Legal

Privacy Policy

Last updated

Bulkit provides a unified API that lets developers publish, schedule, and analyze content across social networks. Running that service means handling two very different kinds of data: information about you, our customer, and information belonging to the social accounts you connect.

This policy explains what we collect, why we collect it, who we share it with, how long we keep it, and the controls you have. It covers bulkit.io, our documentation, our API, our dashboard, and our MCP server.

1. Who we are

Bulkit (“Bulkit”, “we”, “us”) operates the Bulkit API and the websites at bulkit.io and docs.bulkit.io. For the personal data described in this policy, we act as the data controller — except where we process content and social account data on your behalf, where we act as your processor and you remain the controller.

If you are an end user of a product built on Bulkit rather than a Bulkit customer, the developer operating that product is the controller of your data. Contact them first; we will help them respond to your request.

2. What we collect

We collect only what the service needs to function, plus what we need to bill you and keep the platform secure. We do not buy personal data from data brokers.

CategoryExamplesSource
Account dataName, email address, password hash, organization name, team member rolesYou, at signup
Connected account dataSocial platform user IDs, handles, profile names and avatars, OAuth access and refresh tokens, granted scopesThe social platform, when you authorize a connection
Content dataPost text, media you upload for publishing, scheduling times, captions, comments and replies you send through the APIYou or your application
Analytics dataEngagement metrics returned by platform APIs — impressions, likes, comments, reach, follower countsThe social platform
Usage and log dataAPI request metadata, endpoints called, response codes, timestamps, IP address, user agent, API key identifier, audit log entries (including MCP tool calls)Automatically, as you use the service
Billing dataPlan, action counts, invoices, billing email and address, and the last four digits and brand of your cardYou and our payment processor
Support dataMessages you send us and their attachmentsYou

We never receive or store your social platform passwords. Connections are made over OAuth, and we hold only the tokens the platform issues.

3. How we use it

  • Providing the service — authenticating you, publishing and scheduling your posts, returning analytics, and running the MCP server tools you invoke.
  • Billing — metering actions against your plan, issuing invoices, and preventing payment fraud.
  • Security and abuse prevention — rate limiting, detecting credential compromise, investigating misuse, and maintaining the audit log.
  • Reliability — diagnosing errors, monitoring uptime, and debugging failed platform calls.
  • Support — answering your questions and, with your permission, inspecting your account to reproduce a problem.
  • Service communications — transactional email about incidents, breaking API changes, quota limits, and billing.
  • Product improvement — aggregated, de-identified usage statistics (for example, which endpoints are most called). This never involves reading your post content.

We do not sell personal data, we do not share it for cross-context behavioral advertising, and we do not use your content or your connected accounts' data to train machine learning models.

5. Social platform data

When you connect an account from X, Instagram, TikTok, YouTube, LinkedIn, Facebook, Threads, Pinterest, or Bluesky, you authorize Bulkit to act on that account within the scopes you grant. We use that access only to carry out the actions you or your application request.

  • We request the narrowest scopes that support the features you use.
  • OAuth tokens are encrypted at rest and are never exposed through our API or returned in responses.
  • Platform data is used to operate your integration — not to build cross-customer datasets, profiles, or advertising audiences.
  • Disconnecting an account revokes our stored tokens and stops all further access. Where the platform supports it, we also revoke the token on their side.
  • Our use of platform data is additionally governed by each platform's developer terms and policies, which take precedence where they are stricter than this policy.

Data you pull from a platform through Bulkit remains subject to that platform's rules on retention and redistribution. You are responsible for using it accordingly in your own product.

