Privacy Policy
How MultPoster accesses, uses, stores, shares and deletes information, including data received from connected social-platform APIs.
1. Who we are and scope of this policy
MultPoster is operated by multposter.ocenexvr.com. This Privacy Policy applies to the MultPoster public website, user accounts, dashboard, social-account connections, content composer, scheduling, publishing, analytics/status features, support communications and related services.
Privacy contact: moosaminhajvu@gmail.com.
This policy covers MultPoster itself. Each connected social platform also has its own terms and privacy policy governing information processed by that platform.
2. Information you provide directly
Depending on how you use MultPoster, you may provide:
- Account data, such as your name, email address, account identifier and login/session information managed by WordPress.
- Content, such as captions, titles, descriptions, hashtags, media files or media URLs, thumbnails, links and other material you choose to publish.
- Scheduling and destination choices, including which connected accounts should receive a post and when it should be published.
- Support and legal communications, including information you send when requesting support, account access, privacy assistance or deletion.
- Business messaging data, only if you use a messaging integration such as WhatsApp Business, which may include recipient information, template choices and message content supplied by you.
3. Information received from connected platforms
MultPoster requests only the permissions reasonably necessary for the features you choose to use. The exact information available depends on the platform, the scopes/permissions you approve, the type of account you connect and which MultPoster integrations are enabled at that time. We may receive:
- Platform user, channel, page, business, server, group or account identifiers.
- Usernames, display names, channel/page names, account type and basic profile information needed to identify the connected destination.
- OAuth access tokens, refresh tokens, granted scopes/permissions, expiry information, webhook credentials or other authorization material supplied through official platform flows.
- Content/publishing metadata such as media container IDs, remote post/video/message IDs, upload state, publication status, errors and delivery responses.
- Limited account or channel metadata needed to show the user which destination is connected and whether it is eligible for publishing.
MultPoster does not ask users to provide their social-network passwords. Where a platform supports OAuth or another official authorization mechanism, authentication occurs on that platform.
4. Platform-specific disclosures
The following describes the categories of platform data MultPoster may process when the corresponding integration is enabled and the user authorizes it:
Instagram (Meta)
For Instagram Professional accounts (Business or Creator), MultPoster may process the Instagram professional account ID/user ID, username, account type and other basic profile information made available by the approved permissions; OAuth tokens and granted permissions; content/media container IDs; publication status; and remote media IDs. MultPoster uses this data to display the connected account and publish user-directed images, videos, Reels or carousel content. For the current basic publishing use case, MultPoster is designed around instagram_business_basic and instagram_business_content_publish.
Facebook (Meta)
When Facebook Page publishing is enabled, MultPoster may process authorized Page identifiers, Page names/basic Page metadata, permissions, Page/user access tokens needed by the approved API flow, and post/media identifiers and status. This information is used to identify Pages the user is authorized to manage and to publish content the user explicitly selects. MultPoster is not designed to silently automate personal-profile posting.
Threads (Meta)
When Threads is enabled, MultPoster may process Threads user/account identifiers, username/basic profile information, OAuth tokens and scopes, content container identifiers and published Thread identifiers/status. This is used to identify the connected Threads profile and publish content selected by the user.
YouTube / Google
When YouTube is connected, MultPoster may process the user's YouTube channel identifier, channel title/basic channel profile information, OAuth grants, access/refresh tokens where issued, and user-supplied video metadata such as title, description, thumbnail and visibility settings, plus upload/video IDs and upload status. MultPoster uses this information to identify the connected YouTube channel and upload videos or Shorts at the user's direction. MultPoster is intended to request only the Google/YouTube scopes necessary for enabled features, such as youtube.readonly for identifying the connected channel and youtube.upload for uploading content.
TikTok
When TikTok is enabled, MultPoster may process the TikTok account/open identifier, display name and basic profile information made available by approved scopes, OAuth tokens, creator/publishing capability information, user-selected privacy/posting options, content identifiers and publication status. This information is used to connect the creator account and submit user-selected photo/video content through TikTok's approved Content Posting flow.
WhatsApp Business (Meta)
When WhatsApp Business features are enabled, MultPoster may process WhatsApp Business Account and phone-number identifiers, business display/profile information, authorized tokens/permissions, approved template metadata, message identifiers and delivery status. If the user chooses to send a business message, MultPoster may also process the recipient information and message/template data that the user provides for that purpose. WhatsApp is treated as a messaging integration, not a public social-feed destination.
