Privacy Policy
Last updated 19 September 2026
This policy is for the AlphaPost app at app.alphapost.io and the AlphaPost app on Google Play. AlphaPost is run by Naveed Ali Shah. We keep this short and plain so you know exactly what happens to your data.
What we keep
- Your account: your name, your email and your time zone. If you fill in your profile, also your photo, a few lines about you, your website, phone and country. You choose what to add and you can change or clear it any time. Your password is never stored as you typed it. We keep a one way scrambled copy (scrypt) that can check a password but cannot be turned back into it.
- Keys for the accounts you add: for example a Facebook System User token, an X cookie, an Instagram, Pinterest, TikTok or YouTube login, or a Telegram bot token. These are locked with AES 256 encryption before they are saved.
- Your posts: the text, link and image link you write, when you want them sent, and whether each one went out or failed.
- Photos you upload: kept on our server only so the platforms can pick them up. They are deleted 3 days after the post goes out.
- Videos: never stored on our server. A video from your phone passes through in small pieces straight to Facebook, and a scheduled video waits on Facebook's own schedule. For a video link, the platform fetches the video from your link at posting time.
- Your Gemini keys and auto post settings: if you use AI posts, your own Gemini key (locked with the same encryption) and the topic, language and website you set.
- Country and activity: the country you use AlphaPost from (worked out by Cloudflare from your connection, we never save your IP address), when you were last active, which page was open and whether you use the app, a phone browser or a computer. This helps us keep the service running and see how it is used.
- Notifications: if you turn on alerts, a push address for your browser or phone, and the alerts we send you (for example that a post went out). You choose which alerts you want and can turn them off any time.
- Reports: if you report an AI post, we keep the report and the text of that post so we can check it.
- Server logs: like every website, our server keeps normal web logs (IP address, time, page asked for) for a short time, to keep the service safe and fix errors. Your IP is also used for a few minutes to stop password guessing.
The website shows ads through Google AdSense and the Android app through Google AdMob, as described below. You can turn ads off with a Go ad free plan. We do not ask for your contacts, location or camera. A photo or video, including your profile photo, is only read when you pick it yourself.
How we use it
Only to log you in and to send your posts to the accounts you pick, at the time you pick. We never post anything you did not write, schedule, or set up as an auto post. We do not sell your data, and we never use your posts or account data for ads.
Who else sees it
- The platforms you post to (Facebook, Instagram, X, Pinterest, Telegram, TikTok, YouTube) receive your post and the key needed to send it. Their own privacy rules apply once the post is on their site.
- Cloudflare carries the traffic between your device and our server.
- Google Firebase delivers alerts to the Android app, and your browser maker (for example Google or Mozilla) delivers alerts to your browser.
- Google AdMob shows ads in the Android app, together with ad partners such as Unity Ads and AppLovin. They may use your device advertising ID and basic device information to show and measure ads. You can reset or turn off the advertising ID in your phone settings. Where the law asks for it, the app asks for your consent first.
- Google AdSense shows ads on the website. Google may use cookies to show and measure ads. You can manage this at Google ad settings.
- Google Play handles Go ad free plans and tips. Google takes the payment; we never see your card or payment details. We keep only the purchase token, the plan, and when it ends, so we can turn ads off for your account.
- images.weserv.nl receives the image link of an Instagram post, only to turn the picture into the square JPEG that Instagram needs.
- Google Gemini receives your auto post topic, or the title and first lines of your article, to write the post. It uses your own key, so Google's own terms for that key apply.
- Google News, Wikipedia, Wikimedia Commons, Openverse and CoinGecko are searched with the post subject, only to find fresh headlines and a real picture. Nothing about you is sent.
Nobody else. We share data with the police or a court only if the law makes us.
YouTube
AlphaPost uses YouTube API Services to upload videos to your YouTube channel when you ask it to. By connecting YouTube you agree to the YouTube Terms of Service, and Google handles your data under the Google Privacy Policy.
- What we get from YouTube: your channel name and channel ID, and a login token that lets AlphaPost upload videos. We ask Google only for permission to upload videos and to read your channel name.
- How we use it: only to upload the videos you choose, with the title, text and privacy you choose, to the channel you pick. We never read your other videos, comments, subscribers or watch history, and we never post anything you did not send.
- Where it goes: the video goes straight from your device to YouTube. The login token is locked with AES 256 encryption on our server and is never shared or sold.
- Taking it back: remove the channel in AlphaPost under Accounts, which deletes the token at once, or remove AlphaPost from your Google account at Google security settings. Deleting your AlphaPost account deletes everything we have from YouTube.
AlphaPost's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements.
How long we keep it
For as long as you have an account. When you remove one social account, its keys are deleted at once. When you delete your AlphaPost account, your account, all your keys and all your posts are deleted at once and cannot be brought back.
Your choices
- Remove any added account at any time from Accounts.
- Delete your whole AlphaPost account from Settings, or read how to delete your account.
- Ask us what we hold about you, or ask us to fix it, through our contact page.
Safety
All traffic uses HTTPS. Keys are encrypted before saving, and the encryption key is kept on the server apart from the database. No system is perfect, so please use a strong password that you do not use anywhere else.
Children
AlphaPost is not for children under 13 and we do not knowingly keep data about them.
Changes
If we change this policy we will update the date at the top. Big changes will also be shown in the app.
Contact
Questions about your data? Use our contact page.