Security & privacy

Security & privacy

Straight answers about what we collect, where it lives, and what we've certified — and what we haven't, yet.

Encrypted in transit & at rest
Official APIs only
SOC 2 Type II: in progress

What we collect

Account details (name, email, password hash), the Brands and platform connections you set up, the content you draft and publish, and the analytics your connected platforms make available through their official APIs — reach, engagement, follower counts, ad spend and results, and inbox messages tied to your accounts.

We also collect basic product usage (which pages you visit in the console, which features you use) so we can tell what's actually being used.

How we use it

To run the product: schedule and publish your posts, generate the agent's draft suggestions from your own past performance, calculate your reports, and show your team the right permissions. We don't sell your data, and we don't use your content to train models shared with other customers.

Where it lives

Production data is hosted in US-East (Virginia) and EU-West (Ireland) regions, depending on the billing region you sign up under. Backups are encrypted and retained for 30 days. All data is encrypted in transit (TLS 1.2+) and encrypted at rest (AES-256).

Your rights under GDPR

If you're in the EU/EEA or UK, you can request access to your data, export it in a portable format, correct inaccurate records, delete your account and associated data, and object to specific processing. Email privacy@agentpost.top from your account address; we confirm receipt within 3 business days and resolve most requests within 30 days, as required by law.

Team permissions per Brand

Every teammate is assigned one role per Brand, not one role account-wide.

RoleCan do
OwnerFull control, including billing, deleting the Brand, and transferring ownership.
AdminManage platform connections and team members. No access to billing.
EditorCreate, schedule and approve content. Can't invite or remove teammates.
Client-viewerRead-only access to reports and shareable links. Can't edit or publish.

How we connect to platforms

We connect to Facebook, Instagram, LinkedIn, X, TikTok, Pinterest, YouTube, Google Business and the rest of our platform list through their official, documented APIs only — never scraping, never undocumented endpoints. At connect time we show you exactly which permissions we're requesting and why, scope by scope, before you approve.

connect — facebook page permissions · Riverside Coffee Co.

AgentPost is requesting the following permissions from Facebook:

  • pages_manage_posts

    Publish and schedule the posts you approve.

  • pages_read_engagement

    Read reach and engagement for your own posts.

  • pages_show_list

    List the Pages you can choose to manage.

Token health: checked every 6 hours

We monitor the health of every connection token and warn you in the console before one expires or a platform revokes access, instead of letting posts silently fail.

Certifications

SOC 2 Type II: in progress, not yet certified. We're in the audit window and will publish the report when it's issued. We follow GDPR principles for all EU/EEA and UK user data (data minimization, lawful basis for processing, the rights listed above), and honor CCPA requests for California residents (know, delete, opt out of sale — we don't sell personal data).

If something goes wrong

If we discover a breach affecting your data, we notify affected account owners by email and post to our status page. Where GDPR applies, we notify the relevant supervisory authority within 72 hours of becoming aware, as required, and tell you what happened, what data was involved, and what we're doing about it.

Contact

Questions about security or privacy, or a request under GDPR/CCPA: privacy@agentpost.top