Skip to content

Omni Posto

Privacy Policy

This policy explains what data Omni Posto processes, why it is used, which providers may receive it, and what rights you may exercise.

Last updatedJune 19, 2026

1. Data we collect

Omni Posto may process account details, profile information, email address, organization details, content drafted in the product, publishing metadata, and billing information related to your use of the service.

When you connect a social platform, Omni Posto may also process the data required for that integration, such as account identifiers, OAuth permissions, publishing status, and certain performance data.

2. Why we use data

We use data to provide the service, administer workspaces, authenticate users, publish requested content, sync analytics, support billing, secure the platform, and respond to support needs.

Some data may also be used to prevent abuse, investigate incidents, log sensitive actions, and improve the product.

3. Human support access with separate consent

A support or development staff member must first initiate an access request tied to a ticket reference and a specific reason. Reading is possible only when an organization owner or admin approves that request with the required MFA check.

This approval is separate from cookie or analytics consent. It only allows an active staff member to read data needed for the ticket: account, organization, posts, visible media metadata, and displayable analytics.

The approved grant expires automatically after a maximum of 7 days and can be withdrawn at any time from Support access in settings. Every request, approval, revocation, and support read is audited.

  • excluded categories: OAuth secrets, access tokens, refresh tokens, MFA, payment, passwords, and credentials
  • no unrestricted database access for staff in v1
  • withdrawal immediately blocks support reads tied to the approved grant

5. Connected platforms and tokens

OAuth permissions granted to Omni Posto are used only to perform the actions requested by the user on connected accounts.

Technical secrets and tokens are handled with appropriate protections and are not exposed publicly in the user interface.

6. Service providers and processors

Omni Posto relies on technical providers to operate the service. Depending on the features used, this may include hosting and infrastructure, authentication, database and storage services, email delivery, subscription billing, and AI providers.

  • Supabase for database, authentication, and storage
  • Railway for application deployment and hosting
  • Lemon Squeezy for billing and subscription management
  • Resend for transactional email when enabled
  • ZhipuAI and Together AI for AI-assisted features when used
  • official APIs from connected social platforms

7. Retention

Data is kept as long as necessary to provide the service, satisfy contractual requirements, secure the platform, handle disputes, or comply with legal obligations.

Some data related to videos, publications, analytics, or plan limits may be deleted or restricted depending on the active plan, user-requested actions, legal obligations, and account state.

8. Security

Omni Posto uses reasonable technical and organizational safeguards to protect data against unauthorized access, loss, alteration, or disclosure.

No method provides absolute security. You are also responsible for protecting your credentials, devices, and connected accounts.

9. Technical observability

Sentry may receive technical error events to diagnose incidents and protect service stability.

The active configuration uses sendDefaultPii=false and sanitization before sending. Replay or marketing-style session tracking is not enabled without explicit analytics consent.

10. International baseline

Omni Posto applies a strict global baseline: no non-essential tracker before consent, simple withdrawal, data minimization, and GPC honored for any future marketing, sale, or advertising share.

Depending on your region, you may have rights to access, correct, delete, object, restrict, port, or withdraw consent.

11. Your rights

Depending on applicable law, you may request access to, correction of, deletion of, or restriction on certain personal data, and you may object to certain processing where available.

You may also request the disconnection of a social account, deletion of a workspace, or additional information about how your data is handled.

Contact

If you have questions about privacy, personal data, or your data rights, you can contact us at the address below.