Passer au contenu
🇫🇷 FR

This legal document is available in English only for legal accuracy. Translations are provided for general information; the English version governs in all cases.

Legal

PostClaw Privacy Policy

Last updated: May 23, 2026

1. Introduction

Cassau, LLC ("we," "us," or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform PostClaw at postclaw.fun ("the Service").

This policy complies with the General Data Protection Regulation (GDPR) and other applicable privacy laws. If you are located in the European Economic Area, you have additional rights described in Section 8.

2. Data We Collect

We collect information you provide directly, data generated by your use of the Service, and information from third-party integrations.

Information you provide

  • Account information: name, email address, password (hashed).
  • Profile data: company name, profile photo, timezone.
  • Payment information: processed by Stripe; we store only the last 4 digits and billing address.
  • Content you create: posts, captions, media, and workflow configurations.

Automatically collected data

  • Usage data: pages visited, features used, click patterns.
  • Device data: IP address, browser type, operating system.
  • Cookies and similar tracking technologies (see our Cookie Policy).

Third-party integrations

  • OAuth tokens for connected social media accounts (stored encrypted with AES-256-GCM).
  • Analytics data from social platforms you connect.

3. How We Use Your Data

We use collected data to:

  • Provide, operate, and improve the Service.
  • Process transactions and send related information such as purchase confirmations.
  • Send administrative communications (service updates, security alerts).
  • Send marketing communications where you have opted in.
  • Analyze usage patterns to improve user experience.
  • Comply with legal obligations and enforce our Terms of Service.

Our legal basis for processing under GDPR is: contract performance (account and subscription), legitimate interests (product improvement and security), legal obligation, and consent (marketing emails).

4. Data Sharing

We do not sell your personal data. We share data only in the following circumstances:

  • Service providers: Stripe (payments), AWS (infrastructure), Resend (email), and similar vendors who process data on our behalf under data processing agreements.
  • Social platforms: Content you publish is shared with the social media platforms you choose.
  • Legal requirements: We may disclose data if required by law, court order, or government request.
  • Business transfers: In the event of a merger or acquisition, your data may be transferred as a business asset.

5. Data Retention

We retain personal data for as long as necessary to provide the Service and comply with legal obligations:

  • Account data: retained for the duration of your account plus 90 days after deletion.
  • Published posts and analytics: retained for 24 months after publication.
  • Billing records: retained for 7 years as required by financial regulations.
  • Server logs: retained for 30 days.
  • Meta Platform (Facebook, Instagram, Threads) data — including page engagement metrics and Instagram comment metadata — is retained only for active use. Per Meta Platform Terms, any cached Meta data not accessed for 90 days is purged and the user must re-authorize the connection to refresh it.

6. Security

We implement industry-standard security measures including TLS encryption in transit, AES-256-GCM encryption at rest for sensitive credentials, regular security audits, and access controls. However, no method of transmission over the internet is 100% secure.

7. International Transfers

Your data may be transferred to and processed in countries outside your own, including the United States. We ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.

8. Your Rights (GDPR & Others)

Depending on your location, you may have the right to:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Request correction of inaccurate data.
  • Erasure: Request deletion of your personal data ("right to be forgotten").
  • Portability: Receive your data in a structured, machine-readable format.
  • Restriction: Request that we limit processing of your data.
  • Objection: Object to processing based on legitimate interests.
  • Withdraw consent: Withdraw consent for marketing at any time.

To exercise these rights, contact us at [email protected]. We will respond within 30 days.

9. Children's Privacy

The Service is not directed to children under 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us immediately.

10. Contact

For privacy-related inquiries, contact us at [email protected] or through our contact page.

Mailing address:
Cassau, LLC
131 Continental Dr, Suite 305
Newark, DE 19713, USA

11. Google API Services User Data Policy

PostClaw's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Google user data we access

When you connect a YouTube account, PostClaw requests the following OAuth scopes:

  • openid, userinfo.email, userinfo.profile — to identify your account and display your name, email, and avatar within PostClaw.
  • youtube.upload — to upload and publish new videos to your YouTube channel on your behalf, according to the schedule you set in PostClaw.
  • youtube.force-ssl — to list your existing videos, update video metadata (title, description, thumbnail), delete videos you scheduled through PostClaw, and moderate comments on those videos.

