1. Introduction
Auto Schedule Pilot ("we", "our", or "the Service") is a SaaS platform that helps creators and businesses generate AI-powered content and automatically schedule and publish it to social media platforms including Facebook, Instagram, YouTube, TikTok, and Twitter/X. This Privacy Policy describes how we collect, use, store, and protect your information when you use our Service.
By using Auto Schedule Pilot, you agree to the practices described in this policy. If you do not agree, please do not use the Service.
2. Information We Collect
We collect the following categories of information:
- Account information: your name, email address, password (stored as a one-way hash), profile picture, and billing details when you subscribe to a paid plan.
- Connected social accounts: the social media accounts you choose to connect (Facebook Pages, Instagram Business accounts, YouTube channels, TikTok accounts, X accounts), including the public profile information that the platform returns to us.
- Access tokens: the OAuth access and refresh tokens issued by each social platform that allow us to publish content on your behalf with the permissions you have granted.
- Content you upload: videos, images, captions, titles, hashtags, and scheduling metadata you submit to the Service for publishing.
- AI usage data: prompts and generated outputs (titles, captions, descriptions) used to improve your experience and monitor service quality.
- Usage and device data: IP address, browser type, pages visited, timestamps, referring URLs, and basic device information collected automatically through cookies and server logs.
3. How We Use Your Information
We use the information we collect to:
- Authenticate you and provide the Service you have requested.
- Schedule and automatically publish your content to the social accounts you have connected.
- Generate AI-assisted titles, captions, descriptions, and hashtags using third-party AI providers.
- Process payments, manage subscriptions, and send service-related notifications.
- Monitor performance, prevent abuse, and improve features and reliability.
- Comply with applicable legal obligations and enforce our Terms.
4. Social Media Integration
Auto Schedule Pilot connects to social platforms exclusively through their official APIs:
- Facebook Graph API and Instagram Graph API (provided by Meta Platforms, Inc.)
- YouTube Data API (provided by Google LLC)
- TikTok Content Posting API
- X (Twitter) API v2
We only request the specific OAuth scopes required to deliver the features you use — typically the ability to read your basic profile, list your pages or channels, and publish content on your behalf. We never request more permissions than necessary, and we only access the data each platform explicitly authorizes you to share.
Disclaimer: We are not affiliated with, endorsed by, or sponsored by Meta Platforms, Inc. (Facebook, Instagram), Google LLC (YouTube), TikTok Ltd., or X Corp. All product names, logos, and brands are property of their respective owners.
5. How We Share Your Information
We do not sell your personal data. We share information only in the following limited circumstances:
- With social platforms: when publishing content on your behalf, we transmit your content and access tokens to the relevant social media API.
- With service providers: trusted vendors that host our infrastructure, process payments, send transactional email, or provide AI inference, all bound by data-processing agreements.
- For legal reasons: when required by law, court order, or to protect our rights, users, or the public.
- Business transfers: in connection with a merger, acquisition, or sale of assets, with notice to affected users.
6. Third-Party Services
The Service relies on the following categories of third parties:
- Social media APIs: Facebook, Instagram, YouTube, TikTok, and X for publishing.
- AI providers: large-language-model and image-generation providers used to generate titles, captions, descriptions, and creative assets.
- Cloud infrastructure: for hosting, database, file storage, and edge delivery.
- Analytics: aggregated, privacy-respecting analytics to understand product usage.
7. Data Security
We take security seriously. Access tokens and other sensitive credentials are encrypted at rest and transmitted over HTTPS/TLS. Passwords are stored as salted, one-way hashes. Access to production systems is restricted to authorized personnel and protected by multi-factor authentication. Despite these measures, no system can be guaranteed 100% secure; you use the Service at your own risk.
8. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. When you delete your account, we remove your personal data and revoke stored access tokens within a reasonable period, except where retention is required by law or for legitimate business purposes such as fraud prevention.
9. Your Rights
You have the right to:
- Access, correct, or download a copy of your personal data.
- Disconnect any social account at any time from your dashboard.
- Delete your account and associated data.
- Object to or restrict certain processing.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with your local data protection authority.
We follow GDPR-aligned principles and global privacy best practices. To exercise any of these rights, contact us at the email address below.
10. International Data Transfers
Your data may be processed in countries other than the one in which you reside. Where required, we use appropriate safeguards such as Standard Contractual Clauses to protect your information.
11. Children's Privacy
The Service is not intended for users under the age of 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified through the Service or by email. The "Last updated" date at the top reflects the latest revision.
