Privacy
Privacy policy
The short version: the pendpost software runs on your own machine and never phones home, and this website does not track you.
The pendpost software
pendpost is local-first. It runs on your own machine, binds to 127.0.0.1 by default, and does not phone home, so we receive nothing from your installation. Your platform API credentials live in your own .env file and are sent only to the social platforms you configure (Instagram, Facebook, LinkedIn, YouTube, X, Telegram, Discord, Mastodon, Nostr, WordPress, Ghost), never to us. We do not operate a server that your installation talks to.
Platform access and tokens (OAuth scopes)
pendpost connects to each platform through your own developer app, so you grant access to your own software, not to us. It requests only the scopes it needs to read the account you choose and publish on your behalf:
- Instagram and Facebook -
instagram_basic,instagram_content_publish,pages_show_list,pages_read_engagement,business_management: to see the Page and Instagram professional account you select and publish posts to them. - LinkedIn -
w_member_social,r_organization_social,w_organization_social,rw_organization_admin: to publish for the Company Page you administer. - YouTube -
youtube.force-ssl: to upload and manage videos on your channel. - X - read and write access (OAuth 1.0a, or the OAuth 2.0 scopes
tweet.read,tweet.write,users.read,media.write,offline.access): to post on your behalf.
On the self-hosted app the resulting tokens live in your own local .env file and are sent only to the platforms above. If you use the optional 24/7 cloud service from Nomadik GmbH, its tokens are held encrypted per tenant in a vault and used only to publish the posts you approve. You can revoke access at any time from each platform's connected-apps or developer settings, which invalidates the token immediately. See our security page for how the cloud service handles tokens and the approval gate.
Your AI agent and the sources you read
pendpost exposes its tools to the MCP client you connect, such as Claude Desktop, Claude Code or Cursor. Whatever your agent reads through those tools (drafts, plans, comments, insights) goes to that client and its AI model provider under your own account and their privacy terms. Radar's agent scans run on the same agent you configured, and Radar reads public posts from sources you turn on, such as Reddit, Hacker News, Bluesky and Mastodon. None of this passes through Nomadik GmbH.
Data retention
The software keeps its data in its own folder on your machine: plans, drafts, media, activity history, and the .env file with your credentials. It stays there until you delete it, and deleting that folder removes it completely. We hold no copy, so there is nothing for us to retain.
If you use the optional cloud service, it keeps your plans, encrypted tokens and audit records while your subscription runs. After you leave, we keep a short safety window and then permanently delete any managed copy of your data, as described in ourterms.
This website (pendpost.com)
pendpost.com uses privacy-friendly, cookieless analytics (Vercel Web Analytics) to count aggregate page views and understand which pages are useful. It sets no cookies, builds no cross-site profile, and collects no personally identifying information. The only thing that can set a cookie is the optional Google button on our blog pages, and only if you choose to turn it on, as described below.
The site is served by Vercel and its DNS is managed by Cloudflare. Like any web host, they process standard request logs (such as IP address and user agent) to deliver the site and guard against abuse. We do not combine those logs with anything else or use them to identify you.
Google preferred-source button (blog pages only)
Our blog pages offer an optional Google "preferred sources" button that lets you add pendpost as a preferred source in Google Search. It is off by default: no Google code loads when you open a blog page. Only if you click to turn it on do those pages load a script from Google (news.google.com), and only then can Google process your request data and set its own cookies underGoogle's privacy policy; we receive nothing from it and do not control that data. Your choice is remembered in your browser's local storage (a single first-party flag, pendpost-preferred-source); clearing your site data turns it off again. This is why the site still needs no consent banner: nothing loads or is stored until you opt in.
Contact
Questions about privacy? Email hello@pendpost.com. pendpost is published by Nomadik GmbH (Switzerland).
Last updated: 23 September 2026.