Post.Pilot

Privacy policy

Effective October 10, 2026.

The short version

Who we are

Post.Pilot is an iPhone app made and operated by OmniQm Labs LLC ("we", "us", "our"), Orlando, Florida, United States. We decide how your personal information is used for Post.Pilot, so under laws like the GDPR we're its "controller". This policy explains what we collect, why, who we share it with, how long we keep it, and your rights. It applies to the app and to our web pages at postpilot.omniqm.com. Questions or requests: privacy@omniqm.com.

What we collect, and why

Your Post.Pilot account

You sign in with Apple. Apple gives us an anonymous identifier for your Apple ID, which is how we recognize your account; we don't ask Apple for your name or email address. Each sign-in creates a session on your phone; our server stores only a one-way fingerprint of it.

Accounts you connect

When you connect Instagram, Facebook or X, you log in on that service's own page and choose what Post.Pilot may do. We then keep on our server: your username and account identifiers, the permissions you granted, when the access expires, and the access tokens the service gives us, encrypted (AES-256-GCM). For Facebook, we also keep the name of the Facebook Page you chose and the ID of its linked Instagram account. We use this access only to do what you ask in the app: show your statistics, look up the reference accounts you add, learn how you write on X, and publish the posts you approve.

Instagram statistics

To show Insights and suggest good days to post, we read your Instagram professional account's statistics from Meta: followers, views, accounts reached and interactions over recent periods, reach by weekday, and your followers' totals by age group, country and city. Instagram provides the follower information only as totals, never as individual people, and we never collect lists of your followers. We keep the latest numbers for up to 6 hours before reading them again, and delete them when you disconnect Instagram.

Reference accounts

If you connect Facebook and add up to three public Instagram Business or Creator accounts as references, we look them up through Meta's Business Discovery: their public profile details (name, biography, follower and post counts) and their recent public posts (captions, like, comment and view counts, dates, links). We refresh each lookup after about a day while the account is on your list, delete it when you remove the account, and use it only to show you what works for those accounts and to guide the AI's suggestions for you. The AI is told never to copy their words, names or hashtags.

Your photos and videos

With your permission, Post.Pilot reads your photo library on your phone to find good photos and videos. That scanning and filtering happens on your phone. Only these leave it:

We don't use your photos or videos to identify people, recognize faces, or create biometric identifiers or templates.

Drafts, captions and scheduled posts

Drafts and your settings (schedules, writing style, topics) stay on your phone. When you approve a post, we keep on our server what's needed to publish it: its caption or text, kind (post, carousel, Story, Reel or X post), scheduled time, status (scheduled, paused, posted or not posted, with the reason), and once it's out, its link and ID on Instagram or X.

X posts and your writing voice

To write X posts, the app sends the topics and writing style you choose. The first time you have the AI write X posts after connecting X, we read your last 30 posts on X (not replies or reposts) and have the AI write a short description of how you write. We keep only that description, not your posts, refresh it at most once a month, and delete it when you disconnect X.

Your plan and purchases

We keep which plan you're on. If you subscribe to Premium, Apple handles the payment and we never receive your card or payment details. RevenueCat, our subscription service, receives your Post.Pilot account ID, your App Store purchase and subscription records, and basic technical information needed to process them, and tells us whether your subscription is active and when it renews or ends.

Usage limits

We count how many AI drafts you use each week to apply your plan's limits. These counts delete themselves after about five weeks.

Technical logs

Our server keeps technical logs (for example, that a request failed and why) for 30 days. They never contain your photos, captions, posts or access tokens. When you visit our web pages, our hosting provider records standard request information (IP address, browser type, the page and time) for 30 days, for security. Our web pages use no cookies, analytics or trackers.

Messages you send us

If you email us, we keep your message and email address to answer you and for our records.

Phone permissions

Post.Pilot asks for access to your photo library (to suggest drafts and save Reels you remake). It doesn't use your camera, microphone, location, contacts or advertising identifier.

How we use it, and what we never do

We use your information only to provide Post.Pilot: to sign you in, suggest and write drafts, schedule and publish what you approve, show your statistics, apply your plan, provide support, keep the service secure and working, and meet legal obligations.

How the AI works

Post.Pilot uses AI models through Amazon Bedrock, a service of Amazon Web Services: Amazon Nova 2 Lite and, on Premium, Anthropic's Claude Haiku 4.5. They receive only what's described above (small photo copies, still frames, your writing style, topics and voice description, and summaries of reference accounts) and return suggestions. The models run inside AWS: Amazon states that Bedrock doesn't store these requests or use them to train models, and that model providers such as Anthropic don't receive them. AI suggestions can be wrong; every draft waits for your review, and drafts that touch politics, health claims or financial advice are flagged for an extra look.

