Legal

Privacy Policy

Last updated: June 17, 2026 · Effective date: June 17, 2026

This Privacy Policy describes how Nanopost ("Nanopost", "we", "us", or "our") collects, uses, discloses, and safeguards information in connection with the Nanopost platform, websites, applications, and related services (collectively, the "Service"), available at nanopost.xyz. It also explains the privacy rights available to you and how to exercise them.

Please read this Privacy Policy carefully. By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our policies and practices, please do not use the Service.

Nanopost is operated by Huseynbala Gurbanli, a sole proprietor registered in the Republic of Azerbaijan ("the Operator"). For the purposes of applicable data protection law, the Operator is the data controller responsible for personal data processed about users of the Service, except where Nanopost acts as a data processor on behalf of its business customers as described in Section 4.

Contents
  1. Scope & Application
  2. Definitions
  3. Information We Collect
  4. Controller & Processor Roles
  5. How We Use Information
  6. Legal Bases for Processing
  7. Cookies & Tracking
  8. How We Share Information
  9. Sub-Processors
  10. Third-Party Platforms
  11. AI & Automated Processing
  12. International Transfers
  13. Data Retention
  14. Data Security
  15. Your Privacy Rights
  16. EEA & UK Rights (GDPR)
  17. California Rights (CCPA/CPRA)
  18. Data Deletion
  19. Children's Privacy
  20. Marketing Communications
  21. Data Breach Notification
  22. Third-Party Links
  23. Changes to This Policy
  24. Contact Us

1. Scope & Application

This Privacy Policy applies to personal data we process about:

This Privacy Policy does not apply to third-party websites, products, or services that we do not own or control, even if they link to or are linked from the Service.

2. Definitions

Unless otherwise defined in this Privacy Policy, the following terms have the meanings set out below:

3. Information We Collect

3.1 Information you provide to us

3.2 Information from connected third-party accounts

When you connect a third-party social media account to the Service through an authorization (OAuth) flow, we receive and store information from that platform. Depending on the platform, this may include:

3.3 Content data

3.4 Information collected automatically

4. Controller & Processor Roles

Nanopost plays two different roles depending on the data in question:

As a data controller. For personal data of account holders and website visitors — such as account credentials, billing information, and usage data — the Operator determines the purposes and means of processing and therefore acts as a data controller.

As a data processor. When an account holder connects a third-party social media account and uses the Service to process content and associated data (including data relating to that account's audience or commenters), Nanopost generally acts as a data processor on behalf of the account holder, who is the controller of that data. In that capacity, we process such data only in accordance with the account holder's instructions and this Privacy Policy. Account holders are responsible for ensuring they have a lawful basis to provide such data to us and to instruct the processing they request.

5. How We Use Information

We use the information we collect for the following purposes:

6. Legal Bases for Processing

Where data protection law (such as the EU and UK General Data Protection Regulation) applies, we rely on the following legal bases to process personal data:

7. Cookies & Tracking Technologies

We use cookies and similar technologies to operate the Service, remember your preferences, maintain authenticated sessions, and understand how the Service is used. We distinguish between:

Where required by law, we obtain your consent before placing non-essential cookies. You can manage your cookie preferences through the cookie banner presented on our website and through your browser settings. Disabling certain cookies may affect the functionality of the Service.

8. How We Share Information

We do not sell your personal data. We share information only in the following circumstances:

9. Sub-Processors

We engage the following categories of sub-processors to operate the Service. Each is bound by contractual obligations to protect personal data and to process it only as necessary to provide their services to us.

Sub-processorPurposeData involved
Meta Platforms (Instagram Graph API)Connecting Instagram accounts and publishing approved contentAccount identifiers, access tokens, published content
LinkedInConnecting LinkedIn profiles and Company Pages and publishing approved contentAccount identifiers, access tokens, published content
TikTokConnecting TikTok accounts and publishing approved contentAccount identifiers, access tokens, published content
OpenAIAI text generation, image analysis, and image generationBrand and content data submitted for generation
xAI (Grok)Trend analysis from publicly available contentTopic and trend queries
ApifyCollection of publicly available social media postsPublic post data
Amazon Web Services (S3)Storage of generated images and uploaded filesGenerated and uploaded media
SupabasePrimary database for account, brand, and content dataMost stored personal and content data
Upstash (Redis)Task queue and caching infrastructureTransient operational data
HetznerCloud hosting and infrastructureAll data processed by the Service
TelegramOperational review and notification workflowContent review notifications
Email delivery providerSending transactional and waitlist emailsEmail address and message content
Payment processorProcessing subscription paymentsBilling details and transaction records

We may update our sub-processors from time to time as the Service evolves. We will update this list to reflect material changes.

10. Third-Party Platforms

10.1 Meta / Instagram

The Service integrates with the Meta (Instagram) Platform. By connecting your Instagram Business or Creator account, you authorize Nanopost to read your Instagram account information, publish photo and carousel posts to your account only after you explicitly approve each post, and, where you enable it, manage comments on posts published through the Service. We do not sell or transfer Instagram data to third parties for advertising, and we use Instagram data only to provide the features you have requested. Our use of information received from the Meta Platform adheres to the Meta Platform Terms and Developer Policies, including any limited-use requirements.

