Privacy Policy

Last updated: April 11, 2026

1. Introduction

Post Worker ("we", "us", "our") operates the post-worker.com website and the Post Worker social media automation service (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

By using Post Worker, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Account Information

When you sign up, we collect your name, email address, and business information that you provide.

2.2 OAuth Data from Third-Party Platforms

To provide our Service, we request access to your accounts on the following platforms via OAuth 2.0:

  • Facebook & Instagram (via Meta/Facebook Login): We access your Facebook Pages and Instagram Business accounts to publish posts on your behalf. We collect page access tokens, page IDs, and basic profile information (name, profile picture). We request the following permissions: pages_manage_posts, pages_read_engagement, instagram_basic, instagram_content_publish.
  • LinkedIn: We access your LinkedIn organization pages to publish posts. We collect access tokens and organization identifiers.

We only request the minimum permissions necessary to provide the Service. We do not access your private messages, friend lists, or personal posts.

2.3 Content Data

We store the posts generated by our AI and any edits you make, along with publishing schedules and approval history.

2.4 Usage Data

We automatically collect standard log data including IP addresses, browser type, pages visited, and timestamps. This data is used for analytics and security purposes.

3. How We Use Your Information

  • To provide, operate, and maintain the Service
  • To generate and publish social media content on your behalf
  • To notify you about posts awaiting your approval and scheduled posts
  • To improve and personalize the AI content generation
  • To communicate with you about your account and Service updates
  • To detect and prevent fraud, abuse, and security incidents

4. Data Storage and Security

Your data is hosted on Cloudflare infrastructure, utilizing their global network with data centers in the EU and US. All OAuth tokens and sensitive credentials are encrypted at rest and transmitted exclusively over HTTPS/TLS.

We implement industry-standard security measures including:

  • Encryption of all access tokens at rest
  • TLS 1.3 encryption for all data in transit
  • Regular security audits and monitoring
  • Principle of least privilege for all system access

5. Data Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties.

We may share your information only in the following circumstances:

  • Service Providers: We use Cloudflare for hosting and Meta/LinkedIn APIs to publish your content. These providers process data solely to perform services on our behalf.
  • Legal Requirements: We may disclose information if required by law, regulation, or legal process.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction.

6. Data Retention

We retain your data for as long as your account is active or as needed to provide the Service. OAuth tokens are revoked and deleted when you disconnect a platform or delete your account. You may request deletion of your data at any time by contacting us.

7. Your Rights

Depending on your jurisdiction, you may have the following rights:

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Request correction of inaccurate data
  • Erasure: Request deletion of your personal data
  • Portability: Request a machine-readable copy of your data
  • Objection: Object to processing of your data in certain circumstances
  • Revoke Access: Disconnect your social media accounts at any time through the Service or directly through the platform's settings

To exercise any of these rights, please contact us at [email protected].

8. Facebook & Instagram Platform Data

In compliance with Meta Platform Terms:

  • We only use Facebook and Instagram data to provide the Service (publishing posts on your behalf)
  • We do not use platform data for advertising, data brokering, or any purpose unrelated to the Service
  • We do not transfer platform data to any data broker or third party not essential to providing the Service
  • Users can revoke access at any time by removing Post Worker from their Facebook App settings
  • Upon access revocation or account deletion, all associated platform data is deleted within 30 days

9. Cookies

Our website uses minimal, essential cookies for session management. We do not use tracking cookies or third-party advertising cookies.

10. Children's Privacy

Our Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date.

12. Contact Us

If you have any questions about this Privacy Policy, your data, or wish to exercise your rights, please contact our Data Protection Officer:

Email: [email protected]
Website: post-worker.com