Legal

Privacy Policy

Last updated

Postoro connects to your social media accounts, so this policy is written to be specific rather than reassuring. It describes exactly what the software stores, where, for how long, and what it can and cannot do with your accounts.

The short version

  • We store your email, a hash of your password, the social accounts you connect, and the posts and media you create.
  • Your social login tokens are encrypted before they are written to the database and are never sent back to your browser or to anyone else.
  • Media you upload is deleted automatically 7 days after it publishes.
  • We do not sell your data, and we do not use your content to train anything.
  • Postoro only posts what you schedule. It cannot read your direct messages.

1.Who we are

Postoro is a free tool for scheduling and publishing posts to YouTube, Instagram, Facebook, TikTok and LinkedIn from one place. This policy covers the Postoro website and dashboard, operated by Cutlume. In this policy, “we” means the operator of Postoro and “you” means the person using an account.

Postoro is an independent tool. It is not affiliated with, endorsed by, or operated by Google, YouTube, Meta, Instagram, Facebook, ByteDance, TikTok or LinkedIn.

2.What we collect

We collect only what the product needs to work. There is no analytics SDK, no session recording, and no third-party tracker embedded in the dashboard.

Your account

  • Email address — your login identity and how we reach you about your account.
  • Password — stored only as an Argon2id hash. We never store, log, or have any way to read your actual password.
  • Display name (optional) and timezone — your timezone is required so scheduled posts go out at the time you meant.

Sign-in sessions

For each active sign-in we store a hash of the session token, its expiry, the time it was last used, and the IP address and browser user-agent it was created from. This is what lets you see and revoke your own sessions, and it is how we detect a stolen session.

Security log

Security-relevant actions — signing in, connecting or disconnecting a social account, deleting a post — are recorded with the action, the time, the IP address and the user-agent. IP addresses are also held briefly in memory to rate-limit sign-in attempts and uploads.

Your posts

The captions, titles, scheduled times, chosen destinations, and the result of each publish attempt — including the error message when a platform rejects something, because you need to be able to see why.

3.Your connected social accounts

When you connect a platform, that platform sends us an access token after you approve the connection on the platform’s own sign-in screen. Postoro never sees your social media password.

For each connected account we store:

  • Your account identifier on that platform, plus your username, display name and avatar so you can tell your accounts apart.
  • The access token and refresh token, encrypted with AES-256-GCM before being written to the database, along with the permissions granted and the token’s expiry.
  • Platform-specific details needed to publish — for example which Facebook Page or Instagram professional account a post belongs to.
  • If you connect using your own developer credentials, your client ID and client secret, encrypted the same way.

We request the narrowest permissions each platform offers for publishing on your behalf and reading back the resulting post. The exact permissions are shown by the platform on its consent screen before you approve, and you can revoke them at any time from the platform’s own settings as well as from Postoro.

What Postoro cannot do

Postoro does not request access to your direct messages, your private inbox, your contacts, or your ad accounts. It publishes the posts you schedule and reads back their status. It does not post anything you did not create in the composer.

4.Media you upload

Videos and images you upload are stored so they can be sent to each platform at the scheduled time. Alongside the file we keep its filename, type, size, dimensions, duration and a checksum — the dimensions and duration are what let Postoro work out whether a video should publish as a Short or a Reel.

Your media is yours. We do not use it for training, we do not licence it to anyone, and we do not publish it anywhere you did not choose.

One technical detail worth knowing: Instagram’s API does not accept an uploaded file. It requires a publicly reachable link that Instagram fetches itself. That means when you publish to Instagram, the media file must be briefly readable at an unguessable URL for Instagram to download it. This is how every Instagram scheduling tool works, and it applies only to posts you send to Instagram.

5.How long we keep things

  • Media files — deleted automatically 7 days after the post publishes. Keep your own originals; Postoro is not a backup service.
  • Posts and their publish history — kept while your account exists, so you have a record of what went out and where.
  • Social account tokens — kept until you disconnect the account or delete your Postoro account, then removed.
  • Sessions — expire on their own and are purged automatically after expiry.
  • Security log entries — retained for a limited period for abuse and fraud investigation, then deleted. If you delete your account, these entries are detached from you first: the link to your user record is removed, so what remains cannot be traced back to you.

