Privacy Policy

Privacy Policy

Last updated: July 13, 2026

This policy covers the information we use to run the website, dashboard, social publishing tools, API, billing, support, and connected social platform integrations.

Who we are

PostZen is operated by Dead Unicorn Inc., a company located in Alberta, Canada. This policy explains how we handle personal information when you visit PostZen, create an account, connect social accounts, use our API, or contact us.

When this policy refers to Meta Platform Data, it means data we receive from or process through Meta products and APIs when you choose to connect Facebook Pages, Instagram professional accounts, or Threads accounts to PostZen.

When you connect TikTok, PostZen uses TikTok Login Kit and the Content Posting API only for the TikTok features you choose to use, such as connecting your TikTok account, preparing post settings, uploading media, publishing content, and checking publish status.

When you connect YouTube, PostZen uses Google OAuth and the YouTube Data API only for the YouTube features you choose to use, such as identifying the YouTube channel you connect and uploading selected videos with the settings you provide.

Information we collect

  • Account information, such as your name, email address, sign-in provider, verification emails, password reset activity, and workspace profile names.
  • Connected social account information, such as platform, account IDs, usernames, display names, profile URLs, avatars, OAuth scopes, permissions, connection status, and encrypted access or refresh tokens.
  • YouTube and Google account information, when you connect YouTube, such as the connected channel ID, channel title, custom URL, profile URL, thumbnail or avatar URL, granted OAuth scopes including youtube.readonly and youtube.upload where authorized, encrypted Google OAuth access or refresh tokens, connection status, and token expiration details.
  • YouTube publishing information, such as the selected YouTube account, uploaded video URL, title, description, tags, category, privacy status, Made for Kids designation, subscriber notification choice, upload status, errors, and resulting YouTube video ID or link where returned.
  • TikTok account and publishing information, such as TikTok open ID, display name, avatar, granted scopes including user.info.basic, video.upload, and video.publish where authorized, creator info returned by TikTok, privacy options, comment/Duet/Stitch settings, commercial-content disclosure choices, media URLs sent to TikTok, publish IDs, publishing status, errors, and resulting post links where returned.
  • Meta Platform Data, when you connect Meta products, such as app-scoped user IDs, Facebook Page IDs and names, Instagram professional account IDs, Threads account IDs, usernames, profile links, profile photos, granted scopes, connection status, post or media container IDs, permalinks, comments or first-comment text where enabled, basic insights where authorized, and Meta deauthorization or data-deletion request identifiers.
  • Content you provide, including posts, captions, media uploads, alt text, scheduled times, platform options, tags, drafts, publishing status, and related error messages.
  • API and integration data, including API key names, hashed API key tokens, key prefixes, selected profile access, idempotency keys, client references, webhook settings, and delivery events.
  • Billing and payment information needed to manage paid plans. Card details are processed by Stripe; we do not store full card numbers.
  • Support and communication data, such as messages you send us, email delivery records, and troubleshooting details.
  • Basic technical data, such as session cookies, authentication state, security logs, device/browser details, and product usage events needed to operate and secure the service.

How we use information

  • To create accounts, authenticate users, secure sessions, and prevent unauthorized access.
  • To connect social accounts, refresh tokens, validate permissions, display selectable accounts or Pages, publish or schedule content, read analytics where you authorize it, and show connection health.
  • To use youtube.readonly to identify and display the YouTube channel you chose to connect, verify that the account has an available YouTube channel, and keep the connection tied to the correct channel.
  • To use youtube.upload to upload the video you selected to the connected YouTube channel with your chosen title, description, privacy status, tags, category, Made for Kids designation, and subscriber notification setting, and to store the resulting YouTube video ID or URL so you can track the post.
  • To use TikTok user.info.basic for account identification, video.upload and video.publish for sending selected videos or photos to TikTok, creator_info/query for TikTok-required direct-post settings, and publish/status/fetch or related status handling so you can understand the result of a TikTok publish or inbox-upload attempt.
  • To process Meta Platform Data only for the features you request, such as connecting Facebook Pages, Instagram professional accounts, or Threads accounts; publishing or scheduling content and media; posting configured first comments; reading publishing status, permalinks, and authorized insights; honoring deauthorization and deletion callbacks; troubleshooting; security; and compliance.
  • To store media, prepare platform-specific posts, retry failed publishes, keep an audit trail of post status, and send configured webhooks.
  • To provide API keys, profile access controls, support, billing, product improvements, abuse prevention, and required service notices.
  • To comply with legal obligations and enforce our agreements.

Where privacy law requires a legal basis, we process information to perform our agreement with you, follow your instructions or consent, comply with legal obligations, protect PostZen and users, and pursue legitimate interests such as service reliability, security, support, and product improvement.

Cookies and similar technologies

We use necessary cookies and similar browser storage for authentication, security, preferences, and keeping the product usable. We do not sell personal information or use it for cross-site advertising.

When we share information

We share information only as needed to run PostZen, provide features you request, or meet legal requirements.

  • Service providers that host, store, secure, email, bill, monitor, or support PostZen, including backend, storage, email, and payment providers. These providers process information on our behalf to provide services to PostZen.
  • Connected social platforms and API providers, such as Meta/Facebook/Instagram/Threads, TikTok, LinkedIn, YouTube/Google, X, and any other platform you choose to connect.
  • Professional advisers, authorities, or other parties when required by law, to protect rights and safety, or as part of a business transaction.

