Privacy Policy
Last updated: October 11, 2026
This Privacy Policy describes how RepeatPost ("we", "us", "our") collects, uses, shares, and protects your personal information when you:
- Visit our website and related pages
- Use the RepeatPost product (including scheduling, publishing, analytics, and other features)
- Contact us or interact with our support team
This policy is provided by HQ INFOSYSTEM (our company / operator). If you have questions about this Privacy Policy, contact us at support@repeatpost.com.
1. Scope of this Privacy Policy
This Privacy Policy applies to personal information processed in connection with RepeatPost.
If we provide links or integrations to third-party services (for example, social media platforms, payment providers, and analytics tools), those third parties may collect information directly from you. We encourage you to review their privacy policies.
2. Personal Information We Collect
Personal information means information that identifies, relates to, or could reasonably be linked to an individual.
Depending on how you use RepeatPost, we may collect the following categories of personal information:
2.1 Information you provide to us
When you create an account, sign up, request a demo, or contact support, we may collect:
- Contact details: name, email address
- Account details: username, role (for teams/organizations), and account preferences
- Profile and content-related information you enter: information included in your profile, drafts, scheduling details, and messages you send through the product
- Support communications: details you provide in messages to support (and records of those communications)
2.2 Information collected when you use RepeatPost
We may collect usage information and technical information such as:
- Device and browser information (for example, device type, OS version, browser type)
- Log data: IP address, timestamps, pages and features you view, and actions you take within the product
- Interaction data: clicks, schedules created, publish attempts, delivery statuses, and general performance/analytics information
2.3 Information collected from connected accounts and integrations
RepeatPost may integrate with third-party services to enable publishing and scheduling (for example, social media platforms) and other integrations you choose.
When you connect an account/integration, we may receive personal information made available by those third parties, such as:
- Account identifiers (for example, page/channel IDs and display names)
- Publishing history and content you provide for posting
- Engagement/analytics data that is made available by the third party as part of the integration (to the extent permitted by that provider)
- Authentication/authorization data required to access the connected service (for example, access tokens and related authorization records, where applicable)
We use the information received from integrations to operate RepeatPost features you request.
If you add the RepeatPost app to a Slack workspace, the RepeatPost App for Slack section lists exactly what we receive from Slack, how we use it, and how long we keep it.
3. RepeatPost App for Slack
This section applies when you or someone in your workspace installs the RepeatPost app for Slack, connects a Slack workspace to RepeatPost, or uses Sign in with Slack. The app does three things: it publishes posts you schedule in RepeatPost into the Slack channels you choose, it sends alerts about your posts (for example, when a post goes live or fails), and it lets reviewers approve or send back drafts using buttons on a Slack message.
3.1 Data we collect from Slack
When the app is installed and used, we receive and store:
- Workspace details: the workspace (team) ID, workspace name, and workspace domain, read with the
team:readscope. - Installer details: the Slack user ID of the person who installed the app and the time of installation.
- Access tokens: the bot token and user token Slack issues on install. They're encrypted at rest.
- Channel details: the IDs and names of public and private channels, read with the
channels:readandgroups:readscopes so you can pick where posts and alerts go. - Member details: Slack user IDs, display names, and profile photos of workspace members, read with the
users:readscope so RepeatPost can show who approved or sent back a draft. - Sign in with Slack details: if you sign in to RepeatPost with Slack, your name, email address, profile photo, and Slack user ID, received through the
openid,profile, andemailscopes. - Approval actions: when someone clicks Approve or Request changes on a RepeatPost message, the Slack user ID, channel ID, message timestamp, and the button they clicked.
- Message references: the channel ID and timestamp of each message the app posts, so we can update the message after an approval and show delivery status in RepeatPost.
