This document is a working draft. Some sections are marked [REVIEW] pending legal/engineering confirmation before this policy is finalized.

Privacy Policy

Effective Date: [REVIEW: set on publish — not yet live] Last Updated: July 29, 2026 (DRAFT)

Omniprez LLC ("Omniprez," "we," "us," or "our") operates the social-poster mobile application (the "App"), available on the Apple App Store and Google Play, which lets you schedule and publish posts to your connected social media accounts (currently Instagram and TikTok) and view performance analytics for those posts. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have.

By creating an account or using the App, you agree to the collection and use of information as described in this Privacy Policy. If you do not agree, please do not use the App.


1. Who We Are

Omniprez LLC is an Arizona limited liability company (Arizona Corporation Commission entity ID 25086945).

Mailing address: Omniprez LLC 2145 E Gemini Pl Chandler, AZ 85249-2116 United States

Privacy contact: privacy@omniprez.net [REVIEW: confirm inbound mail routing is live for privacy@omniprez.net before publishing. As of this draft, our SES domain identity for omniprez.net (PD-11) provisions only two sending addresses — billing@omniprez.net and insights@omniprez.net — and neither is configured to receive mail. A contact address must actually be able to receive email before we publish it. omniprez.acts@gmail.com is the current operational inbox for the company while omniprez.net inbound is set up.]

For purposes of applicable data protection law, Omniprez LLC is the data controller of the personal information described in this Policy.


2. Information We Collect

2.1 Account and sign-in information

The App uses Google Sign-In as the only supported way to create an account and log in. When you sign in, we receive from Google: your email address, name, and profile picture. We generate our own internal account identifier for you and do not use your Google account ID as your primary identifier in our systems.

We do not currently support Apple Sign-In, email/password accounts, or any other login method. [REVIEW: confirm before publishing whether Apple Sign-In will exist by launch — Apple App Store guidelines generally require an equivalent alternative sign-in option, including Sign in with Apple, when a third-party login like Google Sign-In is offered.]

2.2 Connected social media account information

To schedule and publish posts on your behalf, you connect your Instagram and/or TikTok account(s) to the App through those platforms' own OAuth authorization screens (for Instagram, this flow is provided by Meta). When you connect an account, we receive and store, on our servers only: - The platform username and profile picture associated with the connected account - An access token issued by the platform, which we use to publish content and read analytics on your behalf

We never send your platform access tokens to your device. The App only ever displays whether an account is connected (connected: true/false), its username, and its profile picture — the token itself lives only on our backend.

[REVIEW: our backend also supports a distinct "Facebook Page" connection type (connection_id format facebook#{page_id}) alongside Instagram and TikTok. Confirm with engineering whether Facebook Page publishing is an active, user-facing v1 feature or purely plumbing that supports connecting an Instagram Business account (which requires a linked Facebook Page/Meta login under the hood). This Policy should list every platform a user can actually connect to, and currently states "Instagram and TikTok" per the brief — update if Facebook Pages is a real user-facing connection option.]

2.3 Content you upload

When you create a post, you upload photos or videos and write captions, and choose a scheduled publish time. This content is stored in a private cloud storage bucket (Amazon S3) that is not publicly accessible, solely for the purpose of delivering it to the platform(s) you're publishing to.

[REVIEW: our internal engineering documentation describes two different retention mechanics for uploaded media that need to be reconciled before we describe this publicly: (a) one document states media is deleted immediately after a scheduled post is successfully published, with a 35-day safety-net rule catching any orphaned/failed uploads; (b) a separate document describes a persistent, reusable "media library" where files are retained per subscription tier — Free: 1 day, Pro: 30 days, Max: 1 year — via S3 lifecycle tagging. Confirm with engineering which model reflects current/intended behavior (they may both be true for different features — e.g., in-flight scheduled posts vs. a saved media library — but this Policy should describe the real retention windows accurately, not a guess.]

2.4 Analytics data

We collect engagement metrics for your published posts (for example: reach, impressions, likes, and comments) directly from the connected platforms' APIs, for every subscription tier. What you can see and what we email you depends on your plan:

Plan In-app analytics Email reports
Free Headline reach per post only None
Pro Full 90-day trend view Weekly reach summary
Max Full 90-day trend view Weekly summary + monthly deep-dive

We retain historical analytics as a time series, with a retention window set once, at the time the data point is recorded, based on your plan at that moment. If you later downgrade, already-recorded history is not deleted early — it simply becomes unavailable to view until your plan level would have collected it, and every analytics view and report states "analytics available since [date]" so it's clear what window you're seeing.

