Privacy Policy
Last updated 2 September 2026
This policy explains what Betacarry LLC collects when you use MyPostStation, why, and what you can do about it.
What we collect
Account details. Your name, email address, the organisation you create, and the role you hold in it.
Content you upload. Images and video, captions, and the metadata attached to them.
Connected account data. When you link a social account we receive an access token, your username, account id and account type, plus the performance statistics for content published through us. The next section lists all of it, item by item, and says how long each part is kept.
Activity records. Who did what and when, inside your workspace. This is the audit trail the product exists to provide.
Advertising measurement — only if you agree to it. Which advert or page brought you to this website, and whether you went on to sign up. It is switched off until you say otherwise, and there is a section on it below.
What Instagram and Facebook send us
Connecting an account happens on Meta’s own screen, and what comes back is a key rather than a password. This is all of what Meta then sends us, and all of what we ask for:
- A key to that account, deliberately narrow.It lasts about sixty days and renews itself while you keep using the product. It carries three permissions and no others: read the account’s basic profile, publish content to it, and read the performance figures for what was published. We cannot read your messages, cannot touch your advertising account and cannot change your settings, because we never asked for the permissions that would let us.
- Which account it is. Its id, its username and its account type — and, where Instagram serves them, its follower count, how many posts it has, and the hours of the day its followers are typically online. That last one is a figure about an audience; it names nobody in it.
- What we published for you. For each post that goes out through us, the id Instagram gives it and its public link, so the post in your workspace can point at the real one.
- How those posts performed. Reach, views, likes, comments, saves, shares, follows and total interactions — for the posts published through us, and for no others. We do not read the rest of your account’s history.
Why we keep a copy of the numbers. Instagram stops serving a post’s figures a few weeks after it goes out. If we asked on demand, your own record of what worked would quietly disappear behind you — so each refresh writes a dated snapshot, and those snapshots are what the insights pages are built from.
How long. The key lives until it expires or you disconnect the account, whichever comes first. It is encrypted with AES-256-GCM the entire time it is stored, decrypted only in the moment it is used to publish or to fetch figures, and is never displayed — not to you, not to your team, not in our own support console. The snapshots stay for as long as the workspace does: they are its record of its own work, they describe posts rather than people, and disconnecting an account does not erase the history of what was published from it.
TikTok works the same way, with its own key, its own permissions and its own figures.
Turning a connected account off, from either side
From here. Connected accounts → Disconnect. We delete our copy of the key at that moment. Nothing in the product can publish to that account again, or read anything from it again.
From Instagram.Instagram → Settings → Apps and websites, and remove MyPostStation. On Facebook it is Settings → Business integrations. This withdraws the authorisation at Meta’s end, which is the stronger of the two because it works whether or not you can reach us, and we would rather you had it.
What happens here when you do that.Meta tells us, on a callback that exists for exactly this. For an Instagram account we then erase the stored key, mark the connection disconnected so nothing keeps trying to publish, and write a line in your workspace’s activity log saying the account holder removed us — because “revoked” with no reason reads like our failure, and somebody has to be able to find out why posting stopped.
One limit, stated plainly.For a Facebook Page we cannot yet make that match. Meta’s message names the person who removed us; what we stored is the Page they administer, and those are different identifiers. So a Facebook removal reaches us about somebody we cannot identify, and nothing happens automatically. The authorisation is still withdrawn at Meta’s end and we cannot publish — but if you want the record gone as well, disconnect the Page here or write to us, and we will do it.
What we do not collect
Why we hold it
Where it is stored
Who we share it with
We do not sell your data. We share it only with the services required to run the product: our cloud and hosting providers, our payment processor, and the social platform you have chosen to publish to.
Publishing content sends it to that platform, where their own terms and privacy policy apply.
There is one recipient that is not required to run the product, and it is the only one you can refuse: if you accept advertising measurement, Meta receives the events described below. Nothing goes to Meta for advertising unless you have agreed to it.
How long we keep it
Deleting it, and checking that we did
In the app. Settings → Delete account. It takes effect at once: your sign-in is destroyed, your name, email address and WhatsApp number are removed from your profile and from your membership of the workspace, and every device you were signed in on stops receiving notifications. Nothing in the product will use those details to contact you again. What we cannot do is reach into the activity log and take them out of entries already written there — see below, because it is the one place they survive.
By email. Write to privacy@mypoststation.com from the address on the account, including if what you want deleted is a whole workspace and its media. We reply within one working day and finish within 30 days.
