Legal
Privacy Policy
Last updated: 16 July 2026
This Privacy Policy explains what information Onepostly ("Onepostly", "we", "us", or "our") collects, how we use it, who we share it with, and the choices and rights you have. It applies to the Onepostly website at onepostly.com, the application at app.onepostly.com, and the API at api.onepostly.com (together, the "Service").
Onepostly is a developer API and dashboard for connecting social accounts and publishing, scheduling, measuring, and engaging across platforms from one interface. Because of how the Service works, we necessarily process account connection data, the content you ask us to publish, and related delivery metadata. This policy is written to be clear about exactly what that means.
If you have any questions about this policy or how we handle your data, contact us at privacy@onepostly.com.
1Who is responsible for your data
Onepostly is operated by Nobaly, LLC, a limited liability company formed in the State of New Mexico, USA, which is the controller of the personal data described in this policy. You can reach us at privacy@onepostly.com for any privacy matter, including to exercise the rights described in Section 8.
If you are in the European Economic Area (EEA), the United Kingdom, or another region with data-protection laws, the rights and protections described below apply to you regardless of where Onepostly operates.
If you use Onepostly to process personal data of your own end users (for example, when you connect your customers' social accounts through programmatic OAuth), you are typically the controller of that end-user data and Onepostly acts as a processor for the processing we perform on your instructions to operate the Service.
2Information we collect
2.1 Information you provide
Account information. You create an account with your email address, using a one-time code we send you, or by signing in with Google. Onepostly is passwordless; we never ask you for, or store, a password. If you sign in with Google, we receive your email address, name, and profile picture, and never your Google password.
Workspace and profile information. We store workspace (organization) details such as name, member emails and roles, invitations, and settings you configure in the dashboard.
Content you submit for publishing. Text, media files, captions, scheduling metadata, destination selections, and related instructions you send through the dashboard or API.
Communications. If you email us or contact support, we keep that correspondence.
2.2 Information we collect automatically
Session and security information. When you sign in, we store a session record that includes your IP address and browser user-agent string, together with the session token and its expiry. We use this to keep you signed in and to protect your account.
Bot-protection signals. We use Google reCAPTCHA on sign-in and sign-up to protect against automated abuse. reCAPTCHA collects device and behavioral information directly through your browser and shares it with Google; see Section 4.
API and product usage. We log API requests and operational events needed to provide the Service, enforce plan limits, meter wallet usage, deliver webhooks, debug failures, and secure accounts (for example request timestamps, endpoints called, status codes, and workspace identifiers).
2.3 Connected social accounts
When you connect a social account (via the dashboard or programmatic OAuth), we receive and store identifiers and profile fields returned by the platform (such as account id, handle, display name, and avatar where provided), OAuth access and refresh tokens, token expiry, granted scopes, and connection status. Tokens are stored encrypted. We use them only to perform the actions you request on that account (publish, read insights, manage comments or engagement, refresh tokens, and similar).
2.4 Billing and wallet information
Payments are handled by our payment processor, Stripe. Card numbers and payment details are entered into and processed by Stripe. We store your subscription tier, connected-account allowances, wallet balance and ledger entries for metered usage, and related billing metadata. See Section 4 and Section 5.
2.5 Webhooks and delivery metadata
If you configure webhooks, we store endpoint URLs, subscribed event types, signing secrets (hashed or otherwise protected), and delivery attempt history (status, timestamps, and response codes) so you can debug integrations.
2.6 Information we do not store
- We do not store full card or payment-instrument numbers on Onepostly servers.
- We do not store your Google password or Onepostly account password (we are passwordless).
- We do not sell personal data or share it with advertisers.
3How publishing and connections work
When you publish or schedule content, we store Your Content as needed to queue and deliver it, upload media to our object storage where required, call the destination platform's APIs using your connected-account tokens, and record destination status (queued, published, failed) and platform post identifiers. Scheduled posts are retained until they run or you cancel them.
When you request insights, comments, or engagement actions, we call the relevant platform APIs with your tokens and return normalized results to you. Platforms may impose their own retention, moderation, and visibility rules independently of Onepostly.
Important:Content you publish through Onepostly is sent to third-party social platforms under their terms. Once delivered, that content is also subject to those platforms' privacy and data practices. Disconnecting an account stops future API calls with that token; it does not remove content already published on the platform.
