Back to homepage

WhereToPost

Privacy Policy

Effective date: July 28, 2026

This policy explains what WhereToPost collects, why we collect it, and how you can ask us to delete it. It is written for the current workspace, which uses Google sign-in but does not require a Reddit login and does not auto-post to Reddit.

Who We Are

WhereToPost is a workspace that helps people choose reviewed Reddit communities, check visible rules and public evidence, and follow a lower-risk promotion plan before posting. The service is owned and operated by the WhereToPost team.

We are not affiliated with Reddit. We do not post to Reddit on your behalf, access your Reddit account, or ask for your Reddit password.

What We Collect

  • Google sign-in information such as your name, email address, profile image, Google account identifier, and the session data needed to keep you signed in.
  • Workspace information such as product URLs, product descriptions, goals, Reddit usernames or profile links, community hints, matched communities, tasks, drafts, checks, confirmations, comments, and outcome notes that you save.
  • Legacy report and waitlist information, including submitted product details, generated report content, email address, selected communities, and product-interest responses.
  • Order, checkout, and access information such as the product purchased, amount, currency, order status, customer, checkout, order, and transaction identifiers, payment confirmation records received from Creem, and the paid access attached to your account.
  • Technical and security information such as IP address, user-agent, referrer, rate-limit records, essential session information, and basic product events.

Google Sign-In

We use Google sign-in to create and secure your WhereToPost account. The sign-in flow is not used to read your Gmail, Google Drive files, or Reddit account.

Authentication and session records may include provider identifiers and tokens managed by our authentication system. We use them only to provide and protect sign-in.

Reddit Inputs And Public Data

You choose which Reddit username or profile link to enter. We do not verify that you own the account. If the username is wrong, the check and task plan may describe the wrong public account.

When the limited public-account check is enabled, saving a Reddit username starts a background check. While that account remains attached to an active workspace, recent public activity may be refreshed about once a day, slower-changing profile facts may be refreshed less often, and an older result may be refreshed before a planned Reddit check.

The public-account check may read public profile facts through TikHub and recent public activity through Arctic Shift. Public sources can be incomplete, delayed, or unavailable.

For that account check, we store limited facts and summaries such as profile dates, karma or activity counts, check times, source coverage, and hashed content or subreddit identifiers. We do not store the full post or comment text returned for that check.

After you confirm that Reddit allows a planned post, scheduled checks may search the saved username's recent public submissions in that planned subreddit for up to 24 hours. We store the search status, timestamps, limited source details, and the matched direct URL and identifier. Unselected candidate titles are shown for confirmation when needed but are not stored in the workspace.

When you save a direct Reddit post or comment URL, scheduled checks may read that public URL and Arctic Shift results to look for visibility changes and public interactions. We store the saved URL, Reddit post or comment identifier, monitoring status, check time, and limited counts such as score, comments, or replies. We do not store post, comment, or reply text returned by monitoring.

Browser Extension And AI Providers

The free browser extension works without a WhereToPost account. You choose an AI provider, model, and API endpoint and provide your own API key. The provider, model, endpoint, and optional product facts are stored in the extension's local browser storage. The API key is kept only in the extension's in-memory session storage and is cleared when the browser or extension restarts. WhereToPost does not receive or store your provider API key.

When Edge does not provide temporary current-tab access, clicking refresh asks for optional access to Reddit and its subdomains before the extension reads a post. Your browser may remember that permission until you revoke it. The extension has no background content script and only runs its Reddit reader when you open its side panel, refresh, or generate.

When you click generate on a Reddit post, the extension reads the current post title and body and sends that context, your selected tone, and any optional product facts directly to the AI provider or custom endpoint you selected. The free extension does not route that request through WhereToPost servers.

When you click read community rules, the extension reads only the subreddit name from the active Reddit URL and sends that name to WhereToPost. It does not send the post title or body, draft, product facts, provider endpoint, or API key for this request.

When the community-rule source is approved and enabled, WhereToPost uses public rule data to create a deterministic rule guide. A limited source response may be cached for up to 6 hours, and a normalized guide may be shared across requests for up to 30 days while the checked rule text is unchanged. These shared records are keyed by subreddit and rule-text hash, not by a WhereToPost account, product, Reddit username, post, or draft.

