:

  • With the platforms you publish to. When you schedule a post, we send the content, media and settings you chose to that platform at the scheduled time. Once published, the content is governed by that platform’s terms.
  • Within your workspace. Members of a workspace can see the workspace’s connected accounts (but never their tokens), media, posts and activity, according to their role.
  • With your integrations. If you or your workspace create API keys or webhooks, the data you request or subscribe to is sent to those systems.
  • With service providers who host and operate the Service for us, under contracts that limit their use of the data to providing services to us (see section 11).
  • For legal reasons, when we believe in good faith that disclosure is required by law, a valid legal process, or to protect the rights, safety or property of our users, the public or WePost.
  • In a business transfer, such as a merger or acquisition, where the recipient must continue to protect your information as described in this policy. We will notify you before your information becomes subject to a different privacy policy.
  • With your consent or at your direction.

We do not sell personal information and do not share it for cross-context behavioral advertising.

11. Service providers (subprocessors)

Service providers that process data for WePost
ProviderPurposeData involved
Cloudflare, Inc. Website hosting, content delivery network, DNS, security and DDoS protection, media storage (R2), email routing Website requests, media files and renditions, emails sent to our addresses
Our cloud infrastructure provider Servers that run the WePost application, API, database and publishing workers All Service data, encrypted in transit; tokens additionally encrypted at rest
Email delivery provider Sending account and notification emails Your email address and the message content
Error monitoring provider Diagnosing errors in the Service Technical error details with tokens and credentials removed

We update this list before a new provider begins processing personal data. For the current names of our providers, email privacy@wepo.st.

12. Cookies and tracking

Our website at wepo.st does not set cookies and does not use analytics, advertising pixels or other third-party tracking. The WePost web application uses only strictly necessary cookies and browser storage to keep you signed in, protect your session and remember interface preferences. We do not allow third parties to serve advertising or place advertising cookies through the Service. Our content delivery provider, Cloudflare, may occasionally set a strictly necessary security cookie to protect the site from automated attacks.

13. How we protect information

  • All connections to the Service use HTTPS (TLS).
  • OAuth tokens are encrypted at rest with AES-256-GCM using managed, rotatable keys. They are decrypted only by the services that publish on your behalf, are never returned by our API, and are removed from logs and error reports.
  • API keys and passwords are stored only as one-way hashes.
  • We request the minimum platform permissions our features need.
  • Access to production systems is limited to authorized personnel, protected by two-factor authentication and logged.
  • Every workspace is isolated from every other, and we test that isolation automatically.
  • Backups are encrypted.

No system is perfectly secure. If we become aware of a breach that affects your personal information, we will notify you and the relevant authorities as required by law. See our Security page for more.

14. Data retention

We keep information only as long as we need it for the purposes above:

How long WePost keeps each type of data
DataHow long we keep it
OAuth tokensUntil you disconnect the account, the platform revokes access, or the workspace is deleted. Tokens are then deleted immediately.
Connected account profile dataWhile the account is connected, refreshed regularly. Deleted within 30 days after disconnection (YouTube: see section 6).
Published media copies (renditions)Deleted automatically 7 days after they are created.
Original media you uploadAccording to your workspace’s media retention setting, until you delete it, or until the workspace is deleted.
Posts, schedules and workspace contentUntil you delete them or the workspace, then deleted within 30 days.
Account informationWhile your account is open, then deleted within 30 days after you delete your account.
Application logsUp to 30 days.
Security and audit logsUp to 12 months.
BackupsEncrypted backups expire on a rolling basis within 30 days. Deleted data is not restored from backups for use.
Support and early-access emailsAs long as needed to handle your request, and no longer than 2 years after the conversation ends.

We may keep information longer where the law requires it, for example to resolve disputes or meet tax obligations.

15. International transfers

We and our service providers may process information in countries other than the one you live in, including the United States, the European Union and Israel. The European Commission recognizes Israel as providing an adequate level of data protection. Where the law requires it, we protect transfers with appropriate safeguards, such as the European Commission’s Standard Contractual Clauses or the UK International Data Transfer Addendum.

16. Your rights and choices

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you and receive a copy;
  • Correct inaccurate or incomplete information;
  • Delete your information;
  • Port your information to another service in a structured, machine-readable format;
  • Object to or restrict certain processing, including processing based on legitimate interests;
  • Withdraw consent at any time, for example by disconnecting a social account, without affecting earlier processing; and
  • Complain to your local data protection authority.

California and other US state residents also have the right to know what personal information we collect, use and disclose, to request its deletion or correction, and not to be discriminated against for exercising these rights. We do not sell or share personal information for cross-context behavioral advertising, and we do not use sensitive personal information to infer characteristics about you.

You can manage most of your information directly in the app: edit your profile, disconnect accounts, delete media and posts, or delete a workspace. To exercise any right, email privacy@wepo.st. We may need to verify your identity before acting, and we respond within 30 days. You may use an authorized agent, who must show that you authorized them. See Data Deletion for step-by-step deletion instructions.

17. Children

WePost is not directed to children under 16, and we do not knowingly collect personal information from them. You must be at least 16, and old enough to use each platform you connect, to use WePost. If you believe a child has provided us with personal information, contact privacy@wepo.st and we will delete it.

18. Changes to this policy

We may update this policy as the Service changes. We will post the new version here and update the “Last updated” date. If a change is material, we will notify account owners by email or in the app before it takes effect.

19. Contact us

For privacy questions or requests, email privacy@wepo.st. For security issues, email security@wepo.st.

WePost

Post everywhere from one place. Schedule and publish to every major social platform, with a clear status for every post.

Early access: request an invite

Product

  • Features
  • Pricing
  • Developers
  • Log in

Company

  • Contact
  • Security
  • support@wepo.st

Legal

  • Privacy Policy
  • Terms of Service
  • Data Deletion

© 2026 WePost. All rights reserved.

Instagram, TikTok, YouTube, Facebook, Threads, LinkedIn, Pinterest, Bluesky and X are trademarks of their respective owners. WePost is an independent product and is not affiliated with, endorsed or sponsored by them.