What we collect, why, and who else sees it. Last updated 20 August 2026.
Postspool plans and writes social posts for a business, and its Chrome extension puts the posts you have approved into Instagram's own scheduler. This page describes both.
What you enter in setup: your trade, who your customers are, where you are based, where your customers are, your tone, your Instagram handle, your website and any other social handles, and the paragraph you write about your business. This exists to write your posts and is used for nothing else.
Titles, captions, the images generated for them, their scheduled times, and whether each one is a draft, approved or scheduled. Also how many posts and images you have generated this month, so your plan can be metered.
When the extension connects, we store a random identifier it generated once, a label such as "Chrome on Windows", and when it was first and last seen. This is how the number of devices on your plan is counted. The identifier is random — nothing about it is derived from your computer, and it identifies the installation rather than you.
The extension runs on instagram.com and on postspool.com, and only on those. It does one thing: when you press the button, it opens Instagram's post composer, attaches the picture, types the caption, sets the date and time, and saves the post into Instagram's scheduler.
It sends us the post identifier, whether it succeeded, and the error text if it did not.
What it does not do, by design:
We do not sell your information, we do not share it for advertising, and there are no third-party analytics or tracking scripts on this site.
We keep your account and its posts for as long as the account exists. Device records stop counting against your plan after 30 days without use.
You can delete your account yourself, from the account menu in the dashboard — every brand in it, every post, every picture we keep, at once. We hold the request for 7 days before anything is deleted, so a change of mind is possible: cancel it from the same menu, and nothing was touched. After those 7 days it is done by a daily job and there is no way back. Posts already sitting in Instagram's own scheduler stay there, because they are Instagram's; remove those from Instagram. If you would rather we did it, or you want a copy of what we hold, email kamellokman.s@gmail.com from your account address.
You can remove a device yourself at any time under Connect the extension → Devices, and you can replace your extension key there, which immediately stops the old one working.
Everything travels over HTTPS. Passwords are hashed with scrypt. Your extension key is stored so the server can check it on each request, which means it can be shown back to you — treat it like a password, and replace it if you think someone else has it.
If this changes materially we will say so on this page and update the date at the top. Questions: kamellokman.s@gmail.com.