Security and trust
Last updated: 05/08/2026
Connecting a social account to a tool you have just discovered takes trust. This page sets out what Postloop can do with your accounts, what it will not do, and where your data goes. Everything below is verifiable. What we do not have, we write down too.
1. Nothing is published without your click
Publishing starts from an explicit action of yours inside the application, and from nothing else. A scheduled post is a post you scheduled, at a time you chose. You read and approve every piece of text before it goes out.
Postloop's automatic background work — collecting your stats, follower counts, account health, trend monitoring, service emails — publishes nothing. It reads; it does not write to your networks.
An optional feature can reply automatically to a comment and send a private message. It stays inactive until you turn it on, and it only ever sends messages you wrote yourself, in a scenario you set up.
2. You can cut off access whenever you want, on both sides
From Postloop: Settings → Publishing → Disconnect. The authorisation is removed at our publishing partner straight away, the account goes back to “disconnected”, and whatever we had pulled in from that account is deleted from Postloop. Your posts themselves stay online; we never touch them.
From the social network, without going through us. That is the switch we do not control, and it is the one that matters most:
- Facebook — Settings & privacy → Settings → Apps and websites: facebook.com/settings
- Instagram — access goes through the linked Facebook Page: revoke it from Facebook's business integrations, facebook.com/settings (business tools)
- TikTok — Settings → Security and permissions → Manage app permissions: tiktok.com/setting
- LinkedIn — Preferences → Data privacy → Permitted services: linkedin.com (permitted services)
- YouTube — through your Google account, Security → Third-party apps with account access: myaccount.google.com/permissions
The name shown during authorisation. When you connect an account, the network's authorisation screen shows “Zernio”, not “Postloop”. This is not a mistake: Zernio Software SL is our publishing partner, a company established in the European Union, and it is its application that is registered with the networks to send your posts. We name it explicitly as a processor in §5 of our privacy policy.
3. Where your data lives
Your database, your authentication, your media, error telemetry and product analytics are hosted in the European Union.
Some providers are established outside the Union — email delivery, transcription, and text, voice and image generation. Those transfers rely on the European Commission's standard contractual clauses. The full, current list, with each provider's purpose and location, is published in §5 of our privacy policy — we do not copy it here, so that there is never a second, stale version of it.
4. How long, and how to leave
- Your data is kept for as long as you use your account.
- After the account is deleted, it is erased within 30 days; technical backups are purged afterwards.
- An export of your data is available before you leave, from Settings → Account.
- Permanent account deletion is in the same place — you do not have to email us for it.
5. What we do not do
- We do not sell or hand over your data to anyone.
- We serve no advertising and use no advertising cookies.
- We do no cross-site tracking.
- Product analytics is subject to your consent: if you decline, it never starts. Input fields and the content you write are masked at the source — none of your text, ideas or messages reach an analytics provider.
- We never publish on your behalf (see §1).
6. How the service is protected
- All traffic runs over HTTPS, with HSTS.
- Every response carries security headers: Content Security Policy,
X-Frame-Options: DENY,X-Content-Type-Options: nosniff,Referrer-PolicyandPermissions-Policy. You can check this yourself in seconds, in your browser's developer tools. - Isolation between workspaces is enforced in the database (row-level security), not only in the application: a malformed query cannot cross a workspace boundary.
- No provider access key ever passes through your browser: all calls to social networks are made from our servers.
- Passwords are hashed by our authentication provider; we never see them. Connecting a social network uses OAuth: your password stays with the network.
7. What we do not have
Postloop is not SOC 2 or ISO 27001 certified, and has not been through a third-party security audit. We have no public status page and no contractual uptime commitment. We would rather write that down than let you assume otherwise.
Postloop is a young service, published by a named person at a real address, whose full details you can read in our legal notice.
8. Getting in touch
Any question about security or your data, or a vulnerability to report: contact@postloop.online.
You have rights of access, rectification, erasure, portability and objection over your data; how to exercise them, and the competent supervisory authority, are set out in our privacy policy.