Privacy Policy
Last updated: June 17, 2026 · Effective: June 17, 2026
This Privacy Policy is provided by Asindie, Inc. ("AsIndie", "PostHubify", "we", "us", or "our"), the operator of the PostHubify social media, messaging, and advertising management platform and its API (the "Service"), available at asindie.com and related applications.
- Who we are & scope
- Controller and processor roles
- Information we collect
- Data from connected platforms (per-platform disclosures)
- How we use information & legal bases
- Artificial-intelligence features
- How we share information & sub-processors
- SMS, OTP & telephony data
- Data retention
- How we protect your information
- International data transfers
- Your privacy rights (GDPR/UK GDPR)
- U.S. state privacy rights (CCPA/CPRA)
- Disconnecting accounts & deleting data
- Cookies & similar technologies
- Children
- Business transfers
- Changes to this policy
- Contact us
1. Who we are & scope
PostHubify is a software-as-a-service platform and developer API operated by Asindie, Inc., a company incorporated in the United States. This Policy applies to personal data we process when you visit our websites, create an account, connect third-party accounts, use the dashboard or the API, send messages or SMS/OTP, run advertising, or otherwise use the Service.
It does not apply to the third-party platforms you connect (for example Meta, Google/YouTube, X, TikTok, LinkedIn, Pinterest), which are independently operated and governed by their own privacy policies. When you connect such a platform, you also become subject to that platform's terms and privacy policy.
2. Controller and processor roles
For personal data about you, our customer (your account, billing, and usage data), AsIndie acts as a data controller.
For personal data that you bring into or process through the Service about your own audience and contacts — for example, the followers, commenters, message senders, ad audiences, and SMS recipients of the accounts you connect — AsIndie generally acts as a data processor acting on your documented instructions, and you are the controller. You are responsible for having a lawful basis and any required notices/consents for that data. If you are a business customer subject to the GDPR or comparable law, our Data Processing Addendum is available on request and forms part of your agreement.
3. Information we collect
3.1 Information you provide
- Account & identity. Your name and email address, authenticated through our identity provider (Authentik). We do not store your account password — authentication is handled by the identity provider. We also store your role and workspace/profile membership.
- Billing. Your subscription/plan, wallet balance, transaction ledger, and a payment-processor customer/subscription identifier. We do not collect or store your full card number — payments are processed by Stripe (see §7).
- Support & communications. Messages, requests, and feedback you send us.
- Content. The posts, drafts, captions, hashtags, media (images/video), schedules, campaigns, contacts, automations, and workflows you create or upload.
3.2 Information from connected accounts
When you connect a third-party account, we receive and store the OAuth access and refresh tokens (or equivalent credentials, such as a bot token or app password), the granted scopes, and basic profile metadata (such as username, display name, page/channel/account ID, and avatar URL). Tokens and credentials are encrypted at rest (see §10). Depending on the features you use, we also access content, messages, comments, analytics, and advertising data as described in §4.
3.3 Communications data
- Inbox / direct messages & comments. When you use the inbox or engagement features, we store the messages, comments, and attachments exchanged through your connected accounts, along with sender identifiers provided by the platform.
- Contacts. A platform-agnostic contact directory you build, which may include names, emails, phone numbers, tags, and notes.
- SMS & OTP. Recipient phone numbers (in E.164 format), country, message/verification status, and pricing metadata. One-time-passcodes themselves are never stored in plaintext — only a salted keyed hash (see §8).
3.4 Information collected automatically
- Log & device data. IP address, browser/user-agent, timestamps, requested endpoints, and similar diagnostic data.
- Session. A first-party, HTTP-only session cookie (see §15).
- Audit logs. Records of actions taken in your account (who did what, when) for security and accountability.
4. Data from connected platforms (per-platform disclosures)
PostHubify integrates with the platforms below. For each, we access data only to provide the features you have enabled, acting on your behalf, and only within the scopes you grant during authorization. We do not use data received from these platforms for advertising, to build user profiles unrelated to the Service, to re-identify de-identified data, or to train generalized AI/ML models. You can revoke access at any time (see §14).
