Privacy Policy

Last updated: 8/4/2026

1. Information We Collect

1.1 OAuth Authentication Data

When you sign in with Google OAuth, we collect:

  • Email address (for account identification)
  • Full name (for personalization)
  • Profile picture (for user interface)
  • Google account ID (for secure authentication)

1.2 Application Usage Data

We collect information about your use of our service:

  • Generated Instagram posts and content
  • Credit usage and transaction history
  • Custom prompts and preferences
  • Device and browser information
  • IP address and location data

2. How We Use Your Information

  • Provide and maintain our AI-powered Instagram post generation service
  • Process payments and manage your credit balance
  • Authenticate your identity securely using OAuth 2.0
  • Improve our AI algorithms and service quality
  • Send you important service updates and notifications
  • Comply with legal obligations and prevent fraud

3. OAuth Security & Data Protection

3.1 Secure Authentication

We use OAuth 2.0 with PKCE (Proof Key for Code Exchange) for secure authentication:

  • We never store your Google password
  • Access tokens are encrypted and have short expiration times
  • We use secure, HttpOnly cookies for session management
  • All OAuth communications use HTTPS encryption

3.2 Data Storage & Security

Your data is protected with industry-standard security measures:

  • All data is encrypted in transit and at rest
  • We use secure MySQL databases with access controls
  • Regular security audits and vulnerability assessments
  • Limited access to personal data on a need-to-know basis

4. Information Sharing

We do not sell, trade, or rent your personal information to third parties. We may share your information only in these limited circumstances:

  • With your explicit consent
  • To comply with legal obligations or court orders
  • To protect our rights, property, or safety
  • With trusted service providers who assist in our operations (under strict confidentiality agreements)

5. Your Rights & Choices

5.1 Data Access & Control

You have the right to:

  • Access your personal data
  • Correct inaccurate information
  • Delete your account and associated data
  • Export your data in a portable format
  • Withdraw consent for data processing

5.2 OAuth Account Management

You can manage your OAuth permissions through:

  • Google Account settings (to revoke app access)
  • Our application settings (to disconnect accounts)
  • Contacting our support team for assistance

6. Cookies & Tracking

We use secure cookies for:

  • OAuth session management (HttpOnly, Secure)
  • CSRF protection (SameSite protection)
  • User preferences and settings
  • Analytics and service improvement (anonymized)

You can control cookie settings through your browser preferences.

7. Data Retention

We retain your personal information only as long as necessary:

  • Account data: Until you delete your account
  • Generated content: 2 years or until account deletion
  • Transaction records: 7 years (for tax and legal compliance)
  • OAuth tokens: Automatically expired and refreshed as needed

8. International Data Transfers

Your data may be processed in countries other than your own. We ensure appropriate safeguards are in place to protect your data in accordance with applicable privacy laws.

9. Children's Privacy

Our service is not intended for children under 13. We do not knowingly collect personal information from children under 13. If we become aware of such collection, we will take steps to delete the information.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date.

11. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

  • Email: privacy@instapost.eduwhistle.com
  • Website: https://instapost.eduwhistle.com
  • Address: [Your Business Address]

Note: This privacy policy complies with GDPR, CCPA, and other major privacy regulations. It specifically addresses OAuth 2.0 security best practices and data handling requirements.