Who we share it with

Only with the services that run Post.Pilot for us, under contracts that limit them to providing their service, and only what each needs:

When you connect Meta (Instagram, Facebook) or X, we exchange information with them to provide the features you use, and what you publish becomes public on those services under their own policies.

We may also disclose information if the law requires it (for example a valid court order), to protect the rights, safety or property of our users, ourselves or others, or as part of a merger, acquisition or sale of the business, in which case this policy continues to apply and we'll tell you first. Otherwise, we share information only with your consent.

Where it's stored

Our server and storage are in the United States (AWS, Ohio), and the AI requests are processed in AWS's US regions (Ohio, Virginia and Oregon). If you use Post.Pilot from outside the United States, your information is transferred to and processed in the United States, where privacy laws may differ from yours. Where the law requires safeguards for these transfers, we rely on our providers' data processing terms, including the European Commission's standard contractual clauses where they apply.

How long we keep it

WhatHow long
Small photo copies, video frames, Reel frames and clip previews sent to the AINot kept
Photos and videos uploaded for postingUntil posted or moved back to the Queue, and 30 days at most
Instagram statisticsRefreshed every 6 hours; deleted when you disconnect
Reference account lookupsRefreshed daily while on your list; deleted when you remove the account
Your X voice descriptionUntil you disconnect X
Connected account accessUntil you disconnect or delete your account
Scheduled and past posts, Reel recipes, your planUntil you delete your account
Weekly AI draft countsAbout five weeks
Sign-in sessionsUntil you sign out, or a year without use
Server logs and web page request logs30 days
Emails you send usAs long as needed to help you, and as the law requires

When you delete your account, we delete your information from our systems right away, except what the law requires us to keep. Copies in system backups, if any, are overwritten in the normal course.

Your choices

Your privacy rights

Wherever you live, you can ask us to access the personal information we have about you, correct it, delete it, or give you a copy in a portable format. Write to privacy@omniqm.com from any address, with the username of an account you connected, or use Delete account in the app. We'll confirm the request comes from you (for example by asking you to confirm from within the app or from the connected account), and answer within 45 days, or sooner where the law requires. We won't treat you differently for using your rights.

United States

Residents of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon and other states with privacy laws have the rights above. In the last 12 months we collected the categories described in "What we collect" (identifiers, commercial information about your subscription, user content such as photos, videos and captions, and internet activity limited to the logs described), for the purposes in "How we use it", and disclosed them only to the service providers listed. We don't sell personal information or share it for targeted advertising (including that of anyone under 16) and don't profile you for decisions with legal effects, so there's nothing to opt out of; we honor Global Privacy Control signals all the same. You may use an authorized agent, whose authority we'll verify. If we decline a request, you can appeal by replying to our answer; we'll respond within 45 days and, if we still decline, tell you how to contact your state's attorney general.

Europe, the UK and Switzerland

We process your information because it's needed to provide the service you asked for (contract), with your consent (photo access, connecting accounts; you can withdraw it at any time by turning it off or disconnecting), for our legitimate interests in keeping the service secure and working, and to meet legal obligations. You also have the right to restrict or object to processing, and to complain to your local data protection authority. We answer within one month.

Brazil

Under the LGPD you have the rights above, plus confirmation that we process your data and information about who we share it with. Requests go to privacy@omniqm.com, our contact for data protection matters.

Security

Everything between the app, our web pages and our server is encrypted in transit (HTTPS). Access tokens for your connected accounts are encrypted on our server and never sent to your phone. Uploaded photos and videos sit in private storage, reachable only through short-lived links. Access to our systems is limited to the people who run Post.Pilot. No system is perfectly secure; if a breach affects your information, we'll tell you and the authorities as the law requires.

Children

Post.Pilot isn't meant for children. You must be at least 13 years old to use it, or older where the law of your country requires (for example 16 in some European countries). We don't knowingly collect personal information from children under 13. If you believe a child has given us information, write to us and we'll delete it.

Other services' policies

When you connect or post to other services, their own policies apply to what they collect: Instagram, Facebook, X, Apple, RevenueCat and AWS. Post.Pilot isn't affiliated with or endorsed by Meta or X.

Changes to this policy

When Post.Pilot changes what it does with your information, we update this policy and its effective date. If a change matters, we'll tell you in the app before it takes effect, and ask for your consent where the law requires.

Contact

OmniQm Labs LLC, Orlando, Florida, United States. Privacy: privacy@omniqm.com. Support: support@omniqm.com.