The extension keeps the source context and generated draft in the side panel while you use it. It does not write the Reddit body or generated draft to your WhereToPost account, analytics, or application logs. Copying a draft places the text on your device clipboard.

Your selected provider or custom endpoint processes the information under its own pricing, retention, training, security, and privacy terms. The extension asks for access to the selected provider host when you save or use that provider. Only use endpoints and keys you trust.

The extension uses browser permissions and user-provided data only to provide the rule-guide and draft features the user requests. We do not sell extension data, use it for personalized advertising, or allow people to read it unless the user explicitly shares specific material for support or access is required for security or law.

Payments

Creem provides checkout and acts as the merchant of record for purchases. Creem receives the information needed to complete a purchase, such as your email, billing details, payment details, and order information under its own privacy notice.

WhereToPost stores the order and access records needed to confirm payment and provide the purchased plan, including checkout and payment confirmation records that Creem sends us. Those records may include your Creem customer identifier and email. We do not store your full payment-card number.

How We Use Data

  • Create your account, keep you signed in, and show the projects that belong to you.
  • Analyze product information, arrange daily tasks, save your work, and show community and account checks.
  • Create checkout sessions, confirm orders, and provide paid access.
  • Improve product matching, task planning, risk checks, and service reliability.
  • Prevent abuse, spam, and unsafe requests.
  • Contact waitlist users about product updates or early access.

Service Providers

We use Google for sign-in, Cloudflare for hosting, security, request handling, and site analytics, Neon Postgres for data storage, and Creem for checkout, payment handling, and merchant-of-record services.

When the public-account check is enabled, we use TikHub and Arctic Shift to look up limited public Reddit facts. These providers process data under their own terms and privacy notices.

When the community-rule guide is approved and enabled, TikHub may provide public subreddit rules and limited moderator-maintained community information, such as the description, posting guidance, available post types, and whether post flair is enabled. The source may be incomplete and does not provide the rules' own update time, so the guide does not replace checking Reddit.

The current website workspace uses deterministic product and task logic. We do not currently send workspace input to an AI provider to generate reports or daily tasks. The separate free browser extension sends a user-triggered request directly to the AI provider or custom endpoint selected by that user, as described above.

How We Share Data

  • With service providers that help us host, secure, store, and operate the product.
  • When needed for legal, security, fraud prevention, or abuse investigation reasons.
  • We do not sell personal data.

Data Retention

  • Account and workspace data is kept while you use the service or until it is deleted, subject to records we reasonably need for security, transactions, disputes, or legal obligations.
  • You can permanently delete an individual project from the workspace. This removes the project and its related stored task and readiness records from our application database.
  • Waitlist and legacy report data is kept until you ask us to delete it or it is no longer needed to operate the service.
  • Order, payment, tax, fraud-prevention, and security records may be kept for a reasonable period when needed to complete transactions, protect the service, resolve disputes, or meet legal obligations.
  • Shared community-rule guides may be kept for up to 30 days while their rule-text hash remains unchanged. Older cache entries expire automatically and are not tied to a user's product, Reddit account, post, draft, or API key.

Your Choices

You can delete individual projects in the workspace. You can ask us to delete your WhereToPost account, waitlist email, or legacy report data by contacting support@wheretopost.com. We may need enough information to verify the request and find the relevant records.

You can stop using the service at any time. If we send product emails later, those emails should include a way to unsubscribe.

Cookies And Browser Storage

We use essential cookies to maintain sign-in and security. The app may also use browser storage to cache workspace data and remember interface state so pages load and recover more reliably.

The free browser extension uses extension-local storage for the selected provider, model, endpoint, and optional product facts. The API key uses in-memory extension session storage instead and is cleared when the browser or extension restarts. Removing the extension or using its clear-data control removes both local and session settings, subject to how your browser handles extension data.

Clearing browser data may remove cached copies or local interface state, but it does not automatically delete records stored in your WhereToPost account.

Children

WhereToPost is not intended for children under 13. Do not use the service if you are under 13.

Changes

We may update this policy as the product changes. The effective date above shows when this version became active.

Contact

Questions or deletion requests: support@wheretopost.com