Terms of Service
Last updated: 2026-04-07
These terms govern your use of Postato during the early access period. Postato is in active development and formal terms will be published before general availability. By using Postato, you accept the terms below.
1. About Postato
Postato is an execution layer (REST API plus MCP server) that lets AI agents, applications, and traditional systems create, validate, schedule, publish, and observe content on social networks that you have connected to your account. Postato operates only through the official APIs of supported social networks and never holds the credentials of those networks beyond the OAuth tokens you authorize.
Throughout these terms, "interface" refers to all the ways you can interact with Postato: the REST API, the MCP server, and the web dashboard.
2. Account and access
To use Postato you must create an account, provide accurate information, and be at least 18 years old. You are responsible for keeping your credentials confidential, including all API keys (which take the form smcp_*). Any action taken with your API keys, including actions initiated by AI agents, automations, or third-party integrations you configure, is your responsibility until you revoke the affected key.
You can disconnect any social network account from Postato at any time. Disconnecting revokes the OAuth token Postato held for that account and stops any scheduled or queued action that would have used it.
3. Mediation model
Postato is a mediated carrier, not a custodian of your social network credentials. When you connect a social account, you authorize Postato to act on your behalf on that network through the network's official OAuth flow. Postato stores the resulting tokens encrypted at rest and uses them only to perform the actions you, your applications, or your agents request through the interface.
You are the publisher of any content delivered through Postato. Postato is the courier that carries the content from your interface to the connected platform. You retain full ownership of content you submit and grant Postato a limited, non-exclusive, revocable license to process, format, validate, schedule, transmit, and store that content solely to deliver the service.
4. Acceptable use
By using Postato, you agree to:
- Use Postato only through the interface provided.
- Not use the service to publish content that violates the terms of any connected social network, applicable law, or third-party rights.
- Not use the service for spam, harassment, deception, scraping, automated bulk impersonation, or any illegal activity.
- Take full responsibility for the content you submit and for the actions your agents and integrations take through your account.
- Respect the rate limits applied by Postato and by the connected platforms.
5. Operational behavior
Postato is built for reliable execution but not for instant delivery. You acknowledge and accept the following:
- Postato applies rate limits per API key and per connected platform. Submissions may be queued, delayed, or rejected to respect those limits.
- Postato may retry failed deliveries with exponential backoff. To prevent duplicate publication on retries, you should send an
Idempotency-Keyheader on requests that must not be duplicated. Without that header, retries may produce duplicate posts. - Postato may validate the format, size, and structure of submitted content at request time and reject submissions that do not meet the technical requirements of the destination platform. Validation is technical, not editorial.
- Postato does not guarantee a specific delivery time, throughput, or uptime SLA during early access.
6. Content and moderation
Postato does not pre-approve, moderate, or edit the content you submit. Responsibility for content published through Postato is exclusively yours.
If a connected social network rejects, removes, restricts, or moderates your content after Postato delivers it, that decision belongs to the network and is not Postato's responsibility. Postato is not party to any dispute between you and a connected platform about its content rules.
7. Connected platforms
The platforms currently supported are listed at https://www.postato.com.br. Postato may add, remove, or temporarily suspend support for any platform at any time, including in response to changes in the platform's API or terms.
When you connect a social network account to Postato, the terms of service of that platform also apply to your use of that account. You are responsible for understanding and respecting them.
8. Webhooks
Webhook delivery is optional. If you configure a webhook endpoint, you are responsible for the availability, security, and processing of that endpoint. Postato signs every webhook delivery with HMAC-SHA256 and includes the signature in the X-Webhook-Signature header. You should verify the signature before processing the event. Postato makes reasonable retry attempts but does not guarantee delivery if your endpoint is unavailable.
9. Workspace isolation
Each Postato account is scoped to a workspace. Data belonging to one workspace is not accessible to other workspaces by construction of the platform. You are responsible for managing the boundaries of your own workspace, including who has access to your API keys.
10. Service availability
Postato is in early access. We do not commit to uptime service-level agreements at this stage. We will communicate planned maintenance and unplanned outages as best we can through the channels you have on file.
11. Account termination
You may terminate your account at any time by contacting us at the address below. We will delete your personal data within the period required by applicable law and revoke all active tokens.
We may suspend or terminate accounts that violate these terms, the terms of any connected social platform, or applicable law.
12. Intellectual property
Postato, the Postato brand, the source code, the documentation, and the underlying infrastructure are property of Postato and its licensors. The license granted in section 3 does not transfer any of your intellectual property rights to Postato beyond what is strictly necessary to deliver the service.
13. Limitation of liability
Postato is provided "as is" during early access. To the maximum extent permitted by law, Postato is not liable for indirect, incidental, special, or consequential damages arising from your use of the service. A formal liability section will be published with the general availability terms.
14. Privacy and data protection
The processing of your personal data by Postato is described in the Privacy Policy. Postato complies with the Brazilian General Data Protection Law (LGPD) and you may exercise your rights as a data subject through the contact channels listed there.
15. Governing law
These terms are governed by the laws of the Federative Republic of Brazil. Any dispute arising from these terms or from your use of Postato will be settled in the courts of the city of São Paulo, state of São Paulo, Brazil, to the exclusion of any other forum.
16. Force majeure
Postato is not liable for failures or delays in performance caused by events beyond its reasonable control, including but not limited to natural disasters, acts of government, network failures, outages of third-party services, or acts of war.
17. Severability
If any provision of these terms is held invalid or unenforceable, the remaining provisions remain in full force and effect.
18. Changes
Postato may update these terms. Material changes will be communicated by email to the address on your account at least 15 days before they take effect.
19. Contact
For questions about these terms: legal@postato.com.br