Telegram
For Telegram publishing, MultPoster may process channel/chat identifiers, channel/group names or usernames where available, bot authorization/configuration needed to send messages, user-supplied outbound content and Telegram message IDs/status. For a simple channel-publishing setup, MultPoster does not need to intentionally collect unrelated private conversations.
Discord
For Discord publishing, MultPoster may process server/guild and channel identifiers/names when available, webhook URLs or bot/OAuth authorization information, user-supplied outbound content, and Discord message identifiers/status. In the simple webhook publishing configuration, MultPoster does not need to intentionally read unrelated server-member lists or message history. If future features require additional Discord data, the relevant disclosure and consent flow must be updated before that use.
LinkedIn
When LinkedIn is enabled, MultPoster may process the authenticated member's identifier/basic profile information made available by approved permissions, organization/Page identifiers and names for organizations the member is authorized to manage, OAuth tokens/scopes, and post/media identifiers/status. This information is used to identify the posting identity selected by the user and publish content to the member or eligible organization at the user's direction.
X
When X is enabled, MultPoster may process the authenticated user ID, handle/display name/basic profile information made available by approved scopes, OAuth tokens/scopes, media identifiers and Post identifiers/status. MultPoster uses this data to show the connected X account and publish content only after the user selects X as a destination and initiates or schedules the post.
5. How MultPoster uses information
We use the information described above only as reasonably necessary to:
- Create and secure MultPoster user accounts and sessions.
- Connect social accounts that the user chooses to authorize.
- Display the identity of connected accounts, Pages, channels, organizations, servers or business destinations.
- Prepare, schedule, upload and publish content to destinations selected by the user.
- Refresh authorization where the platform supports refresh tokens and the user has chosen to remain connected.
- Record publication results, remote content IDs, errors and delivery/upload status so users can understand whether a post succeeded.
- Prevent abuse, protect credentials, diagnose failures and maintain service reliability.
- Respond to user support, privacy and deletion requests.
- Comply with applicable law and enforce our Terms and Acceptable Use Policy.
6. Google and YouTube API data — Limited Use disclosure
MultPoster's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google/YouTube user data is used only to provide or improve user-facing MultPoster features that the user has chosen, such as identifying the connected YouTube channel and uploading a video or Short. MultPoster does not sell Google user data, use it for advertising or retargeting, use it to determine creditworthiness, or use it to train a generalized artificial-intelligence or machine-learning model. Human access to Google user data is limited to circumstances permitted by applicable Google policy, such as when the user has requested support and consented to necessary access, when needed for security/abuse investigation, or when required by law.
Users can revoke MultPoster's Google access at any time from their Google Account permissions and can also disconnect/delete the corresponding MultPoster connection as described below.
7. Meta platform data
For Instagram, Facebook, Threads and WhatsApp Business, MultPoster uses data obtained through Meta APIs only for the functionality the user requests and the permissions approved for the app. MultPoster does not sell Meta platform data or use it to build unrelated profiles of users. Users may revoke authorization through their Meta/Instagram/Facebook account settings and may request deletion of MultPoster-held platform data through the Data Deletion process.
8. TikTok, LinkedIn, X, Discord and Telegram platform data
For TikTok, LinkedIn, X, Discord and Telegram, MultPoster processes API/platform data only to provide the connected publishing or messaging feature selected by the user, subject to the provider's developer terms and permissions. MultPoster does not use these APIs for scraping, hidden surveillance, sale of platform data or unauthorized actions on another person's account. Where a platform requires explicit approval before an action is taken, MultPoster is designed to obtain that authorization through the platform connection and the user's publish/schedule action.
9. What MultPoster does not do with connected-platform data
- We do not sell connected-platform API data or access credentials.
- We do not disclose connected-platform data to advertising networks or data brokers for their own advertising or profiling purposes.
- We do not use non-public connected-platform data for surveillance, eligibility/credit decisions or unrelated profiling.
- We do not use connected-platform API data or user content to train a generalized AI/ML model.
- We do not publish to a destination unless the user has connected/authorized that destination and selected or scheduled the publication.
- We do not intentionally request permissions that are unrelated to an enabled MultPoster feature.