3.2 How we use Slack data
We use Slack data only to run the features you turned on:
- Posting scheduled content into the channels you pick, under the display name and icon you set (
chat:write,chat:write.public,chat:write.customize) - Joining the public channels you select so the app can post there (
channels:join) - Adding the app to private channels you choose, on your behalf (
groups:read,groups:write.invites) - Sending the post alerts you turned on
- Recording who approved or sent back a draft, and showing that in RepeatPost
- Signing you in to RepeatPost with your Slack account
3.3 What we don't do with Slack data
- We can't read your conversations. The app requests no history scopes, so it can't read messages in your channels, direct messages, or files. It only sees messages it posted itself and the button clicks on them.
- We never send Slack messages or Slack member data to an AI model. None of it is used as input to the AI features described in the AI Features section, and no Slack data is used to train any AI model. If you connect a Slack workspace as a posting channel, its name and the posts you write for it are handled like any other channel, including by AI assistants you connect yourself.
- We don't sell Slack data or use it for advertising, and we don't share it with third parties except the hosting providers that run RepeatPost, or an AI assistant you connect yourself.
3.4 Data we receive but don't use
Requests Slack sends to RepeatPost contain fields we don't need, such as the enterprise ID, user locale, trigger_id, api_app_id, and team or user fields on event and interaction payloads beyond the ones listed in section 3.1. We don't use these fields for any purpose and don't store them, apart from short lived technical request logs described below.
3.5 How long we keep Slack data
- When you uninstall or disconnect: as soon as the app is removed from your workspace, or you disconnect Slack inside RepeatPost, we revoke and delete the access tokens and delete the workspace, channel, and member details tied to that connection. This happens immediately.
- Request logs: technical logs that may contain Slack IDs are kept for up to 30 days for security and troubleshooting, then deleted.
- Messages already posted: messages the app posted stay in your Slack workspace and follow your workspace's own retention settings. RepeatPost can't delete them after the app is removed. A workspace admin can delete them in Slack.
- When you delete your RepeatPost account: any remaining Slack data follows the timeline in the account deletion section.
3.6 Access, export, and deletion of Slack data
- Remove the app: a workspace admin can uninstall RepeatPost from the Manage apps page in Slack, or you can disconnect the workspace inside RepeatPost. Either one deletes the Slack data described in section 3.5.
- Access or export: email support@repeatpost.com from the address on your RepeatPost account and we'll send you a copy of the Slack data we hold about you or your workspace.
- Deletion without uninstalling: email support@repeatpost.com and tell us what you'd like removed.
Your rights under the GDPR, CCPA, and India's DPDP Act, described in the GDPR section and the CCPA section, apply to Slack data the same way they apply to all other personal information.
4. AI Features
RepeatPost includes AI features that help you write captions, hashtags, and post ideas, rewrite text, and create images and video.
4.1 AI providers and what we send them
When you use an AI feature, we send the prompt you write, any text or media you choose to include, and your brand voice settings (such as visual style, colors, mood, audience, topics to avoid, and a short description of your business). For captions, this can also include example posts and facts you've saved to your brand voice. We send these to:
- OpenAI, for writing and rewriting text, for turning your image and video requests into detailed prompts, and for transcribing voice recordings you dictate
- Google (Gemini and Veo models), for image and video generation
The provider returns the generated result, which we store in your RepeatPost account like any other draft or media file.
When you use the RepeatPost assistant in our web app or our Telegram bot, we also send the workspace information it looks up to answer you. That can include your connected channels, your posts with their status and performance numbers, the names of teammates who created or approved them, workspace names, media files and links, comments people left on your posts, your brand voice settings, and your AI credit balance. In the web app, it can also include your teammates' names and email addresses. This goes to OpenAI only to produce the answer.
In Telegram, the assistant can save drafts but can't schedule, publish, or delete posts. In the web app, it can prepare actions such as publishing, rescheduling, or deleting a post, but nothing happens until you click to confirm.
Slack messages and Slack member data are never sent to these providers.
