Last updated: July 23, 2026

Privacy Policy

Posthive is built with privacy in mind. This policy explains what we collect, why we collect it, and how you can control it. We keep it plain English no legalese walls.


1. Who we are

Posthive is an open-source social media scheduling tool licensed under AGPL-3.0. When you use the hosted version at posthive.co, the data controller is the Posthive team. If you self-host Posthive, you are the data controller for your own instance.

2. What we collect

Account information

When you register we collect your email address and a bcrypt-hashed password. We never store your password in plain text.

Social account credentials

OAuth tokens and app passwords (e.g. Bluesky) are stored AES-256-GCM encrypted in our database. The encryption key is never stored in the database only in the server environment. We cannot read your tokens without the key.

Post content & media

The text and images you schedule are stored so we can publish them at the time you choose. Media files are stored on Supabase Storage (hosted version) or local disk (self-hosted). We do not analyse your content.

Usage data

We collect basic server logs (IP address, request path, timestamp) for debugging and abuse prevention. These are not sold or shared with third parties.

Billing information

Payments are handled by Dodo Payments. We never see or store your card details only a customer ID and subscription status returned by the payment processor.

3. What we do not collect

  • We do not use tracking pixels or third-party analytics scripts.
  • We do not sell, rent, or trade your data to any third party.
  • We do not read or analyse the content of your scheduled posts.
  • We do not build advertising profiles.

4. How we use your data

  • Publishing posts - your content and credentials are used solely to post on your behalf at the scheduled time.
  • Authentication - your email and hashed password authenticate you to the app.
  • Transactional email - we send password reset emails via Resend. No marketing email without your consent.
  • Billing - subscription status determines which plan features are available to you.

5. Data retention

We keep your data for as long as your account is active. When you delete your account, all personal data including social account credentials and scheduled posts is permanently deleted within 30 days. Anonymised aggregate statistics (total post count etc.) may be retained.

6. Third-party services

The hosted version of Posthive uses the following sub-processors:

  • Supabase - database and file storage (EU/US regions)
  • Upstash / Railway Redis - job queue
  • Dodo Payments - payment processing
  • Resend - transactional email

Each processor has its own privacy policy. We only share the minimum data required for them to perform their service.

7. Cookies & local storage

We use a single HTTP-only cookie to store your session (JWT refresh token). This cookie is strictly necessary for the app to function and does not track you across other sites. We do not use advertising cookies.

8. Your rights

Depending on your jurisdiction you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data (right to erasure)
  • Export your data in a portable format
  • Object to or restrict certain processing

To exercise any of these rights, email us at guna@posthive.co. We will respond within 30 days.

9. Security

We use industry-standard practices: HTTPS everywhere, AES-256-GCM credential encryption, bcrypt password hashing, HTTP-only secure cookies, and rate limiting on auth endpoints. No system is 100% secure if you discover a vulnerability please disclose it responsibly to guna@posthive.co.

10. Google API Services — User Data Policy

Posthive's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

What Google data we access

When you connect a YouTube account, Posthive requests OAuth access to your YouTube channel in order to upload and publish videos on your behalf. Specifically, we access:

  • Your YouTube channel identity (channel ID and display name) — to identify which channel to post to
  • The ability to upload videos and set their metadata (title, description, visibility) — to fulfil scheduled video posts

We do not access your Gmail, Google Drive, Google Contacts, Google Calendar, or any other Google service.

How we use Google data

Google user data is used exclusively to publish your scheduled YouTube videos at the time you chose. We do not use it for any other purpose — including advertising, profiling, or any feature unrelated to the scheduling service you requested.

How we protect Google data

Your Google OAuth tokens are encrypted at rest using AES-256-GCM with a key stored only in the server environment — never in the database. Tokens are transmitted only over HTTPS and are never logged or returned in API responses.

Data transfer — Google data

Your Google OAuth tokens and any associated channel data are never sold, rented, or transferred to any third party. The only outbound use of your Google credentials is the direct API call to YouTube's servers to publish your scheduled content. No Google user data is shared with advertisers, data brokers, or any other party.

Data retention and deletion — Google data

Google OAuth tokens are retained for as long as your YouTube account is connected in Posthive. You can disconnect your YouTube account at any time from the Accounts page — this immediately deletes the stored token from our database. When you delete your Posthive account, all Google OAuth tokens are permanently deleted within 30 days.

AI and machine learning restrictions

Posthive does not use any Google user data — including YouTube channel data or video content — to train, develop, or improve any AI or machine learning model. Google user data is not transferred to any third-party AI or ML service.

Limited Use compliance statement

The use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

11. Reddit API Data

Posthive integrates with the Reddit API to allow users to schedule and publish posts to Reddit on their behalf. Our use of the Reddit API complies with the Reddit Data API Terms and the Responsible Builder Policy.

What Reddit data we access

When you connect a Reddit account, Posthive requests the following OAuth scopes:

  • identity — to verify your Reddit username and confirm successful authentication
  • submit — to publish text and link posts to subreddits you explicitly select

We do not request access to your Reddit inbox, comments, votes, moderation tools, subscriptions, or any other Reddit data beyond what is listed above.

How we use Reddit data

Reddit user data is used exclusively to publish posts you have written and scheduled inside Posthive. Every post is user-initiated — you write the content, choose the subreddit, and set the publish time. Posthive never posts to Reddit automatically without your explicit instruction.

  • We do not scrape Reddit content, posts, comments, or user data.
  • We do not store Reddit posts, comments, votes, or any content retrieved from Reddit.
  • We do not use your Reddit credentials to read Reddit feeds or aggregate content.
  • We do not resell, license, or share any Reddit data with third parties.
  • We do not use Reddit data to train, develop, or improve any AI or machine learning model.
  • We do not perform any automated bulk posting, spam, or vote manipulation.
  • We respect all Reddit API rate limits and terms at all times.

How we protect Reddit data

Your Reddit OAuth tokens are encrypted at rest using AES-256-GCM with a key stored only in the server environment — never in the database. Tokens are transmitted only over HTTPS and are never logged, exposed in API responses, or accessible to any third party.

Data retention and deletion — Reddit data

Your Reddit OAuth tokens are retained only while your Reddit account is connected in Posthive. Scheduled post content (title, text, subreddit) is stored until the post is published, after which it remains in your post history for your reference but is never re-used or re-posted automatically. You can disconnect your Reddit account at any time from the Accounts page — this immediately and permanently deletes your stored Reddit token. When you delete your Posthive account, all Reddit tokens and associated data are permanently deleted within 30 days.

12. Self-hosted instances

If you run Posthive on your own infrastructure, this policy does not apply to your instance. You are the data controller and are responsible for your users' data under applicable law.

13. Changes to this policy

We may update this policy as the product evolves. Material changes will be communicated via email or an in-app notice at least 14 days before they take effect. The "Last updated" date at the top will always reflect the current version.

14. Contact

Questions about this policy? Reach us at guna@posthive.co.

© 2026 Posthive. Open source under AGPL-3.0.
PrivacyTerms