Privacy Policy
Last updated 9 September 2026
Social Autopilot is a social media scheduling and automation service. It lets you connect your own social media accounts, plan and schedule posts, optionally generate post content with AI, and publish those posts automatically at the times you choose.
This policy describes what the service stores, why, and how to remove it. It covers the application at this domain only.
Information we process
We store only what the service needs in order to work:
- Account details — your name, email address, and a hashed version of your password. Passwords are hashed with bcrypt and are never stored in readable form.
- Connected social accounts — for each platform you connect: the account, Page, or channel name, its identifier on that platform, and the OAuth access token (and refresh token, where the platform issues one) together with its expiry.
- Scheduled content — the posts you create or approve: their text, the platform, the scheduled time, any images or videos you upload or that are generated for them, publication status, and any error a platform returned.
- Brand profile — if you use the autopilot features, the website address you provide, text read from the public pages of that site, and the facts extracted from it. Each stored fact keeps the page it came from and the exact wording that supports it.
- Domain verification — the domain you claim and a single-purpose random token used to confirm you control it.
- Billing identifiers — if you subscribe, the customer and subscription identifiers issued by our payment processor, plus your plan status. We never receive or store your card details; payment information is handled entirely by the payment processor.
- Operational records — counters used to rate-limit abuse-prone actions such as sign-in attempts, and records of AI generation attempts used to apply plan limits.
How connected account access is used
When you connect a social account, that platform issues an access token which the service stores and uses solely to carry out the actions you have asked for:
- reading the list of Pages, channels, or business accounts you manage, so you can choose which one to post to;
- reading the display name of the selected account, so the interface can show you which account is connected;
- publishing the posts you have scheduled or approved, at the time you scheduled them.
Access tokens are not sold, shared, rented, or used for advertising, profiling, or any purpose other than operating the integrations you have explicitly connected. They are not used to read your private messages, personal timeline, or contacts.
TikTok. When you connect a TikTok account, TikTok gives us two pieces of information about it: an account identifier (open_id), which we store so a scheduled post is published to the right account, and the account's display name, which we store and show on the Connected Accounts screen so you can see which account is linked. We also store the access token and refresh token TikTok issues, together with their expiry. We request only the user.info.basic and video.publish permissions: we do not read your followers, your videos, your profile statistics, or anything else about your account.
Each time you open the TikTok posting screen, we ask TikTok for that account's current settings — the nickname it displays, which audiences the account allows, and whether comments, Duet or Stitch are turned off — so that the choices offered to you are current rather than remembered from earlier. Those settings are used to draw the screen and are not stored.
Nothing is sent to TikTok until you have reviewed the post and confirmed it. You choose the audience yourself — there is no default — along with the comment, Duet and Stitch settings and any commercial content disclosure, and you must agree to TikTok's declaration before the post can be scheduled or published. We store the choices you made for that post and a record that you approved it, including when you did so and the exact declaration you agreed to. Posts that this service suggests automatically are never published to TikTok without that review, and if the post or its settings change afterwards, it has to be reviewed again before it can be published.
When the post is published, its caption and video are sent to TikTok's Content Posting API — either uploaded directly, or retrieved by TikTok from a link on our own domain that is specific to that one post and expires shortly after it is created. Disconnecting the account or deleting your account removes the stored tokens and account record, as described below.
Service providers
The service runs on infrastructure and tools operated by other companies, which process data on its behalf:
- hosting, media storage, and the application database;
- an AI provider, which receives the prompts and brand profile text used to generate captions, images, and video for your posts;
- an email provider, for verification and password-reset emails;
- a payment processor, if you subscribe to a paid plan;
- the social media platforms you choose to connect, which receive the posts you publish through the service.
Disconnecting an account
You can disconnect any social account at any time from Connected Accounts in the dashboard. Disconnecting immediately deletes our stored record for that platform, including the access token.
Please note: disconnecting removes our copy of the token, but it does not revoke the permission on the platform's side. To revoke it fully, also remove the app from that platform's own settings — for example, under Business Integrations or Apps and Websites.
Deleting your account and data
You can delete your account from Settings in the dashboard. Deleting your account permanently removes your user record, your sign-in sessions, every connected social account and its stored tokens, your scheduled and published post records, your brand profile and its stored facts, and your domain verification record. If you have an active paid subscription, it is cancelled as part of the deletion.
The same caveat applies as above: deletion removes our stored copy of your access tokens but does not revoke them at the platform, so you should also remove the app in the platform's own settings.
Posts already published to a social platform are not removed by deleting your account — they exist on that platform and must be deleted there.
Data deletion requests
If you cannot sign in — for example you have lost access to your email, or you connected through a social platform and no longer have access to that account — you can ask us to delete your data instead.
Send a deletion request to ibrahimdemirhan442@gmail.com with the subject "Data deletion request", including:
- the email address on the Social Autopilot account, and
- if you connected a Facebook Page, Instagram business account, YouTube channel, or TikTok account, its name — so we can confirm which records to remove.
Please send the request from the email address registered on the account where possible, as that is how we confirm the request is genuinely yours. If you cannot, we may ask you for another way to confirm ownership before deleting anything, so that no one can have someone else's data erased.
We aim to action verified requests within 30 days and will confirm by email once the deletion is complete.
A deletion request removes the same data as deleting your account from Settings, described in the section above: your account record, sessions, every connected social account and its stored access tokens, your scheduled and published post records, your brand profile and its stored facts, and your domain verification record. An active paid subscription is cancelled as part of the deletion.
Two limits are worth repeating here. Deletion removes our stored copy of your access tokens but does not revoke them at the social platform, so you should also remove Social Autopilot from that platform's own settings. And posts already published to a platform remain on that platform and must be deleted there.
Security
Traffic to the service is served over HTTPS. Passwords are stored only as bcrypt hashes. Access tokens are stored in the application database and are used only by the server. Sign-in, password reset, and email verification are rate-limited to limit abuse.
No online service can promise perfect security, and we do not claim to. If you believe an account has been compromised, change your password and disconnect the affected platforms.
Changes
This policy may be updated as the service changes. The date at the top of this page reflects the most recent revision.
Contact
Questions about this page, your data, or this service can be sent to ibrahimdemirhan442@gmail.com.