How we use Google user data

Google user data is used exclusively to provide the social media scheduling and publishing features you explicitly configure in PostClaw. We do not use Google user data for any other purpose.

Limited Use disclosure

PostClaw complies with Google's Limited Use requirements:

  • We do not use Google user data to serve advertisements.
  • We do not allow humans to read Google user data, except (a) with your explicit consent for support purposes, (b) when necessary for security, to comply with applicable law, or (c) when the data has been aggregated and anonymized.
  • We do not transfer or sell Google user data to third parties, data brokers, or information resellers.
  • We do not use Google user data to train, fine-tune, or develop any generalized AI or machine learning models.

Data storage and deletion

OAuth refresh tokens for Google accounts are stored encrypted with AES-256-GCM. When you disconnect a YouTube account or delete your PostClaw account, all associated Google tokens and cached YouTube data are permanently deleted within 7 days.

You can revoke PostClaw's access to your Google Account at any time by visiting myaccount.google.com/permissions.

12. Meta Platform User Data Policy

PostClaw's use and transfer of information received from Meta Platform APIs (Facebook Graph API, Instagram Graph API, and Threads Graph API) adheres to the Meta Developer Policies and the Meta Platform Terms.

Facebook Page permissions we request

When you connect a Facebook Page, PostClaw requests the following OAuth permissions, each used for a specific feature in the product:

  • public_profile — to identify your Facebook account and display your name and avatar within PostClaw after sign-in.
  • pages_show_list — to list the Facebook Pages you manage so you can choose which Page to schedule and publish content to.
  • pages_manage_posts — to publish scheduled posts (text, single image, multi-photo carousel, video, and Stories) to your Facebook Page on your behalf at the time you configure inside PostClaw.
  • pages_read_engagement — to display engagement metrics (reactions, comments count, shares, comment text and commenter name) for your published Facebook Page posts inside PostClaw's Analytics dashboard and unified inbox.
  • pages_manage_engagement — to post the first comment on behalf of your Page when you enable the "First comment" feature in PostClaw's composer, and to reply to existing comments on your own Page's posts from within PostClaw's unified inbox. PostClaw only operates on Pages you administer and never engages on third-party content.
  • read_insights — to fetch aggregate Page performance metrics (impressions, reach, post-level views, engagement rate) for display in PostClaw's Analytics dashboard.

Instagram Business permissions we request

When you connect an Instagram Business account (linked to a Facebook Page), PostClaw requests:

  • instagram_business_basic — to read your Instagram Business profile information (username, profile picture, account type, follower count, media count) so you can confirm the correct account is connected.
  • instagram_business_content_publish — to publish scheduled Instagram content (single image, carousel, video, Reels, Stories) to your Instagram Business account at the time you configure inside PostClaw.
  • instagram_business_manage_comments — to display, reply to, and manage your own previous replies on your Instagram Business media. PostClaw only operates on media owned by the connected user and never moderates comments on other accounts.
  • instagram_business_manage_insights — to fetch engagement metrics (reach, impressions, saves, shares, video views) for your Instagram Business posts and account-level metrics for display in PostClaw's Analytics dashboard.

Threads permissions we request

When you connect a Threads account (via Meta's Threads Login OAuth flow at threads.net), PostClaw requests:

  • threads_basic — to read your Threads profile information (username, display name, profile picture) so you can confirm the correct account is connected.
  • threads_content_publish — to publish scheduled Threads posts (text, single image, carousel, video) to your Threads account at the time you configure inside PostClaw.
  • threads_manage_replies — to display reply chains on your own Threads posts inside PostClaw's unified inbox and to post replies back to those conversations on your behalf. PostClaw only operates on threads you authored and never replies on third-party threads.
  • threads_manage_insights — to fetch engagement metrics (views, likes, replies, reposts, quotes) for your Threads posts and account-level metrics for display in PostClaw's Analytics dashboard.