4.1 Google & YouTube
PostHubify uses YouTube API Services and other Google APIs (including, where you enable them, Google Business Profile and Google Ads). By using these integrations, you agree to be bound by the YouTube Terms of Service, and your data is also handled under the Google Privacy Policy.
Limited Use. PostHubify's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we use Google user data only to provide or improve user-facing features that are prominent in the PostHubify interface; we do not transfer or sell it to third parties for advertising, data brokering, or credit purposes; we do not use it to train generalized/non-personalized AI or ML models; and humans do not read it except with your affirmative consent, for security/abuse/legal reasons, or where the data is aggregated and anonymized for internal operations.
Revoking access. You can revoke PostHubify's access to your Google account at any time from the Google security settings page: https://security.google.com/settings/security/permissions, or by disconnecting the account in PostHubify.
4.2 Meta — Facebook, Instagram, WhatsApp & Threads
Our use of data from Meta platforms is governed by the Meta Platform Terms and Developer Policies. We access Pages, Instagram professional accounts, WhatsApp Business numbers, and Threads accounts you connect to publish content, manage comments and direct messages, and read insights you request. We store Platform Data only as long as needed to provide the Service, and we delete it when no longer needed, when you disconnect, when you request deletion, or when Meta requires it. See §14 for how to request deletion, including our data-deletion mechanism.
4.3 X (formerly Twitter)
Our use of X content is governed by the X Developer Agreement & Policy. If content you posted or accessed through PostHubify is deleted or modified on X, we will delete or modify our stored copy as soon as reasonably possible, and within 24 hours of a request. We do not associate X content or identifiers with off-X identifiers without express opt-in, and we do not use X content for surveillance or to derive sensitive characteristics.
4.4 TikTok
Our use of TikTok developer data (including the Login Kit, Content Posting/Video API, and Marketing/Ads APIs you enable) is governed by the TikTok Developer Terms of Service. We process TikTok data only for the limited purpose of the features you use, retain it only as long as necessary, and honor deletion requests.
4.5 LinkedIn
Our use of LinkedIn member data via the Marketing and Community Management APIs is governed by LinkedIn's API terms. We access member data only to manage the LinkedIn Pages or profiles you connect, display it only to people associated with those Pages/profiles, and do not use it for any other purpose.
4.6 Pinterest
Our use of Pinterest data follows the Pinterest Developer Guidelines. Except for campaign analytics, we do not persistently store information accessed through Pinterest APIs; we call the API as needed. We do not use Pinterest information for off-platform ad targeting.
4.7 Reddit
Our use of Reddit data follows the Reddit Data API terms and Responsible Builder Policy. When content is deleted on Reddit, we delete related stored content; when a Reddit account is deleted, we delete author-identifying information. We do not match Reddit data with off-platform identifiers or infer sensitive characteristics.
4.8 Other connected services
We also integrate, when you enable them, with Snapchat, Microsoft Advertising, Spotify, Discord, Telegram, LINE, Mastodon, Bluesky (AT Protocol), Tumblr, and Dailymotion. For each, we access only the data needed for the features you use, comply with that service's developer terms, do not share the data with data brokers or advertising networks, do not train AI on message content, and let you disconnect at any time. Because some of these services (e.g., Bluesky/AT Protocol, individual Mastodon instances) do not govern third-party apps, this Policy governs how PostHubify handles data from them.
| Platform | Typical data accessed (per features you enable) |
|---|---|
| Instagram, Facebook, Threads, WhatsApp (Meta) | profile/page metadata, published content, comments, direct messages, insights, ads (audiences, campaigns, conversions) |
| YouTube / Google / Google Business / Google Ads | channel & video metadata, comments, analytics, business locations & reviews, ad campaigns |
| X, TikTok, LinkedIn, Pinterest, Reddit | profile metadata, posts/pins/videos, comments/replies, analytics, and (where enabled) advertising data |
| Discord, Telegram, LINE, Mastodon, Bluesky, Tumblr, Dailymotion, Snapchat, Spotify, Microsoft | profile/account metadata, messages or posts, and engagement/analytics as applicable to the feature |
5. How we use information & legal bases
We use personal data to: (a) provide, operate, and secure the Service; (b) authenticate you and connect your accounts; (c) publish, schedule, and manage content and messages on your behalf; (d) deliver SMS/OTP and process advertising you configure; (e) provide analytics and insights you request; (f) process payments and prevent fraud/abuse (including spend limits); (g) provide support and communicate service notices; (h) comply with legal obligations; and (i) improve the Service (using your own account/usage data and aggregated, de-identified data — never connected-platform data for model training).
