Privacy Policy

Last updated: April 19, 2026  ·  MEDISTRAT SDN. BHD. , Malaysia

1 Introduction

Post2Share ("we", "our", or "us") is a social media management platform operated by MEDISTRAT SDN. BHD. , based in Malaysia. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our services at app.post2share.com.

By using Post2Share, you agree to the practices described in this policy. If you do not agree, please discontinue use of the Service.

2 Information We Collect

We collect the following information when you use Post2Share:

  • Account information: Your name, email address, and password when you register.
  • Google / YouTube data: Name, email, profile picture, and OAuth tokens to publish videos on your behalf.
  • Facebook data: Public profile, email, page access tokens, page IDs — to publish text posts, images, and videos to your Facebook Pages and read page engagement analytics (pages_manage_posts, pages_read_engagement, read_insights).
  • Instagram data: Instagram Business account ID, username, profile picture, and access token — to publish images, videos, and Reels and read engagement insights (instagram_business_basic, instagram_business_content_publish, instagram_business_manage_insights, instagram_business_manage_comments, instagram_business_manage_messages).
  • Threads data: User ID, username, profile picture, and long-lived access token — to publish text, image, and video posts and read post analytics (threads_basic, threads_content_publish, threads_manage_insights).
  • LinkedIn data: OAuth access tokens, your LinkedIn person URN (urn:li:person:...), post IDs, and engagement data (likes, comments) to publish posts and display analytics on your behalf. We request w_member_social and r_member_social scopes.
  • X (Twitter) data: OAuth 2.0 access and refresh tokens to publish tweets and upload media.
  • Content you create: Captions, media files, scheduling data, and campaign information.
  • Usage data: Log data, IP addresses, browser type, workspace activity, and feature usage.

3 How We Use Your Information

  • To authenticate you and manage your account and team workspaces.
  • To publish posts, images, videos, and Reels to your connected Facebook Pages, Instagram Business accounts, LinkedIn profiles, YouTube channels, X accounts, Threads profiles, and Pinterest boards on your behalf.
  • To schedule, queue, and manage content across all connected platforms.
  • To automatically refresh OAuth tokens to maintain uninterrupted publishing access.
  • To power AI Caption generation and AI Media creation using your AI Credit wallet.
  • To send real-time notifications about post status (published, failed, recovered).
  • To enforce role-based permissions within team workspaces.
  • To track post analytics and publishing results per platform.
We do not sell, rent, or share your personal data with third parties for advertising or marketing purposes.

4 Connected Social Platforms

PlatformWhat We AccessStatus
📘 FacebookPublic profile, email, page access tokens — publish text, photos & videos to Pages; read page insights and engagement. Scopes: pages_manage_posts, pages_read_engagement, read_insights, pages_show_list, pages_manage_metadataLive
📷 InstagramBusiness account ID, username, access token — publish images, videos & Reels; read insights. Scopes: instagram_business_basic, instagram_business_content_publish, instagram_business_manage_insights, instagram_business_manage_comments, instagram_business_manage_messagesLive
🧵 ThreadsUser ID, username, access token — publish text, image & video posts; read post analytics. Scopes: threads_basic, threads_content_publish, threads_manage_insightsLive
💼 LinkedInPerson URN, access token — publish text, image & video posts; read post engagement via Community Management API. Scopes: w_member_social, r_member_socialLive
▶️ YouTubeOAuth tokens — upload videos & Shorts, check processing status. Scopes: youtube.upload, youtube, youtube.readonlyLive
✕ X (Twitter)OAuth 2.0 PKCE tokens — publish tweets, upload media. Scopes: tweet.read, tweet.write, users.read, media.writeLive
📌 PinterestUsername, access token, refresh token — create image & video pins on boards. Scopes: pins:write, boards:read, user_accounts:readComing Soon
💬 WhatsAppNot yet connectedComing Soon
🎵 TikTokNot yet connectedComing Soon

5 Google API Services – Limited Use Disclosure

Post2Share's use of data from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

  • We use youtube.upload exclusively to upload videos you create within Post2Share.
  • We use youtube scope to verify video processing status after upload.
  • Google data is never used for advertising, profiling, or any unrelated purpose.
  • We do not transfer Google user data to third parties except as necessary to provide the Service.
  • Revoke access anytime via Google Account Permissions.