6. Who we share it with

We share personal data only in these circumstances:

  • Social platforms — we transmit your content and requests to the networks you have connected, which is the point of the service.
  • Subprocessors — vendors that run parts of our infrastructure on our instructions and under contract: cloud hosting and storage, our payment processor, transactional email delivery, error monitoring, product analytics, and customer support tooling. Each is bound to confidentiality and to processing data only for us.
  • Your own organization — team members you invite can see the account, connections, and audit log according to their role.
  • Legal and safety — where we are legally required to disclose, or where disclosure is necessary to investigate fraud, abuse, or a threat to someone's safety. We will notify you unless legally prohibited.
  • Corporate transactions — if Bulkit is involved in a merger, acquisition, or asset sale, data may transfer to the successor under this same policy, and we will give you notice before it becomes subject to a different one.

A current list of subprocessors is available on request at privacy@bulkit.io, and business customers can request a data processing agreement covering these transfers.

7. How long we keep it

DataRetention
Account dataFor the life of your account, then deleted within 30 days of account closure
OAuth tokensUntil you disconnect the account, the token is revoked, or the account is closed
Post content and scheduled postsFor the life of your account; uploaded media is deleted from our storage after publishing completes and any platform retry window closes
Audit and API logsUp to 12 months, then deleted or aggregated into non-identifying counts
Error and diagnostic logsUp to 90 days
Billing and tax recordsAs long as applicable financial law requires, typically 7 years
BackupsDeleted data persists in encrypted backups for a short rolling window before being overwritten

8. Security

  • All traffic to our API and dashboard is encrypted in transit with TLS; data is encrypted at rest.
  • OAuth tokens and API key secrets are stored encrypted, and API keys are shown in full only once, at creation.
  • Access to production systems is limited to staff who need it, protected by multi-factor authentication, and logged.
  • Every action taken on your account — including calls made by AI agents through the MCP server — is recorded in your audit log.
  • Rate limits protect your connected accounts from runaway automation.

No system is perfectly secure. Scope your API keys to the least privilege that works, rotate them periodically, and store them as secrets rather than in source control. If we become aware of a breach affecting your personal data, we will notify you and the relevant regulators as required by law.

9. International transfers

Bulkit and its subprocessors operate globally, so your data may be processed in countries other than your own, including the United States. Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where applicable) together with supplementary technical measures such as encryption in transit and at rest.

10. Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you and receive a copy.
  • Correct data that is inaccurate or incomplete.
  • Delete your data, subject to records we must keep by law.
  • Export your data in a portable, machine-readable format.
  • Object to or restrict processing based on our legitimate interests.
  • Withdraw consent for marketing email or optional cookies at any time.
  • Not be discriminated against for exercising any of these rights.

Much of this is self-service: you can edit your profile, disconnect social accounts, rotate or revoke API keys, export data, and delete your account from the dashboard. For anything else, email privacy@bulkit.io and we will respond within 30 days.

California residents: we do not sell personal information or share it for cross-context behavioral advertising, so there is no opt-out to offer. You may still exercise the access, deletion, correction, and non-discrimination rights above, and you may use an authorized agent. EEA and UK residents may also lodge a complaint with their local supervisory authority.

11. Cookies and tracking

This marketing site keeps things minimal: your light/dark theme preference is stored in your browser's local storage and never leaves your device. We do not run advertising or cross-site tracking on it.

The dashboard uses strictly necessary cookies to keep you signed in and to protect against cross-site request forgery. If we add product analytics or non-essential cookies, we will ask for your consent first and update this section.

The API itself is authenticated with API keys rather than cookies, so machine-to-machine calls set no cookies at all.

12. Children

Bulkit is a developer tool intended for businesses and adults. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.

13. Changes to this policy

We update this policy when our practices change. The date at the top always reflects the current version. For material changes — new categories of data, new purposes, or new disclosures — we will notify account holders by email or in the dashboard before the change takes effect. Continuing to use Bulkit after that date means you accept the updated policy.

Contact us

Questions about this policy, a data request, or a security concern? Email us and a person will read it. For formal data protection matters, write to the same address with “GDPR” or “CCPA” in the subject line.

privacy@bulkit.io