How we use Meta user data

Meta user data is used exclusively to provide the social media scheduling, publishing, analytics, and engagement features you explicitly configure in PostClaw. Specifically:

  • Identity data (names, usernames, avatars, account types) — used to label connected accounts in the PostClaw interface and attribute scheduled posts to the correct destination.
  • Publishing permissions — invoked only when you create a post and select a Facebook Page, Instagram Business account, or Threads account as the destination. We never publish autonomously.
  • Engagement data (likes, comments, reply chains, reactions, views, shares, reposts, quotes) — fetched on background refresh cycles and on user demand for posts you authored through PostClaw, displayed only to you on your own analytics dashboard and unified inbox.
  • First comment + replies (pages_manage_engagement, instagram_business_manage_comments, threads_manage_replies) — invoked only on user-initiated actions in the composer or inbox; PostClaw never auto-replies.
  • Insights (read_insights, instagram_business_manage_insights, threads_manage_insights) — aggregated within-account metrics only; never aggregated across users to build audience profiles, lookalike audiences, or competitive intelligence products.

We do not use Meta user data for any purpose beyond the features listed above.

Limited Use disclosure

PostClaw complies with Meta's Platform Terms and the following Limited Use principles for Meta user data:

  • We do not use Meta user data to serve advertisements.
  • We do not allow humans to read Meta user data, except (a) with your explicit consent for support purposes, (b) when necessary for security, to comply with applicable law, or (c) when the data has been aggregated and anonymized.
  • We do not sell, transfer, or share Meta user data to third parties, data brokers, or information resellers.
  • We do not use Meta user data to train, fine-tune, or develop any generalized AI or machine learning models.
  • We do not aggregate Meta engagement data across users to build audience profiles, lookalike audiences, or competitive intelligence products.

Data storage, retention, and deletion

  • OAuth access and refresh tokens for Facebook, Instagram, and Threads accounts are stored encrypted at rest using AES-256-GCM and are scoped strictly to your account.
  • Cached Meta Platform data (Page lists, post engagement, comment metadata, reply chains, account-level and post-level insights) is retained only while the connection is active. Per Meta Platform Terms, any cached Meta data not accessed for 90 days is purged automatically; you may re-authorize to refresh it.
  • When you disconnect a Facebook, Instagram, or Threads account from PostClaw, all associated OAuth tokens and cached Meta data are permanently deleted within 7 days.
  • When you delete your PostClaw account, all Meta tokens and cached Meta data are permanently deleted within 7 days.
  • You may revoke PostClaw's access at any time from Facebook Business Integrations settings (covers Facebook + Instagram) or from your Threads app under Settings > Account > Privacy > Other apps and websites.

Data deletion requests

To request deletion of your Facebook-, Instagram-, or Threads-sourced data outside of the in-app disconnect flow:

  • Submit a request via PostClaw's automated Data Deletion Callback URL: https://app.postclaw.fun/v1/meta/data-deletion. Meta posts a signed request here when a user removes PostClaw from their Facebook, Instagram, or Threads app settings; we verify the HMAC-SHA256 signed_request, delete all associated tokens and cached data, and respond with a confirmation code linking to a public status page at https://postclaw.fun/data-deletion/status. Deletion completes within 7 days.
  • Or email [email protected] with your Facebook user ID, Instagram username, or Threads handle for a manual deletion. We respond within 30 days.

13. TikTok Platform User Data Policy

PostClaw's use and transfer of information received from TikTok APIs adheres to the TikTok Developer Terms of Service and the TikTok Content Sharing Guidelines.

