PostSir
Sign in
How PostSir handles your account, the social accounts you connect to it, and the posts you publish through it.
Last updated 4 September 2026
PostSir is operated by WDS Creative PTY LTD, a company registered in South Africa. We are the responsible party for the personal information described here, as that term is used in the Protection of Personal Information Act (POPIA).
For anything in this policy, including access and deletion requests, contact the Information Officer at support@wdscreative.biz.
PostSir publishes posts to social accounts you connect to it. You write a post once, choose which accounts it goes to, and PostSir sends it to each platform on your behalf. It can also schedule posts for later.
It is a tool you operate. It does not post anything you have not asked it to post.
Only what is needed to do the above. There is no advertising, no profiling, and no analytics of any kind.
| What | Why we hold it |
|---|---|
| Your email address and password | To sign you in. The password is stored only as a hash, never as text we can read. |
| Access and refresh tokens for each connected account | To publish on your behalf without asking you to sign in to each platform every time. Encrypted at rest. |
| The account, page or channel identifier, its display name and profile picture | So you can tell your accounts apart when choosing where a post goes. |
| The permissions you granted | To know what PostSir is allowed to do, and to warn you when a permission is missing. |
| Post text, images and video you upload, and the times you schedule | This is the content you asked us to publish. |
| The result of each publish | The platform's post identifier, whether it succeeded, and the error if it did not, so you can see what happened. |
| Engagement figures, where a platform provides them | To show how a post performed. |
If you connect a YouTube channel, PostSir uses YouTube API Services to do it. Everything in this section is about that.
| Permission requested | What it is used for |
|---|---|
youtube.upload | Uploading the video you composed, to the channel you chose, with the title, description and privacy setting you entered. |
youtube.readonly | Two things. Reading the list of channels your Google account manages, so PostSir can show you which channel a post will go to. And reading the view and like counts of videos PostSir itself uploaded, for up to 30 days after upload, so you can see how a post did. |
| Data | Why | How long |
|---|---|---|
| Channel id, channel name and channel picture | To show you which channel is connected and which one a post will go to. | Until you disconnect the channel or revoke access, then erased. |
| Access and refresh tokens | To publish on your behalf without asking you to sign in every time. Stored encrypted. | Until you disconnect the channel or revoke access, then erased. |
| The id of each video PostSir uploaded | So your posting history can link to the video it created. | Until you delete that post or close your account. |
| View and like counts for those videos | To show you how a post performed. | Refreshed once a day for 30 days after the video is published, then deleted. |
PostSir's use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements.
We do not sell Google user data. We do not use it for advertising. We do not use it to train models. We do not transfer it to anyone except the platform it is being published to, and only to carry out an action you asked for.
By using PostSir with a YouTube channel you also agree to the YouTube Terms of Service. Google's own handling of your information is covered by the Google Privacy Policy.
You can withdraw PostSir's access to your Google account at any time at myaccount.google.com/permissions. Access stops immediately when you do. You can also ask us to delete everything we hold, using the contact address at the top of this policy.
The same applies to every other platform PostSir supports, including Facebook, Instagram, LinkedIn, TikTok, Threads and Bluesky. In each case we hold a token to publish on your behalf, the account name and identifier, and the results of what we published. Each platform has its own privacy policy covering what it does with the post once it arrives.
Three ways, depending on how much you want removed.
Posts already published stay on the platform they were published to. Deleting your PostSir data does not remove them, because we no longer control them. Delete those on the platform itself.
No system is perfect, and we do not claim otherwise. If information is ever compromised in a way that affects you, we will tell you and report it to the Information Regulator as POPIA requires.
On a server we control, hosted in South Africa. Content is sent to the social platforms you choose, which operate their own infrastructure internationally. That transfer is the purpose of the product.
Under POPIA you may ask us to show you what we hold about you, correct it, or delete it. You may object to how we use it. You may complain to the Information Regulator of South Africa at inforegulator.org.za.
Ask us first at support@wdscreative.biz and we will deal with it.
PostSir is a business tool and is not intended for anyone under 18.
If this policy changes in a way that affects what we do with your information, we will update the date at the top and tell account holders by email before it takes effect.