Postpipepostpipe

Privacy Policy

Effective 10 August 2026 · postpipe.dev

Postpipe is a social media publishing tool. You connect your own social media accounts, and Postpipe publishes the posts you compose to those accounts on your behalf. This policy describes exactly what we store to do that, how it is protected, and how to get rid of it.

Who we are

Postpipe is operated by Frames Engineering, Inc., a Delaware corporation and the data controller for the information described here.

Registered office: 131 Continental Dr, Suite 305, Newark, DE 19713, United States.
For any privacy question, or to request deletion of your data, contact privacy@postpipe.dev.

What we collect

We only collect what the service needs to function. We do not buy data about you, we do not run advertising, and we do not use tracking or analytics cookies.

Account information

  • Email address — your login identity and the only way we can contact you.
  • Name — optional, used to label your workspace.
  • Password — never stored. We store only a PBKDF2-SHA256 hash with a random per-user salt.
  • Sessions — when you sign in we issue a random session token. We store only its SHA-256 digest, so the token itself cannot be recovered from our database. Sessions expire after 30 days.

Connected social accounts

When you connect a social media account, the platform gives us an access token scoped to the permissions you approved. We store:

  • Access and refresh tokens — encrypted at rest with AES-256-GCM. They are decrypted only in memory, at the moment we call the platform's API on your behalf.
  • Account identifiers and profile basics — the platform's account ID, username, display name, avatar URL, and account type, so the dashboard can show you which account you are posting to.
  • Granted scopes and token expiry — so we can refresh tokens before they lapse and tell you when a reconnection is needed.

We request the minimum scopes needed to publish. We do not read your timeline, your followers, your direct messages, or your analytics.

Content you create

  • Post text, links, scheduling times and per-platform overrides you compose in Postpipe.
  • Media you upload — images and videos, stored in Cloudflare R2.
  • Publication records — for each attempt to publish, we keep the outcome, the resulting post ID and URL, and the platform's error response when something fails. This is how retries, status and troubleshooting work.
  • Audit events — a log of significant actions in your workspace, such as connecting or disconnecting an account.

Developer features

If you create API keys, we store only a SHA-256 hash of the key plus a short non-secret prefix so you can identify it in the list. If you configure webhooks, we store the destination URL and an encrypted signing secret, plus a record of delivery attempts.

Technical logs

Our servers record request metadata — timestamp, path, method, a request ID, and your workspace ID — for debugging and abuse prevention. Your IP address is used for rate limiting and is not stored in a durable profile about you.

How your data is used

PurposeData used
Publishing your postsPost content, media, connected account tokens
Signing you inEmail, password hash, session digest
Showing status and historyPublication records, audit events
Keeping connections aliveRefresh tokens, expiry timestamps
Preventing abuseIP address, request counters
Service emailEmail address

We do not sell your personal data. We do not share it with advertisers. We do not use your content to train machine learning models.

Who we share it with

Social media platforms

This is the core of the service: when you publish, we send that post's text and media to the platforms you selected, using the access token you granted. Instagram, Threads and TikTok photo posts work by the platform fetching your media from a temporary signed URL on our servers; that URL expires shortly after publishing. Once content reaches a platform, that platform's own privacy policy and terms govern it.

Infrastructure

Postpipe runs entirely on Cloudflare — Workers for compute, D1 for the database, R2 for media storage, and Queues for background jobs. Cloudflare processes this data as our infrastructure provider. We do not use any other third-party processor, analytics service, or advertising network.

Legal

We will disclose data if legally compelled to, and to protect the rights or safety of our users or the service.

How we protect it

  • Platform access tokens and webhook secrets are encrypted at rest with AES-256-GCM.
  • Passwords are hashed with PBKDF2-SHA256 and a random per-user salt; sessions and API keys are stored only as SHA-256 digests.
  • All traffic is served over HTTPS.
  • Every workspace is isolated. Each database query is scoped to a single workspace, and content, media and connected accounts cannot be referenced across workspace boundaries.
  • Media served for platform fetching requires a short-lived signed URL; unsigned requests are rejected.

No system is perfectly secure. If you find a vulnerability, please report it to privacy@postpipe.dev rather than disclosing it publicly.

How long we keep it

  • Account and content — kept while your account is open.
  • Sessions — expire after 30 days and are purged automatically.
  • Unattached media uploads — pending uploads that are never attached to a post are garbage collected.
  • Disconnected accounts — when you disconnect a social account, its stored tokens are deleted immediately.

Deleting your data

You can delete most things yourself from the dashboard, at any time:

  • A connected social account — Accounts → Disconnect. This deletes the stored access and refresh tokens right away. It does not delete anything already published to that platform; remove those from the platform itself.
  • A post — Posts → Delete.
  • A media file — Media → Delete.
  • An API key or webhook — from their respective settings pages.

To delete your entire account, email privacy@postpipe.dev from the address you signed up with. We will erase your account, workspace, connected account tokens, posts, media and publication history within 30 days and confirm when it is done.

You can also revoke Postpipe's access directly from any social platform's own settings, which immediately invalidates the token we hold.

Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict its processing, and to complain to your local data protection authority. Email privacy@postpipe.dev and we will respond within 30 days. We will not charge you or degrade your service for exercising these rights.

International transfers

Frames Engineering, Inc. is based in the United States, and Postpipe runs on Cloudflare's global network, so your data is processed in the United States and may be processed in other countries. If you are in the European Economic Area or the United Kingdom, this means your data is transferred outside your region; we rely on Standard Contractual Clauses and the safeguards Cloudflare maintains for those transfers.

Children

Postpipe is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child has created an account, contact us and we will remove it.

Cookies

We set one cookie: pp_session, which keeps you signed in. It is HttpOnly, Secure and SameSite=Lax. There are no advertising, analytics or third-party tracking cookies.

Changes

If we change this policy materially, we will update the effective date above and email registered users before the change takes effect.

Terms of Service Sign in privacy@postpipe.dev