TikTok user data we access

When you connect a TikTok account, PostClaw requests the following OAuth scopes, each used for a specific feature in the product:

  • user.info.basic — to identify your TikTok account and display your display name and avatar within PostClaw after sign-in.
  • user.info.profile — to read your creator nickname and profile picture used by PostClaw's publish modal so you can confirm the correct TikTok account before posting.
  • video.publish — to publish scheduled videos directly to your TikTok feed (Direct Post) at the time you configure inside PostClaw.
  • video.upload — fallback path to upload videos to your TikTok inbox as drafts that you can review and finalize from the TikTok app.
  • video.list — to read your published video metadata (view count, likes, comments, shares) for display in PostClaw's Analytics dashboard.

How we use TikTok user data

TikTok user data is used exclusively to provide the social media scheduling, publishing, and analytics features you explicitly configure in PostClaw. We do not use TikTok user data for any other purpose.

Limited Use disclosure

PostClaw complies with the following Limited Use principles for TikTok user data:

  • We do not use TikTok user data to serve advertisements.
  • We do not allow humans to read TikTok user data, except (a) with your explicit consent for support purposes, (b) when necessary for security, to comply with applicable law, or (c) when the data has been aggregated and anonymized.
  • We do not sell, transfer, or share TikTok user data to third parties, data brokers, or information resellers.
  • We do not use TikTok user data to train, fine-tune, or develop any generalized AI or machine learning models.
  • We do not aggregate TikTok engagement data across users to build audience profiles, lookalike audiences, or competitive intelligence products.

Data storage, retention, and deletion

  • OAuth access and refresh tokens for TikTok accounts are stored encrypted at rest using AES-256-GCM and are scoped strictly to your account.
  • Cached TikTok data (creator profile metadata, published video IDs, post engagement metrics) is retained only while the connection is active.
  • When you disconnect a TikTok account from PostClaw, all associated OAuth tokens and cached TikTok data are permanently deleted within 7 days.
  • When you delete your PostClaw account, all TikTok tokens and cached TikTok data are permanently deleted within 7 days.
  • You may revoke PostClaw's access to your TikTok account at any time from your TikTok app under Settings > Security & Permissions > Manage app permissions.

Data deletion requests

To request deletion of your TikTok-sourced data outside of the in-app disconnect flow, email [email protected] with your TikTok username or open_id. We respond within 30 days.

14. LinkedIn Platform User Data Policy

This section explains the LinkedIn user data PostClaw accesses through LinkedIn's APIs (including the Share on LinkedIn, Sign In with LinkedIn, and Community Management API products) and how we handle it in compliance with the LinkedIn API Terms of Use.

LinkedIn user data we access

When you connect a LinkedIn account, you authorize the following scopes:

  • openid, profile, r_basicprofile — your LinkedIn member ID, name, headline, profile photo, and vanity URL, so you can select which account to publish from and so we can display your identity inside PostClaw.
  • w_member_social — publish posts, comments, and media to your personal LinkedIn feed on your explicit instruction.
  • r_member_social_feed — read aggregate engagement counts (total reactions and total first-level comments) for posts you authored through PostClaw, displayed only on your own analytics dashboard.
  • rw_organization_admin — list LinkedIn Company Pages you administer and manage your admin relationship, so we can offer them as publishing destinations.
  • w_organization_social — publish posts to LinkedIn Company Pages where you hold an admin role, only when you explicitly select that page as the destination.
  • r_organization_social — read aggregate engagement counts for posts you published to a Company Page through PostClaw, displayed only to admins of that page.

How we use LinkedIn user data

LinkedIn user data is used exclusively to provide the scheduling, publishing, and own-account analytics features you configure inside PostClaw. Specifically:

  • Identity data (Profile Data) is used to label connected accounts in the PostClaw interface and attribute scheduled posts to the correct destination. Profile Data is refreshed only when you actively use PostClaw (sign-in, account refresh action), never on an automated background schedule, in line with LinkedIn's Profile Data refresh policy.
  • Publishing scopes (w_member_social, w_organization_social) are invoked only when you explicitly create or schedule a post and select a LinkedIn destination — never autonomously.
  • Engagement data on your own posts (aggregate likes count and aggregate first-level comments count, via LinkedIn's Community Management API socialActions endpoint) is fetched on a background cycle (typically hourly) only for posts you authored through PostClaw, and displayed only to you on your own analytics dashboard.
  • We do not read or store the content of individual comments, the identities of users who reacted to your posts, or any data about LinkedIn members who are not the authenticated user.
  • We do not combine LinkedIn Content with any other LinkedIn content (including non-official content), nor with third-party data in any way that would prevent attribution of the Content back to LinkedIn.
  • We collect the minimum LinkedIn data needed to deliver the features above and do not request scopes or content beyond that minimum.

