Public policy page
Trust center / Privacy

Privacy, without the fog.

This policy explains what Autopubly handles today, how the current Metricool-routed publishing workflow differs from a future direct Pinterest API connection, and how to ask for access or deletion.

Effective
August 13, 2026
Operator
Nadir Dahhak
Privacy contact
privacy@autopubly.com

01Scope and controller

Nadir Dahhak operates Autopubly and is responsible for personal information processed through the public website, accounts, customer workspace, billing, support, and publishing controls described here.

This policy does not cover information a connected provider processes independently under its own policy.

02Information handled

  • Account and security data: email, username, password hash, sessions, activation and plan state, human-verification results, audit events, coarse country information, keyed device/IP identifiers, and encrypted IP addresses.
  • Publishing data: sites, article content, generated media, schedules, destination URLs, job state, failures, and usage/cost records.
  • Current social-routing data: Metricool user and brand identifiers, a selected Pinterest Board identifier/name, encrypted Metricool credentials when a customer supplies them, scheduled-post identifiers and states, and analytics returned by Metricool for the connected brand.
  • Requests and support: the contact details, account identifier, and message supplied with a privacy or support request.

03Current connection

The current released workflow schedules Pinterest content through Metricool. Depending on the customer configuration, the customer either supplies site-specific Metricool API credentials or enters Metricool through its White Label for Integrators connection experience. Pinterest authorization, when used inside that experience, occurs on the provider’s interface—not in an Autopubly password field.

Autopubly does not currently operate a production direct Pinterest OAuth integration. A future direct connection will not be enabled until the required provider approval, production configuration, and updated disclosures are in place.

04Purpose and consent

Information is used to authenticate customers, operate subscriptions, generate requested content, protect isolated workspaces, connect sites, show provider status, and carry out customer-selected publishing actions.

For social publishing, connecting an account does not itself publish anything. Every Pin remains a draft until the customer inspects its exact image, link and Board, reviews or edits its title, copy and schedule, and presses its individual Approve & Schedule action. The server then validates and submits only that approved Pin.

05AI boundary

AI providers may process customer-requested source material and editorial instructions to create article or social copy. Autopubly does not send Pinterest account data, Board records, Pin performance data, Metricool or OAuth credentials, or provider access tokens to AI providers. Autopubly does not use that connected-account data to train models.

Generated copy may later be reviewed and selected by the customer for publishing, but generation occurs before and separately from the provider publishing action.

06No passwords or scraping

Autopubly does not ask for or store Pinterest passwords, session cookies, or private messages. It does not automate a consumer browser, scrape public profiles, follow people, generate engagement, or read other Pinners’ Boards and Pins. Current provider access is limited to the customer-configured Metricool brand and selected destination.

07Sharing

Information is shared only as needed to provide requested functionality: with Metricool for the current social-routing workflow; WordPress for website publishing; Stripe for billing; configured AI providers for customer-requested generation subject to the boundary above; and infrastructure or professional providers needed to host, secure, support, or lawfully operate the service.

Autopubly does not sell connected Pinterest data or share one customer’s publishing configuration, analytics, credentials, or content with another customer.

08Retention

Encrypted IP addresses are automatically removed after the configured IP_ADDRESS_RETENTION_DAYS period, which defaults to 30 days. Keyed security identifiers and audit records may remain longer when needed to prevent abuse or resolve security events.

Account, publishing, provider-configuration, schedule, and analytics records remain while needed to operate the account and until they are changed, removed after a verified request, or retained for a documented legal, fraud-prevention, billing, security, or dispute purpose. Access-restricted database backups are created daily and expire through a rolling 30-day retention cycle. Information removed from active systems may remain in a protected backup until that backup expires.

If direct Pinterest API access is approved and enabled, Autopubly will request only the minimum scopes needed for the customer-selected feature. Pinterest API information will be requested on demand where storage is not permitted and retained only where Pinterest’s terms expressly allow it. OAuth tokens will be protected server-side and removed after verified disconnection or account deletion, subject to the backup rotation and legally required records described above.

09Deletion and disconnect

The public request form creates a request for manual review; submitting it does not instantly erase records or revoke access at a third party. After identity and authority are verified, a connection-only cleanup cancels pending local social jobs, clears the site’s provider and Board credentials/configuration, and removes related Pin schedule, status, and analytics records from active Autopubly systems, subject to limited records that must lawfully be retained.

A connection-only cleanup preserves articles, editorial drafts, and marketing media because they may also belong to the customer’s WordPress workflow. Those are removed only as part of a verified full-account deletion request. Autopubly marks local cleanup separately and does not claim remote revocation is complete until the customer or operator confirms revocation in the relevant Metricool or Pinterest settings. Published Pins remain at Pinterest until the customer removes them there.

10Children

Autopubly is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child supplied personal information, contact privacy@autopubly.com.

11Choices and contact

Depending on applicable law, a customer may request access, correction, export, restriction, objection, disconnection, or deletion. Autopubly verifies requests to protect the account. Contact privacy@autopubly.com or use the public request form.

General product questions can be sent to support@autopubly.com.