Security & privacy
Security & privacy
Straight answers about what we collect, where it lives, and what we've certified — and what we haven't, yet.
What we collect
Account details (name, email, password hash), the Brands and platform connections you set up, the content you draft and publish, and the analytics your connected platforms make available through their official APIs — reach, engagement, follower counts, ad spend and results, and inbox messages tied to your accounts.
We also collect basic product usage (which pages you visit in the console, which features you use) so we can tell what's actually being used.
How we use it
To run the product: schedule and publish your posts, generate the agent's draft suggestions from your own past performance, calculate your reports, and show your team the right permissions. We don't sell your data, and we don't use your content to train models shared with other customers.
Where it lives
Production data is hosted in US-East (Virginia) and EU-West (Ireland) regions, depending on the billing region you sign up under. Backups are encrypted and retained for 30 days. All data is encrypted in transit (TLS 1.2+) and encrypted at rest (AES-256).
Your rights under GDPR
If you're in the EU/EEA or UK, you can request access to your data, export it in a portable format, correct inaccurate records, delete your account and associated data, and object to specific processing. Email privacy@agentpost.top from your account address; we confirm receipt within 3 business days and resolve most requests within 30 days, as required by law.
Team permissions per Brand
Every teammate is assigned one role per Brand, not one role account-wide.
| Role | Can do |
|---|---|
| Owner | Full control, including billing, deleting the Brand, and transferring ownership. |
| Admin | Manage platform connections and team members. No access to billing. |
| Editor | Create, schedule and approve content. Can't invite or remove teammates. |
| Client-viewer | Read-only access to reports and shareable links. Can't edit or publish. |
How we connect to platforms
We connect to Facebook, Instagram, LinkedIn, X, TikTok, Pinterest, YouTube, Google Business and the rest of our platform list through their official, documented APIs only — never scraping, never undocumented endpoints. At connect time we show you exactly which permissions we're requesting and why, scope by scope, before you approve.
AgentPost is requesting the following permissions from Facebook:
pages_manage_posts
Publish and schedule the posts you approve.
pages_read_engagement
Read reach and engagement for your own posts.
pages_show_list
List the Pages you can choose to manage.
We monitor the health of every connection token and warn you in the console before one expires or a platform revokes access, instead of letting posts silently fail.
Certifications
SOC 2 Type II: in progress, not yet certified. We're in the audit window and will publish the report when it's issued. We follow GDPR principles for all EU/EEA and UK user data (data minimization, lawful basis for processing, the rights listed above), and honor CCPA requests for California residents (know, delete, opt out of sale — we don't sell personal data).
If something goes wrong
If we discover a breach affecting your data, we notify affected account owners by email and post to our status page. Where GDPR applies, we notify the relevant supervisory authority within 72 hours of becoming aware, as required, and tell you what happened, what data was involved, and what we're doing about it.
Contact
Questions about security or privacy, or a request under GDPR/CCPA: privacy@agentpost.top