Privacy Policy
Last updated 30 July 2026
Social Autopilot is a social media scheduling and automation service. It lets you connect your own social media accounts, plan and schedule posts, optionally generate post content with AI, and publish those posts automatically at the times you choose.
This policy describes what the service stores, why, and how to remove it. It covers the application at this domain only.
Information we process
We store only what the service needs in order to work:
- Account details — your name, email address, and a hashed version of your password. Passwords are hashed with bcrypt and are never stored in readable form.
- Connected social accounts — for each platform you connect: the account, Page, or channel name, its identifier on that platform, and the OAuth access token (and refresh token, where the platform issues one) together with its expiry.
- Scheduled content — the posts you create or approve: their text, the platform, the scheduled time, any images or videos you upload or that are generated for them, publication status, and any error a platform returned.
- Brand profile — if you use the autopilot features, the website address you provide, text read from the public pages of that site, and the facts extracted from it. Each stored fact keeps the page it came from and the exact wording that supports it.
- Domain verification — the domain you claim and a single-purpose random token used to confirm you control it.
- Billing identifiers — if you subscribe, the customer and subscription identifiers issued by our payment processor, plus your plan status. We never receive or store your card details; payment information is handled entirely by the payment processor.
- Operational records — counters used to rate-limit abuse-prone actions such as sign-in attempts, and records of AI generation attempts used to apply plan limits.
How connected account access is used
When you connect a social account, that platform issues an access token which the service stores and uses solely to carry out the actions you have asked for:
- reading the list of Pages, channels, or business accounts you manage, so you can choose which one to post to;
- reading the display name of the selected account, so the interface can show you which account is connected;
- publishing the posts you have scheduled or approved, at the time you scheduled them.
Access tokens are not sold, shared, rented, or used for advertising, profiling, or any purpose other than operating the integrations you have explicitly connected. They are not used to read your private messages, personal timeline, or contacts.
Service providers
The service runs on infrastructure and tools operated by other companies, which process data on its behalf:
- hosting, media storage, and the application database;
- an AI provider, which receives the prompts and brand profile text used to generate captions, images, and video for your posts;
- an email provider, for verification and password-reset emails;
- a payment processor, if you subscribe to a paid plan;
- the social media platforms you choose to connect, which receive the posts you publish through the service.
Disconnecting an account
You can disconnect any social account at any time from Connected Accounts in the dashboard. Disconnecting immediately deletes our stored record for that platform, including the access token.
Please note: disconnecting removes ourcopy of the token, but it does not revoke the permission on the platform's side. To revoke it fully, also remove the app from that platform's own settings — for example, under Business Integrations or Apps and Websites.
Deleting your account and data
You can delete your account from Settings in the dashboard. Deleting your account permanently removes your user record, your sign-in sessions, every connected social account and its stored tokens, your scheduled and published post records, your brand profile and its stored facts, and your domain verification record. If you have an active paid subscription, it is cancelled as part of the deletion.
The same caveat applies as above: deletion removes our stored copy of your access tokens but does not revoke them at the platform, so you should also remove the app in the platform's own settings.
Posts already published to a social platform are not removed by deleting your account — they exist on that platform and must be deleted there.
Data deletion requests
If you cannot sign in — for example you have lost access to your email, or you connected through a social platform and no longer have access to that account — you can ask us to delete your data instead.
Send a deletion request to ibrahimdemirhan442@gmail.com with the subject "Data deletion request", including:
- the email address on the Social Autopilot account, and
- if you connected a Facebook Page or Instagram business account, its name — so we can confirm which records to remove.
Please send the request from the email address registered on the account where possible, as that is how we confirm the request is genuinely yours. If you cannot, we may ask you for another way to confirm ownership before deleting anything, so that no one can have someone else's data erased.
We aim to action verified requests within 30 days and will confirm by email once the deletion is complete.
A deletion request removes the same data as deleting your account from Settings, described in the section above: your account record, sessions, every connected social account and its stored access tokens, your scheduled and published post records, your brand profile and its stored facts, and your domain verification record. An active paid subscription is cancelled as part of the deletion.
Two limits are worth repeating here. Deletion removes our stored copy of your access tokens but does not revoke them at the social platform, so you should also remove Social Autopilot from that platform's own settings. And posts already published to a platform remain on that platform and must be deleted there.
Security
Traffic to the service is served over HTTPS. Passwords are stored only as bcrypt hashes. Access tokens are stored in the application database and are used only by the server. Sign-in, password reset, and email verification are rate-limited to limit abuse.
No online service can promise perfect security, and we do not claim to. If you believe an account has been compromised, change your password and disconnect the affected platforms.
Changes
This policy may be updated as the service changes. The date at the top of this page reflects the most recent revision.
Contact
Questions about this page, your data, or this service can be sent to ibrahimdemirhan442@gmail.com.