Back to homepage

WhereToPost

Privacy Policy

Effective date: September 5, 2026

This policy explains what WhereToPost collects, why we collect it, and how you can ask us to delete it. It is written for the current workspace, which uses Google sign-in but does not require a Reddit login and does not auto-post to Reddit.

Who We Are

WhereToPost is a workspace that helps people choose reviewed Reddit communities, check visible rules and public evidence, and follow a lower-risk promotion plan before posting. The service is owned and operated by the WhereToPost team.

We are not affiliated with Reddit. We do not post to Reddit on your behalf, access your Reddit account, or ask for your Reddit password.

What We Collect

  • Google sign-in information such as your name, email address, profile image, Google account identifier, and the session data needed to keep you signed in.
  • Workspace information such as product URLs, product descriptions, goals, Reddit usernames or profile links, community hints, matched communities, tasks, drafts, checks, confirmations, comments, and outcome notes that you save.
  • Legacy report and waitlist information, including submitted product details, generated report content, email address, selected communities, and product-interest responses.
  • Order, checkout, and access information such as the product purchased, amount, currency, order status, customer, checkout, order, and transaction identifiers, payment confirmation records received from our payment providers, and the paid access attached to your account.
  • Technical and security information such as IP address, user-agent, referrer, rate-limit records, essential session information, and basic product events.

Google Sign-In

We use Google sign-in to create and secure your WhereToPost account. The sign-in flow is not used to read your Gmail, Google Drive files, or Reddit account.

Authentication and session records may include provider identifiers and tokens managed by our authentication system. We use them only to provide and protect sign-in.

Reddit Inputs And Public Data

You choose which Reddit username or profile link to enter. We do not verify that you own the account. If the username is wrong, the check and task plan may describe the wrong public account.

The public Reddit Shadowban Detector sends the username you submit to a public Reddit profile endpoint. When Reddit blocks that server-side read, the detector may use TikHub as a limited fallback for the same public profile facts. The detector does not sign in to Reddit, read private account state, or scan recent posts and comments.

Anonymous detector results are not saved to a WhereToPost account or workspace. Ordinary application logs record only limited operational status and error codes, not the submitted username or returned profile facts. Technical rate-limit records may still use request information such as IP address as described above.

Saving a Reddit username does not start a recent account-history scan. Recent posts, comments, and external-link activity are not required for the task plan.

A limited internal owner beta may refresh public profile facts such as account age and karma through TikHub. It does not scan recent account activity and is not a general account-monitoring feature. Public profile facts can be incomplete, delayed, or unavailable.

For that account check, we store limited facts and summaries such as profile dates, karma or activity counts, check times, source coverage, and hashed content or subreddit identifiers. We do not store the full post or comment text returned for that check.

After you confirm that Reddit allows a planned post, scheduled checks may search the saved username's recent public submissions in that planned subreddit for up to 24 hours. We store the search status, timestamps, limited source details, and the matched direct URL and identifier. Unselected candidate titles are shown for confirmation when needed but are not stored in the workspace.

When you save a direct Reddit post or comment URL, scheduled checks may read that public Reddit URL to look for visibility changes and public interactions. We store the saved URL, Reddit post or comment identifier, monitoring status, check time, and limited counts such as score, comments, or replies. We do not store post, comment, or reply text returned by monitoring.

Browser Extension And AI Providers

The public Landing Page Roaster reads bounded text from the public page URL you submit and sends that text to our configured AI provider for a copy review. It does not use screenshots or your traffic analytics. The latest review and extracted evidence stay in this browser for up to 24 hours, unless you delete them sooner; refreshing does not extend that time. This tool does not save the review to your account. Ordinary application logs record the provider and finding count, not the submitted URL, page text, or full review.

The public Reddit Post Generator sends the topic, options, confirmed facts, optional website URL, optional subreddit, and the public website facts needed for generation to WhereToPost and its configured AI provider. Reddit post URL context is currently paused; remove that URL to continue without it. The provider name is shown with a successful result. We record limited operational data such as provider, model, token counts, status, and error code, but not the full anonymous prompt or draft in ordinary application logs.

