Last updated September 4, 2026.
PostScheduling uses your license key to authenticate access. PayPal may provide transaction identifiers and payer email information as part of payment confirmation. Facebook Page names, IDs, display-picture URLs and Page Access Tokens are processed when you connect Pages.
After a successful license-key sign-in, PostScheduling records a pseudonymous device identifier, a general browser/device label, IP address, sign-in time and sign-in count. The service owner can view this activity in the private License Manager to identify license sharing or suspicious access. Dashboard refreshes do not create additional login records.
We never ask for or store your Facebook password or 2FA code. User Access Tokens used only for Page discovery are not intentionally persisted. Page Access Tokens required for scheduling are encrypted before storage using AES-GCM. The encryption key is stored separately as a Cloudflare Worker Secret.
The server must technically use a Page Access Token to perform Meta API actions you request and to verify that a saved connection is still valid. Tokens are decrypted inside the Worker for connection checks, scheduling, rescheduling, cancellation and relevant Page API queries. They are not intentionally logged or displayed in the dashboard.
Uploaded media is temporarily placed in Cloudflare R2 so background scheduling jobs can send it to Meta. The application deletes a media object after all queued schedule jobs referencing it have completed.
Payments are processed by PayPal. We do not receive or store your PayPal password or complete payment-card details.
For privacy questions, contact the service operator through the support contact published on PostScheduling.