Posthive is built with privacy in mind. This policy explains what we collect, why we collect it, and how you can control it. We keep it plain English no legalese walls.
Posthive is an open-source social media scheduling tool licensed under AGPL-3.0. When you use the hosted version at posthive.co, the data controller is the Posthive team. If you self-host Posthive, you are the data controller for your own instance.
When you register we collect your email address and a bcrypt-hashed password. We never store your password in plain text.
OAuth tokens and app passwords (e.g. Bluesky) are stored AES-256-GCM encrypted in our database. The encryption key is never stored in the database only in the server environment. We cannot read your tokens without the key.
The text and images you schedule are stored so we can publish them at the time you choose. Media files are stored on Supabase Storage (hosted version) or local disk (self-hosted). We do not analyse your content.
We collect basic server logs (IP address, request path, timestamp) for debugging and abuse prevention. These are not sold or shared with third parties.
Payments are handled by Dodo Payments. We never see or store your card details only a customer ID and subscription status returned by the payment processor.
We keep your data for as long as your account is active. When you delete your account, all personal data including social account credentials and scheduled posts is permanently deleted within 30 days. Anonymised aggregate statistics (total post count etc.) may be retained.
The hosted version of Posthive uses the following sub-processors:
Each processor has its own privacy policy. We only share the minimum data required for them to perform their service.
We use a single HTTP-only cookie to store your session (JWT refresh token). This cookie is strictly necessary for the app to function and does not track you across other sites. We do not use advertising cookies.
Depending on your jurisdiction you may have the right to:
To exercise any of these rights, email us at guna@posthive.co. We will respond within 30 days.
We use industry-standard practices: HTTPS everywhere, AES-256-GCM credential encryption, bcrypt password hashing, HTTP-only secure cookies, and rate limiting on auth endpoints. No system is 100% secure if you discover a vulnerability please disclose it responsibly to guna@posthive.co.
Posthive's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
When you connect a YouTube account, Posthive requests OAuth access to your YouTube channel in order to upload and publish videos on your behalf. Specifically, we access:
We do not access your Gmail, Google Drive, Google Contacts, Google Calendar, or any other Google service.
Google user data is used exclusively to publish your scheduled YouTube videos at the time you chose. We do not use it for any other purpose — including advertising, profiling, or any feature unrelated to the scheduling service you requested.
Your Google OAuth tokens are encrypted at rest using AES-256-GCM with a key stored only in the server environment — never in the database. Tokens are transmitted only over HTTPS and are never logged or returned in API responses.
Your Google OAuth tokens and any associated channel data are never sold, rented, or transferred to any third party. The only outbound use of your Google credentials is the direct API call to YouTube's servers to publish your scheduled content. No Google user data is shared with advertisers, data brokers, or any other party.
Google OAuth tokens are retained for as long as your YouTube account is connected in Posthive. You can disconnect your YouTube account at any time from the Accounts page — this immediately deletes the stored token from our database. When you delete your Posthive account, all Google OAuth tokens are permanently deleted within 30 days.
Posthive does not use any Google user data — including YouTube channel data or video content — to train, develop, or improve any AI or machine learning model. Google user data is not transferred to any third-party AI or ML service.
The use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Posthive integrates with the Reddit API to allow users to schedule and publish posts to Reddit on their behalf. Our use of the Reddit API complies with the Reddit Data API Terms and the Responsible Builder Policy.
When you connect a Reddit account, Posthive requests the following OAuth scopes:
We do not request access to your Reddit inbox, comments, votes, moderation tools, subscriptions, or any other Reddit data beyond what is listed above.
Reddit user data is used exclusively to publish posts you have written and scheduled inside Posthive. Every post is user-initiated — you write the content, choose the subreddit, and set the publish time. Posthive never posts to Reddit automatically without your explicit instruction.
Your Reddit OAuth tokens are encrypted at rest using AES-256-GCM with a key stored only in the server environment — never in the database. Tokens are transmitted only over HTTPS and are never logged, exposed in API responses, or accessible to any third party.
Your Reddit OAuth tokens are retained only while your Reddit account is connected in Posthive. Scheduled post content (title, text, subreddit) is stored until the post is published, after which it remains in your post history for your reference but is never re-used or re-posted automatically. You can disconnect your Reddit account at any time from the Accounts page — this immediately and permanently deletes your stored Reddit token. When you delete your Posthive account, all Reddit tokens and associated data are permanently deleted within 30 days.
If you run Posthive on your own infrastructure, this policy does not apply to your instance. You are the data controller and are responsible for your users' data under applicable law.
We may update this policy as the product evolves. Material changes will be communicated via email or an in-app notice at least 14 days before they take effect. The "Last updated" date at the top will always reflect the current version.
Questions about this policy? Reach us at guna@posthive.co.