PostSteward

root@poststeward:~$ cat privacy

Privacy Policy

This policy explains how PostSteward handles information when an owner connects social accounts, gives an AI agent scoped publishing authority, schedules work or inspects publishing evidence.

Effective date: 19 September 2026 · Contact: community@oneclickpostfactory.com

1. Information PostSteward processes

2. Why the data is used

Operate the service

Authenticate owners, route approved content to the exact connected account, run explicit schedules and expose scoped agent operations.

Keep publishing safe

Verify identities and scopes, prevent blind duplicate retries, detect authority drift and preserve ambiguous outcomes for inspection.

Provide evidence

Keep durable receipts so owners and agents can distinguish scheduled, verified, unverified, failed and uncertain provider effects.

Support and security

Investigate faults, enforce limits, respond to deletion/privacy requests and protect workspaces against unauthorised access.

3. Service providers and external platforms

PostSteward may interact with services chosen by the owner, including identity providers, social networks such as X, Threads/Meta and LinkedIn, Cloudflare infrastructure, GitHub for an optional connected source, and Stripe when paid billing is enabled. Those providers process information under their own terms and privacy policies.

Posting to a social network is an external effect: once content is published, that network may retain copies, engagement, logs or other information independently of PostSteward.

4. Security

5. Retention and deletion

Operational records are retained while they are useful to the workspace and within service safety ceilings. Owners can request workspace erasure. A completed deletion removes locally usable provider credentials, sessions, grants, workspace application records, linked private-source credentials, provider OAuth state and related workspace mappings.

A minimal completed-deletion tombstone may be retained to prevent restored historical state from resurrecting deleted publishing authority. Provider-side posts and provider-side authorisation grants are controlled by the relevant external platform and may require separate deletion or revocation there.

6. Your choices and requests

Depending on applicable law, you may have rights to request access, correction, export, restriction or deletion of personal data. You may also disconnect a social account or revoke an agent grant from the connected workspace.

For a privacy request, email community@oneclickpostfactory.com. Include the email address used to sign in and the nature of the request. Do not send passwords, access tokens, API keys or social-provider secrets by email.

7. Changes to this policy

This policy may be updated as PostSteward's production capabilities, providers or legal obligations change. Material changes will be reflected by updating this page and its effective date.