Privacy policy

Last updated 7 October 2026

Coolposts (coolposts.co and app.coolposts.co) is a tool to plan, publish and measure posts on the social accounts its users connect, and to read and answer the comments and messages those accounts receive. This policy explains what we store, why, and how to have it deleted.

Who we are

Coolposts is run from Spain. For anything about your data, write to hello@coolposts.co.

What we store

  • Your account: email, name (optional), a hashed password, when you signed up and when you last used the app.
  • Connected accounts (Instagram, Facebook Pages, X, TikTok, LinkedIn, YouTube, Bluesky, Threads, Pinterest): their id, username, name, profile picture and the access tokens the platform issues to us when you connect them.
  • Your posts: what you write and upload, when it's scheduled, and, once published, its link and the statistics the platform reports (reach, views, likes, comments, shares, saves, clicks). Posts you publish outside Coolposts on a connected account are imported so you see them in your calendar.
  • Account statistics: followers, profile visits, website clicks and the hours your followers are online, as the platform reports them.
  • Comments and messages: comments on your posts and direct messages sent to your connected Instagram and Facebook accounts, with the sender's public name and id, so you can read and answer them in Coolposts. If you set up comment-to-DM, we send a private message from your account to people who comment the keyword you chose.
  • Billing: if you buy a paid plan, which plan, whether it's monthly or yearly, and the state of the subscription (active, renewal date, cancelled). Your card, billing address and tax ID are handled by Stripe; we never see or store your card number.
  • Bio pages and links: the pages and links you create. For each visit or click we record the time, a hashed identifier that changes every day (made from the visitor's IP address and browser, which we don't store), the app it came from, the type of device, the referring site, and an approximate country and city worked out from the IP address at that moment with the DB-IP database. We keep only that country and city, never the IP address itself. We don't use cookies. If you turn on conversions, the sign-ups or sales your own website reports to us.
  • Website analytics: if you add our tag to your website, each page view on it: the time, the page address, the site it came from (and any utm tags), the type of device, an approximate country and city, and the same daily hashed identifier. No cookies, and the IP address isn't stored. You're responsible for telling your site's visitors about it in your own privacy policy.
  • Canva: if you connect your Canva account to design post images, your Canva user id, the access tokens Canva issues to us (encrypted), and the id of each design you open from a post so it can be reopened. Your designs stay in your Canva account; we keep only the images you bring back into your posts.

Forms on bio pages

When a business adds a form to its Coolposts bio page, the details visitors send through it (name, email and, if the business asks for them, phone number and message) are collected on behalf of that business, which is the data controller. Coolposts processes them only as its processor: to store them, show them to the business and email them to it. We don't use them for our own purposes and never contact the people who sent them. To access or erase this data, contact the business directly; the business can delete any submission at any time, and all of a page's submissions are deleted with the page or the business's account.

How we use it

Only to provide the features you use: publishing your posts, showing your calendar, inbox, analytics and bio pages, and sending the messages you set up. We don't sell or rent your data, don't show ads, don't build profiles of the people who interact with you and don't use your data or theirs to train AI models.

Data from Meta (Instagram, Facebook and Threads)

We access Instagram, Facebook and Threads through Meta's APIs, with the permissions you grant when you connect an account: publishing to your accounts, reading the comments, messages and insights of those accounts, and replying from them. We use this data only inside your own Coolposts workspace and only for the features above. It is kept while the account is connected, and for up to 90 days after you disconnect it so you can reconnect without losing your history; it is deleted sooner if you ask (see data deletion).

Who we share it with

Our service providers, only to run Coolposts: Railway (hosting and database), Hostinger (website and email), Stripe (payments, invoices and tax), Google Drive when you add media from it (only the files you pick; Coolposts copies them and can't see anything else in your Drive), Adobe when you design in Adobe Express (the editor runs on Adobe's side under your own Adobe account; Coolposts receives only the image you save to a post, and sends Adobe only a photo you choose to edit), Canva when you design in Canva (you connect your own Canva account; Coolposts creates the designs you start from a post, uploads to your Canva account only a photo you choose to edit, and exports the design you bring back), UserSignal for the support chat and help centre (the messages you send it and, when you write from the app, your name, email, plan and an account id so it can answer about your account), Pixabay and GIPHY when you search stock photos, videos or GIFs (they receive only the words you search, sent from our servers), Google when you connect a YouTube channel (Coolposts uses YouTube API Services; see the YouTube Terms of Service and the Google Privacy Policy; you can remove Coolposts' access at any time in your Google account's security settings), and OpenAI for the AI writer: only the text you ask it to write or rework and your brand's writing style are sent, when you use it, and OpenAI doesn't use them to train its models. The platforms you connect receive what you publish or send through them. Nobody else.

How long we keep it

For as long as your account exists. When you disconnect a social account we delete its access tokens at once and stop reading it; its comments, messages, statistics and imported posts are kept for 90 days so a reconnect picks up where you left off, then deleted. You can delete them straight away with Delete data in Coolposts. When you ask us to delete your Coolposts account we delete everything within 30 days. See data deletion.

Your rights

You can ask to access, correct, export or delete your data, or object to how we use it, by writing to hello@coolposts.co. If you're not happy with our answer you can complain to the Spanish data protection authority (AEPD, aepd.es). People who comment on or message a Coolposts user's account can write to us too.

Security

Everything travels over HTTPS, passwords are hashed, and access tokens are kept on our servers and never shown in the app.

Changes

If we change this policy we'll update the date above, and tell you in the app or by email when the change matters.