6.How your data is protected

  • Every social token and developer secret is encrypted at rest with AES-256-GCM, an authenticated cipher — tampered ciphertext fails to decrypt rather than decrypting to something wrong.
  • Tokens are never returned by any API response and never sent to the browser. The endpoints that list your accounts select specific columns so token fields cannot be serialised by accident.
  • Passwords are hashed with Argon2id using current OWASP parameters.
  • Sessions are opaque random tokens stored as hashes, so a database copy does not yield usable sessions — and every session can be revoked server-side immediately.
  • A Content-Security-Policy, HSTS, frame-blocking and a restrictive permissions policy are applied to every response, and sign-in and upload endpoints are rate-limited.

No system is perfectly secure, and we will not claim otherwise. If we discover a breach affecting your data, we will tell affected users by email and describe what happened and what to do.

7.Who we share data with

We do not sell your personal data. We share it only in these cases:

  • The platforms you choose. When you publish, the caption and media go to that platform, which then handles them under its own privacy policy — Google/YouTube, Meta for Instagram and Facebook, TikTok, and LinkedIn.
  • Infrastructure providers. The hosting and storage providers that run the service on our behalf, which process data only on our instructions.
  • Legal requirements. Where we are required by law to disclose information, or need to in order to investigate abuse or protect users.

8.Advertising and cookies

Postoro is free to use. It is funded by advertising shown on the public marketing pages — never inside your dashboard, and never mixed into your content. Advertising is not switched on yet; this section describes what will happen when it is, and this page will be dated again on the day it changes.

Ads are served by Google AdSense. Google and its partners may use cookies or similar technologies to serve and measure ads, including personalised ads based on your prior visits to this and other websites. You can opt out of personalised advertising in Google’s Ads Settings, and manage cookies in your browser. Advertising cookies are never used to identify you inside Postoro or linked to your connected social accounts.

Cookies we set ourselves

  • Session cookie — strictly necessary. It keeps you signed in and is HTTP-only, so page scripts cannot read it.
  • Theme preference— your dark or light choice, stored in your browser’s local storage, not sent to us.
  • Sign-in protection — short-lived values used during the OAuth handshake to prevent request forgery.

9.Your rights and choices

  • Disconnect any platform at any timefrom the Accounts page. This deletes the stored tokens for that account. You can also revoke Postoro’s access from the platform’s own security settings, which we recommend doing as well.
  • Sign out everywhere from Settings, which revokes every active session immediately — the right response if you think an account is compromised.
  • Delete your account yourself, at any time. Settings → Delete your account. It takes effect immediately: your profile, sessions, connected accounts and their stored tokens, posts, and uploaded files are erased from our database and from storage, and anything still scheduled is cancelled. There is no recovery period and we keep no backup copy of it. Posts already published to a platform stay on that platform — we have no way to remove them once they are live, so delete those on the platform itself.
  • Access, correct or export your data. Email us at hello@cutlume.com from your account email address and we will action it within 30 days. You can use the same address to ask us to delete your account if you cannot sign in to do it yourself.

Depending on where you live you may have additional rights under laws such as the GDPR or the DPDP Act, including the right to object to processing and to complain to your local data protection authority. The legal basis for processing your account and publishing data is performance of the contract you enter into by using Postoro; for security logging and abuse prevention it is our legitimate interest in keeping the service safe.

10.Children

Postoro is not intended for anyone under 13, and you must in any case meet the minimum age required by every platform you connect. If we learn that we hold data for a child under 13, we will delete it.

11.Where your data is stored

Postoro’s database and media storage run on infrastructure that may be located outside your country, and the social platforms you publish to operate globally. Where data is transferred internationally, it is protected by appropriate safeguards and remains subject to this policy.

12.Changes to this policy

If we change what we collect, how long we keep it, or who we share it with, we will update this page and change the date at the top. For material changes affecting your accounts or your media, we will also email you before the change takes effect.

13.Contact

Questions about privacy, data requests, or a security issue you want to report — email hello@cutlume.com. Security reports are read first.