Privacy Policy

Last updated: September 26, 2026

Who we are

SuprPost (“we”, “us”) provides a social media scheduling and publishing platform. This policy explains what information we collect, why, and how you can control it. Contact us at support@suprpo.st with any questions.

Information we collect

  • Account information: your name, email address, and profile photo from Google Sign-In when you create a SuprPost account.
  • Connected social accounts: when you connect an Instagram (or other platform) account, we receive your account’s username, profile picture, account type, and an access token that authorizes us to publish and manage content on your behalf. Access tokens are encrypted at rest and are never shown in the SuprPost interface.
  • Content you create: posts, captions, and media (images/video) you upload to schedule or publish through SuprPost, stored in our database and object storage.
  • Usage data: basic technical logs (e.g. request timestamps) used for reliability and abuse prevention.

How we use your information

We use connected-account tokens solely to perform actions you request — publishing posts, reading insights, and managing comments/messages on the accounts you explicitly connect. We do not sell your data or share it with third parties for advertising.

How we store and protect data

Account and workspace data is stored in MongoDB; uploaded media is stored in Cloudflare R2 object storage. Social platform access tokens are encrypted before being written to the database. Access to production data is restricted to the operators of SuprPost.

Your controls

You can disconnect any connected social account at any time from SuprPost, which immediately deletes the stored access token and, on platforms that allow it (X, YouTube, and Bluesky), also revokes SuprPost’ authorization on the platform. See our Data Deletion Instructions for how to request deletion of your account and all associated data.