Privacy Policy
What WeDo Posting collects when you connect a Meta account, how your tokens and content are protected, and how to remove everything.
1. Scope
This policy explains what WeDoPosting collects when you use WeDo Posting, why, and how to remove it. WeDo Posting is a tool for planning, generating, reviewing, and publishing social-media content to accounts you connect yourself.
2. Signing in with Meta
Signing in is done through Meta, using Facebook Login. Meta gives us an account identifier that is specific to our application, your name, and your profile picture. We do not request your email address, your friends, or any other profile information, and we cannot read your personal Facebook feed or messages.
3. Facebook Pages and Instagram accounts
With the permissions you approve, we read the list of Facebook Pages your Meta account manages and, for each Page, the Instagram Professional account linked to it. For those we store the identifier, name, username, profile picture, and the permissions you hold on the Page — enough to show you the destinations and to publish where you tell us to. We only ever access Pages and Instagram accounts you connect, and only while that connection remains.
4. Access tokens and AI provider keys
Publishing requires access tokens from Meta, and content generation uses an AI provider key that you supply. Both are encrypted before they are stored, using AES-256-GCM with a key held only on the server, and both are used solely on the server for requests belonging to your own workspace. They are never sent to your browser, never written to logs, and never returned by our API.
5. Content you create
We store the projects and subprojects you create, their names, descriptions, and briefs, the reference images you upload, and the images and captions generated for you together with the prompts used to produce them and the schedule that triggered each run.
6. Publishing records
For every attempt to publish we record the destination, whether it succeeded, the identifier and link of the resulting post, and any error Meta returned. This is what lets you see per-destination results and retry a failure. Attempts made while an account is in dry-run mode are recorded without anything being sent to Meta.
7. Cookies
WeDo Posting sets one cookie, to keep you signed in. It holds a signed reference to your account, is restricted to our own site, cannot be read by scripts in your browser, and expires after thirty days. We do not use advertising, analytics, or tracking cookies, and we do not track you across other sites.
8. How information is used
Information is used only to run the service you asked for: to sign you in, to show your connected destinations, to generate and schedule content, to publish where you approve, to report results back to you, and to diagnose failures. We do not sell your information, we do not use it for advertising, and we do not use your content or credentials to train AI models.
9. Who else is involved
Publishing and account discovery happen through Meta’s APIs, so the content and destinations you choose are sent to Meta. Content generation sends your briefs, reference images, and prompts to the AI provider whose key you connected. Both are independent services governed by their own terms and privacy practices. We do not share your data with anyone else.
10. How media is stored
Reference images you upload and images generated for you are stored as files and served from our media paths. Anyone holding the direct link to a file can open it without signing in, so treat those links as you would any unlisted URL and avoid uploading material that must remain confidential.
11. Retention and deletion
Information is kept while your account exists and for as long as it is needed to run the service. You can disconnect a Meta account, switch off a single destination, remove an AI provider key, or archive a project at any time, and you can ask us to delete your account and everything we hold. Verified deletion requests are completed within 30 days. Step-by-step instructions are on our Data Deletion page.
12. Your choices
You may ask for a copy of your data, ask for it to be corrected, withdraw a connection, or ask for deletion, by writing to mountainmediacontact@gmail.com. You can also remove our access at any time from Facebook’s Apps and Websites settings, which immediately invalidates the tokens we hold.
13. Security
Tokens and provider keys are encrypted at rest, credentials are handled only on the server, and access to your workspace is limited to your own signed-in account. No service can promise perfect security, and we do not claim to; if we become aware of a breach affecting your data we will inform you.
14. Children and changes
WeDo Posting is not intended for children. We may update this policy as the product changes and will revise the date at the top when we do; material changes will be communicated in the product.
15. Contact
For questions about this policy or about your data, contact WeDoPosting at mountainmediacontact@gmail.com.