← Back to OnePost

Privacy Policy

What OnePost handles, where it goes, and how you stay in control.

Effective date · 31 August 2026

This policy describes the OnePost Studio website and Windows beta, operated under the OnePost Studio name. Privacy contact: officialcontact022@gmail.com. Features marked as in setup process data only when they are configured and used; this policy does not announce their release.

1. Information we handle

  • Account information: platform account, Page or channel IDs, display names, handles and the permissions you grant.
  • Authorization: OAuth access and refresh tokens used to perform authorized operations. OnePost does not ask for your social-account password.
  • Publishing: video files you select, local file information, titles, captions, destination selections, remote post IDs and upload results.
  • Optional automation: configured keywords and messages, account/post/comment IDs, comment text, commenter information provided by the platform and reply status/error records.
  • Support: the email address, message and attachments you choose to send us.
  • Technical information: hosting and platform providers may process IP addresses, browser information, request metadata, cookies and diagnostic logs when serving the site or connected services.

2. Why we use it

Information is used to connect accounts you authorize, publish to destinations you select, show results, run explicitly enabled automation when available, troubleshoot errors and answer support or data requests. Social-platform data is not used for advertising profiles, sale or training general-purpose AI models by OnePost.

3. Local and cloud storage

The desktop app stores account configuration and publishing history on your PC. It uses Windows-backed Electron secure storage for tokens when available. The current beta has a fallback that is encoding rather than encryption if that facility is unavailable; local device security still matters.

The hosted Meta login service temporarily handles authorization results, including tokens, to return them to the desktop app. Its login-session records have a configured ten-minute expiry and retrieved results are removed.

If cloud automation is configured and enabled, account authorization, rule configuration and comment/reply records are also sent to the cloud service. The automation implementation encrypts stored account tokens and uses a cloud database for rules and activity. Do not assume that all app data stays on your PC.

4. Who receives information

Selected video content and metadata are sent to the social platforms you choose. Cloudflare provides the hosted OAuth service and, where activated, automation infrastructure. Cloudflare Pages hosts this copy of the OnePost website and may process request metadata to deliver and secure it. A separate Blogger copy remains hosted by Google. Email sent to support is handled through Gmail. We may disclose information where necessary to comply with applicable law, protect security or respond to your request.

OnePost’s YouTube integration uses YouTube API Services when enabled. See the Google Privacy Policy. Other connected platforms apply their own privacy policies to their services.

5. Website cookies and external links

The custom OnePost website does not add advertising trackers or a newsletter database. This Cloudflare-hosted site does not add analytics scripts or application cookies. Hosting providers may still process technical request metadata for delivery and security. The separate Blogger copy may use Google cookies and measurements. External links and email buttons take you to services with their own policies. Interactive website previews run in the page and do not publish videos or connect social accounts.

6. Retention and deletion

Local configuration and history remain on your device until you remove them. Removing an account from OnePost removes its local account entry but is not the same as revoking platform authorization or deleting cloud records. Temporary OAuth records expire as described above.

For cloud automation, records may remain after a rule is paused or a local slot is removed. The beta does not yet provide a complete self-service cloud deletion function or automatic retention schedule. Request cloud deletion through support; we will verify ownership, identify the records and confirm the outcome. We do not claim that pausing a rule automatically erases historical records.

7. Your choices

You can choose not to connect an account, remove local accounts, pause available automation rules and revoke authorization through the relevant platform. For Google/YouTube, visit Google Account connections. Revocation prevents future authorized access but does not itself erase content already posted to a platform.

You may request access, correction or deletion of information handled by OnePost by emailing support. Available rights depend on applicable law. See Data Deletion for the practical steps.

8. Security, age and changes

No storage or transmission method is completely secure. Use a protected Windows account and do not share tokens or developer credentials. OnePost is intended for adults managing authorized accounts, not for children. If you believe a child has provided personal information, contact support.

We may revise this policy as the product changes and will update its effective date. Review it before enabling a newly released integration or cloud feature.