Home  /  Security

Security and data handling

Connecting your social accounts to any tool is a real decision. Here is exactly what EaseMyPost holds, what it can do with it, and how you take it back.

How accounts are connected

Connection happens through the platform's own login — Facebook Login for Instagram and Facebook, Google OAuth for YouTube. We never ask for, receive or store your password for any platform. What we receive is a scoped access token.

How tokens are stored

Access tokens are stored encrypted, not in plain text. They are used only to perform the actions you have approved: publishing content, reading performance metrics, and replying to comments and messages where you have enabled it.

What we cannot do

Revoking access

You can revoke at any time, from either side:

AI and your content

Drafting uses third-party AI models. Your brand information and past posts are sent to those models to produce drafts for you. We do not sell your data, and we do not use your business content to train models for anyone else's benefit.

Failures are surfaced, not hidden

When a post fails — an expired token, a platform outage, a rejected upload — you are told, and the post is marked failed. A system that quietly swallows errors is worse than one that breaks loudly, because you find out from a customer instead of from us.

Reporting a problem

If you believe you have found a security issue, email [email protected] with the details. We will confirm receipt and tell you what we are doing about it.

We are an early-stage product and we would rather describe our security posture plainly than claim certifications we do not hold. We have no SOC 2 or ISO 27001 audit. If your business requires one, we are not the right fit yet.

Want it running on your page?

We onboard a few businesses at a time and set it up with you.

Get early access