Where the GDPR or UK GDPR applies, our legal bases are: performance of a contract (providing the Service you request), consent (which you give when you authorize a platform connection or opt in to communications, and may withdraw), legitimate interests (securing and improving the Service, preventing fraud and abuse), and legal obligation (tax, accounting, and compliance).
6. Artificial-intelligence features
PostHubify offers optional AI features (for example, generating draft post copy and building automation/workflow graphs from natural-language instructions). When you use these features, the text you submit — such as your prompt, brief, target platform, and any content you choose to include — is sent to our AI sub-processor (Anthropic, the Claude API) to produce the requested output. We do not send your stored direct messages, comments, contacts, or connected-platform data to AI providers unless you explicitly include such content in a request. AI providers act under contract as our sub-processors and do not train their models on your inputs for this Service. AI output is probabilistic and may be inaccurate; you are responsible for reviewing it before publishing and for disclosing AI use where required by a platform or law. Where you provide your own AI provider key ("bring your own key"), your inputs are sent to that provider under your own arrangement.
7. How we share information & sub-processors
We do not sell your personal data. We share personal data only as follows:
- With the platforms you connect, to carry out the actions you request (e.g., publishing a post, sending a message, creating an ad).
- With sub-processors who provide infrastructure and services to us, under contracts that restrict their use of the data, listed below.
- For legal reasons — to comply with law, enforce our terms, or protect rights, safety, and security.
- In a business transfer — see §17.
Current sub-processors:
| Sub-processor | Purpose | Data |
|---|---|---|
| Supabase (PostgreSQL) | Primary database hosting | All stored account, content, messaging, and billing-reference data (credentials encrypted) |
| Cloudflare (R2 storage / network) | Media object storage & site delivery | Images, video, and generated media you upload or create |
| Stripe | Payment processing | Billing contact and payment data (card data handled solely by Stripe; see Stripe Privacy Policy) |
| Telnyx | SMS delivery & phone-number provisioning | Recipient phone numbers (E.164) and message content/metadata |
| Anthropic | AI text/graph generation (optional features) | The prompt/brief and any content you include in an AI request |
| ElevenLabs | Text-to-speech (optional video voiceover) | The script/text you submit for narration |
| Authentik | Authentication / identity provider | Email, name, and authentication state (passwords held by the identity provider, not by PostHubify) |
| The connected platforms (§4) | Carrying out your requested actions | As applicable to each action |
We keep this list current and provide reasonable notice of material changes to business customers under a Data Processing Addendum. We do not use data received from connected platforms for advertising, data brokering, or AI-model training.
8. SMS, OTP & telephony data
If you use our SMS, one-time-passcode (OTP), or phone-number features, we process recipient phone numbers (E.164), destination country, and delivery status to route and deliver messages through our telephony provider (Telnyx), and to bill usage. OTP codes are stored only as a per-record salted keyed hash and are never retained in plaintext. You are responsible for obtaining any required consent from recipients, complying with anti-spam and A2P messaging rules (including carrier registration requirements), honoring opt-outs, and not sending prohibited content. We enforce velocity and daily spend limits to mitigate fraud and messaging abuse.
9. Data retention
We retain personal data for as long as your account is active and as needed to provide the Service, then delete or de-identify it within a reasonable period, except where longer retention is required for legal, tax, accounting, security, or dispute-resolution purposes. Specific practices include: connected-account tokens are kept only while the connection is active and are deleted promptly on disconnection or revocation; OTP codes and short-lived tokens expire automatically; invite links expire after 7 days; billing records are retained as required by law; and platform content is deleted or updated to reflect deletions on the source platform as described in §4 and §14. You can request deletion at any time (see §14).