4.2 Training and retention by AI providers
We use these providers through their business APIs. Under their API terms, the providers don't use the content we send to train their models. They may keep it for a limited period, typically up to 30 days, to detect abuse, and then delete it.
4.3 AI output can be inaccurate
AI generated content can be inaccurate, outdated, incomplete, or inappropriate, and it can repeat mistakes in the prompt it was given. Review and edit AI output before you publish it anywhere, including to Slack. Our Terms of Service explain that you're responsible for the content you publish.
This section covers the AI built into RepeatPost. If you connect an outside assistant such as Claude or ChatGPT to your account, the AI assistants and connectors section explains what it can reach and how to cut it off.
4.4 What the RepeatPost assistant remembers
The assistant keeps a list of what it has learned about how you post, so its suggestions get closer to what you'd write yourself. You can see that list under What I've learned in the AI Agent sidebar, remove any entry from it, or switch off Learn from how I post. Turning it off stops the assistant building the list and leaves the rest of the assistant working normally.
Your brand voice also learns from the edits you make to AI-written captions, so later captions sound more like you.
If you'd rather we removed the list or reset what your brand voice has learned, email us at support@repeatpost.com.
5. AI Assistants and Connectors
This section applies when you connect a third-party AI assistant to your RepeatPost account, for example Claude by Anthropic or ChatGPT by OpenAI. The connection runs over the Model Context Protocol, known as MCP, and is authorized with OAuth. Once connected, the assistant can read what you allow it to read and act on your behalf inside the limits you set. This is separate from the AI features built into RepeatPost, which are covered in the AI Features section.
5.1 Connecting an AI assistant
You authorize each assistant yourself, and each person connects with their own RepeatPost sign in. A connection can reach every workspace that person belongs to. Before the connection is made, a RepeatPost sign in and consent page shows you:
- Which application is asking: the name of the assistant requesting access
- Where it will send you back to: the website you return to once you approve
- What it wants to do: the permissions it's requesting, listed individually
Nothing is shared until you approve that screen.
5.2 You choose what it can do
The consent screen lists the permissions separately so you can grant some and refuse others. They cover:
- Seeing your workspaces, channels, posts, media, brand voices, and AI credit balance
- Creating drafts, editing posts, and managing media, folders, and brand voice settings
- Scheduling or publishing posts
- Deleting posts and media
- Using your workspace's AI credits
An assistant can only do what you approved, and it's held to your own role in the workspace on top of that. A Viewer still can't publish. If your posts on a channel need approval, posts your assistant schedules or publishes there still go to approval first. Granting a permission to an assistant never gives it more than you have yourself.
5.3 What the assistant receives
When you ask a connected assistant to do something, we return what that request needs and nothing further. Depending on what you asked, that can include your channels' names and profile pictures, post content, schedules and performance numbers, the names and profile photos of teammates who created or approved a post, approval notes, workspace names, brand voice settings, your AI credit balance, links to your media, and channel lists for Slack and Discord.
The assistant's provider then handles that information under its own privacy policy, which we'd encourage you to read. We don't control how a third-party assistant stores or uses what it receives, and we can't retrieve it once it's been sent.
Slack is treated like any other channel. If you've connected a Slack workspace as a posting channel and you allow it, a connected assistant can see the workspace's name, list its channels, and post to them. Neither a connected assistant nor the RepeatPost assistant can read your Slack messages or see your Slack members. The RepeatPost App for Slack section sets out everything we receive from Slack and what we do with it.
5.4 How long access lasts
The connection uses short lived access tokens, valid for 15 minutes, which the assistant renews on its own in the background. The renewal credential lasts 30 days. A connection stays live until it's disconnected, or until 30 days pass without the assistant renewing its access, whichever comes first.
5.5 Disconnecting
You can cut off a connected assistant at any time from that assistant's own settings, or by emailing support@repeatpost.com and asking us to revoke it. Once a connection is revoked, the assistant can't renew its access, and any access it still has ends within a few minutes.