Limited Use disclosure

PostClaw uses LinkedIn member data strictly to deliver user-facing features and complies with LinkedIn's Limited Use requirements:

  • We do not sell, rent, lease, sublicense, or transfer LinkedIn member data to data brokers, advertisers, or any third party (other than independent contractors processing on our behalf under written confidentiality agreements).
  • We do not use, sell, transfer, or process LinkedIn Content for the purposes of advertising, including retargeting or personalized ads, on or off LinkedIn.
  • We do not use LinkedIn data to train, fine-tune, or develop any generalized AI or machine learning models.
  • We do not allow humans to read LinkedIn member data, except (a) with your explicit consent, (b) for security or abuse investigations, (c) to comply with applicable law, or (d) where data is aggregated and anonymized.
  • We do not aggregate LinkedIn engagement data across users to build competitive intelligence, industry benchmark products, audience profiles, or lookalike audiences.
  • We do not use LinkedIn data in any manner that facilitates bias, discriminatory practices, or surveillance — including surveillance by any government entity.

Consent and re-consent

Before PostClaw accesses any LinkedIn Content, you grant explicit consent through LinkedIn's OAuth flow, which discloses the scopes requested, the data accessed, how it is used, how to withdraw consent, and how to request deletion. When your LinkedIn OAuth access token or Member Token expires, you must reconnect your account in PostClaw Settings → Connected Accounts to grant fresh consent; PostClaw will not silently extend access beyond what you authorized.

Data storage, retention, and deletion

  • LinkedIn OAuth access tokens, refresh tokens, and Member Tokens are stored encrypted at rest using AES-256-GCM and are scoped strictly to your account.
  • Cached LinkedIn data (account identity, Company Page list, published post URNs, aggregate engagement snapshots) is retained only for the duration necessary to provide the scheduling and analytics features to you, and is purged within 7 days of disconnection or PostClaw account deletion.
  • Engagement snapshots older than 90 days are pruned automatically — we keep only enough history to render your analytics dashboard.
  • You can revoke PostClaw's LinkedIn access at any time from LinkedIn Settings → Data Privacy → Permitted Services; revocation triggers immediate token invalidation on our side.
  • Upon termination of PostClaw's LinkedIn API access, cessation of PostClaw's services, or request by LinkedIn, we will immediately delete all LinkedIn Content held on your behalf, except where deletion would cause us to violate any applicable law or governmental obligation.

Data deletion requests

You may request deletion of your LinkedIn-derived data held by PostClaw at any time by:

  • Disconnecting the LinkedIn account from PostClaw Settings → Connected Accounts. Upon disconnect, PostClaw initiates immediate deletion of all LinkedIn Content (OAuth Access Token, Member Token, and all cached Content) collected on your behalf. System propagation completes within 7 days.
  • Emailing [email protected] for a manual deletion request. We respond within 30 days.
  • Closing your PostClaw account — all LinkedIn tokens and Content are immediately marked for deletion and fully purged within 7 days.

15. Pinterest API User Data Policy

PostClaw's use and transfer of information received from the Pinterest API adheres to the Pinterest Developer Guidelines and the Pinterest API Terms of Service.

