Legal

Privacy Policy

Effective · Last updated

This Privacy Policy explains how Caelpost collects, uses, shares, stores and deletes personal data when you use our website caelpost.com, our web application and our integrations with Instagram and other social networks.

By creating an account or connecting a social account you confirm that you have read this policy. You must also agree to our Terms of Service.

1. Who we are

Caelpost is a social media publishing and automation platform operated by Dynarra, a software company based in Nairobi, Kenya (“Caelpost”, “we”, “us”, “our”). We are the data controller for the account data described below. For content and data that you process about other people through Caelpost (for example, people who comment on your Instagram posts), you are the controller and we act as your processor.

Contact for anything in this policy: privacy@caelpost.com.

2. Summary

  • We collect only what we need to run the features you use: publishing, scheduling, analytics and Comment-to-DM automations.
  • Data from Instagram is used only to provide those features to the account owner who connected it.
  • We do not sell personal data, use it for advertising, or use your content to train AI models.
  • You can disconnect an account or delete your data at any time, from inside Caelpost, from Instagram, or by emailing us.

3. Data we collect

3.1 Account data (you give us)

  • Name, email address and profile picture.
  • Password (stored only as a salted hash) or sign-in through Google or Apple, in which case we receive your name, email and profile picture from that provider.
  • Passkeys: only the public key and device metadata. The private key never leaves your device.
  • Workspace name, team members you invite, their roles and email addresses.
  • Your acceptance of these terms: the date, time and version you agreed to.

3.2 Content you create

  • Posts, captions, hashtags, schedules, drafts, templates, brand voice settings and link-in-bio pages.
  • Images and videos you upload, generate or clip, stored in our file storage.
  • Comment-to-DM automations you configure: keywords, messages, links and replies.

3.3 Connected social accounts

When you connect a social account we store the account ID, username, display name, profile picture, follower count, the access token that lets us act on your instructions (and a refresh token where the network issues one), its expiry date, and the IDs of posts we publish for you. Connections are made directly between you and each network using Caelpost's own registered developer apps. For Facebook we store the Pages you chose to connect; for Pinterest, your board names so you can pick where pins go. Bluesky is connected with an app password you create, which we exchange for a session token and do not store.

3.4 Billing

Payments are processed by Paddle, our merchant of record. We do not see or store your card number. We store your customer ID, plan, subscription status and invoices.

3.5 Technical and usage data

  • IP address, browser and device type, recorded in server and security logs.
  • Privacy-friendly page analytics (Vercel Analytics) that use no cookies and no cross-site tracking.
  • Error logs needed to keep the service running.
  • Click counts on short links and on links sent through Comment-to-DM, so you can see how your campaigns perform. Automated clicks from bots are filtered out.

4. Instagram and Meta Platform Data

When you choose Connect Instagram, you sign in on Instagram and approve the permissions below. We receive data from Meta only for your Instagram professional (Business or Creator) account, and only for the purposes listed. This data is called “Platform Data” and we handle it in line with the Meta Platform Terms and Developer Policies.

PermissionData we accessWhy we use it
Profile and mediainstagram_business_basicYour account ID, username, name, profile picture, account type, follower count and the list of your posts and reels.To show which account is connected, let you pick posts for automations, and display your content in Caelpost.
Publish contentinstagram_business_content_publishPermission to create posts, reels, carousels and stories on your account.To publish the content you create or schedule in Caelpost, only at the time you choose.
Commentsinstagram_business_manage_commentsComments on your posts and reels, and the username of the person who commented.To detect the keywords you set in Comment-to-DM and post the public reply you wrote.
Direct messagesinstagram_business_manage_messagesMessages people send to your account, button taps on Caelpost messages, and whether the person follows you.To send the automated DM you configured to people who comment or message a keyword, and to deliver the link when they tap.
Insightsinstagram_business_manage_insightsPerformance metrics for your posts, such as reach, views, likes, comments, saves and shares.To show analytics for the posts you publish through Caelpost.

Data about people who interact with your account

If you use Comment-to-DM, we process limited data about people who comment on your posts or message your account: their Instagram-scoped ID, username, the text of the comment or message, whether they tapped a button in our message, whether they follow your account (checked only after they have messaged you), and whether they opened the link you sent. We use this only to send the replies you configured, to avoid messaging the same person twice, and to show you aggregate results. We never contact these people for any other purpose, never add them to marketing lists, and never combine their data across different Caelpost customers.

Webhooks

Meta sends us real-time notifications (webhooks) about new comments, messages and button taps on connected accounts. Each notification is verified with a cryptographic signature before we process it. Notifications for accounts without an active automation are discarded.

5. How we use data

PurposeDetailsLegal basis
Provide the servicePublish and schedule posts, run your automations, show analytics, store your media.Performance of our contract with you
Account and securitySign you in, verify your email, prevent fraud and abuse, keep tokens valid.Contract; legitimate interests
SupportAnswer your questions and investigate problems you report.Contract; legitimate interests
Service emailsVerification codes, password resets, failed posts, expiring connections, billing.Contract
Improve the productAggregated, de-identified usage statistics.Legitimate interests
Legal obligationsTax and accounting records, responding to lawful requests.Legal obligation

AI features

When you use AI features (captions, scripts, images, voiceovers, video clipping and transcription) we send the prompt and the content you selected to the AI provider that performs the task, receive the result and return it to you. We do not send Instagram comments or messages from other people to AI providers. We do not use your content, or Platform Data, to train AI models.

