PRIVACY POLICY
Last updated: 3 August 2026
1. Data controller
The Mypostlify service is operated by a self-employed individual registered in Switzerland, AVS No. 756.1225.2844.82 (“we”, “the operator”). We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU GDPR. For any question about the processing of your personal data, contact us at admin@mypostlify.com.
2. What data we collect
We may process:
- Name;
- Email address;
- Phone number;
- IP address;
- Browser and device technical data;
- Authentication data;
- Content and posts you create and schedule through connected social accounts;
- Media files you upload to the service for publishing;
- Data received from the social networks you connect — see section 5;
- Cookie identifiers and analytics/advertising data (see section 8).
3. Purposes and legal basis
We process data to:
- provide the service and perform our contract with you;
- authenticate users and ensure security (legitimate interest);
- issue invoices and meet accounting/tax obligations (legal obligation);
- provide technical support;
- run analytics and advertising — only with your consent.
4. Data retention
Account data, your content and scheduled posts are kept while your account is active and deleted after the account is terminated, except for records we must keep by law (e.g. invoices). Data received from connected social networks is kept only while that network stays connected — see sections 5 and 6. Analytics/advertising data is retained according to the providers’ settings.
5. Connected social networks
Mypostlify publishes content to social networks on your behalf and brings the reactions back into one workspace. You choose which networks to connect. We access only the accounts, Pages, channels and profiles that you explicitly connect, we act only when you ask us to, and we never post, comment or moderate automatically.
Access tokens are stored encrypted. Data received from a network is visible only inside the workspace of the user who connected that account. We never sell it and never share it with third parties, other than the infrastructure providers listed in section 7.
What each network gives us:
- Facebook Pages — the list of Pages you manage (only the one you pick is stored), your Page’s posts and their reaction and comment counters, comments left by other people on those posts, and Page statistics. We publish posts and photos or videos to the Page, reply to comments on behalf of the Page, post the Page’s own comments, and hide, unhide or delete comments when you tell us to.
- Instagram — connected through Instagram Login, not through a Facebook Page. We read the account id, username and profile picture, the account’s own posts, the comments under them, and account and post statistics. We publish photos, videos and carousels, and reply to, hide or delete comments at your request.
- Threads — the profile id and username, the profile’s own posts, the replies under them, and profile and post statistics. We publish posts and reply to or hide replies at your request. Threads offers no delete action for other people’s replies, so we do not provide one.
- Telegram — you supply a bot token that you created yourself and pick the channel or group. We store the token and the chat identifier and use them to publish your messages. Telegram’s Bot API gives us no access to your personal Telegram account or your private chats.
- X (Twitter) — the profile id and username, and permission to publish the posts you compose.
- TikTok — the basic profile (open id, display name, avatar) and permission to upload the videos you compose.
- YouTube — the name of the channel you connect and permission to upload the videos you compose.
- LinkedIn — your identity through OpenID Connect (id, name, picture) and permission to publish the posts you compose to your profile or to a company page you administer.
Meta platforms (Facebook, Instagram, Threads)
Data obtained from Facebook, Instagram and Threads is Platform Data within the meaning of the Meta Platform Terms, and we handle it accordingly: it is used only to provide the features described above, it is never sold or transferred, and it is deleted when you disconnect the account or delete your Mypostlify account. Disconnecting a network in “Social accounts” immediately deletes the stored access token together with everything we cached for that account — the post feed, the comments, the metrics and the statistics snapshots.
YouTube
Mypostlify uses YouTube API Services. By connecting a YouTube channel you also agree to the YouTube Terms of Service, and the Google Privacy Policy applies to the data Google processes. You can revoke Mypostlify’s access to your Google account at any time at myaccount.google.com/permissions. We store only the channel name and the identifiers of the videos we uploaded for you; that data is refreshed or deleted within 30 days.
Other networks
You can revoke Mypostlify’s access at any time from the settings of the network itself: connected apps in X, TikTok and LinkedIn, or by revoking the bot token in Telegram’s BotFather. Revoking access in the network stops any further publishing immediately; to also remove what we have already stored, disconnect the account in Mypostlify or ask us to delete it (section 6).
6. Deleting your data
You are always in control of the data we hold:
- Disconnect one network. Open “Social accounts” in your workspace and press “Disconnect account”. The access token and everything we cached for that account — posts, comments, metrics and statistics snapshots — are deleted immediately and irreversibly.
- Delete everything. Email admin@mypostlify.com from the address registered in your account with the subject “Data deletion”. We verify the request, delete your account together with all connected accounts, content, media files and platform data, and confirm by email within 30 days. Only records we are legally required to keep, such as invoices, remain.
Deleting your Mypostlify account does not delete the posts that were already published to your social networks — those belong to your accounts on those networks and have to be removed there.
7. Sharing with third parties
We share data only with:
- Stripe — payment processing;
- cloud/hosting providers — infrastructure;
- the social networks you connect (Meta — Facebook, Instagram, Threads; Telegram; X; TikTok; YouTube; LinkedIn) — to publish your content and to bring back the comments and statistics of your own accounts;
- Google (Analytics, Ads) and Meta (Pixel) — analytics and advertising, only with your consent;
- government authorities — where required by law.
We do not sell your personal data.
8. Cookies and similar technologies
We use:
- necessary cookies — authentication, language and security (always on);
- analytics and advertising cookies/pixels — Google Analytics, Google Ads and Meta Pixel — used only after you accept them in our cookie banner.
You can change or withdraw your choice at any time via “Cookie settings” or by clearing cookies in your browser.
9. International transfers
The operator is based in Switzerland, which the EU recognises as providing an adequate level of data protection. Some providers (e.g. Stripe, Google, Meta) may process data outside Switzerland or the EEA; such transfers rely on appropriate safeguards, such as adequacy decisions or the EU Standard Contractual Clauses.
10. Security
We apply technical and organisational measures, including encryption of access tokens, access control and protection against unauthorised access.
11. Your rights
You have the right to access, rectify, erase and port your data, to restrict or object to processing, and to withdraw consent at any time. You also have the right to lodge a complaint with a data-protection supervisory authority — in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC); in the EU/EEA, your local authority.
12. Contact
For any privacy request, email admin@mypostlify.com.
We use cookies and similar technologies for site analytics and advertising (Google, Meta). Choose whether to allow them. Privacy policy