ZempostZempost
Privacy Policy
How Zempost handles user, connected account, content, token, and publishing data.
Last updated: July 9, 2026
Overview
Zempost is a social publishing app used to connect social media accounts, compose content, schedule posts, publish posts, and review publishing results from one dashboard.
This Privacy Policy explains what information the app processes, why it is processed, and how it is protected when you use Zempost.
Information We Collect
We collect account information needed to sign in and identify the user, such as name, email address, profile details, and authentication session data.
When you connect social platforms, we process platform account details such as page or profile names, account IDs, usernames, permissions, token expiry dates, and connection health information returned by the relevant platform.
We also process content you create in the app, including post text, media files, captions, scheduling settings, selected platforms, first comments, publishing status, platform responses, and related diagnostics.
How We Use Information
We use this information to provide the app, authenticate users, connect social accounts, upload media, schedule and publish posts, show post history, display account health, and troubleshoot failed publishing attempts.
We may use operational logs and platform error responses to maintain reliability, improve publishing workflows, and help users understand what action is required when a platform rejects a post or token.
We process personal data to perform the service requested by users, protect the app, comply with legal obligations, and support Zempost's legitimate operational interests in reliable and secure publishing workflows.
Connected Social Platforms
Zempost may connect to platforms such as Facebook, Instagram, LinkedIn, X/Twitter, TikTok, Pinterest, and YouTube through each platform's OAuth and API systems.
The app only requests platform permissions needed for the connected publishing workflow. Platform data is used to perform actions requested by the user, such as listing available accounts, validating media, publishing posts, or refreshing connection status.
YouTube API Services
Zempost uses YouTube API Services to let you connect your YouTube channel and to upload, publish, and delete videos at your request. By connecting your channel, you agree to the YouTube Terms of Service.
Information accessed through the YouTube API is handled in accordance with the Google Privacy Policy.
You can review and revoke Zempost's access to your Google and YouTube account at any time through your Google Account security settings, in addition to disconnecting the account from within Zempost.
Limited Use of Google User Data
Zempost's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We only use Google and YouTube user data to provide and improve the publishing features you explicitly request, such as listing your connected channel and uploading, publishing, or deleting your videos. We do not use this data for advertising, and we do not sell it or transfer it to third parties except as necessary to provide the service, to comply with applicable law, or as part of a merger or acquisition. We do not allow humans to read this data unless we have your consent, it is necessary for security purposes, to comply with applicable law, or the data has been aggregated and anonymized.
Data Controller
Zempost is the controller for personal data processed through the app unless a separate written agreement says otherwise.
For privacy, data protection, or controller identity questions, contact faraz@zempost.com.
How We Protect Your Data
We apply technical and organizational security measures designed to protect sensitive data, including social platform access tokens, refresh tokens, and data obtained through the YouTube API and other connected platforms.
Data in transit: all connections between your browser, the app, connected platform APIs, and our servers are encrypted using HTTPS/TLS. Sensitive credentials are only transmitted over these encrypted channels.
Data at rest: user data and platform credentials are stored in a managed, access-controlled database that encrypts data at rest. Access tokens and refresh tokens are stored on our servers and are never exposed to your browser or embedded in client-side code.
Access controls: we enforce row-level access controls so each user can only access their own accounts, content, and connections. Administrative and infrastructure access is limited to authorized personnel on a least-privilege basis, and we do not allow personnel to read your Google or YouTube data except with your consent, for security purposes, to comply with applicable law, or where the data has been aggregated and anonymized.
Credential handling and revocation: connected-account credentials are used only to perform the publishing actions you request. When you disconnect a social account, or delete your account, the associated stored credentials are removed or invalidated so they can no longer be used to access the platform.
Monitoring and incident response: we log operational activity, monitor for unauthorized access, and maintain processes to investigate and respond to suspected security incidents. No method of transmission or storage is completely secure, but we work to protect your information using industry-standard practices.
Tokens and Security
Access tokens and related credentials are stored for the purpose of keeping connected accounts available for publishing and scheduling. These credentials are treated as sensitive data, are protected using the measures described in “How We Protect Your Data,” and are not sold or shared for advertising.
Users or administrators can disconnect social accounts, which removes or invalidates the app's stored connection for that account within Zempost.
Sharing and Disclosure
We share information with connected social platforms only as needed to complete user-requested actions, such as uploading media, creating posts, checking account status, or reading publish results.
We may disclose information if required by law, to protect the app and its users, or to investigate abuse, security incidents, or unauthorized access.
Data Retention
We keep app data for as long as needed to operate Zempost, maintain post history, support scheduled publishing, meet operational requirements, and resolve support or security issues.
When an account, post, media item, or platform connection is deleted, associated data is removed from active app workflows unless retention is required for logs, backups, legal obligations, or security purposes.
Your Choices
You can choose which social accounts to connect, which platforms to publish to, and whether a post is saved as a draft, scheduled, or published immediately.
You may request access, correction, deletion, or disconnection of your Zempost data by contacting faraz@zempost.com or by visiting our Data Deletion page.
Your Rights (GDPR and CCPA)
Depending on where you live, you may have the right to access, correct, delete, restrict, export, or object to the processing of your personal data.
California residents may have the right to know what personal information is collected, request deletion, and opt out of sale or sharing. Zempost does not sell personal information.
We aim to respond to verified privacy requests within 30 days unless a longer period is permitted or required by applicable law.