Privacy policy
This policy describes the data used by the hosted Postslot service.
Who runs Postslot
Gain Ovuta, operating as an individual trading as Postslot, reachable at [email protected].
What Postslot stores
- Posts you write, their schedule, tags, notes, and the links to where they were published.
- Media you upload, on this server's disk.
- Access tokens for the social accounts you connect, encrypted at rest. They are used only to publish what you schedule, read engagement numbers for your own posts, and show replies and mentions addressed to your accounts.
- Team member names, roles, and password hashes.
- Replies, mentions, likes and follows on your connected accounts, so you can answer them from one inbox.
Authentication and service providers
For accounts using Supabase sign-in, Supabase processes the email address and password used to authenticate and stores account identity and workspace membership. Postslot does not store those passwords; it stores encrypted session tokens. Existing local-login accounts use password hashes on the Postslot server.
DigitalOcean hosts the application, uploaded media and scheduler data on our United States server. Supabase provides authentication and the identity database; this project's primary region is Ireland (eu-west-1). Cloudflare provides domain, DNS and email-routing services. Our pages also load web fonts from Google Fonts, which receives browser connection information when fonts are requested.
What Postslot does not do
- Postslot does not sell personal data or use it for advertising.
- We share data with the service providers described above as needed to operate Postslot, with the social networks you connect, with the AI provider if the assistant is enabled (the content you ask it to process), and with notification or webhook destinations you configure.
Social network data
When you connect an account, the network's API gives Postslot an access token. Postslot uses it for the scopes you approved: publishing, reading your own posts' metrics, and reading notifications. You can revoke access at any time in the network's settings or by removing the channel in Postslot, which deletes the stored token.
Data deletion
Remove a channel to delete its tokens and inbox items. Delete a post to remove it from Postslot (this does not delete it from the network). To delete everything, the operator deletes the data directory. See data deletion instructions.
Retention
Data stays until deleted by a team member or the operator. Rolling backups keep the last 30 snapshots.
Last updated: 5 September 2026