1. Introduction
OmniPost is a social media content management and publishing platform. It lets you sign in, connect your YouTube and Instagram accounts, upload a video, use AI to generate platform-ready content from that video, and publish the content to your connected accounts.
This Privacy Policy explains what information OmniPost collects, how it is used, when it is shared, and the choices and controls available to you. It applies to the OmniPost application and the services offered through it. By using OmniPost, you agree to the practices described here.
This policy describes how OmniPost works today. Features not described here are not part of the current service.
2. Information We Collect
We collect only the information needed to provide the features described in this policy. Depending on the parts of OmniPost you use and the accounts you connect, this may include:
- Account information: When you sign in with Google, we create a OmniPost account and store your email address, your name, your profile picture URL, and a Google account identifier used to recognize you on future sign-ins.
- Google authentication information: We use Google Sign-In to authenticate you. We request only the basic identity scopes (openid, email, and profile). The OAuth tokens issued during Google Sign-In are used to complete the sign-in and are not stored by OmniPost.
- Connected YouTube account information: If you connect YouTube, we store the identity of the channel you authorize (channel ID, channel title, and channel thumbnail) and the OAuth credentials needed to act on your behalf. These credentials are held on our servers only and are never sent to your browser.
- Connected Instagram account information: If you connect Instagram, we store the identity of the professional (Business or Creator) account you authorize (account ID, username, display name, and profile picture) and the access token needed to publish on your behalf. This token is held on our servers only.
- Uploaded videos and media: When you upload a video, we store the video file in a private storage bucket, along with metadata such as the file name, file type, file size, and processing status.
- AI-generated content: We store the results of AI processing, including the transcript and a structured understanding of your video (such as a suggested title, summary, topic, and key points), and the platform content generated from it (for example a YouTube title and description, an Instagram caption, hashtags, and a call to action), including any edits you make before publishing.
- Technical and log information: To operate and secure the service, our servers process standard technical information such as your requests to our API and related error and diagnostic logs. We maintain a server-side session to keep you signed in.
Some information is required for OmniPost to function (for example, your Google account identity to sign in). Other information is provided only when you choose to use a feature, such as connecting a social account or uploading a video.
3. How We Use Information
We use the information we collect to:
- Authenticate you and keep you signed in to your OmniPost account.
- Let you connect and manage your YouTube and Instagram accounts.
- Store the videos you upload and make them available to you inside the app.
- Process your uploaded video with AI to produce a transcript, an understanding of the video, and platform-specific content suggestions.
- Publish the content you approve to the social accounts you have connected.
- Operate, maintain, secure, debug, and improve the reliability of the service.
We do not use your information for advertising, and we do not sell your information.
5. Third-Party Services
OmniPost relies on the following categories of third-party services. Depending on the services used by your account, the information shared with each provider is limited to what is needed for the described purpose.
- Google: Used for Google Sign-In (authentication). We receive your basic Google profile identity (email, name, and profile picture) so we can create and recognize your account.
- YouTube (via Google APIs): When you connect YouTube, we use the YouTube Data API to identify your channel and, when you choose to publish, to upload a video to your channel on your behalf.
- Instagram / Meta: When you connect Instagram, we use the Instagram API (with Instagram Login) to identify your professional account and, when you choose to publish, to create and publish a Reel on your behalf.
- AI processing provider: We send audio extracted from your uploaded video and the resulting transcript to our AI provider to transcribe the audio and generate content suggestions. Your raw video file is not sent to the AI language model.
- Cloud infrastructure and storage providers: We use managed cloud services to store your uploaded videos in a private bucket, to host our database, and to run background processing. These providers store and process data on our behalf to operate the service.
These third parties have their own privacy policies governing how they handle information. We encourage you to review the policies of any platform you connect to OmniPost.
6. Google User Data and API Services
This section explains, specifically, how OmniPost handles data obtained through Google, including Google Sign-In and the YouTube Data API.
What Google data OmniPost accesses and why:
- Basic Google profile: Through Google Sign-In (openid, email, profile scopes), OmniPost receives your email, name, and profile picture. This is used only to create your account, sign you in, and identify you within OmniPost. The OAuth tokens from Google Sign-In are not stored.
- YouTube channel identity: When you connect YouTube, OmniPost reads only the identity of your own channel so it can show which channel is connected.
- YouTube video upload: When you choose to publish, OmniPost uses the YouTube upload permission to upload a video to your channel on your behalf. OmniPost does not read your existing videos, playlists, analytics, or statistics.
How Google user data is handled:
- Google user data is not sold.
- Google user data is not used for advertising.
- Google user data is not transferred to others except as necessary to provide the features you request and as permitted by applicable Google policies, to comply with applicable law, or as part of a business transfer.
