Privacy Policy

Last updated: · Applies to cometpost.app, the cometpost application, and the cometpost API and MCP server.

1. Who we are

cometpost is a social media scheduling and cross-posting service operated by Cometpost LLC, a Washington limited liability company (“cometpost”, “we”, “us”). For the purposes of the EU and UK General Data Protection Regulation, we are the data controller for the personal data described in this policy.

For privacy questions, requests or complaints, contact privacy@cometpost.app. We answer privacy enquiries within 30 days.

This policy is specific to cometpost and describes what the product actually does. It is not a generic template. cometpost is currently in development. This website collects nothing at all from visitors — there is no account, no form and no tracking, as set out in section 14. The rest of this policy describes how the service handles data once it launches and you use it.

2. Summary

  • We collect what is needed to publish the posts you schedule — and not more.
  • From each connected platform we take your profile identifier, display name and avatar so you can tell which account is connected, plus permission to publish what you scheduled.
  • We do not read your private messages, do not scrape your followers, and do not request or use data beyond the scopes you granted.
  • We do not sell your data, share it with data brokers, use it for advertising or profiling, or use your content to train machine-learning models.
  • You can export or delete everything at any time. Deleting your account deletes your data.

3. What data we collect

3.1 Account details

Your email address, and a name or display name if you give one. If you sign in with a third-party identity provider, we receive the email address and basic profile information that provider returns. We store a hash of your password if you set one; we never store passwords in plain text, and we never see or store the password of any social media account.

3.2 Authentication tokens for connected social accounts

When you connect a social media account, that platform issues cometpost an access token (and usually a refresh token). We store these encrypted, together with the identifier of the account they belong to, their scopes and their expiry. They are used only to publish on your instruction and to keep the connection alive.

3.3 Content you upload or compose

Text, captions, titles, descriptions, hashtags, links, images, video and audio that you upload to or write in cometpost, including drafts you never publish, and per-platform variants of them.

3.4 Scheduling and publishing metadata

Which accounts a post is destined for, the scheduled time and time zone, the status of each publication attempt, the identifier the platform returned for a published post, and any error the platform returned when an attempt failed.

3.5 Usage and diagnostic data

Basic technical information generated when you use the service: IP address, browser or client user agent, timestamps, the pages or API endpoints requested, and error and performance logs. This is used to operate, secure and debug the service.

3.6 Billing data

If and when paid plans exist, our payment processor collects and processes your payment details. We receive only the information needed to manage your subscription — for example, the plan, the billing status, the country, and the last four digits and brand of the card. We never receive or store full card numbers.

3.7 Support correspondence

If you email us, we keep the message and our reply so we can handle the request and follow up.

4. What we access from each connected platform, and why

Every connection is made through the platform's own OAuth authorisation screen, which shows you exactly what you are granting before you grant it. We request the narrowest permissions that make publishing work. Two things are common to every platform:

  • Profile identifiers, display name and avatar — so the interface can show you which account is connected and you do not publish to the wrong one. We store the account identifier, the handle or display name, and the avatar URL.
  • Permission to publish content you authored and scheduled — used only at the moment a post you scheduled is due, and only to the accounts you selected for that post.

Per platform, specifically:

Platform What we access Why
TikTok Basic profile (open ID, display name, avatar); creator posting information such as the privacy options and interaction settings available to your account; permission to upload and publish video content. To show which TikTok account is connected, to present the posting options TikTok allows your account, and to publish the video you scheduled.
YouTube (Google) Your YouTube channel identifier and channel title; permission to upload a video and set its title, description, tags, thumbnail and visibility. To show which channel is connected and to upload and publish the video you scheduled. We do not access your Gmail, Drive, Contacts, or any other Google service.
Instagram (Meta) The Instagram professional account you select, its identifier, username and profile picture; permission to create and publish media (images, carousels, Reels) to that account. To identify the account and publish the post you scheduled. We do not read your direct messages and do not retrieve your follower list.
Threads (Meta) Your Threads profile identifier, username and profile picture; permission to publish posts. To identify the account and publish the post you scheduled.
Facebook Pages (Meta) The list of Pages you manage and the Page you select — its identifier, name and picture — and a Page access token; permission to publish content to that Page. To let you pick the right Page, show it in the interface, and publish the post you scheduled. We do not access your personal Facebook profile beyond what is needed to determine which Pages you manage, and we do not read your messages.
X Your X account identifier, username and profile picture; permission to create posts and upload media. To identify the account and publish the post you scheduled. We do not read your direct messages and do not collect your followers.

To state it plainly, on every platform:

  • cometpost does not read your private or direct messages.
  • cometpost does not download, scrape or store your followers, friends or contacts.
  • cometpost does not read your feed, your saved items or other people's content.
  • cometpost does not access, request or use any data beyond what the permissions you granted require in order to publish what you scheduled.
  • cometpost does not post anything you did not create and schedule.