Pinterest data we access

When you connect a Pinterest account, PostClaw requests the following OAuth scopes, each used for a specific feature in the product:

  • user_accounts:read — to identify your Pinterest account and display your username and avatar within PostClaw so you can confirm the correct account is connected before scheduling Pins.
  • boards:read — to list your Boards so you can choose which Board to publish a Pin to.
  • boards:write — required by Pinterest to publish Pins to your existing Boards. Pinterest categorizes pin-to-board publishing as a board-write operation, so this scope is requested alongside pins:write for any scheduling functionality. PostClaw does not create, rename, or delete Boards on your behalf.
  • pins:read — to read engagement metadata (impressions, saves, outbound clicks) for Pins you authored through PostClaw, displayed only on your own analytics dashboard.
  • pins:write — to publish scheduled Pins (image or video, with title, description, destination URL, and alt text) to a Board you administer at the time you configure inside PostClaw.

How we use Pinterest data

Pinterest data is used exclusively to provide the scheduling, publishing, and own-account analytics features you explicitly configure in PostClaw. Specifically:

  • Identity data is used to label the connected Pinterest account in PostClaw's interface and attribute scheduled Pins to the correct destination.
  • Board lists are fetched on demand to populate the Board selector in PostClaw's composer; we cache them briefly to reduce repeated API calls.
  • Pin engagement metrics (impressions, saves, outbound clicks) are fetched only for Pins you authored through PostClaw, displayed only to you on your own analytics dashboard.
  • We use Pinterest data only to serve you (the person whose account it is) and never combine it with other Pinterest accounts or other services.

Limited Use disclosure (Pinterest)

PostClaw complies with the following Limited Use principles for Pinterest API data, in line with the Pinterest Developer Guidelines:

  • We do not share or sell Pinterest API data to any third party, data broker, advertising service, or information reseller.
  • We do not use Pinterest API data to target advertising outside of Pinterest.
  • We do not bundle, repackage, or resell Pinterest content on other advertising networks or to data brokers.
  • We do not combine your Pinterest account information with other Pinterest accounts or with information from other services.
  • We do not use Pinterest data to train, fine-tune, or develop any generalized AI or machine learning models.
  • We do not allow humans to read Pinterest API data, except (a) with your explicit consent for support purposes, (b) when necessary for security or to comply with applicable law, or (c) when the data has been aggregated and anonymized.
  • We do not solicit or collect Pinterest login credentials; authentication is performed exclusively through Pinterest's OAuth flow.

Data storage, retention, and deletion

  • OAuth access and refresh tokens for Pinterest accounts are stored encrypted at rest using AES-256-GCM and are scoped strictly to your account.
  • Per Pinterest Developer Guidelines, PostClaw does not persistently store Pinterest API information beyond what is needed to deliver own-account analytics. Board lists and Pin metadata are cached only briefly and refreshed by calling the Pinterest API on demand.
  • Pin engagement metrics from your own account are retained only for the duration of your active connection and pruned within 7 days of disconnection.
  • When you disconnect a Pinterest account from PostClaw, all associated OAuth tokens and cached Pinterest data are permanently deleted within 7 days.
  • When you delete your PostClaw account, all Pinterest tokens and cached Pinterest data are permanently deleted within 7 days.
  • You may revoke PostClaw's access to your Pinterest account at any time from your Pinterest account at Settings > Security & Privacy > Apps and websites; revocation triggers immediate token invalidation on our side.

Children's data (Pinterest)

Per Pinterest Developer Guidelines, applications intended for children under the age of 13 are not permitted on the Pinterest platform. PostClaw is not directed to or intended for use by children under 13, and we do not knowingly collect Pinterest API data from such users.

Data deletion requests

To request deletion of your Pinterest-sourced data outside of the in-app disconnect flow, email [email protected] with your Pinterest username. We respond within 30 days.

16. Other Third-Party Social Platforms

In addition to Google (Section 11), Meta (Section 12), TikTok (Section 13), LinkedIn (Section 14), and Pinterest (Section 15), PostClaw integrates with the following platforms. Each integration uses the minimum OAuth scopes required to deliver the scheduling and analytics features you enable, and each platform's specific data-handling obligations are detailed below.

16.1 X (Twitter) Developer Policy

PostClaw's use of X (formerly Twitter) data adheres to the X Developer Policy and the X Developer Agreement.

