PostPilot

Security

Last updated: June 2026

1. Our Commitment to Security

PostPilot.Help is operated by Smith Medical, P.C. We know you are trusting us with access to your social media accounts and the content you publish through them, and we take that responsibility seriously. This page explains, in plain language, the measures we use to help keep your data and connected accounts safe.

Security is an ongoing process rather than a one-time achievement. We continually review and improve our practices as the platform grows and as the broader threat landscape changes.

2. Data Encryption

We protect your information both while it travels to and from our servers and while it is stored:

  • In transit: All traffic between your browser or device and PostPilot.Help is encrypted using industry-standard TLS (the same technology behind the padlock in your browser).
  • At rest: Data stored in our backend, including connected-account credentials, is encrypted at rest by our infrastructure providers.

3. Authentication and Sign-In

Sign-in to PostPilot.Help is handled by Clerk, a dedicated authentication provider. This means your login is managed by a specialist service rather than by code we maintain ourselves.

You can sign in with email or with Google or Apple. When you use Google or Apple sign-in, we never see or store your password for those providers; they simply confirm your identity to us.

4. How We Handle Your Social Account Access

When you connect a social account such as YouTube, X, Instagram, Facebook, LinkedIn, TikTok, or Threads, you authorize us through that platform's official sign-in flow (OAuth) and the platform issues us a secure access token. For open platforms like Bluesky and Mastodon, you instead provide an app password or access token that you create yourself in that platform's settings. In both cases, that credential is what lets us act on your behalf.

  • Stored securely: Access tokens are stored in encrypted form in our backend and are not exposed in the app interface.
  • Used only for what you ask: Tokens are used solely to publish and schedule the posts you create, and to retrieve the account information needed to do so.
  • Least-privilege scopes: When connecting accounts, we request the narrowest set of permissions (OAuth scopes) we need to provide the features you use, and nothing more.
  • Revocable anytime: You can disconnect any social account from within PostPilot.Help at any time, which removes our stored access. You may also revoke access directly from the social platform's own security settings.

5. Infrastructure

PostPilot.Help runs on reputable cloud providers rather than self-managed servers, so it benefits from their physical security, redundancy, and operational practices:

  • Hosting: Our web application is hosted on Vercel.
  • Backend and database: Our application data and functions run on Convex.

6. Payment Security

Paid plans and one-time packs are processed by Stripe, a leading payment provider. PostPilot.Help never stores your full card number on our own systems. Your card details are sent directly to Stripe, which handles payment processing and is responsible for the secure handling of that information.

7. Monitoring and Patching

We monitor our application and infrastructure for unusual activity and apply security updates to our software and dependencies on an ongoing basis. When a relevant vulnerability is identified in a component we rely on, we work to patch it promptly.

8. Responsible Disclosure

We welcome reports from security researchers and users who believe they have found a vulnerability in PostPilot.Help. If you discover a potential security issue, please email us at smithappsupport@gmail.com with enough detail for us to reproduce and investigate it.

Please give us a reasonable opportunity to address the issue before disclosing it publicly, and avoid accessing or modifying other users' data while testing. We appreciate good-faith reports and will work with you on a resolution.

9. Your Responsibilities

Security is a shared effort. You can help keep your account safe by following these practices:

  • Use a strong, unique password for your account, and enable any additional login protections offered by Google or Apple if you sign in with them.
  • Protect app passwords and access tokens that you generate for platforms like Bluesky and Mastodon. Treat these like passwords, do not share them, and revoke them if you believe they have been exposed.
  • Keep your devices secure and sign out on shared or public computers.
  • Contact us right away if you notice suspicious activity on your account.

10. No Absolute Guarantee

While we work hard to protect your information using the measures described above, no online service can promise perfect security. We do not claim any specific certification or guarantee that our systems are immune to all risks. We commit to applying reasonable, industry-aligned safeguards and to improving them over time.

11. Governing Law and Contact

This Security overview is provided for transparency and is governed by, and read together with, the jurisdiction set out in our Terms of Service. Questions about our security practices can be sent to smithappsupport@gmail.com, which also serves as our designated contact for copyright matters.