Legal
Privacy Policy
Last updated 2026-08-06
On this page
1. What we collect
To run your account, we hold: your email and account details; the documents and URLs you submit for a campaign; the credentials for the social account(s) you connect; and your own AI provider API key.
2. How your AI key is handled
Every credential you give us — your connected-account authorization and your AI provider key — is encrypted at rest and never displayed in full again once saved; only a masked last few characters are ever shown back to you.
Your AI provider key is used only to generate your own posts. It is never pooled, shared, or used on behalf of any other customer.
3. Data isolation
Your documents, posts, and account connections are yours alone. One customer's data is never visible to another, by design — not "usually kept separate," but structurally isolated at every level of the system.
4. Published posts
Once a post is live on a platform, we can't recall it. Deleting a campaign, or your account, removes it from ExoPost but not from a platform it was already published to — that has to be done on the platform itself.
5. Account deletion
Requesting deletion starts a short hold period during which you can cancel the request. After that window, your data is fully and irreversibly removed.
6. Third parties we work with
We work with a small number of processors to run the service: a payment processor for billing, an email delivery provider for account and notification email, and — on your instruction — your own chosen AI provider and the social platforms you connect. For site analytics we use Vercel Analytics and Cloudflare Analytics (both privacy-conscious, cookie-free); we also plan to use Umami Analytics, a privacy-focused, self-hostable analytics tool. No data is sold.
7. Your rights
You can access, export, or request deletion of your data at any time from your account settings, or by reaching out through our Contact page.
8. Contact
Questions about this policy can be sent through our Contact page.