Where a platform returns metrics for a post cometpost published (for example, whether the upload succeeded, or basic post status), we use that only to show you the outcome of your own post.

5. How we use data

We use personal data solely to provide, secure and support the scheduling and publishing service you signed up for. Specifically:

  • to create and administer your account and authenticate you;
  • to store your drafts and scheduled posts and show them back to you;
  • to transmit your content to the platforms you connected and selected, at the time you chose;
  • to report the outcome of each publication attempt, including platform errors;
  • to keep the service secure — detecting and preventing abuse, spam, fraud and unauthorised access, and enforcing our terms;
  • to diagnose faults and improve reliability and performance;
  • to process payments and manage subscriptions, if you have a paid plan;
  • to reply to your support and privacy requests;
  • to send service messages you need to receive, such as a failed-publish notification, a security alert, or a change to these policies; and
  • to comply with legal obligations.

We do not run a mailing list. We send marketing email only where you have explicitly opted in, and every such email has an unsubscribe link.

6. What we never do

These are commitments, not aspirations:

  • We do not sell or license your personal data to anyone, for any purpose. We have never done so and we do not intend to.
  • We do not share your data with data brokers, list vendors, or any party that aggregates or resells personal information.
  • We do not use your data for advertising, ad targeting, or behavioural profiling, and we do not run third-party advertising or tracking code.
  • We do not use your content to train machine-learning or AI models, our own or anyone else's, and we do not permit our sub-processors to do so.
  • We do not use platform data for anything other than the feature you granted it for.

If this ever changes, it would be a material change to this policy, and we would notify you in advance under section 18 — and where consent is required, we would ask for it rather than assume it.

Where the EU or UK GDPR applies, we rely on the following legal bases:

PurposeLegal basis
Providing the service, including publishing your postsPerformance of a contract (Art. 6(1)(b))
Connecting a social account and using the granted scopesPerformance of a contract, and your consent given at the platform's authorisation screen (Art. 6(1)(a)/(b))
Security, abuse prevention, diagnosticsLegitimate interests in operating a secure service (Art. 6(1)(f))
Billing and financial recordsContract and legal obligation (Art. 6(1)(b)/(c))
Replying to an email you sent usLegitimate interests in answering enquiries (Art. 6(1)(f))
Responding to legal requestsLegal obligation (Art. 6(1)(c))

8. Sub-processors and sharing

We share personal data only with the categories of recipient below, only as needed, and under contracts that require them to protect it and to process it only on our instructions.

CategoryWhat they receivePurpose
Hosting and edge network Request data including IP address; application data at rest Running the website, application and API
Database and object storage Account data, encrypted tokens, content you upload Storing your data
Payment processing Your payment and billing details, collected directly by the processor Taking payment for paid plans, when those exist
Transactional email Your email address and the message content Sending account and security email
Error and performance monitoring Diagnostic logs, which may include an account identifier and IP address Detecting and fixing faults
The social platforms you connect The content and metadata of the post you scheduled for that platform Publishing your post — this is the point of the service

A current, named list of sub-processors is available on request from privacy@cometpost.app, and we will publish it here when the service launches.

We may also disclose data:

  • when required by law, a court order, or a valid legal request — we will notify you unless legally prohibited;
  • to establish, exercise or defend legal claims, or to protect the rights, safety or property of cometpost, our users or the public; and
  • in a merger, acquisition or sale of assets, in which case we will notify you before your data becomes subject to a different privacy policy, and the acquirer will be bound by commitments no weaker than those in section 6.

Content you publish becomes visible according to the settings of the platform you published it to, and is then governed by that platform's own privacy policy.

9. Google API Services Limited Use

cometpost's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Concretely, for data obtained through Google and YouTube APIs:

  • we use it only to provide and improve the user-facing features that the user granted access for — identifying the connected YouTube channel and uploading and publishing the videos the user scheduled;
  • we do not transfer it to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition, and in each case with user consent where required;
  • we do not use it for serving advertisements of any kind;
  • we do not allow humans to read it, unless we have the user's affirmative agreement for specific messages, it is necessary for security purposes such as investigating abuse, to comply with applicable law, or the data has been aggregated and anonymised; and
  • we do not use it to develop, improve or train generalised or non-personalised AI or machine-learning models.

Use of YouTube features is also subject to the YouTube Terms of Service and the Google Privacy Policy. You can revoke cometpost's access to your Google account at any time via Google security settings.

10. Security

  • In transit: all traffic to and from cometpost uses HTTPS with TLS. We do not accept unencrypted connections.
  • At rest: databases and object storage are encrypted at rest by our infrastructure providers.
  • OAuth tokens: access and refresh tokens for your connected social accounts are additionally encrypted at the application layer before being written to the database, with keys held separately from the data and not in source control.
  • Passwords: stored only as salted hashes using a modern password-hashing function, never in plain text or reversible form.
  • Access control: access to production data is limited to people who need it to operate the service, requires multi-factor authentication, and is logged.
  • Minimisation: we request the narrowest platform scopes that let the feature work, and we do not log request bodies containing your content or tokens.

