Tokens are never logged
Access tokens, refresh tokens, authorization headers, and session secrets are excluded from logging by policy and in code.
Connecting a social account to a third-party tool is a real decision. This page says plainly what Selfpost holds, what it never records, and how to take it all back.
Launch updates only. No spam. Privacy policy
Connected accounts show which platform they belong to, what they are permitted to do, and whether the connection is still healthy.
Every destination is checked before you schedule, so a platform rule stops the post here rather than at the publish time you were counting on.
/w/[workspaceId]/composerNothing here is exotic. It is worth writing down because the alternative is asking you to assume it.
Access tokens, refresh tokens, authorization headers, and session secrets are excluded from logging by policy and in code.
Each permission is requested for a stated publishing or analytics purpose, and the reason is shown at the point of connection.
Every media, post, account, and analytics operation verifies workspace membership server-side. A client-supplied identifier is never trusted.
You can disconnect an account or request deletion of associated data at any time, through a documented route.
Media stored on your behalf is served through signed, time-limited URLs rather than left publicly addressable.
Selfpost is not open for signups yet. Leave your address and we will email you the moment it is. Or walk the whole publishing flow right now in the demo, no account needed.
Launch updates only. No spam. Privacy policy