Your accounts, handled with care.
Connecting a social account means trusting us with something that matters. Here's how we earn that, in plain language. No security theatre.
- AES-256every stored token encrypted
- 100%official platform APIs
- 0passwords seen or stored
- 1 clickdisconnect, or delete it all
“Will this get my account banned?”
No. We post through each platform's official developer API, the sanctioned path the platforms build for tools like ours. We never scrape and never automate a logged-in browser session. That's also why some networks take time to turn on: we go through each one's formal app review rather than cutting corners.
“Can you see or take my stuff?”
We ask for the narrowest permissions that do the job: publish posts, and read the performance of your own content. Every token is encrypted, every workspace is walled off from every other, and your content is never used to train AI models. Disconnect or delete everything in one click.
Safe by construction.
Official APIs only
Every post travels through the platform's own developer programme. No scraping, no unofficial endpoints, no session tricks.
Encrypted tokens
OAuth tokens are encrypted with AES-256-GCM before they touch our database. Never logged, never returned, never exposed.
Narrow scopes
We request the least each feature needs: publish, and read insights for your own posts. Not your messages, not your contacts.
No model training
Your posts, brand kit and media are never used to train AI models. The AI works for you, on your material, under your direction.
Walled-off workspaces
Every piece of data is scoped to your workspace and enforced at the database layer, on every request.
You stay in control
Disconnect a channel and its tokens are wiped immediately. Nothing publishes without your approval.

What we keep. What we never will.
What we store, and why
- Access tokens, encrypted with AES-256-GCM, so we can post for you.
- The media and drafts you put in your library.
- Performance numbers for your own posts, to power your analytics.
What we'll never do
- See or store your platform passwords. OAuth means we never can.
- Read your DMs, inbox or contacts. We never ask for them.
- Train AI models on your content, or sell your data.
- Post anything without your explicit approval.
- Stamp a “made with postme.live” watermark on your work.
Reviewed, and accountable.
- Least-privilege scopesonly what a feature needs
- Independently reviewedadversarial audits, June & July 2026
- Encrypted at restAES-256-GCM tokens
- Network-isolatedhardened infrastructure
- A real companyOutback Yak ↗
postme.live is built by Outback Yak, a registered Melbourne software firm (ABN 11 672 730 773). Meta's app review cleared in July 2026, and we show each platform's verification here the day it clears.
Asked, and answered straight.
- Will connecting my accounts get them banned?
- No. We post through each platform's official developer API, the sanctioned path built for tools like ours, and we pass each platform's formal app review. The things that get accounts flagged (scraping, automating a logged-in browser) are things we never do.
- Can you see my passwords?
- No, and we never could. You connect through each platform's own sign-in (OAuth), so your password never touches us. We receive a scoped access token and encrypt it with AES-256-GCM before it is stored.
- Do you train AI on my content?
- Never. Captions and designs are generated on request, for you, from your material. Your content is not used to train any model, ours or anyone else’s.
- What happens when I disconnect a channel?
- Its stored tokens are wiped immediately. Your own post history stays in your workspace until you choose to delete it.
- Where is my data stored?
- On hardened, network-isolated infrastructure hosted in Australia, with the sub-processors we use listed in our Privacy policy.
- How do I report a security issue?
- Email [email protected]. A person reads every report, and we act quickly on anything credible.
Your data, your call
Disconnect anytime
Removing a channel wipes its stored tokens immediately while keeping your own post history intact.
Delete everything
One request removes your data for good. See Data deletion.
Read the fine print
Our Privacy policy, Terms, and Permissions spell out the rest.
Found something that looks off? Tell us at [email protected]. A person reads every report.