ButtonPost privacy policy
This policy describes what ButtonPost stores during the private beta, what stays on your device, and how account deletion works.
Last updated: October 8, 2026What ButtonPost stores
ButtonPost stores the minimum cloud data needed to operate accounts, platform connections, publishing authorization, billing, and abuse protection.
- Account identity from Supabase Auth, including your email address and basic profile metadata returned by your sign-in provider.
- Platform connection metadata such as platform name, connection status, external account id, and username.
- X OAuth user credentials and DEV API keys encrypted at rest before they are written to the database.
- Paddle customer/subscription identifiers, plan, subscription status, billing period end, and cancellation state. ButtonPost does not store your payment card number.
- Short-lived rate-limit records containing your ButtonPost user id, protected action scope, and timestamp.
Your posts and browser history
Draft text and ButtonPost publication history are local-first. The current private beta stores them in your browser rather than syncing the full post body into the ButtonPost database.
Content selected for X or DEV publishing is sent to the ButtonPost server only when you explicitly publish. ButtonPost processes that content to perform the requested publish action.
Local Runner data
Browser sessions for Local Runner destinations such as Xiaohongshu, Jike, and LearnBlockchain stay on your computer. ButtonPost does not upload those browser cookies to Supabase or Vercel.
Local Runner profiles live under ~/.buttonpost. Deleting your ButtonPost cloud account does not remove files from your own computer.
Uploaded media
Images uploaded for X or DEV cloud publishing are stored in Vercel Blob under an opaque, account-scoped namespace. New media URLs do not expose your Supabase user id.
During the private beta, ButtonPost does not apply an automatic media retention window. Account deletion removes cloud media that was uploaded after account-scoped media ownership was introduced. Older development/test blobs created before user ownership cannot be reliably attributed and are handled as legacy test data.
Services used by ButtonPost
- Supabase for authentication and account-scoped database storage.
- Vercel for application hosting and Blob media storage.
- Paddle for checkout, subscription billing, invoices, and the customer portal.
- X and DEV Community when you connect and publish to those services.
Those providers process information under their own policies when you use their services.
Account deletion
You can request permanent deletion from Settings → Account. ButtonPost first removes account-scoped cloud media, then cancels an active Paddle subscription, then deletes the Supabase Auth user. Database rows linked to that Auth user are deleted through foreign-key cascades, including profiles, subscription entitlement, runner device records, platform connections, and encrypted platform secrets.
The browser also clears ButtonPost localStorage after a successful deletion. Local Runner files on your computer remain under your control.
Security and support
ButtonPost uses authenticated sessions, row-level security, account-scoped encrypted credentials, short-lived media authorization, and rate limits. No internet service can guarantee absolute security.
For private-beta support, email support@buttonpost.app. Do not send passwords, API keys, payment card information, webhook secrets, or other sensitive credentials by email or in a public issue.