Privacy Policy
Last updated: 5 September 2026
What we store
- Account data: your email address, a salted hash of your password (never the password itself), and workspace/team membership.
- Social account connections: when you connect a social account we store the OAuth access and refresh tokens the platform issues, encrypted at rest, plus basic profile info (name, avatar, account id) so you can tell channels apart. We can only do what those tokens allow — publish the posts you schedule and read basic profile info. We never see your social-account passwords.
- Your content: post text and uploaded media, stored until you delete the post.
- Billing: subscription state from Razorpay. Card and payment details are handled by Razorpay and never touch our servers.
What we don't do
- We don't sell or share your data with advertisers.
- We don't post anything you didn't schedule.
- We don't read your social inboxes or private messages — the access we request is limited to publishing and basic profile info.
Connected platforms
SchedulSmart publishes to Instagram, Facebook, X (Twitter), LinkedIn, YouTube, TikTok and Pinterest. For each one we hold only the OAuth token you granted and the profile fields needed to label the channel. Disconnecting a channel deletes its tokens; you can also revoke our access from the platform's own settings at any time.
TikTok. With your authorisation we read your basic profile (open id, display name, avatar) so you can tell the channel apart, and — when you select the TikTok channel in the composer, and again when the post is published — your current posting settings from TikTok's creator-info endpoint (the privacy levels available to you, whether comments, Duet and Stitch are enabled, and your maximum video length) so the composer can offer exactly the choices TikTok allows. A video is sent to TikTok only when you choose to post it: either published directly to your profile with the privacy level you pick, or delivered to your TikTok inbox as a draft for you to finish in the TikTok app. We do not read your TikTok videos, followers, statistics, messages or watch history, and we never post to TikTok without an explicit action from you.
Processors we rely on
Cloudflare (hosting, database, media storage), Razorpay (payments), and Resend (transactional email such as signup verification). Each processes data only to provide the service.
Deleting your data
Disconnecting a channel deletes its stored tokens. Deleting a post deletes its content. To close your account and remove its data entirely, email admin@appifycommerce.com from the account's address. You can also revoke SchedulSmart's access at any time from each social platform's own security settings.
Contact
Privacy questions: admin@appifycommerce.com.