Then check it. Deleting your account in the app gives you a confirmation code, and the deletion status page turns that code into a plain statement of what was asked for, what was deleted, and what was kept. It needs no account — by then you may not have one — and it holds nothing that names you. That is also why we cannot look a lost code up for you: there is nothing on our side to search by. Codes work for 180 days, and then the record goes too.
Or ask Meta.From inside Facebook or Instagram you can ask for the data an app holds about you to be deleted, and Meta forwards that request to us. For an Instagram account we delete the connection — the stored key, the handle, the account type, the follower and quota figures — and the cached audience figures for it, day-by-day history included. Meta then shows you a confirmation code, and it opens the same status page as above. What stays is the workspace’s own record of what it published — the posts, and the figures attached to each one — because that is the workspace’s business record rather than the account’s. If nothing of yours was here to delete, the page says exactly that rather than implying work we did not do; and the Facebook limit described above applies to these requests too, which is why an email to us is still the surer route for a Page.
What survives, and why.The activity entries naming you stay. Each is sealed to the one before it, so removing or rewriting one would break every entry after it and destroy the tamper-evidence this product is sold on — and a workspace owner has to be able to answer “who approved this?” about someone who has since left. Being sealed cuts both ways, and we would rather say so than let you find out: those entries still carry the name you had when each was written, and entries about an invitation still contain the address it was sent to. Everywhere else in the workspace — the team list, and anything reading from it — you appear as “Deleted user”. Billing records are kept for as long as the law requires. Anything already published to Instagram, Facebook or TikTok lives on that platform rather than here, and only you can take it down there.
Your choices
You can disconnect a social account at any time, from your settings or from Instagram’s own settings — the section above says exactly what each of those does.
You can accept or refuse advertising measurement, and change that answer whenever you like, using the buttons further down this page.
You can delete your account yourself, as described above. You can also ask for a copy of your data or a correction to it, by writing to privacy@mypoststation.com. Depending on where you live you may have additional rights under local data protection law, including the Nigeria Data Protection Act and the UK/EU GDPR.
Adverts, and what Meta is told
Meta appears twice in this policy for two unrelated reasons. Above, it is the company whose platform you publish to, and everything in that section happens because you asked us to post something. Here, it is an advertising network we may buy adverts from. Nothing crosses between the two: the advertising code cannot reach your posts, your captions, your connected accounts or your team, and none of that is ever sent.
When we advertise on Instagram and Facebook, we need to be able to tell that someone who saw an advert later signed up — otherwise there is no way to know whether the money was worth spending. That is the entire purpose of this, and it is the only purpose.
It is off until you accept it. There is no advertising pixel on this site, and nothing is sent to Meta, unless you have pressed Accept. Refusing costs you nothing — the site and the product work identically either way, and we do not ask again for six months.
If you do accept, two things happen:
- Your browser loads Meta’s advertising pixel, which records that this browser visited, which pages it looked at, and whether it reached the signup form.
- Our own server reports a short list of moments to Meta’s Conversions API — that an account was created, or that a subscription started. It is the same event seen from our side, because a browser-only record is blocked or lost often enough to be misleading.
What is sent.The name of the event, an id used to stop the same conversion being counted twice, the time, the page it happened on with any query string removed, the amount and currency where there is one, and your browser’s user-agent string. That is the whole of it by default. It describes what happened, not who it happened to.
Identifying you to Meta is a second switch, and it is off. There is a separate setting, off unless somebody deliberately turns it on, that adds identifying fields to those events so Meta can match them to an account it already holds: your email address, your phone number if we have one, an internal id for your workspace, your IP address, and Meta’s own pixel cookies. The first three are hashed with SHA-256 before they leave our servers and cannot be turned back into the original — we never send your email address in the clear, under any setting. The last two Meta requires in the clear, which is one of the reasons they sit behind the same switch.
It is a separate switch because a hash is still personal data, and because none of it can be recalled once Meta holds it. That makes it a decision for the person who owns the promise on our front page, rather than a default somebody picks while wiring up an advert.
What is never sent. Your posts, your captions, your uploaded images and video, your connected social accounts, your access tokens, who is in your workspace, or anything about what your team does inside the product. None of it is reachable from the advertising code, and none of it goes to Meta.
Meta is a separate company and handles what it receives under its own terms. Instagram and Meta are trademarks of Meta Platforms, Inc.
Cookies
The complete list, in the order you would meet them:
- One essential cookie keeps you signed in. The service cannot work without it, so it is not optional and it is not covered by the choice above.
- One cookie recording your answer to the advertising question, so we stop asking. It holds the answer, the date, and nothing else. Remembering that you said no is the one thing we cannot do without storing something.
- Meta’s pixel cookies — only if you accepted, and never before. Refuse, or ignore the question, and they are never set.