Privacy Policy
netpin.me is a social media post scheduler. This policy explains what data we collect, why, how long we keep it, and how you get it deleted. The short version: we use your data only to publish the posts you asked us to publish. We never sell your data, and we never share it with third parties for their own purposes.
1. Who we are
netpin.me is the data controller for the personal data described in this policy. The service is operated from the United Kingdom, and our servers and database are hosted in the United Kingdom.
This policy is written to satisfy both the UK GDPR and the EU GDPR (Regulation (EU) 2016/679), and it applies to you wherever you live — including customers in Romania and elsewhere in the European Union.
You can reach us about anything in this policy at contact@netpin.me. If you are in the EU and need a postal address for a formal request, ask and we will provide one.
2. What we collect
Account data
Your email address and username. Your password is stored only as a bcrypt hash — we never store or see it in plain text. If you sign in with Google or Facebook instead, we receive your name, email address and avatar URL from that provider.
Content you create
The text of your posts, any images or video you upload, the scheduled time, the platforms you chose, and the delivery status of each post (pending, sent or failed).
Connected platform data
When you connect a social media account we store the access token (and refresh token, where the platform issues one) plus an identifier for the account — a handle, page name or numeric id, depending on the platform — so we can publish on your behalf and show you which account is connected. Every credential is encrypted at rest. Section 3 sets out exactly what this means platform by platform.
Engagement data on your own posts
For posts we published for you, we may read back public engagement counts — likes, comments, shares, and impressions or reach where the platform exposes them — so we can show you how a post performed. We only ever request this for posts netpin.me itself published.
Replies and mentions (Inbox)
If you connect Bluesky or Mastodon, the Inbox feature polls for replies and mentions directed at your connected account so you can read them in netpin.me. That includes the text of the reply and the handle of the person who wrote it.
Listening data
If you use the Listening feature, we search the public timelines of Bluesky and Mastodon for the terms you choose to track, and store the matching public posts — their text, the author's public handle, their public follower count, and a link back to the original. This is public content published by third parties; we collect it only to show you mentions of the terms you track, we do not enrich it with data from anywhere else, and you can delete a tracked term and its results at any time.
Technical data
We store a small amount of data in your browser's local storage: a session token when you are signed in, your theme preference, your unsaved post draft, and — if you use netpin.me before signing in — a randomly generated identifier so your drafts and queue stay attached to your browser. We do not use advertising or third-party tracking cookies.
3. Data from the platforms you connect
You choose which platforms to connect, one at a time, and you approve the permissions on that platform's own authorisation screen. We request the narrowest set of permissions that lets us publish for you. The following applies to every platform below:
- We use platform data solely to publish the content you scheduled, to identify which connected account it belongs to, and — where noted — to report engagement on posts we published for you.
- We never sell, rent or trade platform data, never share it with third parties, never use it for advertising or profiling, and never use it to train machine-learning models.
- Every credential is encrypted at rest and used only to act on your behalf.
- You can disconnect any platform from the Accounts screen, which deletes its stored credentials immediately. You can also revoke access from within the platform's own settings. Either action stops all future access.
TikTok
Permissions requested: video.publish — nothing else. We cannot read your existing videos, your followers, your comments, your direct messages or your analytics.
Read when you compose a post: TikTok requires us to load your current posting settings before showing you the TikTok options, so that the choices we offer are your real ones. That call returns your display name, your profile picture, the privacy levels your account allows, whether you have turned off comments, Duet or Stitch, and your maximum video length. It is shown to you in the compose form and used to build the post; it is not stored on our servers.
Stored: an access token, a refresh token, and open_id — a pseudonymous account identifier specific to this app, which is how we know which connected account a scheduled post belongs to. We also store the choices you make for each TikTok post (who can view it, whether comments, Duet and Stitch are allowed, and whether you disclosed it as promotional or branded content) so the post can be published exactly as you set it.
Facebook (Meta)
Permissions requested: pages_manage_posts, pages_read_engagement, pages_show_list. netpin.me publishes to a Facebook Page you administer, never to your personal profile or timeline, and we do not request access to your friends, your personal posts or your messages.
Stored: the Page id, a Page access token, and the Page's name. pages_read_engagement is used to read back likes, comments, shares and impressions on posts netpin.me published for that Page.
Instagram (Meta)
Permissions requested: instagram_basic, instagram_content_publish, pages_show_list, pages_read_engagement. This requires an Instagram Business or Creator account linked to a Facebook Page you administer.
Stored: the Instagram Business Account id, the associated Page access token, and your Instagram username. Engagement permissions are used to read back likes, comments and reach on posts netpin.me published for you.
Permissions requested: w_organization_social — a write-only permission. netpin.me posts to a LinkedIn company page you are authorised to manage; it cannot post to your personal profile and cannot read your feed, connections or messages.
Stored: the organisation id you supply, an access token, and the organisation's name (fetched once so the connection is recognisable in the interface).
X (Twitter)
Permissions requested: tweet.write, users.read, offline.access. users.read identifies the account you connected; offline.access issues a refresh token so a scheduled post does not fail when the short-lived token expires. We do not request permission to read your timeline or your direct messages.
Stored: an access token and a refresh token.
Permissions requested: pins:write, boards:read. The read permission lists your boards so you can choose where a pin goes; the write permission creates the pin.
Stored: an access token, and a refresh token where Pinterest issues one.