10. Sharing and service providers
We share information only where reasonably necessary to operate MultPoster or where the user directs us to send content to a connected platform. Categories of recipients may include:
- The social platform selected by the user, because publishing requires transmitting the content and required metadata to that platform.
- Hosting and infrastructure providers that store or process MultPoster application data on our behalf. This deployment uses Hostinger infrastructure. If infrastructure providers change, this policy will be updated where required.
- Security, email, support or technical service providers if separately enabled by the operator and only to the extent necessary for their service.
- Authorities or other parties where legally required, or where reasonably necessary to protect rights, safety or service security in accordance with applicable law.
We do not permit service providers to use connected-platform data for their own advertising or unrelated purposes.
11. OAuth tokens, credentials and security
Supported platforms should be connected through their official OAuth, bot, business-login or webhook authorization mechanisms. MultPoster does not need the user's social-network password. Stored connection credentials are encrypted at rest by the plugin using keys derived from the WordPress security configuration. We also use HTTPS for the public web application and apply access controls so one MultPoster user cannot intentionally access another user's stored connection records through normal application functionality.
No system can guarantee absolute security. Users should protect their MultPoster account, connected-platform accounts, recovery methods and administrator credentials.
12. Retention
MultPoster retains data only for as long as reasonably necessary for the purposes described in this policy, to provide requested publishing history, maintain security, comply with legal obligations or resolve disputes. In general:
- Connection tokens/credentials are retained while the relevant social account remains connected or until the connection is revoked, deleted or otherwise invalidated.
- Drafts and scheduled-content records are retained until deleted by the user or removed according to service operations.
- Publication records and remote post IDs may be retained as history so users can see whether scheduled/published jobs succeeded, until the user deletes their MultPoster data or retention is otherwise no longer necessary.
- Security/server logs may be retained for a limited period appropriate for troubleshooting, fraud prevention, security and legal compliance.
13. Disconnecting accounts, revoking access and deleting data
You can disconnect individual social accounts from MultPoster. You may also revoke MultPoster directly from the connected platform's own account/app authorization settings. Revoking at the platform prevents future authorized API activity but may not by itself erase records already stored in MultPoster.
To remove MultPoster-held connection records, encrypted tokens, drafts/schedules and publication history associated with your account, use our Data Deletion page or contact moosaminhajvu@gmail.com. Deleting MultPoster records does not automatically delete content already published on a third-party social network; already-published content should be managed on that platform.
For Google/YouTube, users may also revoke access from the Google Account third-party connections/permissions controls. For Meta products, users may revoke access through the applicable Meta/Instagram/Facebook authorization settings.
14. Legal bases and user choices
Where data-protection law requires a legal basis, processing may rely on performance of the service requested by the user, the user's consent/authorization for connected-platform access, legitimate interests such as security and reliability, and compliance with legal obligations. The exact basis can depend on the user's jurisdiction and the type of processing.
Subject to applicable law, users may have rights to request access, correction, deletion, portability, restriction or objection, and to withdraw consent where processing is based on consent. Contact us using the details below to exercise applicable rights.
15. Cookies, logs and technical information
MultPoster runs on WordPress and may use cookies or similar browser storage that are necessary for authentication, security and preferences. Our servers and hosting environment may also generate technical logs such as IP address, user agent, request time, error information and security events where reasonably necessary to operate and protect the service. Optional analytics or advertising technologies are not part of the core publishing requirement and, if separately introduced, must be disclosed and consented to where required. See our Cookie Policy.
16. International processing
Connected social platforms and infrastructure/service providers may operate in multiple countries. Information may therefore be processed outside the user's country of residence. Where required by applicable law, appropriate transfer mechanisms or safeguards should be used by the relevant controller/processor.
17. Children
MultPoster is not directed to children and should not be used by anyone below the minimum age required by applicable law or by the social platform they wish to connect. We do not knowingly design MultPoster to collect children's platform data for advertising or profiling.
18. Changes to integrations or this policy
Social-platform APIs, permissions and policies change over time. We may update this Privacy Policy when MultPoster adds or changes integrations, requests different scopes, changes service providers, or when legal/platform requirements change. If a change materially expands how connected-platform data is used, we will update the disclosure and obtain additional authorization or consent where required before using the data for the new purpose.
19. Contact
For privacy questions, platform-data requests or deletion assistance, contact moosaminhajvu@gmail.com.
Questions? moosaminhajvu@gmail.com