WordsPost ← wordspost.com

Privacy Policy

Last updated: August 31, 2026

WordsPost is an editorial automation service operated by Maksym Drovalov (sole proprietor, Kyiv, Ukraine), publishing under the WordsPost brand. It writes and schedules articles for client websites and announces new articles on the client's own social media accounts. This page explains what we do with the data Meta platforms (Facebook, Instagram, Threads) share with us when a client connects an account.

What we access

When a client (a website owner, or an agency acting on a website owner's behalf) connects a Facebook Page, Instagram professional account, or Threads account to WordsPost, Meta issues us an access token scoped to that account. Through it we can read:

We do not request access to a client's personal Facebook profile, friends list, private messages, or any data belonging to the account's followers.

What we do with it

The access token is used for exactly one purpose: publishing a short announcement post — a link and a short text — to the connected Page, Instagram account, or Threads account whenever the client publishes a new article. We also read basic engagement counters back so the client can see how an announcement performed inside our own reporting.

We do not use Platform Data to build advertising audiences, to profile individual people, to train machine-learning models, or for any purpose beyond operating the publishing service the client signed up for.

What we never do

Storage and security

Access tokens are stored encrypted at rest in our database. They are only decrypted, in memory, at the moment a post is published or a statistics reading is made, by our automated publishing service. Access to the database and to the decryption key is limited to the people operating WordsPost.

Retention and deletion

We keep an account's access token for as long as the client's connection stays active. A client can disconnect an account at any time — from their Meta Business settings (removing WordsPost's access there immediately invalidates the token on Meta's side), or by asking us directly. Once disconnected, we delete the stored token and stop making any further calls for that account. Published posts themselves remain on the client's own Page or account, exactly as any other post they've made — deleting the connection does not delete past posts.

Your rights

If you are a client, or represent one, and want to know exactly what we hold for your account, or want it deleted sooner than the automatic process above, write to us — we will confirm what's stored and delete it on request.

Changes to this policy

If how we handle Platform Data changes in a material way, we will update this page and change the date at the top.

Contact

Maksym Drovalov (WordsPost) — [email protected]