Privacy Policy
Last updated: August 16, 2026
1. Introduction
FoPost is operated by Porter Bridge, LLC, a Delaware limited liability company ("we," "our," or "us"), located at 131 Continental Dr, Suite 305, Newark, DE 19713, United States. Porter Bridge, LLC is the data controller responsible for the personal information described in this policy.
FoPost provides an AI-powered social media automation engine available as an open-source SDK (self-hosted) and a managed Cloud service. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website (fopost.com), Cloud dashboard (app.fopost.com), SDK packages, API, and related services (collectively, the "Service").
By using FoPost, you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use of the Service.
2. Information We Collect
2.1 Personal Information
When you create an account or interact with our Service, we may collect:
- Name and email address
- Billing and payment information (processed securely via third-party providers)
- Organization or company name
- Profile information you provide
2.2 Social Media Account Data
When you connect social media accounts to FoPost, we access data necessary to publish and manage content on your behalf across the 30 supported platforms, including X (Twitter), Facebook, Instagram, Instagram Business, LinkedIn, TikTok, YouTube, Threads, Bluesky, Pinterest, Reddit, Discord, Mastodon, Telegram, Slack, DEV.to, Hashnode, Medium, Substack, Tumblr, WordPress, Google Business Profile, Dribbble, Twitch, Kick, Nostr, Lemmy, MeWe, Whop, Skool, and Listmonk. This includes:
- Account identifiers and access tokens
- Profile information (name, handle, avatar)
- Content you create, schedule, or publish through the Service
- Engagement metrics and analytics data where available
2.3 Usage Data
We automatically collect certain information when you use our Service:
- IP address, browser type, and operating system
- Pages visited, features used, and actions taken
- Device information and unique identifiers
- API request logs and SDK usage patterns (Cloud service only)
2.4 Self-Hosted SDK
If you use our open-source SDK in a self-hosted environment, your content and social media credentials remain on your own servers. We do not collect, access, or store any of your data in self-hosted deployments unless you explicitly opt in to telemetry or connect to our Cloud API endpoints.
2.5 Google API Services (YouTube and Google Drive)
FoPost uses YouTube API Services so you can connect your YouTube channel and publish and manage videos. By connecting a YouTube account you also agree to the YouTube Terms of Service. Information FoPost receives from Google APIs is handled in accordance with the Google Privacy Policy.
Through the YouTube Data API, FoPost accesses only your own channel: your channel's basic information, the public statistics of videos you publish through FoPost, and the ability to upload videos to, and delete videos from, your channel on your behalf. We do not access any other user's YouTube data.
If you connect Google Drive, FoPost can access only the specific files you select in the Google file picker. We use that access to copy the files you pick into yourFoPost media library, and to refresh a picked file when you ask us to. We never browse, list, or read anything else in your Drive, and imported copies are stored, protected, and deleted exactly like files you upload directly (see Sections 8 and 10). Disconnecting Google Drive stops all further access; already imported copies remain in your library until you delete them or your account.
FoPost does not use any data obtained through Google APIs, including Google Workspace APIs such as Google Drive, to develop, improve, or train generalized or non-personalized artificial intelligence or machine learning models.
FoPost's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can review or revoke FoPost's access to your Google account at any time from your Google Account permissions page, or by disconnecting the account in FoPost.
2.6 Canva and Dropbox Imports
If you connect Canva or Dropbox, FoPost can read only what is needed to import the items you choose: with Canva, the designs you select and their exported image or video files; with Dropbox, the files you select. We use that access to copy your selection into your FoPost media library and to refresh an imported item when you ask us to. We do not modify or delete anything in your Canva or Dropbox account, and we do not disclose imported content to anyone except as described in Section 6.
Imported copies are stored, protected, and deleted exactly like files you upload directly (see Sections 8 and 10), and the rights described in Section 9 apply to them. We do not use content imported from Canva, Dropbox, or any other connected source to develop, improve, or train generalized artificial intelligence or machine learning models. Disconnecting a source in FoPost stops all further access, and you can also revoke FoPost's access from your Canva or Dropbox account settings; already imported copies remain in your library until you delete them or your account.
2.7 Connected View Data
A connected account can also see content that is not yours: replies, comments and mentions from other people, and the public posts of accounts you ask us to track. Where we read that, we store what the platform returns, which can include the text of an item, its author's public name, handle and avatar, a link to it, and its timestamp. Section 5 explains what we do with it and where it can never go.
