Privacy Policy

Last updated: July 18, 2026

Social Fanout ("we," "us") provides an API and dashboard for publishing content and managing explicitly authorized social interactions on behalf of authenticated users. This policy explains what data we collect, how we use it, and the choices you have.

Data We Collect

Account data:

OAuth credentials from connected platforms: When you connect a social account (Meta, X, Pinterest, LinkedIn, TikTok, YouTube, Bluesky, etc.), we receive and store:

Tokens are stored server-side in Supabase and are not returned by public API or dashboard responses. They are used only for the capability you authorize: publishing submitted content; subscribing to and receiving authorized comments or customer-initiated messages; sending a public comment reply, setting comment visibility, deleting a stored app-created comment reply, or sending a standard-window private text reply when you explicitly request that action; and refreshing access where the connected platform supports refresh. Social Fanout does not generate, schedule, or autonomously send comment or message replies; authenticated callers initiate those actions and supply the reply text.

For Pinterest specifically, Social Fanout does not request or retain API-derived profile metadata, token-response metadata, permission-scope copies, or a Board inventory. We store only the OAuth tokens needed to access the API plus locally generated connection and refresh-timing metadata. Board names and IDs are fetched with no-store caching only while you choose a destination; the selected Board ID is used for that immediate request and is not retained. The returned Pin ID is shown once in the publish response but is not stored in jobs, history, idempotency bodies, or outbound webhooks. Pinterest scheduling and replay are unavailable because they would require retaining the Board ID.

Content you publish:

Standalone Instagram Comments data: When an authenticated user explicitly enables the dedicated Instagram Comments app, Social Fanout stores only these normalized fields under a separate Comments connection:

We do not retain the full raw signed webhook payload for this lane. Dismiss is local: it changes only the Social Fanout inbox status and makes no Instagram request. The dedicated feature can set upstream visibility on the owned inbound comment and can delete only a reply Social Fanout previously created and stored; it does not accept arbitrary provider identifiers or delete the inbound comment.

A valid Comments-app-signed data-deletion request removes only the dedicated Comments connection and records linked to that connection from Social Fanout. It does not remove sibling Instagram Publishing or Messages records, including Publishing job/post history, even when those apps authorize the same Professional account. That account-data callback is distinct from the explicit moderation controls and does not itself delete or hide provider content. Provider-side content remains subject to completed customer-requested actions and Instagram's own controls and retention.

Standalone Instagram Messages data: When an authenticated user explicitly enables the dedicated Instagram Messages app, Social Fanout stores only the normalized information needed to receive a customer-initiated message, display it to the owning account, enforce the standard reply window, and send a text reply after an explicit authenticated request:

We do not retain the full raw signed Messages webhook payload. The recipient is derived only from the signed inbound event and is never accepted from the reply request. Social Fanout uses the earlier valid provider/receipt time to enforce the standard 24-hour reply window on the server. Social Fanout does not generate, schedule, or autonomously send Messages replies; it sends caller-supplied text only after an explicit authenticated request. It exposes no cold-DM, media-reply, recipient-override, or Human Agent workflow. Instagram message content is not used for advertising, profiling, or model training.

A valid Messages-app-signed data-deletion request removes only the dedicated Messages connection, credentials, normalized events, send actions, subscription attempts, and operation fences from Social Fanout. It does not remove sibling Instagram Publishing or Comments records solely because they reference the same Professional account. Ordinary Messages disconnect first requires Instagram to confirm that this dedicated app's webhook subscription was removed; if that provider step is unconfirmed, Social Fanout retains the connection behind a recovery fence and instructs the user to retry or revoke the app in Instagram. A verified privacy deletion still erases local data even if provider unsubscribe cannot be confirmed.

Operational data:

How We Use Data

We do not sell your data. We do not use your posts, comments, or messages to train models. We do not analyze that content for advertising.

Sharing

Data is shared with:

We do not sell, rent, or share your data with advertisers, data brokers, or analytics resellers. We do not share posts, comments, or messages beyond the connected platform and any customer-configured webhook described above.

Platform-Specific Terms

Our use of data received from each connected platform complies with that platform's developer terms, including:

For Meta and Threads, a valid platform-signed deletion request immediately deletes the matching connection tokens, publishing job and post-history copies (including authored text and media references), and engagement data associated with the connection or its authorized Page/Instagram account IDs before we return a completion code. Our configured deauthorization paths use the same verified local purge implementation when a valid request reaches them; live provider delivery and response expectations are verified separately. Disconnecting a provider in the Social Fanout dashboard normally purges linked engagement data and hard-deletes that connection row and its OAuth credentials. For standalone Instagram Comments we also make a best-effort request for Instagram to remove the app webhook subscription; this provider-side unsubscribe behavior is not represented as guaranteed. If Instagram does not confirm that step, local deletion still completes and the dashboard tells you to revoke Social Fanout in Instagram settings. If you revoke only from a provider's own settings, the token becomes unusable but that provider may not notify us; disconnect in Social Fanout or email us to ensure the stored connection is removed. For standalone Instagram Messages, ordinary disconnect requires a confirmed provider unsubscribe before local purge; an unconfirmed response keeps the row for safe recovery. A valid signed Messages privacy request still completes local erasure.

YouTube API Services

When you connect a YouTube channel, Social Fanout uses YouTube API Services to publish videos to — and read the status of — the channel you connect. By connecting a YouTube channel you agree to be bound by the YouTube Terms of Service, and our access, use, and handling of information from YouTube API Services is also governed by the Google Privacy Policy.

Your Rights and Controls

Retention

Security

OAuth tokens are stored server-side and API keys are stored as one-way hashes. All traffic is TLS-encrypted. We use scoped, least-privilege credentials for every third-party integration. We do our best, but no service is unbreakable — if you suspect a breach, email us at hello@socialfanout.com.

Children

This service is not intended for users under 16. We do not knowingly collect data from children.

Changes

If we change this policy materially, we'll update the date above and email active users at least 14 days before changes take effect. Continued use after a change means you accept the new terms.

Contact

Questions, deletions, complaints: hello@socialfanout.com

← Back to socialfanout.com