When you connect an X account, PostClaw requests these OAuth 2.0 scopes:

  • tweet.read — read posts you authored through PostClaw to display engagement on your analytics dashboard.
  • tweet.write — publish posts, threads, replies, and media uploads to your X account on your explicit instruction.
  • users.read — display your username, display name, and avatar so you can confirm the correct account.
  • media.write — upload images, GIFs, and video to attach to scheduled posts.
  • offline.access — issue a refresh token so we can re-authenticate at scheduled publish time without prompting again. PostClaw also chains an OAuth 1.0a token at connection time, exclusively for v2 media upload requests where OAuth 2.0 returns 403 (a documented X API regression). The 1.0a token is scoped to the same user and used only for media upload signing.

X-specific data handling commitments:

  • We synchronize cached X Content within 24 hours of any change on X. If you delete a post on X, we remove the cached copy and engagement snapshot within 24 hours. If your account becomes suspended, protected, or blocked, we honor that state.
  • We do not access, store, or display X Direct Message content.
  • We do not use X Content or information obtained from the X API to target advertising outside of X.
  • We do not redistribute X Content to third parties. PostClaw operates only on your own account; we never share Post IDs, User IDs, or Content with any third party.
  • We do not use X data to train, fine-tune, or develop any AI or machine learning model.
  • We do not attempt to associate or match X users with off-X identities without their express opt-in consent, except where you yourself are the connected user.
  • OAuth 2.0 + OAuth 1.0a tokens are stored encrypted at rest (AES-256-GCM) and purged within 24 hours of account disconnection per X's offline-storage sync rule.
  • X analytics refresh is on-demand only (no background polling cron) because of X's pay-per-API-call billing model — engagement counts update when you click "Refresh engagement" in PostClaw.

16.2 Dribbble API

PostClaw's use of the Dribbble API adheres to the Dribbble Developer API documentation and Dribbble's Terms of Service.

When you connect a Dribbble account, PostClaw requests these OAuth scopes:

  • public — read your public Dribbble profile (username, avatar, team memberships) so you can confirm the correct account and select a team destination for uploads.
  • upload — publish Shots (image uploads with title and description) to your Dribbble account or to a team you administer, on your explicit instruction.

Dribbble-specific data handling commitments:

  • We do not store Dribbble shot or attachment content beyond the brief upload window required for the multipart Shot creation flow; once Dribbble accepts the Shot, our copy is discarded.
  • We do not share Dribbble account data, Shot metadata, or team membership data with any third party.
  • We do not use Dribbble data for advertising, retargeting, AI training, or audience profiling.
  • OAuth tokens are stored encrypted at rest (AES-256-GCM) and revoked when you disconnect the account or close your PostClaw account, with full purge within 7 days.
  • You may revoke PostClaw's access at any time from Dribbble account settings.

16.3 Federated networks (Bluesky & Mastodon)

PostClaw integrates with two federated social networks. Federated networks have no central authority — your data resides on the server you chose, and your relationship with that server's operator is governed by that server's terms and privacy policy.

Bluesky (AT Protocol) — PostClaw connects via Bluesky's DPoP-bound OAuth (preferred) or, for legacy accounts, app passwords. We use the AT Protocol to publish posts, replies, and media on your behalf. We never read your DMs, follower list, or feeds beyond what is required to publish on your own behalf. PostClaw uses the atproto and transition:generic scopes. Tokens (DPoP-bound JWTs or app passwords) are stored encrypted at rest (AES-256-GCM). Per Bluesky's community guidelines, "Bluesky Social is not responsible for the content or practices of Developer Applications"; you can revoke PostClaw at any time from Bluesky account settings.

Mastodon (ActivityPub) — PostClaw registers as an OAuth application per-instance you connect (cached in our mastodon_apps store), requesting read, write, and push scopes per Mastodon's recommended minimal-scope guidance. Each Mastodon instance has its own privacy policy, content rules, and rate limits that govern your experience there — PostClaw cannot override those. Tokens are stored encrypted at rest (AES-256-GCM), per-instance, and revoked on disconnection.

