Who we are
SmoothLayers LLC operates PostBison. In this policy, “PostBison,” “we,” and “us” refer to that operator.
Questions or privacy requests may be sent to privacy@postbison.com.
Data we collect
Account and session information
Better Auth stores your name, email address, email-verification state, account login records, and password hash when you use email and password. Sessions include a session token, expiration time, and may include IP address and user-agent information. If you use Google or Microsoft sign-in, PostBison receives the provider account identifier and authentication credentials needed for that sign-in.
Connected social profiles
When you connect Instagram, Facebook, or TikTok, we store provider and platform account identifiers, profile details the provider returns, granted permissions, credential issue and expiry times, connection health, and brand assignment. Active provider identifiers remain available to operate the connection; they are not all stored only as digests. Social access and refresh credentials are encrypted before database storage.
Brands, posts, and media
We store brand names, descriptions, settings, member roles, post text, schedules, time zones, approval state, target status, and related operational history. Customer post images and videos use a private Cloudflare R2 bucket. A limited gateway can make media available when a social provider needs to retrieve it. A brand may also have a publicly accessible brand logo stored through Vercel Blob; it is not a private R2 object.
Security and compliance records
We store allowlisted sign-in, sign-out, social-connect, and social-disconnect events, plus connection-health observations and rate-limit records. Meta deletion safeguards and confirmation receipts are digest-only compliance records. Those digests cannot be used to recover the original provider identifier or confirmation code.
Meta permissions we request
When you connect a Facebook Page, PostBison asks Meta for the following permissions. We request each one because a feature you use needs it, and we request no more than those features require.
- pages_show_list — to list the Pages you administer so you can choose which ones to add to PostBison.
- pages_read_engagement — to read Page details and confirm a connection is still valid, so PostBison reports its health honestly rather than claiming a Page is ready to publish when it is not.
- pages_manage_posts — to publish the posts you compose and schedule, to the Pages you select. PostBison does not post content you did not author, to a Page you did not select, or at a time you did not schedule.
Connecting an Instagram account uses instagram_business_basic, and connecting TikTok uses user.info.basic, user.info.profile, and user.info.stats. Publishing permissions for those platforms — instagram_business_content_publish and video.upload — are requested only where that delivery path is available to you, and are described in the delivery limits in the Terms of Service.
From these permissions we store the account or Page identifier, the profile or Page name, the permissions actually granted, and an encrypted access credential. We do not read your private messages, and we do not collect your followers’ personal information. Disconnecting a profile in PostBison, or removing PostBison from your Meta settings, deletes the stored credential.
How we use data
We use the information described above to:
- create and secure accounts, verify email addresses, and maintain sessions;
- connect social profiles and keep their permissions and health state current;
- separate work by brand and enforce user and brand access checks;
- store, validate, schedule, and prepare post content and media;
- send transactional verification, reset, and connection-health email;
- prevent abuse, diagnose failures, and maintain service reliability; and
- honor signed Meta deauthorization and data-deletion callbacks.
PostBison does not currently publish posts to social platforms. Scheduling content stores the requested plan and related target records, but does not cause publication.
When information is shared
PostBison uses vendors to operate the service: Neon for PostgreSQL data storage in an AWS US East region, Vercel for application hosting and public brand-logo storage, Cloudflare R2 for private customer media, Resend for transactional email, and Sentry for sanitized operational error and performance monitoring.
When you choose to connect a social platform, information is also exchanged with that platform to authenticate the connection, retrieve the profile data and permissions you requested, and respond to provider compliance callbacks. Google or Microsoft receives authentication requests if you choose its sign-in option.
These providers apply their own terms and privacy practices. Although PostBison’s PostgreSQL database is configured for US East, this policy does not claim that every service provider processes all data only in the United States.
Security and monitoring
PostBison encrypts connected-social credentials before storing them, keeps private post media out of a public R2 bucket, authorizes brand-scoped operations on the server, and limits sensitive projections so credentials do not reach page components.
Sentry is configured for sanitized operational monitoring: error messages, request data, user data, and arbitrary metadata are removed before events are sent, and tracing is capped. It is used to identify operational failures, not product analytics or advertising tracking. No product-analytics or advertising-tracking dependency is installed in this codebase.
No technical safeguard is perfect. Please protect your credentials and notify us at privacy@postbison.com if you believe your account or a connection has been compromised.
Retention and deletion
Security events and social-account health observations expire after 90 days and are pruned by nightly maintenance. Publishing transition records are pruned nightly on that same schedule and carry 90-day expiration timestamps. Work is bounded, so a large backlog may require more than one nightly run.
Meta compliance-deletion guards stop applying after 15 minutes, but those guard rows are not currently part of nightly pruning. Digest-only deletion-status receipts stop resolving after 30 days, and expired receipts are removed when a new receipt is created. Session, verification, OAuth-state, and rate-limit records carry expiration timestamps; expiration does not necessarily mean the database row is removed immediately.
The current code does not apply one automatic deletion period to every account, brand, post, or media record. Those records may remain until the related record is deleted or the service implements another documented lifecycle.
A valid signed Meta deletion request removes the matching Instagram or Facebook social connection and coordinates related publishing-target data. It does not delete your entire PostBison account. Disconnecting a social profile clears its stored credentials and many profile fields, while platform and provider identifiers can remain on the disconnected connection record.
Your choices
- You may disconnect a supported social profile from PostBison.
- You may revoke PostBison access from the relevant social provider.
- You may avoid Google or Microsoft sign-in and use email and password.
- You may contact privacy@postbison.com to ask about access, correction, or deletion of your information.
The legal rights available to you depend on your location. This draft does not invent a jurisdiction-specific process that has not yet been supplied by the service owner.
Changes and contact
We may update this policy when the service or its data practices change. The effective date at the top identifies the current version.
Contact: privacy@postbison.com. For the rules that govern use of PostBison, read the Terms of Service.