Privacy Policy
Last updated: July 8, 2026
PostOnly is a write-only posting app made by Aspect Services, LLC. Its design philosophy extends to your data: the app sends what you write to the networks you choose, and keeps as little as possible for itself. This policy describes exactly what is stored, where, and for how long.
What's stored on your device
Your drafts, destination groups, and post history are stored locally on your Mac or iPhone — not on a PostOnly server. Account credentials (OAuth tokens, API keys, app passwords, webhook URLs) are stored in the system Keychain, encrypted by the operating system. When you connect an account, PostOnly fetches basic profile details from that network (such as your username, account ID, and display name) solely to label the account inside the app; those details are stored on your device only. Local data is included in your device backups under your control, and is removed when you delete the app or disconnect an account.
What passes through PostOnly's server
Most posts travel directly from your device to the network you're posting to. A small server at api.postonly.app exists for four narrow jobs, none of which involves keeping your data:
Sign-in relay
For networks that use OAuth (such as LinkedIn, Threads, Instagram, Facebook, Slack, and X), the relay passes the sign-in handshake between the network and your device. It is stateless: it has no user accounts, no sessions, no cookies, and it does not store your tokens — they go straight to your device's Keychain.
Temporary image hosting
Some networks (Threads, Instagram, Facebook) can only accept images fetched from a public URL. When you attach an image for those networks, PostOnly uploads it to the server just long enough for the network to fetch it, then deletes it immediately after your post publishes. Any file the app fails to delete expires automatically within one hour. Images are never retained beyond that.
X posting proxy
Posts to X are sent through PostOnly's proxy (X's API access is paid, covered by the X Posting subscription). Your post text and images pass through to X and are not stored. To verify your subscription, the app sends your Apple purchase receipt with each post; the server verifies it cryptographically and does not store it. The only record kept is a monthly usage counter tied to an opaque Apple transaction identifier — a random-looking ID that contains no name, email, or other personal detail — used to enforce fair-use limits. Counters expire automatically.
Purchase receipt validation
Receipt checks are performed on the server using Apple's published cryptographic keys. Nothing is stored, and nothing is sent onward to Apple or anyone else.
Server logs
The server keeps short-lived operational logs for security, debugging, and abuse prevention (for example: request type, status code, counts, and the IP address used for rate limiting). Logging is redacted by design: post content, credentials, tokens, and receipts never appear in logs.
What PostOnly does not do
PostOnly does not read your timelines, feeds, followers, or existing posts on any network. It contains no advertising, no analytics, no tracking, and no third-party SDKs. Aspect Services, LLC does not sell, rent, or share your data with anyone.
Data retention and deletion
PostOnly's servers do not retain your content or credentials, so there is normally nothing to delete on our side. To remove data:
On your device: disconnect an account in the app to delete its credentials from your Keychain, or delete the app to remove all local data (drafts, history, settings).
On our server: temporary images are deleted at publish time and expire within one hour regardless. If you revoke PostOnly's access from within Facebook, Instagram, or Threads, Meta notifies our deletion endpoint and the request completes immediately — because no stored data exists for your account.
If you have any deletion question or request, contact us via the support page and we will respond promptly. Because PostOnly's servers hold no personal data, requests under privacy laws such as the GDPR or CCPA (access, rectification, erasure, portability) can typically be satisfied immediately — there is nothing on our side to export or erase beyond the temporary items described above.
Purchases
All purchases are processed by Apple through the App Store. PostOnly never sees your payment details. Apple's own privacy policy governs payment processing.
Third-party networks
Once your content is posted to a network (Bluesky, Mastodon, Threads, Facebook, Instagram, LinkedIn, X, Telegram, Discord, Slack, Micro.blog, or your own Total CMS site), that network's privacy policy governs it. PostOnly is only the messenger.
Children
PostOnly is not directed at children under 13, and we do not knowingly collect personal information from them.
Changes
If this policy changes, the new version will be posted here with an updated date. Material changes will be called out in the app's release notes.
Contact
Questions about privacy can go to the address on the support page.