Disconnecting doesn't reach back into data the assistant's provider already received. To ask that provider to delete it, use the controls or contact route in their privacy policy. Deleting your RepeatPost account revokes connected assistants too, as described in the account deletion section.
6. How We Use Your Personal Information
We use personal information to provide RepeatPost and to support the legitimate business operations of our service. Typical purposes include:
- Providing and operating RepeatPost: account creation, authentication, scheduling, publishing, and managing your content workflows
- Maintaining and improving features: analyzing usage and performance so we can enhance the product
- Customer support: responding to inquiries, troubleshooting, and handling account/service requests
- Communication: sending service-related emails (for example, updates, security notices, and support responses) and, where permitted, marketing communications
- Security and risk management: detecting fraud, unauthorized access, or abuse; maintaining system integrity; and enforcing our terms
- Analytics and research: measuring how the service is used to improve functionality and user experience
- Compliance: meeting legal obligations, responding to lawful requests, and protecting our rights and interests
7. Cookies and Similar Technologies
We use cookies and similar technologies (such as local storage and web beacons) to:
- Enable essential site functions (for example, remembering your session)
- Understand how users interact with RepeatPost (for analytics and performance monitoring)
- Support preferences (for example, saving language or UI settings)
- Provide relevant advertising or marketing measurement (where permitted by applicable law)
For full details about the cookies we use and how to manage your preferences, please see our Cookie Policy.
7.1 Cookie categories
We use:
- Essential/strictly necessary cookies: required for core functionality
- Performance/analytics cookies: help us measure usage and improve our site
- Preference/functional cookies: remember your settings and preferences
- Marketing cookies: help measure marketing performance and show tailored content (only where permitted)
7.2 Consent and controls
If your jurisdiction requires consent for non-essential cookies, we will request your consent via our cookie consent banner.
You can manage your cookie preferences through:
- The cookie consent banner displayed on your first visit
- Your browser settings (note: disabling cookies may affect site functionality)
8. When and Why We Share Personal Information
We do not sell personal information in exchange for money. We may share personal information in the following circumstances:
8.1 With service providers (processors)
We may share personal information with vendors that help us operate RepeatPost, such as:
- Hosting and infrastructure providers
- Email delivery and support platforms
- Analytics and monitoring tools
- Customer support and ticketing tools
- Payment processing providers (where applicable)
- AI model providers (OpenAI and Google), for content you submit to AI features and, when you use the RepeatPost assistant, the workspace information it looks up to answer you, as described in the AI Features section
These vendors process personal information on our behalf and are contractually required to protect it.
A third-party AI assistant you choose to connect works differently. It acts on your instructions, not ours, so it isn't one of our vendors and doesn't process your information on our behalf. The AI assistants and connectors section covers what it receives and how long its access lasts.
8.2 With integrations and connected third parties
When you connect or use a third-party service through RepeatPost, your information may be transmitted to that third party according to the permissions and settings you provide.
We do not control how those third parties use your data. Review their privacy policies for details.
8.3 For legal and safety purposes
We may disclose personal information if we believe it is reasonably necessary to:
- Comply with applicable laws, regulations, subpoenas, or other legal processes
- Protect the rights, safety, and security of RepeatPost, our users, or others
- Investigate and prevent fraud, security incidents, or violations of our policies
8.4 Business transfers
In connection with a merger, acquisition, reorganization, or sale of assets, personal information may be transferred as part of that transaction. We will take steps designed to ensure appropriate protections.
9. International Data Transfers
Your personal information may be processed and stored in countries other than the one where you reside, including in locations where our service providers operate.
Where required by law, we implement appropriate safeguards for international transfers (for example, contractual protections such as Standard Contractual Clauses or equivalent mechanisms).
10. Data Retention
We retain personal information only for as long as necessary for the purposes described in this policy, including to provide RepeatPost services, comply with legal obligations, resolve disputes, and enforce agreements.