Both networks share these data-handling commitments:

  • We access only your own account's data — never other users' content or follower graphs.
  • We do not share federated network data with third parties, use it for advertising, or use it for AI training.
  • Tokens and cached metadata are purged within 7 days of disconnection or PostClaw account closure.

16.4 Common data we access across platforms

For every connected platform we access only what is needed to deliver features you enable:

  • Identity data — profile name, profile photo, account ID, and list of pages, teams, or channels you manage, to let you select a destination for your posts.
  • Publishing permissions — the ability to create posts, videos, stories, comments, and media uploads on accounts you explicitly connect.
  • Post results — the platform-assigned post ID and basic success/failure status returned after publication.
  • Engagement metadata — where enabled by you, high-level metrics (likes, comments, reach) used to display analytics inside PostClaw, only for posts you authored through PostClaw.

16.5 Common handling commitments

  • Access and refresh tokens for all platforms are stored encrypted at rest with AES-256-GCM and are never shared with third parties.
  • We do not sell platform data, transfer it to data brokers, or use it for advertising on or off the source platform.
  • We do not use content or engagement data retrieved from any connected social platform to train, fine-tune, or develop generalized AI or machine learning models.
  • We access platform data only while the account is connected and only to perform actions you have explicitly configured. We do not autonomously publish or interact with third-party content.
  • When you disconnect an account or delete your PostClaw account, we revoke tokens and delete associated cached platform data within 7 days (within 24 hours for X, per its stricter sync rule), except where retention is required by law (for example, financial records).
  • You may revoke PostClaw's access at any time from the connected platform's own authorized-apps settings.

17. AI and Machine Learning

PostClaw offers optional AI-assisted features such as caption suggestions, image generation, and content repurposing. When you use these features, your inputs are sent to the AI model provider(s) configured for your account.

  • We do not use your content, connected social platform data, or Google user data to train, fine-tune, or develop any generalized AI or machine learning models operated by PostClaw.
  • Inputs you submit to AI features are processed by upstream providers solely to return a result to you. We select providers that offer a "no-training" commitment for API data or operate under equivalent enterprise agreements.
  • You are solely responsible for reviewing AI-generated content before publishing it to any social platform.
  • If you "bring your own key" (BYOK) for an AI provider, data handling is additionally governed by that provider's terms.

18. Subprocessors

We engage the following third-party subprocessors to operate the Service. All subprocessors are bound by written data processing agreements:

  • Amazon Web Services (AWS) — cloud infrastructure, database, and file storage (United States, European Union regions).
  • Cloudflare — content delivery network, DDoS protection, DNS (global).
  • Stripe — payment processing and subscription billing (United States).
  • Resend — transactional email delivery (United States).
  • AI model providers — Google Gemini, OpenAI, Anthropic, DeepSeek, Together AI, ElevenLabs, Fish Audio, MiniMax, Kling, and similar services, used only when you invoke an AI-assisted feature.

We update this list when subprocessors change. Subscribe to product updates or contact [email protected] to be notified of material changes.

19. California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act and California Privacy Rights Act provide you with additional rights regarding personal information we collect about you.

Categories of personal information we collect

In the preceding twelve months, we have collected the categories of personal information described in Section 2 of this policy, including identifiers, commercial information, internet activity, and inferences used to provide and improve the Service.

Your California rights

  • Right to know — request disclosure of the personal information we have collected, used, and shared about you.
  • Right to delete — request deletion of personal information we have collected from you, subject to legal exceptions.
  • Right to correct — request correction of inaccurate personal information.
  • Right to opt out of sale or sharing — we do not sell your personal information and do not share it for cross-context behavioral advertising.
  • Right to limit use of sensitive personal information — where applicable.
  • Right to non-discrimination — we will not discriminate against you for exercising any of these rights.

To exercise any of these rights, email [email protected]. We will respond within the timeframes required by law.

20. Data Breach Notification

We maintain incident response procedures to detect, contain, and investigate security incidents. If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify affected users and applicable supervisory authorities without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33–34 and other applicable laws.