Legal
Privacy Policy
Last updated September 21, 2026. SproutPost turns your website into social content and publishes it to the accounts you connect.
1. Data we collect
Account data: name, email, and login identifiers from our authentication providers (Google, GitHub).
Your content: project URLs, brand profiles you write or we draft from your public site, generated post copy, ideas, and scheduling choices.
Connected social accounts: when you connect Facebook Pages, Instagram, Threads, LinkedIn, TikTok, YouTube, Pinterest, or Bluesky, we receive the platform's OAuth tokens plus the minimum profile identifiers needed to publish (Page IDs, Instagram/Threads user IDs, LinkedIn member ID, TikTok open ID, YouTube channel ID, Pinterest username, Bluesky DID/handle). Bluesky uses an app password you create — never your main password.
Published posts: the text, media references, and returned post IDs for content you choose to publish, so we can show status and errors.
2. How we use it
Exclusively to operate the service: generate drafts from your brand profile, publish only what you explicitly approve or schedule, show publishing status, and keep your connections working (token refresh). We never sell data, never post without your action, and never use your content to train models for other users.
3. How tokens are stored
OAuth access and refresh tokens are encrypted at rest (AES-256-GCM) and are never exposed to the browser or logged. They are transmitted only to the issuing platform's API to perform actions you requested.
4. Sharing
We share data only with the platforms you connect (Meta, LinkedIn, TikTok, Google / YouTube, Pinterest, Bluesky) to execute your publish requests, and with our infrastructure providers (hosting, Neon Postgres database). No advertising SDKs, no data brokers.
5. Retention
Account and content data is kept while your account is active. Disconnecting a social account immediately deletes its stored tokens. Deleting your SproutPost account deletes projects, drafts, connections, and tokens within 30 days (backups age out on the same schedule).
6. Your rights & deletion
Disconnect any account anytime in Accounts → Social connections. For full deletion (account + everything), see our data deletion instructions or email privacy@sproutpost.app — we confirm within 7 days.
7. Children
SproutPost is for business use and is not directed at children under 13.
8. Changes & contact
Material changes are announced in-app before they take effect. Data controller: SproutPost, privacy@sproutpost.app.