Privacy
Privacy policy
The short version: the pendpost software runs on your own machine and never phones home, and this website does not track you.
The pendpost software
pendpost is local-first. It runs on your own machine, binds to 127.0.0.1 by default, and does not phone home, so we receive nothing from your installation. Your platform API credentials live in your own .env file and are sent only to the social platforms you configure (Instagram, Facebook, LinkedIn, YouTube, X), never to us. We do not operate a server that your installation talks to.
Platform access and tokens (OAuth scopes)
pendpost connects to each platform through your own developer app, so you grant access to your own software, not to us. It requests only the scopes it needs to read the account you choose and publish on your behalf:
- Instagram and Facebook -
instagram_basic,instagram_content_publish,pages_show_list,pages_read_engagement,business_management: to see the Page and Instagram professional account you select and publish posts to them. - LinkedIn -
w_member_social,r_organization_social,w_organization_social,rw_organization_admin: to publish for the Company Page you administer. - YouTube -
youtube.force-ssl: to upload and manage videos on your channel. - X - read and write access (OAuth 1.0a, or the OAuth 2.0 scopes
tweet.read,tweet.write,users.read,media.write,offline.access): to post on your behalf.
On the self-hosted app the resulting tokens live in your own local .env file and are sent only to the platforms above. If you use the optional 24/7 cloud service from Nomadik GmbH, its tokens are held encrypted per tenant in a vault and used only to publish the posts you approve. You can revoke access at any time from each platform's connected-apps or developer settings, which invalidates the token immediately. See our security page for how the cloud service handles tokens and the approval gate.
This website (pendpost.com)
pendpost.com uses privacy-friendly, cookieless analytics (Vercel Web Analytics) to count aggregate page views and understand which pages are useful. It sets no cookies, builds no cross-site profile, and collects no personally identifying information. There is no consent banner because there is nothing to consent to.
The site is served by Vercel and its DNS is managed by Cloudflare. Like any web host, they process standard request logs (such as IP address and user agent) to deliver the site and guard against abuse. We do not combine those logs with anything else or use them to identify you.
The waitlist form
If you submit your email through the managed-offering waitlist form on the home page, we send it to ourselves (to hello@pendpost.com) so we can reach out about the managed offering. We use it only for that, we do not sell or share it, and you can ask us to delete it at any time by emailing hello@pendpost.com. The message is delivered by Resend, our email provider, acting on our behalf. The form itself sets no cookies and adds you to no automated marketing list.
Contact
Questions about privacy? Email hello@pendpost.com. pendpost is published by Nomadik GmbH (Switzerland).
Last updated: 28 June 2026.