Privacy policy

This policy describes the data used by the hosted Postslot service.

Who runs Postslot

Gain Ovuta, operating as an individual trading as Postslot, reachable at [email protected].

What Postslot stores

Authentication and service providers

For accounts using Supabase sign-in, Supabase processes the email address and password used to authenticate and stores account identity and workspace membership. Postslot does not store those passwords; it stores encrypted session tokens. Existing local-login accounts use password hashes on the Postslot server.

DigitalOcean hosts the application, uploaded media and scheduler data on our United States server. Supabase provides authentication and the identity database; this project's primary region is Ireland (eu-west-1). Cloudflare provides domain, DNS and email-routing services. Our pages also load web fonts from Google Fonts, which receives browser connection information when fonts are requested.

What Postslot does not do

Social network data

When you connect an account, the network's API gives Postslot an access token. Postslot uses it for the scopes you approved: publishing, reading your own posts' metrics, and reading notifications. You can revoke access at any time in the network's settings or by removing the channel in Postslot, which deletes the stored token.

Data deletion

Remove a channel to delete its tokens and inbox items. Delete a post to remove it from Postslot (this does not delete it from the network). To delete everything, the operator deletes the data directory. See data deletion instructions.

Retention

Data stays until deleted by a team member or the operator. Rolling backups keep the last 30 snapshots.

Last updated: 5 September 2026