- You can revoke OmniPost’s access to your Google data at any time through your Google Account permissions settings, and you can disconnect your connected YouTube account from within OmniPost.
OmniPost's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
To request deletion of the Google-derived data associated with your account, disconnect your YouTube account and delete your uploaded videos within the app, or contact us using the details in the Contact Information section. OmniPost is an independent application and is not certified, endorsed, or approved by Google.
7. OAuth and Social Media Permissions
OmniPost uses OAuth to connect to your accounts. OAuth lets you grant specific permissions without sharing your passwords with us. We request only the permissions needed for the features OmniPost provides.
The permissions we request and why:
- Google Sign-In: Basic identity scopes (openid, email, profile) so you can sign in and we can create your OmniPost account.
- YouTube: A read permission used only to identify the channel you connect, and an upload permission used only to publish a video to your channel when you choose to. We do not request analytics or partner scopes.
- Instagram: A basic permission to read your professional account identity, and a content-publishing permission used only to publish a Reel when you choose to. We do not request insights or messaging permissions.
OmniPost accesses only the data necessary for the functionality described in this policy, and only for the connected account you authorize. You can disconnect any connected account from within OmniPost at any time, and you can also revoke access directly from your Google Account or Instagram account settings.
8. Data Storage and Security
We take reasonable technical and organizational measures to protect your information. Uploaded videos are stored in a private bucket that is not publicly accessible; playback inside the app uses short-lived signed links that expire. Sign-in relies on a server-side session, and your session identifier is stored only as a hashed value in a secure, HTTP-only cookie.
OAuth credentials for your connected YouTube and Instagram accounts are stored on our servers only, are never sent to your browser, and are not exposed in our API responses. No method of transmission or storage is completely secure, so while we work to protect your information, we cannot guarantee absolute security.
9. Data Retention
We retain information for as long as it is needed to provide the service to you.
- Account and connection information: Retained while your OmniPost account exists and, for a connected account, until you disconnect it.
- Uploaded videos: The stored video file is automatically removed from our storage after a limited period following upload or publishing. You can also delete an uploaded video at any time from within the app.
- Generated content and analysis: The transcript, analysis, and generated content associated with your videos are retained so you can review and reuse them, until removed as described in the sections below.
We may retain limited information where necessary to comply with legal obligations, resolve disputes, or enforce our agreements, and residual copies may persist for a limited time in routine backups.
10. User Rights and Data Deletion
You have control over the information associated with your OmniPost account. Directly within the app, you can:
- Delete an uploaded video, which removes the stored video file and its record.
- Disconnect a connected YouTube or Instagram account, which removes the stored connection and its credentials.
- Sign out to end your current session.
To request access to, correction of, or deletion of the personal information we hold about you — including the transcript, analysis, and generated content associated with your videos — contact us at contact@omnipost.studio. We will verify your request and respond within a reasonable timeframe. Some information may be retained where required for legal or security reasons or where it persists temporarily in backups.
11. Account Deletion
You can remove your data step by step at any time: delete your uploaded videos and disconnect your YouTube and Instagram accounts from within the app. To delete your entire OmniPost account and the remaining personal information associated with it, email us at contact@omnipost.studio from the address associated with your account.
When your account is deleted, we remove your account profile and associated stored data, except for information we are required or permitted to retain for legal, security, or backup purposes for a limited period. Deleting your OmniPost account does not delete content you have already published to YouTube or Instagram; you can manage that content directly on those platforms.
12. Disconnecting YouTube and Instagram
You can disconnect a connected YouTube or Instagram account from within OmniPost at any time. When you disconnect an account, we delete the stored connection for that account, including the OAuth credentials we held for it. After disconnecting, OmniPost can no longer access that account or publish on your behalf until you reconnect it.
You can also revoke OmniPost’s access independently: for Google and YouTube, through your Google Account permissions settings; for Instagram, through the apps and websites settings on your Instagram account.
13. Cookies and Similar Technologies
OmniPost uses a single strictly necessary cookie to keep you signed in. This session cookie is HTTP-only and holds only a session identifier; it is required for the app to work and cannot be turned off without preventing sign-in.
We do not use advertising cookies, and we do not use cookies to track you across other websites.
14. Children's Privacy
OmniPost is not directed to children and is intended for use by adults. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can remove it.
15. International Data Transfers
OmniPost relies on third-party service providers that may store and process information in countries other than the one you live in. Where information is transferred across borders, it remains subject to this Privacy Policy and to the protections offered by the providers involved.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to the service or for legal or operational reasons. When we make material changes, we will update the "Last updated" date at the top of this page. Your continued use of OmniPost after an update means you accept the revised policy.
17. Contact Information
If you have questions about this Privacy Policy or how your information is handled, contact us at contact@omnipost.studio.