Data & privacy
What we store, how it is protected, and how to remove it whenever you want.
What Postfor stores
| Data | Why |
|---|---|
| Account details (email, name) | To identify your workspace and send service notifications. |
| Connected channel profile (username, display name, avatar) | So you can tell your channels apart in the interface. |
| OAuth access and refresh tokens | To publish the posts you scheduled. Stored encrypted. |
| Your posts and media | To schedule, preview and publish your content. |
| Published post metrics | To show analytics for content you published through Postfor. |
What Postfor never stores
- Your social media passwords — authorisation always happens on the platform's own site via OAuth.
- Private messages or direct messages from any connected platform.
- Data belonging to accounts you have not explicitly connected.
How tokens are protected
Access and refresh tokens are encrypted at rest and are only decrypted at the moment a scheduled post needs to be published. All traffic between your browser, Postfor and the social platforms runs over HTTPS.
Tokens are scoped to the minimum permissions each integration needs. Postfor requests publishing and basic profile access, nothing more.
Disconnecting a channel
Open Channels, select the channel and click Disconnect. The stored tokens are deleted straight away and no further posts can be published to that account. You can also revoke access from the platform's own settings — for TikTok, see Connecting TikTok.
Deleting your account
Go to Settings → Account → Delete account. This permanently removes your workspace, posts, media library, analytics and all connected channel tokens. Content already published to a social platform stays there, because it belongs to you — delete it on the platform if you want it removed.
If you would prefer us to handle the deletion, write to [email protected] from your account email address and we will process it.
Your rights
Depending on where you live you may have the right to access, correct, export or erase the personal data we hold about you, and to object to certain processing. Contact [email protected] to exercise any of these rights.
The full legal detail is in our Privacy Policy and Terms of Service.