Privacy policy
Privacy policy
Last updated: 10 September 2026
1. Scope
Postkit is a locally run command-line tool that lets an operator use official social-platform APIs, including Meta's Marketing API. This policy describes information processed when Postkit is configured and used. It does not replace the privacy policies of Meta or any other platform the operator chooses to connect.
2. Information Postkit processes
Depending on the command an operator runs, Postkit may process:
- OAuth access tokens and refresh-related metadata;
- the authorized platform user's identifier and account identifiers;
- ad-account, campaign, ad-set, ad, creative, and performance data returned by Meta;
- content, targeting, media, and destination details supplied by the operator for an API request; and
- app configuration supplied by the operator, such as an OAuth client ID and redirect URI.
3. Where information is stored
Postkit is designed to store credentials and its local account metadata
on the operator's computer, in the operator-controlled .postkit
vault. Postkit does not operate a hosted Postkit account service or a
central database for those credentials.
4. Why information is used
Information is used solely to authenticate the operator, perform the command they requested, display the resulting platform response, and maintain the local credential state needed for later authorized use. For example, a Meta Ads token may be used to read insights or create a paused draft only when the operator asks Postkit to do so.
5. Sharing
Postkit sends information to the official platform API selected by the operator only as necessary to complete the requested action. It does not sell personal information or share it with advertising networks, data brokers, or unrelated third parties.
6. Retention and security
Locally stored credentials remain on the operator's computer until the operator deletes them, replaces them, or the platform revokes them. Operators are responsible for securing the computer and any backups that contain their local Postkit vault.
7. Your choices and deletion
An operator can remove a stored Meta Ads credential by running
postkit accounts delete meta_ads --yes. This removes the
local Postkit credential; it does not remove records held by Meta.
Meta-side content and ad-account records must be managed through Meta's
own tools and policies.
For privacy or deletion help, contact xkmxlfirdxus@gmail.com.
8. Changes
This policy may change when Postkit's data practices change. The latest version will be published at this URL with its updated date.