Privacy Policy
XPost Privacy Policy
Effective date: June 16, 2026
XPost is a video cross-posting and scheduling service operated by All AI Company. In this policy, the terms we, us, and our refer to All AI Company. This policy explains what information we collect, how we use it, and the choices available to people who use the app.
Information We Collect
We collect the information needed to authenticate users, connect social accounts, and publish scheduled content. This can include:
- Email address and authentication session information.
- Connected account details returned by authorized social platforms, such as channel, Page, board, or account names and IDs.
- OAuth access tokens and refresh tokens for connected providers. These tokens are encrypted before storage.
- Post content you create in the app, including captions, titles, destination platforms, scheduled times, public media URLs, uploaded media references, and publishing status.
- Operational logs such as publish results, provider response IDs, error messages, timestamps, and basic request metadata needed to run and secure the service.
How We Use Information
We use information to:
- Sign users in and protect access to the dashboard.
- Connect authorized social accounts through OAuth and retrieve the destinations available to the user, such as channels, boards, Pages, or creator accounts.
- Create, schedule, and publish posts to the destinations selected by the user.
- Refresh provider tokens, troubleshoot failed publishing attempts, maintain security, and prevent misuse.
- Comply with applicable platform rules, legal obligations, and developer program requirements.
Connected Social Platforms
When you connect a social platform, that platform may share account, destination, and token information with XPost based on the permissions you approve. XPost uses those permissions only to provide the requested scheduling and publishing features. You can revoke access through the relevant provider account settings, and you may ask us to remove stored connection data.
YouTube API Services. XPost uses YouTube API Services to upload and manage videos on the YouTube channel you connect. By connecting YouTube you agree to the YouTube Terms of Service, and your Google data is handled under the Google Privacy Policy. You can revoke the access you granted to XPost at any time through Google security settings. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: we use Google and YouTube data only to provide the user-facing features of XPost, and never for advertising or to train AI models.
Service Providers
We use trusted infrastructure providers to operate the app, including Vercel for hosting and Supabase for authentication, database, and storage services. We may also send content and authorization requests to social platforms you connect, such as Pinterest, Meta, Google/YouTube, TikTok, LinkedIn, or other providers added to the product.
We do not sell personal information, run third-party advertising in the app, or use connected account content to train AI models.
Data Retention
We keep account, connection, post, and publishing information for as long as needed to provide the service, troubleshoot publishing activity, comply with platform rules, or meet legal obligations. Users may request deletion of their account data or connected account tokens. Some operational records may be retained for a limited period where needed for security, abuse prevention, or compliance.
Security
We use reasonable technical and organizational safeguards for the size and nature of the service. OAuth tokens are encrypted before storage, access to the dashboard is restricted, and provider secrets are kept server-side. No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security.
Your Choices
- You can choose which social accounts and destinations to connect.
- You can revoke platform access directly from the relevant social platform settings.
- You can request access, correction, export, or deletion of data associated with your account.
- You can stop using the app at any time and ask us to remove stored provider tokens.
Deletion instructions are available at /data-deletion.
Children
XPost is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
Changes
We may update this policy as the product, providers, or legal requirements change. The updated policy will be posted on this page with a new effective date.
Contact
For privacy questions or requests, contact All AI Company at support@allaicompany.com.