Legal

Privacy Policy

Last updated: June 21, 2026

1. Who We Are

Post-Pilot is a social media automation platform operated by ShadowRealm Network (“we,” “us,” or “our”). We help food trucks, restaurants, cafes, and hotels automate their social media content across multiple platforms via official APIs.

2. Information We Collect

We collect information you provide directly and information generated by your use of the service:

  • Account data — name, email address, password (hashed), and business details you enter during onboarding.
  • Platform OAuth tokens — access tokens issued by Facebook, Instagram, TikTok, YouTube, and Google when you connect your accounts. We store these securely to publish on your behalf. We never store your platform passwords.
  • Content data — posts you generate, schedule, edit, or publish through Post-Pilot.
  • Usage data — pages visited, features used, errors encountered, and timestamps, used to improve the product.
  • Billing data — handled entirely by our payment processor (Stripe). We do not store card numbers.

3. How We Use Your Information

  • To provide and operate the Post-Pilot service.
  • To publish content to your connected platforms on your schedule.
  • To send transactional emails (post confirmations, billing receipts, error alerts).
  • To improve product features and fix bugs.
  • To comply with legal obligations.

We do not sell your personal data to third parties. We do not use your content to train AI models for other customers.

4. Data Sharing

We share data only as necessary to operate the service:

  • Platform APIs — Facebook, Instagram, TikTok, YouTube, Google Business receive your post content and scheduling instructions as directed by you.
  • Infrastructure — Railway (hosting), Supabase or similar (database), Stripe (payments). These providers process data on our behalf under appropriate data processing agreements.
  • Legal requirements — we may disclose data if required by law or to protect rights and safety.

5. Data Retention

We retain your account data for as long as your account is active. If you cancel, your account moves to the Free plan and data is retained for 90 days before deletion upon request. OAuth tokens are revoked immediately upon platform disconnection.

6. Security

We use industry-standard security practices including encrypted connections (HTTPS/TLS), hashed passwords (bcrypt), and encrypted storage for OAuth tokens. No system is 100% secure; we encourage using a strong, unique password for your Post-Pilot account.

7. Your Rights

Depending on your location, you may have rights to access, correct, export, or delete your personal data. To exercise any of these rights, contact us at privacy@postpilot.io.

8. Cookies

We use session cookies to keep you logged in and preference cookies to remember your settings. We do not use third-party advertising cookies.

9. Children

Post-Pilot is not directed at children under 13. We do not knowingly collect personal data from children.

10. Changes to This Policy

We may update this policy from time to time. We will notify registered users by email of material changes at least 14 days before they take effect.

11. Contact

Questions about this policy? Email us at privacy@postpilot.io or write to ShadowRealm Network, Post-Pilot Privacy, [Address].