6. What we never do

  • Sell, rent or trade personal data or Platform Data.
  • Use Platform Data for advertising, profiling, building audiences or retargeting.
  • Share Platform Data with data brokers or any party not listed in section 7.
  • Use data to make decisions about anyone’s eligibility for credit, housing, employment, insurance or similar.
  • Access accounts or content you have not connected, or act on your account without your instruction.
  • Use your content or Platform Data to train machine-learning models.

7. Sharing and service providers

We share data only with service providers that process it on our behalf, under contracts that require them to protect it and use it only to provide their service to us, and with the social networks you ask us to publish to.

ProviderPurposeData involved
VercelApplication hosting, file storage, cookieless analyticsAll application data, uploaded media
NeonDatabase hostingAll application data
Meta (Instagram, Facebook, Threads)Publishing, comments, messages, insightsContent you publish, replies you configure
X, LinkedIn, Google (YouTube), TikTok, Pinterest, Reddit, Discord, BlueskyPublishing to the accounts you connectContent you choose to publish there
PaddlePayments, invoicing, tax (merchant of record)Name, email, billing details
ResendTransactional emailEmail address, email content
Google, AppleOptional sign-inSign-in profile
OpenAI, fal.ai, ElevenLabs, GroqAI generation, voice, transcriptionPrompts and content you submit to AI features
ModalVideo processing and clippingVideos you submit for processing

We may also disclose data if required by law, to protect the rights, safety or property of our users or the public, or as part of a merger or acquisition, in which case the successor must honour this policy.

8. How long we keep data

DataRetention
Account and workspace dataWhile your account is active. Deleted within 30 days after you delete your workspace or ask us to.
Instagram access token and profileUntil you disconnect the account, remove Caelpost on Instagram, or delete your workspace. Removed immediately from our live systems.
Comment-to-DM activity (comments, messages, delivery status)90 days, then deleted automatically. Aggregate counters (e.g. “120 DMs sent”) are kept without personal data.
Posts and mediaUntil you delete them or your workspace.
Server and security logsUp to 30 days.
Billing recordsAs long as tax law requires, typically up to 7 years.
BackupsOur database provider keeps rolling backups for a limited period; deleted data leaves backups as they expire.

9. How to delete your data

You can delete data at any time, in any of these ways:

  • Disconnect an account: in Caelpost, open Dashboard → Channels and disconnect it. Its token is deleted and its automations stop.
  • Remove us from Instagram: in the Instagram app go to Settings → Website permissions → Apps and websites and remove Caelpost. Meta notifies us and we delete the data for that account automatically.
  • Delete your workspace: workspace owners can go to Dashboard → Settings → Danger Zone → Delete Workspace.
  • Email us: write to privacy@caelpost.com from your account email. We complete deletion within 30 days and confirm by email.

Step-by-step instructions are also on our Data Deletion page.

10. Your rights

Depending on where you live (including under the GDPR, the UK GDPR, the Kenya Data Protection Act 2019 and US state privacy laws), you have the right to:

  • Access the personal data we hold about you and get a copy in a portable format (JSON).
  • Correct inaccurate data.
  • Delete your data.
  • Restrict or object to processing based on legitimate interests.
  • Withdraw consent at any time, for example by disconnecting a social account. This does not affect processing before withdrawal.
  • Complain to your data protection authority, such as the Office of the Data Protection Commissioner in Kenya, the ICO in the UK, or your local EU authority.

To exercise a right, email privacy@caelpost.com. We reply within 30 days and may need to confirm your identity. We do not sell or “share” personal data for cross-context behavioural advertising as defined by California law.

If you are someone who interacted with a Caelpostcustomer's Instagram account and want your data removed, contact that business, or email us and we will delete it and let the business know.

11. Security

  • All traffic is encrypted in transit with HTTPS (TLS).
  • Our database and file storage are encrypted at rest by our hosting providers.
  • Access tokens are never exposed to your browser or to other customers, and are used only by our servers.
  • Webhooks from Meta are verified with HMAC signatures; scheduled jobs require a secret key.
  • Access to production systems is limited to the people who need it to run the service.

No system is perfectly secure. If we become aware of a breach affecting your personal data we will notify you and the relevant authorities as required by law. Report vulnerabilities to security@caelpost.com.

12. Cookies

CookiePurposeDuration
Session cookiesKeep you signed in and protect against forged requests. Essential.Session up to 7 days
cp_terms_acceptedRemembers that you accepted the Terms at sign-up so we can record it.1 day
Theme preferenceRemembers light or dark mode, stored in your browser.Persistent

We do not use advertising cookies, third-party tracking pixels or fingerprinting.

13. International transfers

We are based in Kenyaand our infrastructure is hosted mainly in the United States. When data moves across borders we rely on safeguards such as Standard Contractual Clauses and our providers' data processing agreements, as required by the GDPR and the Kenya Data Protection Act.

14. Children

Caelpost is for businesses and creators aged 18 and over. It is not directed at children and we do not knowingly collect data from anyone under 18. If you believe a child has given us data, email privacy@caelpost.com and we will delete it.

15. Changes to this policy

If we make material changes we will update the date at the top, notify you by email or in the dashboard, and ask you to accept the new version before you continue using Caelpost. Previous versions are available on request.

16. Contact

Dynarra — Caelpost Privacy

Nairobi, Kenya

Privacy and data requests: privacy@caelpost.com

General support: support@caelpost.com