Bluesky
Bluesky does not use OAuth here. You paste your handle and an app password — a revocable credential you generate in Bluesky's settings, which is not your account password. Please do not use your main password.
Stored: your handle and that app password, encrypted at rest. It is used to publish your posts, to poll replies and mentions for your Inbox, and to read engagement on posts we published. Revoke the app password in Bluesky's settings at any time to cut off access instantly.
Mastodon
Mastodon also uses direct credentials. You supply your instance URL and an access token you generate on that instance, scoped by you.
Stored: the instance URL and that access token, encrypted at rest, used to publish your posts and to read replies, mentions and engagement on them.
Each platform also handles your data under its own privacy policy, which governs your relationship with them: TikTok, Meta (Facebook and Instagram), LinkedIn, X, Pinterest, Bluesky, and the privacy policy of whichever Mastodon instance you use.
4. How we use your data
- To publish your posts to the platforms you selected, at the times you selected.
- To authenticate you and keep your account secure.
- To show you your queue, calendar and delivery results, including why a post failed.
- To report how the posts we published for you performed.
- To show you replies and mentions in your Inbox, and results for the terms you track in Listening.
- To send you service email you have asked for — password resets, and account notices.
- To keep the service working: diagnosing errors and preventing abuse.
We do not build advertising profiles and we do not use your content to train anything.
5. Legal bases for processing
Under the UK GDPR and the EU GDPR we must have a lawful basis for each use of your data. Ours are:
- Performance of a contract — running your account and publishing your scheduled posts.
- Consent — connecting each social media account; you can withdraw it at any time by disconnecting.
- Legitimate interests — keeping the service secure, preventing abuse, and fixing faults.
- Legal obligation — retaining billing records where tax law requires it.
6. Who we share data with
We do not sell, rent or trade your personal information or your content. Data leaves netpin.me in only two situations:
- The platforms you chose. The posts you schedule are transmitted to the social media accounts you connected. That transfer is the service you asked for.
- Service providers acting on our instructions. A small number of infrastructure providers process data only to deliver the service, never for their own purposes: our hosting provider, Brevo (transactional email such as password resets), and Stripe (payment processing — card details go directly to Stripe and never touch our servers).
We may also disclose data where the law compels us to, or to protect our rights, users or infrastructure from harm.
7. How we protect your data
- All traffic is served over HTTPS.
- Passwords are hashed with bcrypt; the plain text is never stored.
- Platform access tokens are encrypted at rest and used only to publish on your behalf.
- Access to production systems is restricted to those who need it.
No system is perfectly secure, but we take these measures seriously and will notify you and the relevant regulator of a qualifying breach as the law requires.
8. How long we keep it
We keep your data while your account is active. Posts and their delivery history remain in your account until you delete them or delete your account. Platform credentials are deleted the moment you disconnect that platform. Inbox and Listening results are removed when you disconnect the platform they came from or delete the tracked term. When you delete your account, your profile, scheduled posts and connected accounts are removed from our systems; backups age out on a rolling basis, and billing records are kept only as long as tax law requires.
9. Your rights
You can change your email or password, and permanently delete your account, from Account Settings. You can disconnect any platform from the Accounts screen.
If you are in the UK or the EU, the GDPR gives you the right to:
- Access a copy of the personal data we hold about you;
- Rectify data that is inaccurate or incomplete;
- Erase your data (“the right to be forgotten”);
- Restrict or object to our processing, including processing based on legitimate interests;
- Port your data to another service in a machine-readable format;
- Withdraw consent at any time — for example by disconnecting a platform — without affecting processing carried out before you withdrew it.
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects, so the related Article 22 right does not arise.
To exercise any of these, email contact@netpin.me. We respond within one month, free of charge.
Complaining to a regulator
You can complain to a supervisory authority at any time, and you do not have to come to us first:
- Romania — Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), dataprotection.ro.
- Elsewhere in the EU — the data protection authority of the country where you live, work, or where you think the problem occurred.
- United Kingdom — the Information Commissioner's Office, ico.org.uk.
If you are a California resident, you have the right to know what we collect, to request deletion, and not to be discriminated against for exercising those rights; note that we do not sell personal information.
10. International transfers
Your account, your posts and your platform credentials are stored on servers in the United Kingdom.
If you are in the EU, that means your data leaves the EEA when you use netpin.me. This transfer is lawful without any further paperwork: the European Commission has adopted an adequacy decision for the United Kingdom, formally recognising that UK law protects personal data to a standard essentially equivalent to the EU GDPR. Your GDPR rights travel with your data and remain fully enforceable.
Some of our service providers process limited data outside the UK and EEA. Where that happens we rely on appropriate safeguards — the EU Standard Contractual Clauses together with the UK Addendum, or the UK International Data Transfer Agreement. You can ask us which safeguard applies to a particular provider.
Separately, when you schedule a post to a social platform, that content is transmitted to the platform you chose and is then handled under that platform's own policy and its own transfer arrangements — which may involve countries outside the UK and EEA. That transfer happens because you asked us to publish there.
11. Children
netpin.me is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child has given us personal data, email contact@netpin.me and we will delete it.
12. Changes to this policy
We may update this policy as the service develops. We will update the date at the top of this page, and for material changes we will notify you by email or in the app.
13. Contact
Questions, requests, or concerns about your data: contact@netpin.me.
This page is written in plain language for transparency. It is not legal advice; review it against your own obligations before relying on it.