10. How we protect your information
- Encryption of credentials at rest. Connected-account access/refresh tokens and other sensitive credentials are encrypted using authenticated AES-256-GCM with a server-side key.
- Encryption in transit. Data is transmitted over TLS/HTTPS.
- Hashing. API keys are stored only as hashes; OTP codes only as salted keyed hashes; passwords are not stored by us (held by the identity provider).
- Webhook integrity. Inbound webhooks (e.g., Stripe, Meta, Telnyx, Telegram, LINE) are verified with cryptographic signatures.
- Abuse protections. Server-side request validation, protections against server-side request forgery (SSRF), idempotency controls, role-based access, and spend/velocity limits.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security; we work to protect your data using commercially reasonable measures.
11. International data transfers
We and our sub-processors may process data in the United States and other countries. Where we transfer personal data from the EEA, UK, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum), or another lawful transfer mechanism.
12. Your privacy rights (GDPR / UK GDPR)
Subject to applicable law, you have the right to: access your personal data; rectify inaccurate data; erase data ("right to be forgotten"); restrict or object to processing; data portability; withdraw consent at any time; and lodge a complaint with your supervisory authority. To exercise these rights, contact us (see §19). We will respond within the timeframes required by law (generally within one month under the GDPR).
13. U.S. state privacy rights (CCPA/CPRA and similar)
If you are a California resident (or a resident of another U.S. state with comparable law), you have the right to know/access the categories and specific pieces of personal information we collect, to delete it, to correct it, to opt out of any "sale" or "sharing" of personal information, and to limit use of sensitive personal information, without discrimination for exercising these rights.
We do not sell personal information for money. Certain advertising features you may choose to use (for example, building custom or matched audiences, or sending conversion events to a platform such as Meta, Reddit, or Pinterest) may constitute "sharing" for cross-context behavioral advertising under California law. You control whether to use those features. To opt out, do not enable audience/conversion features, or contact us using the "Do Not Sell or Share My Personal Information" request channel at support@posthubify.com. We honor recognized opt-out preference signals (such as Global Privacy Control) where required. You may use an authorized agent to submit requests.
14. Disconnecting accounts & deleting data
You can disconnect any connected account at any time from the PostHubify dashboard; doing so deletes the stored credentials for that connection and stops further processing. You can also revoke PostHubify's access directly from the platform (for example, Google: security.google.com/settings/security/permissions; and the equivalent app/connected-apps settings on Meta, X, TikTok, LinkedIn, Pinterest, and others).
To request deletion of your data, disconnect the relevant accounts and/or contact us at support@posthubify.com with the subject "Data Deletion Request". We honor platform-specific deletion obligations, including Meta data-deletion requests (we provide a data-deletion request channel and process automated deletion signals where a platform sends them), removing content that is deleted on the source platform, and deleting author-identifying data when an account is deleted on the source platform. We will confirm completion of verified deletion requests.
15. Cookies & similar technologies
We use a small number of first-party cookies that are strictly necessary to operate the Service — primarily an HTTP-only session cookie to keep you signed in, and short-lived state cookies used to protect OAuth connection flows from cross-site request forgery. We do not use third-party advertising or cross-site tracking cookies in the Service.
16. Children
The Service is intended for businesses and professionals and is not directed to children. You must be at least 18 years old (or the age of majority in your jurisdiction) to use the Service. We do not knowingly collect personal data from children; if you believe a child has provided us data, contact us and we will delete it.
17. Business transfers
If AsIndie is involved in a merger, acquisition, financing, reorganization, or sale of assets, personal data may be transferred as part of that transaction, subject to this Policy or a successor policy with comparable protections.
18. Changes to this policy
We may update this Policy from time to time. We will post the updated version with a new "Last updated" date and, for material changes, provide additional notice (for example, by email or in-app). Your continued use of the Service after an update means you accept the revised Policy.
19. Contact us
For privacy questions, data-subject requests, deletion requests, or to request our Data Processing Addendum:
- PostHubify privacy & data requests: support@posthubify.com
- Operating company — Asindie, Inc.: contact@asindie.com
- Web: posthubify.com · asindie.com · See also our Terms of Service