2.5 Subscription and billing information

Subscriptions to Pro and Max plans are billed entirely by Apple (App Store) or Google (Google Play), depending on which store you downloaded the App from. We never receive, process, or store your payment card number or other payment instrument. We receive and store only: - The plan you are subscribed to and its expiration/renewal date - A store-issued transaction identifier (Apple's originalTransactionId or Google's purchaseToken) that lets us verify your subscription status with Apple's or Google's servers and match webhook notifications (renewals, cancellations, refunds, grace periods) back to your account

2.6 Feedback you submit

If you submit feedback (bug reports, feature requests, account issues, or other comments) through the App, we collect the text you write, the category you select, and any optional screenshots or video you attach (up to 5 files). Feedback is retained for 90 days.

[REVIEW: confirm the exact internal handling of feedback before publishing. We have not found automated code that files feedback into an external issue tracker as of this draft — if feedback is manually reviewed and may be recorded in our internal engineering tracker to plan product improvements, this Policy should say so in general terms without overstating automation that doesn't exist.]

2.7 Information we do not collect

We do not use third-party advertising networks, third-party analytics/tracking SDKs (e.g., Meta Pixel, Google Analytics for Firebase, Mixpanel, Amplitude), or any mechanism that shares your data for advertising purposes. We verified this against the App's actual dependencies as of this draft; [REVIEW: re-verify at each release before repeating this claim, since adding such an SDK later would make this statement false.]


3. How We Use Your Information

We use the information described above to: - Create and maintain your account - Publish and schedule content to your connected social media accounts, at the times you choose - Show you analytics about how your posts are performing, and email you periodic reports if you're eligible and haven't opted out - Verify and manage your subscription with Apple/Google, and send you transactional emails about your subscription (upgrade confirmations, payment failures, grace periods, expiration/downgrade notices) from billing@omniprez.net - Send you analytics report emails, if applicable to your plan, from insights@omniprez.net - Respond to feedback and support requests - Maintain the security of the App and investigate abuse or fraud - Comply with legal obligations

We do not sell your personal information, and we do not use it to serve you third-party advertising.


4. How We Share Your Information

We share information only as necessary to operate the App:

We do not otherwise share, rent, or sell your personal information to third parties.


5. Data Retention

Data category Retention
Account/profile info Until account deletion
Post records (captions, schedule, results) Retained indefinitely — there is currently no automatic deletion; [REVIEW: confirm this is the intended long-term policy, or whether a retention limit should be added]
Uploaded media (S3) See § 2.3 — [REVIEW: reconcile conflicting retention documentation before publishing]
Analytics time series Free: up to 7 days; Pro/Max: up to 90 days, TTL fixed at time of recording per § 2.4
Feedback + attachments 90 days
Subscription/billing records Retained for the life of the account plus a period required for financial/legal record-keeping [REVIEW: confirm exact post-cancellation retention period]

6. Your Choices and Rights


7. Children's Privacy

The App is not directed to children under 13, and we do not knowingly collect personal information from children under 13. [REVIEW: the App currently has no technical age-gating step at sign-up beyond whatever Google's own Sign-In flow enforces. Confirm with counsel whether a COPPA-compliant age-affirmation step is needed before this statement can be made without qualification, and whether TikTok's/Instagram's own minimum-age policies create any additional obligation for us as a scheduling tool built on top of their APIs.] If we learn that we have collected personal information from a child under 13, we will delete it promptly. Parents who believe their child has provided us with personal information should contact privacy@omniprez.net.


8. Data Security

We use industry-standard safeguards to protect your information, including: - Encrypted storage of platform access tokens (never exposed to the mobile app) - Private, non-public cloud storage for uploaded media, accessed only via short-lived signed URLs - Google-verified authentication (we independently verify Google idTokens against Google's public keys; we never trust unverified claims) - Row-level data isolation, so one account cannot read or write another account's data

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. [REVIEW: our internal security documentation (social-poster-backend/docs/security.md) also lists known, not-yet-mitigated gaps — no rate limiting on our public API entry point, no brute-force protection on login, and no web application firewall. These are operational security matters for engineering to close, not typically disclosed at this level of detail in a public privacy policy, but flagging here so legal/leadership is aware of the actual current security posture behind the general assurance above.]


9. International Users

The App is operated from and hosted in the United States. If you use the App from outside the United States, your information will be transferred to, stored, and processed in the United States, which may have different data protection laws than your country. [REVIEW: pair with § 6 GDPR paragraph — the same open question about EU/international user volume applies here.]


10. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version in the App and update the "Last Updated" date above. Material changes will be notified through the App or by email where required by law.


11. Contact Us

Omniprez LLC 2145 E Gemini Pl, Chandler, AZ 85249-2116, United States privacy@omniprez.net [REVIEW: see § 1 — confirm this inbox is live before publishing]


This document is a working DRAFT prepared for internal legal review and is not yet published or in effect. Every [REVIEW] marker above must be resolved — and the marker text itself removed — before this Policy is finalized, hosted at a public URL, and referenced from the App Store / Google Play listings or the App's sign-up flow.