Privacy policy
Last updated: September 4, 2026
Postmatic is an API and a dashboard for publishing and scheduling content on social networks, Instagram today. This policy states which data we process, why, for how long, and how you delete it. It applies to postmatic.dev and to the API at api.postmatic.dev.
Who we are
Postmatic is operated by Cleidson França, in Brazil. Contact: privacidade@postmatic.dev.
Your account data
- Email, used to sign in (email code) and for notices about your account.
- Organization name and internal project identifiers.
- API keys: we store only the hash; the full key is shown once, at creation.
- Session cookies from Supabase Auth, strictly necessary to keep you signed in. We do not use tracking or advertising cookies.
Meta and Instagram data
When you connect an Instagram account, we use the Instagram Graph API (Instagram API with Instagram Login), from Meta Platforms, Inc. In that process:
- What we receive: the Instagram account identifier, username, account type, profile picture, the permissions granted, and a long-lived access token. After each publish we make, we receive the identifier and permalink of that post.
- Why: to publish and schedule posts on behalf of your account, to check whether the connection is still valid, and to show that information on the dashboard. We do not read messages, comments, followers, or posts that were not made by Postmatic.
- Where it lives: in a database and a bucket hosted on Supabase. The access token is stored encrypted (AES-256-GCM) and is never shown on the dashboard, in logs, or in API responses.
- How long: for as long as the Instagram account stays connected. Disconnecting it, deleting your Postmatic account, or removing the app from your Instagram settings deletes the token and the connection data. Images uploaded for publishing are stored until the account is deleted.
- Who we share it with: nobody but Meta itself, which receives the publishing calls. We do not sell or hand over data to third parties.
Our use of Meta's data follows the Meta Platform Terms and the Developer Policies. You can revoke access at any time under Settings → Security → Apps and websites, on Instagram.
Images and post content
Text and images you submit for publishing are kept so we can publish them on the chosen date and show the history on the dashboard; they are stored until the account is deleted. Images coming from a URL are copied into our bucket before publishing, because Meta requires a stable, public URL.
Usage data and logs
We keep, for up to 30 days, technical logs of every API request: time, route, HTTP status, and IP address, hosted at our API provider. They are used for security, usage limits, and support. Logs never contain tokens, API keys, or post content.
Where data is processed
Database, authentication, and storage on Supabase; API and dashboard on Railway. Both may run on servers outside Brazil, under data-protection agreements.
Your rights
You can access, correct, and delete your data at any time. Full deletion is one click away, at Account → Delete account; the paths are described on the data deletion page. For other requests, write to privacidade@postmatic.dev.
Changes to this policy
Material changes are announced by email at least 15 days in advance. The version in force is always the one published on this page.