Retention periods may vary depending on:
- The nature of the data
- Whether it is needed for ongoing account/service administration
- Legal, regulatory, and security requirements
- How long it is reasonably required for troubleshooting, analytics, and protection against misuse
Slack data is deleted as soon as the RepeatPost app is uninstalled or the workspace is disconnected. See the RepeatPost App for Slack section for details.
If you request deletion, we will delete or anonymize personal information when feasible, subject to lawful exceptions (for example, where we must retain records to comply with legal obligations). For the specific timeline that applies when you close your RepeatPost account, see the account deletion section.
11. Account Deletion
You can delete your RepeatPost account at any time, from inside the app or from the web. There's no fee, no form to wait on, and no need to contact support first.
11.1 How to delete your account
In the RepeatPost app for iOS or Android, open More, then Settings, then Profile, then Delete Account, and confirm when prompted.
If you've already uninstalled the app, or you'd rather not use it, go to our account deletion page and follow the steps there. You don't need to reinstall RepeatPost to ask us to delete your account.
We may ask you to confirm your identity before we act on the request, usually by verifying the email address on the account.
11.2 What happens after you request deletion
Deletion is permanent and takes effect right away. It isn't the same as signing out, pausing your plan, or disconnecting a channel, and signing back in won't bring the account back.
As soon as you confirm, we:
- Close your account and sign you out on every device.
- Revoke any AI assistant you connected, so it can no longer act on your behalf. Any access it still has ends within a few minutes.
- Cancel scheduled and queued posts in workspaces you own, and stop anything more from being published from them.
- Stop all background activity for workspaces you own, such as analytics updates, automations, automated comment replies and messages, and platform webhooks.
- Cancel the subscriptions of workspaces you own, including storage add-ons, so you aren't charged again.
- Stop sending notifications about your account and the workspaces you own. You get one email confirming the deletion, and nothing after that.
11.3 What we delete
Once your account is deleted, no one can sign in to it, including you, and your email address is released so it can be used for a new account.
Within 30 days, usually about 7 days after you delete your account, we permanently erase the personal information tied to it from our systems. This happens automatically, so you don't need to ask. It covers:
- Your profile, login details, two-step verification settings, and account preferences
- Workspaces you own and everything in them, including posts, drafts, schedules, media files, brand voices, AI chats, automations, and analytics
- Your connected social channels and their access tokens, plus your Slack, Telegram, Canva, and Google connections, which we disconnect and revoke where the service allows it
- Your notifications, device tokens, and notification settings
- Your memberships in workspaces owned by someone else
- Support conversations, once they're no longer needed to resolve an open issue
Posts you created in a workspace someone else owns stay with that workspace, because they belong to its owner. Activity logs in those workspaces show "Deleted user" instead of your email address.
11.4 What we keep, and why
These survive deletion:
- Billing and tax records. Invoices, payment records, and the transaction data behind them are kept for the period required by applicable tax and accounting law. We can't delete these on request, and that's a statutory obligation rather than a choice.
- Aggregated statistics. Figures that no longer identify you or your account may be kept to measure how the service performs. This information can't be linked back to you.
We also keep an empty account record with no personal information in it, so posts and activity in other people's workspaces still point to a "Deleted user". Copies of erased information may stay in our encrypted backups for a limited time, until those backups are replaced. Nothing else is kept.
11.5 Paid plans and app store subscriptions
Cancel your subscription before you delete your account.
If you subscribed through the Apple App Store or Google Play, Apple or Google handles that billing, not RepeatPost, and it keeps renewing until you cancel it with them. Deleting your RepeatPost account will not stop it. Apple subscriptions are managed in your Apple subscription settings. Google Play subscriptions are managed in the Play Store under Payments and subscriptions. Our Refund Policy covers what happens to amounts you've already paid.
