Privacy Policy
How PostPing handles Discord, configuration, monitoring, and service data.
Last updated: 14 July 2026
1. Scope
This Privacy Policy explains how this PostPing installation handles data when you visit the website, sign in with Discord, manage follows, or operate local monitoring.
2. Discord OAuth data
PostPing requests the Discord OAuth scopes identify and guilds. It receives your Discord user ID, username, display name, avatar, and server list. The server list is filtered so the dashboard shows only servers you can manage. PostPing never receives your Discord password.
3. Bot and server data
PostPing stores the IDs and names needed to operate follows, including Discord server IDs, channel IDs, followed usernames, platform type, delivery cursor, language preference, timestamps, error status, and notification history.
4. Local browser data
When X, Instagram, or TikTok local monitoring is used, session cookies and browser storage are kept inside the data/browser-profile directory on the host machine. These sessions may contain sensitive account access. They are not intended to be sent to dashboard users or third parties.
5. Configuration and credentials
Bot tokens, Discord OAuth secrets, YouTube API keys, session secrets, domain settings, and monitoring preferences are stored in config.json on the host machine. They must be protected by the server operator.
6. Logs and technical data
PostPing may keep in-memory logs and local database records containing timestamps, platform names, account handles, success or error messages, delivery counts, and runtime diagnostics. Server access logs may also be created by the operating system, proxy, firewall, or hosting provider.
7. Cookies
The dashboard uses essential cookies for Discord OAuth state verification and authenticated sessions. These cookies are required for login security and dashboard operation. PostPing does not include advertising or cross-site tracking cookies.
8. How data is used
Data is used to authenticate dashboard users, verify server-management permissions, monitor configured accounts, prevent duplicate notifications, deliver Discord messages, diagnose failures, protect the service, and display system status.
9. Sharing
PostPing does not sell personal data. Data is shared only as needed with services you choose to use, such as Discord OAuth, Discord message delivery, YouTube API requests, and social platforms accessed by the local browser. Hosting and network providers may process traffic as part of normal infrastructure operation.
10. Retention
Dashboard sessions expire according to config.json. Notification history may be pruned automatically. Follow records, browser sessions, configuration, and the SQLite database remain on the host machine until the operator removes them.
11. Security
PostPing uses OAuth state checks, HTTP-only cookies, CSRF checks, permission validation, local persistent storage, and restricted dashboard actions. No system is perfectly secure. The operator must keep the machine, domain, TLS certificate, Discord credentials, config.json, and data directory protected.
12. Your choices
You can log out, remove follows, remove PostPing from a Discord server, revoke the application in Discord settings, clear platform browser sessions, or ask the installation operator to delete locally stored information associated with your use.
13. Children
PostPing is not intended to knowingly collect personal information from children below the minimum age required by Discord or applicable law.
14. Changes
This policy may be updated when the service, integrations, or legal requirements change. The revision date is shown at the top of the page.