10.2 LinkedIn

Where you connect a LinkedIn personal profile or Company Page, you authorize Nanopost to publish approved content to that profile or page on your behalf. We process LinkedIn account data and access tokens solely to provide this functionality, in accordance with the LinkedIn API Terms of Use and applicable LinkedIn policies.

10.3 TikTok

Where you connect a TikTok account, you authorize Nanopost to publish approved content to that account on your behalf. We process TikTok account data and access tokens solely to provide this functionality, in accordance with the TikTok Developer Terms and applicable TikTok policies. Depending on the review status of our application with TikTok, content may initially be published with restricted visibility as required by TikTok.

10.4 Revoking platform access

You can disconnect any connected account from within the Service at any time. You may also revoke our access directly through the connected-apps settings of the relevant platform. Upon disconnection or revocation, the associated access token is deleted from our systems.

11. AI & Automated Processing

The Service uses artificial intelligence to analyze content and generate captions and images. Brand and content data you provide may be transmitted to our AI sub-processors for the purpose of generating output you have requested. We do not use this data to train our own foundation models. Our AI sub-processors process data in accordance with their own terms and privacy commitments.

The Service is designed with a human-in-the-loop model: AI-generated content is queued for your review, and no content is published to a connected account without an explicit human approval action. The Service does not make decisions that produce legal or similarly significant effects about individuals through solely automated means.

12. International Data Transfers

Nanopost is operated from the Republic of Azerbaijan, and our sub-processors may store and process data in the European Economic Area, the United States, and other jurisdictions. As a result, your personal data may be transferred to, and processed in, countries other than the country in which you reside, which may have different data protection laws.

Where we transfer personal data subject to the GDPR outside the EEA or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision where available. You may contact us to request further information about the safeguards we apply.

13. Data Retention

We retain personal data for as long as necessary to fulfil the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. Specific practices include:

When personal data is no longer required, we will delete or anonymize it.

14. Data Security

We implement administrative, technical, and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, and destruction. These measures include encryption of data in transit using HTTPS, token-based authentication, access controls, and secure storage of credentials. Access tokens are used only to perform the actions you have explicitly authorized.

No method of transmission or storage is completely secure. While we strive to protect your personal data, we cannot guarantee absolute security, and you provide information to us at your own risk. You are responsible for keeping your account credentials confidential.

15. Your Privacy Rights

Depending on your location, you may have some or all of the following rights regarding your personal data:

To exercise any of these rights, contact us using the details in Section 24. We will respond within the time period required by applicable law. We may need to verify your identity before fulfilling your request. You will not be charged for exercising your rights unless your request is manifestly unfounded or excessive.

16. EEA & UK Rights (GDPR)

If you are located in the European Economic Area or the United Kingdom, the rights described in Section 15 apply to you under the GDPR. In addition, you have the right to lodge a complaint with your local supervisory authority if you believe our processing of your personal data infringes applicable law. We would, however, appreciate the opportunity to address your concerns before you approach the supervisory authority, so we encourage you to contact us first.

17. California Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, provides you with specific rights regarding your personal information:

To exercise these rights, contact us using the details in Section 24. You may designate an authorized agent to make a request on your behalf, subject to verification.

18. Data Deletion

You can disconnect any connected social media account from within the Service at any time; upon disconnection, the associated access token is immediately deleted from our systems. To request deletion of your account and associated personal data, contact us at privacy@nanopost.xyz. We will process verified deletion requests within thirty (30) days, except where retention is required by law. Some residual data may remain in backups for a limited period before being overwritten.

19. Children's Privacy

The Service is intended for use by businesses and individuals who are at least eighteen (18) years old, or the age of majority in their jurisdiction. The Service is not directed to children, and we do not knowingly collect personal data from children. If you believe that a child has provided us with personal data, please contact us and we will take steps to delete such information.

20. Marketing Communications

We may send you marketing communications about the Service where permitted by law or where you have consented. You can opt out of marketing communications at any time by following the unsubscribe instructions included in those communications or by contacting us. Opting out of marketing communications will not affect transactional or service-related messages necessary to operate the Service.

21. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required by applicable law, affected individuals, without undue delay and in accordance with our legal obligations.

The Service may contain links to third-party websites, products, or services that are not operated by us. This Privacy Policy does not apply to those third parties, and we are not responsible for their content or privacy practices. We encourage you to review the privacy policies of any third-party services you access.

23. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will revise the "Last updated" date at the top of this page and, where appropriate, provide additional notice. Your continued use of the Service after the effective date of an updated Privacy Policy constitutes your acceptance of the changes.

24. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our processing of your personal data, please contact us:

Huseynbala Gurbanli (Operator of Nanopost)
Sole proprietor, Republic of Azerbaijan

Privacy enquiries and data requests:
privacy@nanopost.xyz
nanopost.xyz