5b Facebook & Instagram – Meta Platform Policy

Post2Share's use of Facebook and Instagram data complies with the Meta Platform Policy and Meta Developer Policies.

  • We access Facebook Pages and Instagram Business accounts only after explicit OAuth authorization by the account owner.
  • Facebook and Instagram data (page tokens, post IDs, analytics) is used exclusively to provide the Post2Share publishing and analytics service.
  • We do not use Meta platform data for advertising, profiling, or any purpose unrelated to the service you requested.
  • We do not share Facebook or Instagram user data with third parties except as required to deliver the service.
  • Revoke access anytime via Facebook App Settings or Instagram account settings.
Post2Share is subject to Facebook App Review for permissions including pages_manage_posts, instagram_business_content_publish, and related scopes. We only request permissions necessary for the features you use.

5c Threads – Meta Threads Policy

Post2Share's use of Threads data complies with the Threads API Policy.

  • We access Threads accounts only after explicit OAuth authorization by the account owner.
  • Threads data (user ID, post IDs, analytics) is used exclusively to publish content and display analytics within Post2Share.
  • We request threads_basic, threads_content_publish, and threads_manage_insights scopes.
  • Long-lived Threads tokens are auto-refreshed and stored securely.

6 OAuth Token Storage & Refresh

  • Facebook: Long-lived Page access tokens (60-day expiry) auto-refreshed via fb_exchange_token grant. Page tokens are stored per connected Page.
  • Instagram: Long-lived tokens (60-day expiry) auto-refreshed via ig_exchange_token grant before expiry.
  • LinkedIn: OAuth tokens stored securely with 60-day expiry. We request w_member_social for publishing and r_member_social for reading post engagement analytics. Expired tokens require manual reconnection.
  • X (Twitter): OAuth 2.0 tokens automatically rotated on each use.
  • YouTube / Google: Tokens refreshed via Google's OAuth 2.0 refresh flow.
  • Threads: Long-lived tokens (60-day expiry) auto-refreshed via th_refresh_token grant.
  • Pinterest: Tokens auto-refreshed via Pinterest OAuth 2.0 refresh token flow.

All tokens are stored encrypted and only used to perform actions you initiate within Post2Share.

7 AI Credits & Data Processing

Post2Share includes an AI Credit system used for AI image generation (Seedream 4.5 by ByteDance), AI caption writing, analytics, and automation. Your prompts may be sent to third-party AI providers to generate results. We do not store prompts beyond what is necessary to deliver the generation. AI Credits never expire and are managed in your AI Credit Wallet in Settings.

8 Data Storage & Security

Your data is stored on secure cloud infrastructure with encrypted storage of OAuth tokens, HTTPS/TLS for all data in transit, role-based access controls, and regular security reviews. While we take reasonable precautions, no system is completely secure.

9 Data Retention

We retain your data for as long as your account is active. Upon account deletion, personal data is removed within 30 days except where required by law. Aggregated, anonymized analytics data may be retained.

10 Your Rights

Under Malaysian law (PDPA 2010) you have the right to access, correct, or delete your personal data, withdraw consent, and disconnect any connected social account from within platform Settings. Contact us at info@post2share.com to exercise these rights.

11 Cookies & Local Storage

Post2Share uses essential browser storage (cookies and localStorage) to maintain login sessions and workspace preferences. We do not use tracking cookies or third-party advertising cookies.

12 Children's Privacy

Post2Share is not intended for users under 18. We do not knowingly collect data from minors. If you believe a minor has registered, contact us and we will delete the account promptly.

13 Changes to This Policy

We may update this policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. Continued use after changes constitutes acceptance.

14 Contact Us