← Home

Privacy Policy

Last updated: 9 August 2026

Post Proofer ("we", "us") helps businesses and agencies plan, approve and publish social-media posts to their own Instagram and Facebook accounts. This policy explains what we collect, how we use it, and your choices. Questions: nelly@guestlistsocial.com.

Information we collect

  • Account details — your email address and, if provided, your name, so you can sign in and we can contact you.
  • Content you create — the captions, images, videos and schedules you add to plan your posts.
  • Connected social accounts (Meta) — when you connect a Facebook Page and its linked Instagram Business account, we receive the account's ID and username, the list of Pages you manage, and an access token that lets us act on your behalf. We also read post and account insights for accounts you connect, to show you performance.
  • Usage data — basic logs (e.g. errors, timestamps) needed to run and secure the service.

How we use Meta (Facebook & Instagram) data

We use the permissions you grant only to provide features you ask for:

  • Publish the specific posts you have created and approved, to the accounts you connected, at the times you scheduled.
  • Show which account a post will go to, and confirm the correct Page/Instagram account is linked.
  • Show insights (reach, engagement) for your own published posts.

We do not sell your data, use it for advertising, or share Meta data with third parties for their own purposes. We do not post anything you have not created and approved. Access tokens are stored encrypted on our servers and are never shown to other members of your team.

Who we share it with

We use a small number of service providers ("subprocessors") purely to run the product, under contract and only for that purpose:

  • Supabase — database and authentication.
  • Vercel — application hosting.
  • Resend — sending transactional email (invites, review digests).
  • Anthropic — optional AI features you trigger (e.g. caption suggestions).
  • Meta — to publish your content and read your insights, as above.

We may also disclose information if required by law.

How long we keep it

We keep your data while your account is active. When you delete your account (or an account/team), we delete the associated content, connected-account records and access tokens. See Data Deletion. Some minimal logs may be retained briefly for security and then removed.

Your choices and rights

  • Disconnect a social account at any time in the app, which removes our stored token for it.
  • Request access to, correction of, or deletion of your data by emailing privacy@postproofer.com.
  • Revoke our access from Meta directly: Facebook → Settings & Privacy → Settings → Business Integrations, or Instagram → Settings → Apps and Websites.

Security

We use industry-standard measures (encryption in transit, access controls, server-side token storage) to protect your data. No system is perfectly secure, but we work to keep yours safe.

Children

Post Proofer is for businesses and is not directed to children. Do not use it if you are under 18.

Changes

We may update this policy; we'll change the "last updated" date above and, for material changes, notify you.

Contact

Email nelly@guestlistsocial.com with any privacy questions or requests.