Privacy Policy
Last updated: August 21, 2026
This Privacy Policy describes how AutoPost Studio (“AutoPost”, “we”, “us”), operated by Husin in Indonesia, handles information when you use the application at the AutoPost Studio website.
1. Who we are
AutoPost Studio is a content management and scheduling tool. It is not a social network. Contact: hsnlee69@gmail.com.
2. Information we collect
- Account data: email and authentication details needed to sign in to AutoPost.
- Connected platform accounts: identifiers such as account or channel name, platform user IDs, granted OAuth scopes, and token expiry metadata after you authorize a connection.
- OAuth tokens: access and refresh tokens stored only on the server in encrypted form. Tokens are not sent to the browser and are not intentionally written to logs.
- User media and post data: files you upload, captions, titles, hashtags, destination URLs, board selections (for Pinterest), schedules, and publish status records you create in the app.
- Operational logs: limited diagnostic events about scheduling and publish attempts (without secrets or signed media URLs).
3. How we use information
We use the information above only to:
- Authenticate you and operate your private AutoPost workspace.
- Complete official OAuth flows and maintain connections you authorize to platforms such as YouTube, TikTok, Instagram, Facebook, Threads, and Pinterest.
- Store and deliver your media as needed to schedule and publish content you request through official platform APIs.
- Show status in Dashboard, Calendar, and History.
- Respond to support, privacy, and deletion requests.
We do not sell users' personal data. We do not sell OAuth credentials. We do not use connected-account credentials for unrelated advertising or profiling.
4. OAuth and token security
Platform connections use each provider’s official OAuth. Callback handling validates signed state and a short-lived HttpOnly nonce cookie. Encrypted tokens are read and written only by server-side components. You may disconnect an account at any time; we attempt remote revocation when supported, then remove local credentials.
5. Media and scheduling
Media you upload remains under your control for the purpose of scheduling and publishing your own content. Retention may follow product settings (for example automatic cleanup after a post reaches a terminal state unless you choose to keep media). Signed delivery URLs used to hand media to platform APIs are generated server-side and are not intended for public browsing.
6. Sharing
We share data with platform providers only as required to perform actions you authorize (for example creating a Pin you scheduled). Infrastructure providers that host the app and storage may process data under our instructions. We do not operate AutoPost as a public social graph that shares your posts with other AutoPost users.
7. Retention and deletion
We retain account, connection, and post records as needed to operate the service and respond to your requests, subject to any legal obligations. To request deletion of your AutoPost account data, email hsnlee69@gmail.com from the email associated with your account. We will verify ownership before processing.
You can also disconnect individual platform accounts inside the app to revoke AutoPost’s access and clear stored tokens for that connection.
8. Changes
We may update this policy from time to time. The “Last updated” date at the top will change when we do. Continued use of AutoPost after an update means you acknowledge the revised policy.
9. Contact
Operator: Husin (Indonesia)
Email: hsnlee69@gmail.com
See also the Terms of Service.