
Last updated: June 2026
PostPilot.Help is operated by Smith Medical, P.C. We know you are trusting us with access to your social media accounts and the content you publish through them, and we take that responsibility seriously. This page explains, in plain language, the measures we use to help keep your data and connected accounts safe.
Security is an ongoing process rather than a one-time achievement. We continually review and improve our practices as the platform grows and as the broader threat landscape changes.
We protect your information both while it travels to and from our servers and while it is stored:
Sign-in to PostPilot.Help is handled by Clerk, a dedicated authentication provider. This means your login is managed by a specialist service rather than by code we maintain ourselves.
You can sign in with email or with Google or Apple. When you use Google or Apple sign-in, we never see or store your password for those providers; they simply confirm your identity to us.
When you connect a social account such as YouTube, X, Instagram, Facebook, LinkedIn, TikTok, or Threads, you authorize us through that platform's official sign-in flow (OAuth) and the platform issues us a secure access token. For open platforms like Bluesky and Mastodon, you instead provide an app password or access token that you create yourself in that platform's settings. In both cases, that credential is what lets us act on your behalf.
PostPilot.Help runs on reputable cloud providers rather than self-managed servers, so it benefits from their physical security, redundancy, and operational practices:
Paid plans and one-time packs are processed by Stripe, a leading payment provider. PostPilot.Help never stores your full card number on our own systems. Your card details are sent directly to Stripe, which handles payment processing and is responsible for the secure handling of that information.
We monitor our application and infrastructure for unusual activity and apply security updates to our software and dependencies on an ongoing basis. When a relevant vulnerability is identified in a component we rely on, we work to patch it promptly.
We welcome reports from security researchers and users who believe they have found a vulnerability in PostPilot.Help. If you discover a potential security issue, please email us at smithappsupport@gmail.com with enough detail for us to reproduce and investigate it.
Please give us a reasonable opportunity to address the issue before disclosing it publicly, and avoid accessing or modifying other users' data while testing. We appreciate good-faith reports and will work with you on a resolution.
Security is a shared effort. You can help keep your account safe by following these practices:
While we work hard to protect your information using the measures described above, no online service can promise perfect security. We do not claim any specific certification or guarantee that our systems are immune to all risks. We commit to applying reasonable, industry-aligned safeguards and to improving them over time.
This Security overview is provided for transparency and is governed by, and read together with, the jurisdiction set out in our Terms of Service. Questions about our security practices can be sent to smithappsupport@gmail.com, which also serves as our designated contact for copyright matters.