Privacy Policy
Last updated
Bulkit provides a unified API that lets developers publish, schedule, and analyze content across social networks. Running that service means handling two very different kinds of data: information about you, our customer, and information belonging to the social accounts you connect.
This policy explains what we collect, why we collect it, who we share it with, how long we keep it, and the controls you have. It covers bulkit.io, our documentation, our API, our dashboard, and our MCP server.
1. Who we are
Bulkit (“Bulkit”, “we”, “us”) operates the Bulkit API and the websites at bulkit.io and docs.bulkit.io. For the personal data described in this policy, we act as the data controller — except where we process content and social account data on your behalf, where we act as your processor and you remain the controller.
If you are an end user of a product built on Bulkit rather than a Bulkit customer, the developer operating that product is the controller of your data. Contact them first; we will help them respond to your request.
2. What we collect
We collect only what the service needs to function, plus what we need to bill you and keep the platform secure. We do not buy personal data from data brokers.
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email address, password hash, organization name, team member roles | You, at signup |
| Connected account data | Social platform user IDs, handles, profile names and avatars, OAuth access and refresh tokens, granted scopes | The social platform, when you authorize a connection |
| Content data | Post text, media you upload for publishing, scheduling times, captions, comments and replies you send through the API | You or your application |
| Analytics data | Engagement metrics returned by platform APIs — impressions, likes, comments, reach, follower counts | The social platform |
| Usage and log data | API request metadata, endpoints called, response codes, timestamps, IP address, user agent, API key identifier, audit log entries (including MCP tool calls) | Automatically, as you use the service |
| Billing data | Plan, action counts, invoices, billing email and address, and the last four digits and brand of your card | You and our payment processor |
| Support data | Messages you send us and their attachments | You |
We never receive or store your social platform passwords. Connections are made over OAuth, and we hold only the tokens the platform issues.
3. How we use it
- Providing the service — authenticating you, publishing and scheduling your posts, returning analytics, and running the MCP server tools you invoke.
- Billing — metering actions against your plan, issuing invoices, and preventing payment fraud.
- Security and abuse prevention — rate limiting, detecting credential compromise, investigating misuse, and maintaining the audit log.
- Reliability — diagnosing errors, monitoring uptime, and debugging failed platform calls.
- Support — answering your questions and, with your permission, inspecting your account to reproduce a problem.
- Service communications — transactional email about incidents, breaking API changes, quota limits, and billing.
- Product improvement — aggregated, de-identified usage statistics (for example, which endpoints are most called). This never involves reading your post content.
We do not sell personal data, we do not share it for cross-context behavioral advertising, and we do not use your content or your connected accounts' data to train machine learning models.
4. Legal bases (EEA and UK)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under the GDPR:
- Performance of a contract — to deliver the service you signed up for, including account, connection, content, and billing data.
- Legitimate interests — to keep the platform secure, prevent abuse, debug failures, and improve the product, balanced against your rights.
- Legal obligation — to retain financial records and to respond to lawful requests.
- Consent — for optional marketing email and any non-essential cookies. You can withdraw consent at any time without affecting the service.
7. How long we keep it
| Data | Retention |
|---|---|
| Account data | For the life of your account, then deleted within 30 days of account closure |
| OAuth tokens | Until you disconnect the account, the token is revoked, or the account is closed |
| Post content and scheduled posts | For the life of your account; uploaded media is deleted from our storage after publishing completes and any platform retry window closes |
| Audit and API logs | Up to 12 months, then deleted or aggregated into non-identifying counts |
| Error and diagnostic logs | Up to 90 days |
| Billing and tax records | As long as applicable financial law requires, typically 7 years |
| Backups | Deleted data persists in encrypted backups for a short rolling window before being overwritten |
8. Security
- All traffic to our API and dashboard is encrypted in transit with TLS; data is encrypted at rest.
- OAuth tokens and API key secrets are stored encrypted, and API keys are shown in full only once, at creation.
- Access to production systems is limited to staff who need it, protected by multi-factor authentication, and logged.
- Every action taken on your account — including calls made by AI agents through the MCP server — is recorded in your audit log.
- Rate limits protect your connected accounts from runaway automation.
No system is perfectly secure. Scope your API keys to the least privilege that works, rotate them periodically, and store them as secrets rather than in source control. If we become aware of a breach affecting your personal data, we will notify you and the relevant regulators as required by law.
9. International transfers
Bulkit and its subprocessors operate globally, so your data may be processed in countries other than your own, including the United States. Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where applicable) together with supplementary technical measures such as encryption in transit and at rest.
10. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you and receive a copy.
- Correct data that is inaccurate or incomplete.
- Delete your data, subject to records we must keep by law.
- Export your data in a portable, machine-readable format.
- Object to or restrict processing based on our legitimate interests.
- Withdraw consent for marketing email or optional cookies at any time.
- Not be discriminated against for exercising any of these rights.
Much of this is self-service: you can edit your profile, disconnect social accounts, rotate or revoke API keys, export data, and delete your account from the dashboard. For anything else, email privacy@bulkit.io and we will respond within 30 days.
California residents: we do not sell personal information or share it for cross-context behavioral advertising, so there is no opt-out to offer. You may still exercise the access, deletion, correction, and non-discrimination rights above, and you may use an authorized agent. EEA and UK residents may also lodge a complaint with their local supervisory authority.
12. Children
Bulkit is a developer tool intended for businesses and adults. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
13. Changes to this policy
We update this policy when our practices change. The date at the top always reflects the current version. For material changes — new categories of data, new purposes, or new disclosures — we will notify account holders by email or in the dashboard before the change takes effect. Continuing to use Bulkit after that date means you accept the updated policy.
Contact us
Questions about this policy, a data request, or a security concern? Email us and a person will read it. For formal data protection matters, write to the same address with “GDPR” or “CCPA” in the subject line.
privacy@bulkit.io
5. Social platform data
When you connect an account from X, Instagram, TikTok, YouTube, LinkedIn, Facebook, Threads, Pinterest, or Bluesky, you authorize Bulkit to act on that account within the scopes you grant. We use that access only to carry out the actions you or your application request.
Data you pull from a platform through Bulkit remains subject to that platform's rules on retention and redistribution. You are responsible for using it accordingly in your own product.