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service
- Process and publish content to your connected social media platforms
- Power AI-driven content optimization and recommendations
- Process payments and manage subscriptions
- Communicate with you about your account, updates, and support
- Analyze usage patterns to improve the Service
- Detect, prevent, and address fraud, abuse, or technical issues
- Comply with legal obligations
4. AI-Powered Features
FoPost includes AI-powered features such as content optimization, smart scheduling, and automated content adaptation. When you use these features through our Cloud service:
- Your content may be processed by our AI models to generate suggestions and optimizations
- We do not use your content to train our AI models without your explicit consent
- AI-generated content suggestions are provided for your review before publishing
- You retain full ownership of all content, including AI-assisted modifications
5. Connected Views and Derived Signal
A connected account can see things on its platform that are not your own content: the replies, comments and mentions that reach it, and, where you name accounts to track, what those accounts publish publicly. We call that your connected view. We read it through the platform's official interfaces, under the authorisation you gave when you connected the account, and only for the accounts you connected and the accounts you asked us to track.
5.1 What we do with a connected view
We process it to run the features you are using, and we derive aggregate and derived signal from it: counts, scores, benchmarks and trend statistics that describe patterns rather than any individual item. That signal powers your analytics, timing suggestions and benchmarks, and helps us improve the Service.
5.2 What never leaves your workspace
The contents of a connected view are never disclosed to another customer, in any form. That covers:
- The text of posts, comments, replies or messages
- The identity of the people who appear in your connected view
- Direct messages, and your follower or audience lists
- Anything from which the above could be reconstructed
There is no anonymised version of those contents that we treat as shareable. Text is identifiable on its face, so the rule is that it does not move.
5.3 When a statistic may be shared
A statistic derived from your connected view is only ever published outside your workspace once it covers enough distinct sources and enough distinct customers that no single item, account or customer can be recovered from it. A number describing one customer is that customer's data, and it stays with them. This is enforced in the product, not left to judgement.
5.4 What happens when you leave
Disconnecting a social account removes the connected-view records read through it. Deleting a workspace removes that workspace's records, and closing your account removes them for every workspace your departure leaves empty. Aggregate statistics that already cover enough distinct sources and customers to be non-identifying may be retained, on the same basis as the aggregated data described in our retention section: they no longer describe you.
If you use FoPost to process data you are responsible for as a controller, our Data Processing Agreement sets out the same commitments in contractual form.
7. Government and Law Enforcement Requests
We may receive requests from public authorities for user data. We do not disclose data to any public authority voluntarily. Every request is handled under the following process:
- Legality review: we review each request to confirm it is valid, properly issued, and legally binding on us before any data is disclosed
- Right to challenge: we object to, narrow, or challenge any request we believe to be unlawful, overbroad, or improperly issued
- Data minimization: where disclosure is required, we disclose only the minimum information necessary to satisfy the request
- Documentation: we record each request, the authority making it, our legal reasoning, and the response we provided
Where we are legally permitted to do so, we notify affected users before disclosing their data.
8. Data Security
We implement industry-standard security measures to protect your data, including:
- Industry-standard encryption of sensitive data in transit and at rest
- Secure storage of API tokens and credentials using encryption
- Regular security audits and vulnerability assessments
- Access controls and authentication for all internal systems
While we strive to protect your information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
9. Your Rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict processing of your data
- Data portability: receive your data in a structured, machine-readable format
- Withdraw consent where processing is based on consent
To exercise any of these rights, please contact us via our form. We will respond within 30 days.
10. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service. Specific retention periods:
- Account and content data: retained while your account is active, then deleted within 30 days of account deletion
- Social media access tokens: revoked and deleted immediately when you disconnect an account or delete your account
- Connected view records: deleted when you disconnect the account they were read through, when the workspace holding them is deleted, or when closing your account leaves that workspace with no members
- Billing and tax records: retained for 7 years after the transaction, as required by tax and accounting law
- Application and API logs: retained for up to 12 months, then deleted
- Error reports: retained for up to 90 days by our error-monitoring provider
- Aggregated, anonymized data: may be retained indefinitely for analytics, as it can no longer identify you
Content you have already published to a third-party platform is not affected by deletion of your FoPost account. To remove it, delete it on that platform. See our data deletion instructions for how to request deletion.
12. International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for international data transfers in compliance with applicable data protection laws.
13. Children's Privacy
FoPost is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal information, we will take steps to delete such information.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page and updating the "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the updated policy.
15. Contact Us
If you have questions about this Privacy Policy, please reach out via our contact form:
Porter Bridge, LLC (operator of FoPost)
131 Continental Dr, Suite 305, Newark, DE 19713, United States
Website: fopost.com