VERIFIED & TRANSPARENT

Privacy Policy

Effective Date: September 4, 2026 • Last Reviewed: September 4, 2026

At a Glance: How Honkpost Treats Your Data

Honkpost is a social media queue management and autonomous scheduling tool operated by Axel Wisniewski (individual operator, Miami, Florida, United States). We believe in complete architectural transparency:

Zero Data Selling

We never sell, rent, or monetize your posts, account details, or audience metrics.

Zero Ad Tracking

No third-party advertising pixels (no Meta Pixel, no TikTok Pixel, no remarketing tags).

AES-256-GCM Encryption

Connected platform OAuth tokens are encrypted at rest with authenticated AES-256-GCM.

Google Gemini AI Disclosure

Post drafts and instructions are shared with Google Gemini solely when you invoke AI generation.

1. Service Operator & Contact Details

This Service (honkpost.com) is operated by Axel Wisniewski as an individual creator and developer, located in Miami, Florida, United States. Honkpost is not currently incorporated as a separate corporate entity.

Operator: Axel Wisniewski (Individual)
Location: Miami, Florida, United States
Official Website: https://honkpost.com

2. Information We Collect & How It Is Used

We collect only information essential to authenticating your account, scheduling your posts, and dispatching content to your connected social channels:

  • Account Registration Data: When you sign up, we collect your email address and password. Passwords are cryptographically hashed using the scrypt key derivation function with unique per-user salts. Plaintext passwords are never recorded, logged, or stored.
  • OAuth Tokens & Connected Channels: When you connect an account (such as 𝕏/Twitter or Bluesky), we receive authorization tokens and your public profile handle/identifier. All sensitive OAuth access tokens and refresh tokens are encrypted at rest with authenticated AES-256-GCM.
  • Post Content & Schedule Parameters: Post draft copy, scheduling times, selected platforms, hashtags, and auto-reply plug links that you submit directly or via autonomous agents.
  • Uploaded Media Files: Images and media assets you upload to attach to scheduled posts. Media is stored in secure cloud object storage (Vercel Blob) and accessed exclusively to dispatch posts.
  • API Keys & Agent Audit Logs: When you generate API keys for Model Context Protocol (MCP) clients (such as Claude Desktop or Cursor), the secret key is hashed with SHA-256 at rest. We record an audit log (timestamp, key prefix, and tool name) for security traceability.

3. Third-Party Subprocessors Genuinely in Use

Honkpost relies on select infrastructure providers to securely host, store, and execute scheduling operations. We do not maintain unvetted sub-processors:

Neon (Neon Inc.)Database

Provides managed, serverless PostgreSQL hosting with automated failover and encryption at rest. Stores encrypted credentials, post queue records, and account mappings.

Vercel (Vercel Inc.)Hosting & Media Storage

Hosts our Next.js application at the network edge and provides Vercel Blob cloud storage for user-uploaded post media.

Google Gemini (Google LLC)AI Language Processing

Powers AI post drafting, viral hook synthesis, and autonomous scheduling reasoning. When you request AI drafting or chat with the agent copilot, your prompt instructions and draft copy are sent to Google Gemini (gemini-3.6-flash). Google does not use API inputs to train foundation models per their developer API terms.

Replicate (Replicate Inc.)Media Generation

Used only by locally-run media generation tooling. Media generation is disabled on the hosted service at honkpost.com, so no data from your account is sent to Replicate when you use the website.

cron-job.orgCron Dispatcher

Triggers our periodic serverless endpoint (/api/cron/publish-due) to atomically dispatch scheduled posts at their appointed time. No personal user data is sent to the cron dispatcher.

4. Commitments: What We Do NOT Do

We hold a strict zero-surveillance philosophy:

  • No selling or trading: We never sell, broker, or rent your personal information, email address, or content to third parties.
  • No advertising networks: We do not run Google AdSense, Meta audience networks, or behavioral tracking displays.
  • No cross-site tracking pixels: We do not install third-party tracking cookies or social network pixels.
  • No unauthorized publishing: Honkpost will never publish posts to your social media accounts without your explicit command or pre-configured schedule.

5. Your Rights: Data Control, Export & Deletion

You maintain complete dominion over your data and credentials at all times:

Disconnect Channel

Click "Disconnect" in Settings → Social Channels to immediately wipe that network's encrypted OAuth token.

Revoke API Keys

Click "Revoke" in Settings → Developers to instantly invalidate any agent or MCP bearer token.

Full Account Deletion

Email axel.wisniewski2025@gmail.com to permanently purge all account records and media.

Upon receipt of an account deletion request, your user account, scheduling history, encrypted OAuth tokens, and uploaded media files will be permanently purged from PostgreSQL and Vercel Blob within thirty (30) business days.

6. Security Safeguards

We implement administrative, technical, and physical safeguards designed to protect personal information, including transport layer security (TLS 1.3 encryption for all HTTP traffic), AES-256-GCM token encryption at rest, atomic database transactions with row-level locks, and strict per-user tenant isolation on every database query and MCP server execution.

7. Governing Law & Policy Updates

This Privacy Policy is governed by and construed under the laws of the State of Florida, United States. If we make material modifications to our data practices, we will update the "Effective Date" at the top of this page. Continued use of Honkpost after changes are posted constitutes acknowledgment of the updated terms.

Questions about our privacy practices?
Reach Axel Wisniewski directly via email.
axel.wisniewski2025@gmail.com