TRUST & YOUR DATA

Where it lives. Who touches it.

Handing your brand's social accounts to software is a real decision, so here is the honest version: which company you are dealing with, which machines hold your photos, which AI reads them, and how fast you can pull the plug. No badges we haven't earned.

01

Where your data lives

Your photos and videos go to DigitalOcean Spaces in London — region lon1. They are not copied to a US bucket, and paid marketplace files are stored privately and served through short-lived signed links rather than left open to the internet.

The application and its PostgreSQL database run in DigitalOcean's London region too. To be precise about what we can actually show you: the London region is what our deployment configuration specifies for the app and its attached managed database.

Access tokens for your social accounts are encrypted before they are written to the database, using AES-256-GCM. The app refuses to store them in plain text in production.

02

Who processes it

One AI provider touches your content: OpenAI. Your caption text and the photo itself are sent to OpenAI to write the caption — the model looks at the image, which is how it can describe the actual job rather than invent one.

OpenAI is a US company, so this is a transfer outside the UK. We would rather say that plainly than bury it. Under OpenAI's business API terms, content sent through the API is not used to train their models. That is the commitment we rely on, and we are not going to claim anything stronger than it.

Where SitePost generates a brand graphic from scratch — not a photo you uploaded — that request may go to OpenAI or to Google's image model. Your own photos are never sent to Google.

Beyond AI: Stripe handles payments and card numbers never reach us, and Meta and LinkedIn receive the posts you have asked us to publish. Our full sub-processor list lives in the privacy policy.

03

Account access

We connect through the official Meta Business (Facebook Graph) and LinkedIn OAuth flows. You log in on their site, not ours. We never see, ask for, or store your Facebook, Instagram or LinkedIn password.

The permissions we request are scoped to the job: read your Pages and their engagement, publish posts, and read insights. We deliberately do not request Meta's business_management scope.

You can disconnect any channel in seconds from Settings → Accounts. That immediately deletes our copy of the access token, so we lose the ability to post. It does not reach into Meta or LinkedIn to revoke the grant on their side — if you want it gone everywhere, remove SitePost in your Meta Business or LinkedIn settings as well. Most tools quietly skip that second step; we would rather tell you about it.

04

What happens when you cancel

Posts we already published belong to you and stay exactly where they are, on your own channels. Cancelling SitePost does not delete your Instagram grid.

You cancel from your billing settings, through Stripe. There is no exit fee, no notice period, and no phone call to sit through. You keep paid features to the end of the period you have already paid for.

There is no one-click export button yet — see the gaps below. Until there is, email [email protected] and we will send you your queued posts, captions and media.

If you want everything erased rather than just switched off, use the data deletion page. We process within 30 days; billing records we are legally required to keep are held for the statutory period and then deleted on schedule.

WHAT WE HAVEN'T GOT

The gaps, said out loud.

Anyone can write a trust page listing what they do well. Here is the other column.

  • No self-serve data export. You have to ask us, and we do it by hand. It is on the list.
  • No ISO 27001 or SOC 2 certification. We are a small UK company and we have not been through those audits — if a supplier questionnaire needs one, we will fail it, and we would rather you found that out here than three weeks in.
  • Our AI provider is in the United States, not the UK. Covered above.
  • No contractual uptime guarantee unless we have signed a separate SLA with you.
05

Who we are

SitePost is a trading name of Skyla's Choice Ltd, a real registered company you can look up. There is a person on the other end of the email address below.

Skyla's Choice Ltd

Company no. 16059710 · Registered in England & Wales

Registered office: 9 Beverley Drive, Kimberley, Nottingham, England, NG16 2TW

Email: [email protected]

The detail behind all of this lives in our privacy policy, terms and data deletion instructions. If you think we have got something wrong on this page, tell us and we will correct it.