Google and YouTube data controls

PostZen uses YouTube API Services to provide YouTube features. By connecting a YouTube channel or publishing to YouTube through PostZen, you also agree to the YouTube Terms of Service at https://www.youtube.com/t/terms. Google’s Privacy Policy, which describes how Google handles your information, is available at https://policies.google.com/privacy.

PostZen does not upload content to YouTube until you choose a connected YouTube channel, provide or select a video and YouTube post settings, and submit the post. YouTube publishing controls include title, description, visibility, tags, Made for Kids designation, and subscriber notification choices.

PostZen uses Google user data only to provide and improve user-facing YouTube connection and publishing features. We do not sell Google user data, transfer it to advertising platforms or data brokers, use it for retargeting or interest-based advertising, or determine credit-worthiness.

PostZen does not create, use, or share aggregated or anonymized datasets derived from Google user data. We do not use Google user data to train AI/ML models or transfer it to third-party AI/ML services for model training.

You can revoke PostZen access to your Google account at any time from Google account security settings at https://security.google.com/settings/security/permissions. Revoking access may stop future YouTube publishing until you reconnect.

TikTok data and publishing controls

PostZen does not publish or upload content to TikTok until you choose a TikTok account, provide or select media and post settings, and submit the post. TikTok publishing controls may include direct posting, inbox draft uploads, visibility, comment, Duet, Stitch, and commercial-content disclosure settings returned or required by TikTok.

We do not sell TikTok account data, tokens, creator info, post settings, media, or publishing status. We use TikTok data only to provide the connected TikTok features, operate and secure PostZen, troubleshoot, comply with law and platform requirements, and honor your choices.

Meta Platform Data restrictions

We do not sell, rent, or transfer Meta Platform Data to ad networks, ad exchanges, data brokers, or other advertising or monetization services. We do not use Meta Platform Data for cross-site advertising, unrelated profiling, or training general-purpose AI models.

We process Meta Platform Data only as described in this policy, our agreements with users, applicable law, Meta Platform Terms, and other applicable Meta policies. We keep the public privacy policy URL current in our Meta App Dashboard and other app stores or developer dashboards where required.

Storage, security, and transfers

We use reasonable administrative, technical, and organizational safeguards. OAuth tokens are encrypted before storage, API keys are stored as hashes, and access is limited to what is needed to operate PostZen.

We require service providers that handle connected-platform data to protect it, keep it confidential, use it only to provide services to PostZen, and delete it when it is no longer needed for those services, subject to legal limits.

Because we use cloud providers and connected platforms, information may be processed outside Alberta or Canada. Those locations may have different privacy laws.

Retention and deletion

We keep information for as long as needed to provide PostZen, maintain security, resolve disputes, comply with legal obligations, and preserve legitimate business records. We delete or de-identify connected-platform data when it is no longer needed to provide the service, when you disconnect or delete an account, when a platform deauthorizes our app, when Meta or another platform requires deletion, or when you make a valid deletion request, subject to legal limits.

Some backups, logs, billing records, security records, and legal records may be retained for a limited period where required or reasonably necessary.

Data deletion requests

To request deletion of your personal information, Google user data, YouTube account data, Meta Platform Data, or other connected-platform data, email hello.postzen@gmail.com with the subject "Data deletion request" and include the email address, workspace, and connected social account you want us to review. We may ask for information needed to verify the request.

When a verified deletion request is accepted, we delete or disconnect the applicable account records, encrypted OAuth credentials, cached avatars, unpublished drafts, media, API keys, and other personal information we control, unless retention is required by law, security, billing, dispute resolution, or legitimate business records. Content already published to a connected social platform must be removed from that platform through the platform or through PostZen features where available.

For Google and YouTube, you can also revoke PostZen from your Google account security permissions. If you request deletion or revoke access, we delete or disconnect the YouTube account records, encrypted OAuth credentials, cached channel details, unpublished drafts, media records we control, and related personal information we control, subject to the limits above.

For Meta products, you can also remove PostZen from your Facebook, Instagram, or Threads app settings. Where Meta sends us a signed data-deletion request, our callback deletes the related connected account records and credentials we control and returns a confirmation code and status URL to Meta.

Your choices

  • You can update account details and workspace profile information in the product where those controls are available.
  • You can revoke PostZen access from a connected social platform, including from Google account security permissions for YouTube, disconnect accounts in PostZen, remove API keys, delete supported content, and cancel scheduled posts where those controls are available.
  • You can request access, correction, deletion, or portability of your personal information, subject to legal limits.
  • You can opt out of non-essential communications. We may still send transactional, security, billing, or service messages.

Children

PostZen is not directed to children under 13 and should not be used by anyone who cannot legally enter into the applicable agreement for the service.

Changes to this policy

We may update this policy as PostZen, platform requirements, or legal requirements change. The updated date shows when the current version took effect. If a change materially affects how we process information, we will provide notice as required by law or through the service.

Contact

For privacy questions, access requests, correction requests, or data deletion requests, contact Dead Unicorn Inc. at hello.postzen@gmail.com.