Privacy Policy

Effective date: July 11, 2026

Crossposting ("we", "us") is a social media scheduling tool. This policy explains what data we collect, why, and the control you have over it. The short version: we collect only what is needed to publish your content where you tell us to, and you can delete everything at any time.

1. What we collect

Account information: your name, email address, and a hashed password (we never store passwords in plain text).

Connected social accounts: the platform name, handle, and — for live integrations — the access credentials you provide (such as a Bluesky app password) or OAuth tokens issued by the platform. These are used only to publish the content you ask us to publish.

Content: the captions, images, and videos you upload for posting, plus your scheduling preferences.

Basic usage data: pages visited and actions taken inside the app, used to keep the service reliable.

2. How we use your data

To operate the service: publishing and scheduling your posts on the platforms you connect, showing your analytics, and providing support.

We do not sell your data. We do not share your content or credentials with third parties, except the social platforms you explicitly connect — and only to publish on your behalf.

3. Social platform access (Meta, and others)

Crossposting integrates with Meta platforms — Facebook Pages, Instagram, and Threads — as well as Bluesky and TikTok. When you connect one of these accounts, we receive and use only the data and permissions strictly needed to publish content you create: your account/page ID and handle, and the OAuth access tokens the platform issues.

Specifically, for Meta we request only publishing-related permissions (for example, to post to a Facebook Page or Instagram professional account you own and manage). We never read your private messages, followers lists, ad data, or any information unrelated to publishing the posts you schedule.

You can disconnect any account at any time from the Accounts page, which removes its credentials and tokens from our database immediately.

4. Storage and security

Passwords are hashed with bcrypt. Sessions use httpOnly cookies. Platform credentials are stored server-side and are never exposed to your browser or other users.

Uploaded media is stored on our servers solely to publish and display your posts.

5. Data deletion

You can delete your entire account and all associated data (posts, media, connected accounts, tokens, and credentials) at any time from Settings → Danger zone. Deletion is immediate and irreversible.

To delete only the data associated with a specific connected platform, disconnect that account from the Accounts page — this immediately removes its tokens and credentials from our database.

To request deletion of any data we obtained from Meta (Facebook, Instagram, or Threads), disconnect the account or email support@crossposting.xyz with the subject "Data deletion request". We will confirm and complete the deletion within 30 days.

6. Cookies

We use a single session cookie to keep you signed in. We do not use advertising or cross-site tracking cookies.

7. Platform compliance

Our use of information received from Meta APIs (Facebook, Instagram, and Threads) follows Meta's Platform Terms and Developer Policies. Data obtained through these APIs is used only to provide the publishing features you request, is never sold or transferred to data brokers, and is not used for advertising or any purpose unrelated to the service.

The same applies to every other platform we integrate with: data and tokens are used solely to publish on your behalf.

8. Changes and contact

If this policy changes, we will update this page and note the new effective date below.

Questions? Email support@crossposting.xyz.