Effective 10 August 2026 · postpipe.dev
Postpipe is a social media publishing tool. You connect your own social media accounts, and Postpipe publishes the posts you compose to those accounts on your behalf. This policy describes exactly what we store to do that, how it is protected, and how to get rid of it.
Postpipe is operated by Frames Engineering, Inc., a Delaware corporation and the data controller for the information described here.
Registered office: 131 Continental Dr, Suite 305, Newark, DE 19713, United States.
For any privacy question, or to request deletion of your data, contact privacy@postpipe.dev.
We only collect what the service needs to function. We do not buy data about you, we do not run advertising, and we do not use tracking or analytics cookies.
When you connect a social media account, the platform gives us an access token scoped to the permissions you approved. We store:
We request the minimum scopes needed to publish. We do not read your timeline, your followers, your direct messages, or your analytics.
If you create API keys, we store only a SHA-256 hash of the key plus a short non-secret prefix so you can identify it in the list. If you configure webhooks, we store the destination URL and an encrypted signing secret, plus a record of delivery attempts.
Our servers record request metadata — timestamp, path, method, a request ID, and your workspace ID — for debugging and abuse prevention. Your IP address is used for rate limiting and is not stored in a durable profile about you.
| Purpose | Data used |
|---|---|
| Publishing your posts | Post content, media, connected account tokens |
| Signing you in | Email, password hash, session digest |
| Showing status and history | Publication records, audit events |
| Keeping connections alive | Refresh tokens, expiry timestamps |
| Preventing abuse | IP address, request counters |
| Service email | Email address |
We do not sell your personal data. We do not share it with advertisers. We do not use your content to train machine learning models.
This is the core of the service: when you publish, we send that post's text and media to the platforms you selected, using the access token you granted. Instagram, Threads and TikTok photo posts work by the platform fetching your media from a temporary signed URL on our servers; that URL expires shortly after publishing. Once content reaches a platform, that platform's own privacy policy and terms govern it.
Postpipe runs entirely on Cloudflare — Workers for compute, D1 for the database, R2 for media storage, and Queues for background jobs. Cloudflare processes this data as our infrastructure provider. We do not use any other third-party processor, analytics service, or advertising network.
We will disclose data if legally compelled to, and to protect the rights or safety of our users or the service.
No system is perfectly secure. If you find a vulnerability, please report it to privacy@postpipe.dev rather than disclosing it publicly.
You can delete most things yourself from the dashboard, at any time:
To delete your entire account, email privacy@postpipe.dev from the address you signed up with. We will erase your account, workspace, connected account tokens, posts, media and publication history within 30 days and confirm when it is done.
You can also revoke Postpipe's access directly from any social platform's own settings, which immediately invalidates the token we hold.
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict its processing, and to complain to your local data protection authority. Email privacy@postpipe.dev and we will respond within 30 days. We will not charge you or degrade your service for exercising these rights.
Frames Engineering, Inc. is based in the United States, and Postpipe runs on Cloudflare's global network, so your data is processed in the United States and may be processed in other countries. If you are in the European Economic Area or the United Kingdom, this means your data is transferred outside your region; we rely on Standard Contractual Clauses and the safeguards Cloudflare maintains for those transfers.
Postpipe is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child has created an account, contact us and we will remove it.
We set one cookie: pp_session, which keeps you signed in. It is HttpOnly, Secure and SameSite=Lax. There are no advertising, analytics or third-party tracking cookies.
If we change this policy materially, we will update the effective date above and email registered users before the change takes effect.