Privacy Policy
Last updated: 1 September 2026
Postroz is a social media publishing scheduler. It publishes video content that you own to social media accounts that you own and have authorised. This policy explains what data Postroz handles, why, and how you can remove it.
1. Information we collect
- Account authorisation data. When you connect an Instagram, TikTok or Facebook account, the platform issues Postroz an access token. We store that token and your account's public identifier, username and display name, so that we can publish on your behalf.
- Content you upload. The video files, captions and hashtags you add to your library.
- Publishing records. When each post was scheduled and published, the resulting post link, and any error returned by the platform.
- Operational logs. Technical logs needed to run and debug the service.
2. How we use it
- To build your publishing plan and publish your content at the times you chose.
- To show you the status of scheduled and published posts.
- To notify you when a post succeeds or fails, or when an authorisation is about to expire.
- To keep the service secure and to diagnose faults.
We do not use your content or data for advertising, we do not sell it, and we do not use it to train models.
3. Sharing with platforms
To publish a post, Postroz sends your content and caption to the platform you selected, using that platform's official publishing API. This is the only routine sharing of your data with a third party, and it happens only for accounts you connected yourself. Each platform's own privacy policy then applies to the published content: Instagram and Facebook (Meta Platforms), TikTok (TikTok Pte. Ltd.). We may also disclose data where legally required.
4. Storage and retention
- Data is stored on servers rented and controlled by the operator of Postroz.
- Access tokens are encrypted at rest and used only to call the platform on your behalf.
- Uploaded videos are retained while they remain in your library so they can be published on schedule.
- Publishing records are retained so you have a history of what was posted.
5. Deleting your data
- Disconnect an account in Postroz, or revoke access from the platform's own settings, and Postroz stops publishing to it and discards its token.
- Delete a video from your library to remove the stored file.
- Delete everything by contacting us at the address below.
Content already published to a social platform lives on that platform and must be deleted there.
6. Security
Access is restricted to authorised operators. Traffic is encrypted in transit with TLS, secrets are stored outside of source code, and tokens are encrypted at rest. No system is perfectly secure, but we take measures appropriate to the data we hold.
7. Children
Postroz is a business tool and is not directed at children. We do not knowingly collect data from anyone under 13, or under the minimum age required by the platform being connected.
8. Changes
If this policy changes materially we will update the date above and, where appropriate, notify connected users.
9. Contact
Questions, or a request to delete your data: support@postroz.com