No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant supervisory authority as required by law and without undue delay. To report a vulnerability, email security@cometpost.app.

11. Retention and deletion

DataKept for
Account detailsWhile your account exists
OAuth tokens for connected accountsUntil you disconnect that account, the token is revoked, or your account is deleted — whichever comes first
Drafts, scheduled posts and uploaded mediaWhile your account exists, or until you delete them
Publishing history and status logsUp to 24 months, then deleted or aggregated so it no longer identifies you
Diagnostic and security logsUp to 90 days
Billing and tax recordsAs long as tax and accounting law requires, typically 7 years
Support correspondenceUp to 24 months after the request is closed
Email you send usUp to 24 months after the exchange ends

When you delete your account:

  • your account record, drafts, scheduled posts, uploaded media and connected-account tokens are deleted from live systems within 30 days;
  • pending scheduled posts are cancelled immediately and will not be published;
  • we ask each connected platform to revoke the tokens we hold, and you can also revoke them yourself — see the data deletion page;
  • encrypted backups are rotated out within a further 60 days, after which no copy remains; and
  • we keep only what law requires, such as billing records, and anonymised aggregate counts that cannot identify you.

Deleting your cometpost account does not remove posts that were already published to a platform. Those live on that platform and must be deleted there.

12. Your rights

Wherever you live, you can ask us to do the following, free of charge, by emailing privacy@cometpost.app:

  • Access — get a copy of the personal data we hold about you.
  • Export — receive it in a portable, machine-readable format.
  • Correct — fix data that is inaccurate or incomplete.
  • Delete — erase your account and associated data.
  • Restrict or object — limit or object to processing based on legitimate interests.
  • Withdraw consent — for anything based on consent, with no effect on processing already carried out.

We respond within 30 days. We will ask you to verify your identity — normally by replying from the email address on the account — and we will not treat you differently for exercising a right.

EU/UK residents. You have the right to lodge a complaint with your local data protection supervisory authority. We would appreciate the chance to address your concern first.

California residents. Under the CCPA/CPRA you have the right to know what personal information is collected, used and disclosed; to delete it; to correct it; and to opt out of its sale or sharing. We do not sell or share personal information as those terms are defined by the CCPA, and we do not use or disclose sensitive personal information for purposes beyond those permitted, so there is no opt-out to exercise. You may use an authorised agent to make a request, and we will not discriminate against you for making one.

Washington residents. Requests under the Washington My Health My Data Act can be sent to the same address. cometpost does not collect consumer health data.

13. Disconnecting a social account

You can disconnect any connected account at any time from within cometpost, or from that platform's own connected-apps settings. Either way:

  • the tokens we hold for that account stop working and are deleted from live systems;
  • scheduled posts targeting that account are cancelled and will not be published; and
  • the profile information we cached for that account — identifier, display name, avatar URL — is deleted.

Revoking access does not delete posts that were already published, and does not delete your cometpost account. Step-by-step revocation links for each platform are on the data deletion page.

14. This website

cometpost.app collects nothing about you. It is a set of static pages. There is no account, no sign-up, no mailing list and no form of any kind — so there is nothing for us to store about a visit.

It sets no cookies and runs no analytics, advertising or tracking scripts. There is no tracking pixel, no social widget, no embedded video and no content loaded from a third-party CDN — the fonts are the ones already on your device and every image is served from this domain. That is why there is no cookie banner: there is nothing to consent to.

If you email one of the addresses on this site, we receive your address and your message, and use them only to answer you (see sections 3.7 and 11).

Our hosting provider, Cloudflare, processes standard request logs, including IP addresses, to deliver the site and protect it from attack.

The cometpost application, when it launches, will use a strictly necessary session cookie to keep you signed in. If we ever add analytics, it will be privacy-preserving and disclosed here before it is switched on.

15. International transfers

cometpost is operated from the United States and uses infrastructure providers that operate globally, so your data may be processed in the United States and other countries. Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), together with additional technical measures such as encryption in transit and at rest.

When you publish to a social platform, your content is transmitted to that platform's own infrastructure, wherever it is located.

16. Children

cometpost is not directed at children. It is intended for people aged 18 or over, and we do not knowingly collect personal data from anyone under 13 — or under 16 in jurisdictions where that is the applicable age of digital consent. If you believe a child has provided us with personal data, email privacy@cometpost.app and we will delete it promptly.

17. Changes to this policy

We may update this policy. The current version always lives at https://cometpost.app/privacy and the “last updated” date at the top reflects the most recent change.

For material changes — anything that expands how we use your data or who receives it — we will notify you at least 30 days in advance by email and in the application, and we will obtain your consent where the law requires it.

18. Contact

Cometpost LLC, a Washington limited liability company.

A postal address for formal notices is available on request from legal@cometpost.app.