Privacy Policy
Last updated: 8 October 2026
Hitpost (“Hitpost”, “we”) is a tool to schedule and publish posts to your own social media accounts. It is operated by Prosperitas SCP, 1 Bellevue Palace, 98000 Monaco. This policy explains what we collect, why, and the choices you have. Questions: [email protected].
What we collect
| Data | Why |
|---|---|
| Your email address and password (stored only as a one-way hash) | To create your account and let you log in |
| Two-factor login secret (encrypted) | To check the codes from your authenticator app |
| Login sessions: date, IP address and browser type | To keep you logged in and to protect your account (for example, blocking repeated wrong passwords) |
| From Instagram, when you connect an account: its ID, username, account type, follower and post counts, and an access token (encrypted) | To show which account you are posting to and to publish the posts you schedule |
| From TikTok, when you connect an account: its ID, display name, username, avatar, the posting options TikTok allows for it, and access and renewal tokens (encrypted) | To show which account you are posting to, and to send the videos you schedule to it as drafts or posts |
| From YouTube (Google), when you connect a channel: the channel ID, name and handle, and access and renewal tokens (encrypted) | To show which channel you are posting to and to upload the videos you schedule |
| Videos, photos, captions and schedules you add | To publish them at the time you choose |
| Results from Instagram about your posts (published or not, error messages) | To show you what happened and fix problems |
| Clicks on your Hitpost short links: time, country and whether it looked like a bot. No IP addresses are stored. | To show you how many people clicked your links |
| Plan and payment status. Payments are handled by our payment provider; we never see or store card numbers. | To run your subscription |
How we use Instagram data
We use data from Instagram only to provide the features you use in Hitpost: connecting your account, publishing the posts you schedule, and showing you their status. We do not sell it, use it for advertising, or share it with anyone except as needed to run the service (see below). Our use follows Meta's Platform Terms and Developer Policies. You can disconnect Hitpost at any time in Hitpost, or on Instagram under Settings → Website permissions → Apps and websites.
How we use TikTok data
We use data from TikTok only to connect your account, show which account a post goes to, and upload the videos you schedule as drafts or direct posts with the settings you choose. We do not sell it or use it for advertising. You can disconnect Hitpost in Hitpost, or in the TikTok app under Settings and privacy → Security and permissions → Apps and services permissions.
How we use YouTube and Google data
When you connect a YouTube channel, Hitpost asks Google for two permissions: “Manage your YouTube videos” (youtube.upload), used only to upload the videos you schedule, with the title, description and visibility you choose; and “View your YouTube account” (youtube.readonly), used only to show which channel is connected. We don't read your other videos, comments, analytics or anything else in your Google account.
Hitpost's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, do not sell it, do not use it to train AI models, and do not let people read it except with your permission, for security, or where the law requires.
Hitpost uses YouTube API Services. By connecting a channel you also agree to the YouTube Terms of Service, and Google's handling of your data is described in the Google Privacy Policy. You can remove Hitpost's access at any time in Hitpost (Settings → Accounts → Remove) or on your Google account security page; we then delete the stored tokens.
Who processes data for us
- Hetzner Online GmbH (Germany): our servers, where your data is stored.
- Cloudflare, Inc.: secure connection to our site, short links, and encrypted backups.
- Meta Platforms (Instagram), TikTok and Google (YouTube): receive the posts and videos you choose to publish.
- Our payment provider (Paddle, once payments open) and our email provider (for password-reset emails).
Each only receives what it needs for its part of the service. Some of them may process data outside your country, under standard contractual safeguards.
Security
Connections are encrypted (HTTPS). Passwords are hashed; access tokens and two-factor secrets are encrypted at rest. Backups are encrypted before they leave our server. You can turn on two-factor login on your Account page.
How long we keep data
We keep your data while your account is open. When you delete your account, your data is deleted from our live systems immediately, and from encrypted backups within 8 weeks as they expire. See how to delete your data.
Cookies
We use one essential cookie to keep you logged in. No advertising or tracking cookies.
Your rights
You can ask to access, correct, export or delete your data, or object to how we use it, by writing to [email protected]. You can also complain to your data protection authority (in Monaco: the APDP; in the EU: the authority of your country).
Children
Hitpost is a business tool for people aged 18 and over.
Changes
If we change this policy we will update the date above, and tell you by email or in the app if the change is important.