Hitpost

Privacy Policy

Last updated: 8 October 2026

Hitpost (“Hitpost”, “we”) is a tool to schedule and publish posts to your own social media accounts. It is operated by Prosperitas SCP, 1 Bellevue Palace, 98000 Monaco. This policy explains what we collect, why, and the choices you have. Questions: [email protected].

What we collect

DataWhy
Your email address and password (stored only as a one-way hash)To create your account and let you log in
Two-factor login secret (encrypted)To check the codes from your authenticator app
Login sessions: date, IP address and browser typeTo keep you logged in and to protect your account (for example, blocking repeated wrong passwords)
From Instagram, when you connect an account: its ID, username, account type, follower and post counts, and an access token (encrypted)To show which account you are posting to and to publish the posts you schedule
From TikTok, when you connect an account: its ID, display name, username, avatar, the posting options TikTok allows for it, and access and renewal tokens (encrypted)To show which account you are posting to, and to send the videos you schedule to it as drafts or posts
From YouTube (Google), when you connect a channel: the channel ID, name and handle, and access and renewal tokens (encrypted)To show which channel you are posting to and to upload the videos you schedule
Videos, photos, captions and schedules you addTo publish them at the time you choose
Results from Instagram about your posts (published or not, error messages)To show you what happened and fix problems
Clicks on your Hitpost short links: time, country and whether it looked like a bot. No IP addresses are stored.To show you how many people clicked your links
Plan and payment status. Payments are handled by our payment provider; we never see or store card numbers.To run your subscription

How we use Instagram data

We use data from Instagram only to provide the features you use in Hitpost: connecting your account, publishing the posts you schedule, and showing you their status. We do not sell it, use it for advertising, or share it with anyone except as needed to run the service (see below). Our use follows Meta's Platform Terms and Developer Policies. You can disconnect Hitpost at any time in Hitpost, or on Instagram under Settings → Website permissions → Apps and websites.

How we use TikTok data

We use data from TikTok only to connect your account, show which account a post goes to, and upload the videos you schedule as drafts or direct posts with the settings you choose. We do not sell it or use it for advertising. You can disconnect Hitpost in Hitpost, or in the TikTok app under Settings and privacy → Security and permissions → Apps and services permissions.

How we use YouTube and Google data

When you connect a YouTube channel, Hitpost asks Google for two permissions: “Manage your YouTube videos” (youtube.upload), used only to upload the videos you schedule, with the title, description and visibility you choose; and “View your YouTube account” (youtube.readonly), used only to show which channel is connected. We don't read your other videos, comments, analytics or anything else in your Google account.

Hitpost's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, do not sell it, do not use it to train AI models, and do not let people read it except with your permission, for security, or where the law requires.

Hitpost uses YouTube API Services. By connecting a channel you also agree to the YouTube Terms of Service, and Google's handling of your data is described in the Google Privacy Policy. You can remove Hitpost's access at any time in Hitpost (Settings → Accounts → Remove) or on your Google account security page; we then delete the stored tokens.

Who processes data for us

Each only receives what it needs for its part of the service. Some of them may process data outside your country, under standard contractual safeguards.

Security

Connections are encrypted (HTTPS). Passwords are hashed; access tokens and two-factor secrets are encrypted at rest. Backups are encrypted before they leave our server. You can turn on two-factor login on your Account page.

How long we keep data

We keep your data while your account is open. When you delete your account, your data is deleted from our live systems immediately, and from encrypted backups within 8 weeks as they expire. See how to delete your data.

Cookies

We use one essential cookie to keep you logged in. No advertising or tracking cookies.

Your rights

You can ask to access, correct, export or delete your data, or object to how we use it, by writing to [email protected]. You can also complain to your data protection authority (in Monaco: the APDP; in the EU: the authority of your country).

Children

Hitpost is a business tool for people aged 18 and over.

Changes

If we change this policy we will update the date above, and tell you by email or in the app if the change is important.