4Third parties and sub-processors
We share the minimum data necessary with the following service providers to operate the Service. Each processes data on our behalf or as an independent controller for their own stated purposes.
| Provider | Purpose | Data shared |
|---|---|---|
| Cloud infrastructure and hosting providers | API compute, queues, database, and hosting | Account and workspace data, API request metadata, post and connection records, and operational logs needed to run the Service. |
| Object storage | Media and related file storage for publishing | Uploaded media files and object metadata associated with your workspace. |
| Social platforms | OAuth connection and API actions you request | OAuth tokens and the content, media, and action parameters needed to publish, read insights, manage comments or engagement, and refresh connections. |
| Stripe | Payments, subscriptions, saved payment methods, and wallet top-ups | Your user or workspace identifier and email (to create a customer record) and subscription or top-up details. Card and payment data are handled by Stripe. |
| Auth (OAuth) and bot protection (reCAPTCHA) | For auth: your authentication request and the profile fields Google returns. For reCAPTCHA: device and interaction signals collected by Google in your browser. | |
| Email delivery provider | Transactional email (OTP codes, invites, notices) | Recipient email address and message content needed to send the email. |
We do not sell your personal data, and we do not share it with advertisers.
International transfers.Some of these providers operate outside your country. Where required, transfers are made under appropriate safeguards (such as the provider's standard contractual clauses). By using the Service you understand that your data may be processed in other countries.
The specific infrastructure and platform providers we use may change over time as we improve the Service and add social platforms.
5How we use your information
We use the information we collect to:
- Provide the Service: authenticate you, manage workspaces, connect accounts, publish and schedule content, deliver webhooks, show history and insights, and operate API access.
- Operate billing: manage subscriptions, wallet top-ups, metered deductions, and plan limits through Stripe and our own ledgers.
- Secure the Service: keep you signed in, detect and prevent abuse (including via reCAPTCHA), protect API keys, and investigate incidents.
- Communicate with you: respond to your messages and send service-related notices (for example security, billing, or product changes).
- Improve the Service: understand reliability, errors, and feature usage so we can make Onepostly better.
Legal bases (for EEA/UK users). We process your data to perform our contract with you (providing the Service and billing), to pursue our legitimate interests (securing and improving the Service) in a way that does not override your rights, and to comply with legal obligations. Where we rely on consent (for example, certain optional cookies or processing), you may withdraw it at any time.
6Data retention
- Account, workspace, and session data. Retained for the life of your account or workspace membership. Sessions expire automatically.
- Connected accounts and tokens. Retained until you disconnect the account, the token is revoked or expires without refresh, or the workspace is deleted.
- Posts, media, and delivery records. Retained so you can view history, retry or debug failures, and support webhooks, until you delete them where the product allows or you delete the workspace/account, subject to short-lived backups and legal holds.
- Webhook configurations and delivery logs. Retained while the endpoint exists and for a limited period afterward for debugging and security.
- Billing and wallet records. Retained as long as necessary for accounting, tax, and legal purposes, which may be after account closure.
When you delete your account from your account settings, we delete your personal data, together with the workspaces you solely own and their connections, posts, API keys, webhooks, and billing data held by us, except where we must keep certain records to meet a legal, accounting, or security obligation. We also cancel any active subscription and remove saved payment methods from our payment processor where the processor allows; the processor may retain billing records as required by law.
Some operational records are kept independently of your account and are not removed by account deletion, including short-lived email verification codes (which expire on their own), billing-event records we retain for accounting, and security and audit records. These are deleted or expire under their own schedules.
8Your rights and choices
Depending on where you live, you have some or all of the following rights:
- Access: get a copy of the personal data we hold about you.
- Correction: fix inaccurate or incomplete data. You can update most profile information in the app.
- Deletion: delete your account and its personal data from your settings, or ask us to do it for you.
- Portability: receive certain data in a portable format.
- Objection and restriction: object to or restrict certain processing.
- Withdraw consent: where we rely on consent.
To exercise any of these, email privacy@onepostly.com. We will respond within the timeframe required by applicable law. You also have the right to lodge a complaint with your local data-protection authority.
9Security
We take reasonable technical and organizational measures to protect your data. OAuth tokens and similar secrets are encrypted at rest. API access is gated by authentication. Media and workspace data are stored with access controls appropriate to a multi-tenant service. Our own secrets are kept out of logs where practical. No system is perfectly secure, and we cannot guarantee absolute security, but we work to protect your data and to limit what is stored.
10Age
Onepostly is intended for adults. You must be at least 18 to use it, and we do not knowingly collect data from anyone under 18. If you believe someone under 18 has provided us data, contact privacy@onepostly.com and we will delete it.
11Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you. Your continued use of the Service after a change takes effect means you accept the updated policy.
12Contact
For any privacy question or request, contact us at privacy@onepostly.com.