11.6 Removing some data without closing your account
You don't have to delete everything to clean things up. Inside RepeatPost you can disconnect a single social channel, delete an individual post or media file, or leave a workspace, and your account stays open. For anything broader, email us at support@repeatpost.com and tell us which category of information you want removed.
12. Security Measures
We use administrative, technical, and organizational measures designed to protect personal information. These measures may include encryption in transit (for example, via HTTPS/TLS), access controls, and secure storage practices.
No method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security. However, we work to reduce risk and respond to security incidents.
13. Children's Privacy
RepeatPost is not intended for children under the age of 18. We do not knowingly collect personal information from children.
If you believe a child has provided personal information to us, contact us at support@repeatpost.com so we can take appropriate steps.
14. Your Privacy Rights and Choices (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, you may have the rights provided by applicable data protection law. Depending on circumstances, these rights may include:
- Right of access
- Right to rectification
- Right to erasure (deletion)
- Right to restriction of processing
- Right to data portability
- Right to object to processing
- Rights related to automated decision-making (where applicable)
You may also withdraw consent where we process information based on consent (withdrawal will not affect processing already performed).
14.1 Legal bases for processing
We process personal information based on one or more of the following legal bases (depending on the purpose):
- Performance of a contract: to provide RepeatPost features you request
- Legitimate interests: to operate, improve, secure, and provide support for the service
- Consent: where required for certain cookies/marketing or other processing
- Legal obligation: to comply with applicable laws and legal processes
14.2 How to exercise your rights
To exercise your rights, contact us at support@repeatpost.com.
To exercise your right to erasure, you can also delete your account yourself. The account deletion section explains how, what gets removed, and how long it takes.
We may need to verify your identity before processing certain requests.
15. Your Privacy Rights and Choices (CCPA/CPRA)
If you are a California resident, you may have rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). These rights may include:
- Right to know what personal information we collect, use, disclose, and share
- Right to delete personal information
- Right to correct inaccurate personal information (in some circumstances)
- Right to opt out of certain processing (for example, "sale" or "sharing" for cross-context behavioral advertising, where applicable)
- Right to limit use of sensitive personal information (where applicable)
- Right to non-discrimination for exercising privacy rights
15.1 Do we "sell" personal information?
We do not sell personal information for money.
15.2 Do we "share" personal information for cross-context behavioral advertising?
Depending on your consent choices and applicable requirements, we may share personal information with vendors/partners for purposes that can be considered "sharing" under CPRA (for example, certain advertising/analytics technologies).
You may be able to opt out through:
- The cookie consent banner on our website
- Contacting us at support@repeatpost.com with an opt-out request
15.3 Submitting a request
To submit a privacy request, contact us at support@repeatpost.com. To exercise your right to delete, you can also close your account directly using the account deletion section.
We will respond within the timeframes required by law after verifying your identity and request details.
16. Your Privacy Rights (India DPDP Act 2023)
If you are located in India, you may have rights under the Digital Personal Data Protection Act, 2023, including:
- Right to access personal data we hold about you
- Right to correction and erasure of your personal data
- Right to grievance redressal
- Right to nominate another person to exercise your rights
To exercise any of these rights, contact our Grievance Officer at support@repeatpost.com. You can act on your right to erasure yourself through the account deletion section.
17. Data Processing Agreements (DPAs) / Business Customers
If you are using RepeatPost on behalf of an organization, you may have additional contractual terms governing data processing (for example, a DPA or other enterprise agreement). If you need details about data processing arrangements, contact us at support@repeatpost.com.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page and may notify you as required by applicable law.
Please review this policy periodically for updates.
19. Contact Us
For questions about this Privacy Policy or to exercise privacy rights, contact:
- Email: support@repeatpost.com
- Company: HQ INFOSYSTEM
- Address: 425, Silver Stone Arcade, Singanpore Road, Surat, Gujarat, India 395004