The public generator stores only the latest successful anonymous draft and its form values in the current browser for up to 24 hours. Editing, refreshing, or signing in does not extend that time. Reset, deletion, expiry, or a successful Save to Workspace removes the local copy. If browser storage is unavailable, the page tells you that the draft may be lost.

Save to Workspace requires sign-in and a project you can still edit. A successful save stores the title, body, target subreddit, source draft identifier, and import time as an idea that needs new Workspace checks. A failed save leaves the local copy until its original expiry.

The free browser extension works without a WhereToPost account. You choose an AI provider, model, and API endpoint and provide your own API key. The provider, model, endpoint, and API key are stored in extension-local browser storage on your device. The key remains available after browser restarts, extension reloads, and extension updates until you clear local data or uninstall the extension. The extension does not add its own encryption to this local value. WhereToPost does not receive or store your provider API key. Older saved product-facts fields are deleted when the updated extension first loads.

A content script runs only on the supported Reddit hosts to detect when you open Reddit's native comment or reply composer and to place the local WhereToPost AI button inside that composer. Detecting the composer and showing the button does not read the post or comment text. After install or reload, the extension may re-inject that content script into already-open Reddit tabs so the in-page button remains available without a manual page refresh.

Before generation, you may add an optional point, fact, or experience that you can confirm. When you click generate, the extension reads the current post title and body and, for a comment reply, only the exact comment associated with that reply composer. It ignores the rest of the comment thread. It sends that context, the selected tone, the optional take, and the requested output mode directly to the AI provider or custom endpoint you selected in one request. The English mode requests one English draft in the selected tone. The Simplified Chinese mode requests the same English posting draft and a matching Chinese reference. Changing the selected tone does not send another request until you click Generate or Regenerate. The selected comment and optional take are not saved with drafts or reused on another Reddit post. The free extension does not route that request through WhereToPost servers.

The in-page draft dialog returns one draft for the selected goal and tone. The extension writes the English draft into the exact Reddit reply box only after you click Insert. It never clicks Reddit's Comment or Reply submit button, so you remain responsible for reviewing, editing, and manually publishing.

When you click read community rules, the extension reads only the subreddit name from the active Reddit URL and sends that name to WhereToPost. It does not send the post title or body, comments, page HTML, Reddit username, draft, provider endpoint, or API key for this request. Public extension reads only return a saved result for communities on an explicit supported list; that list is currently empty, so most communities show that no reliable saved result is available and do not trigger a paid source call.

When the community-rule source is approved and enabled, WhereToPost uses public rule data to create a deterministic rule guide. A limited source response may be cached for up to 6 hours, and a normalized guide may be shared across requests for up to 30 days while the checked rule text is unchanged. These shared records are keyed by subreddit and rule-text hash, not by a WhereToPost account, product, Reddit username, post, or draft.

The extension saves generated and edited comment drafts in extension-local browser storage for the exact Reddit post or selected-comment key and selected tone. The side panel keeps separate drafts per selected tone. It keeps at most 20 drafts for up to 30 days and stores the English draft, optional Chinese reference, post title, subreddit, tone, exact post or comment key, and update time, but not the Reddit post body or selected comment text. Editing an English draft clears that tone's old Chinese reference. Drafts are not written to your WhereToPost account, analytics, or application logs. Clear local data removes them, and copying an English draft places the text on your device clipboard.

Your selected provider or custom endpoint processes the information under its own pricing, retention, training, security, and privacy terms. The extension asks for access to the selected provider host when you save or use that provider. Only use endpoints and keys you trust.

The extension uses browser permissions and user-provided data only to provide the rule-guide and draft features the user requests. We do not sell extension data, use it for personalized advertising, or allow people to read it unless the user explicitly shares specific material for support or access is required for security or law.

Payments

Checkout is provided by the payment provider shown when you purchase, currently Creem or Waffo Pancake depending on the checkout environment. That provider receives the information needed to complete a purchase, such as your email, billing details, payment details, and order information under its own privacy notice.

WhereToPost stores the order and access records needed to confirm payment and provide the purchased plan, including checkout and payment confirmation records that the provider sends us. Those records may include a provider customer identifier and email. We do not store your full payment-card number.

How We Use Data

  • Create your account, keep you signed in, and show the projects that belong to you.
  • Analyze product information, arrange daily tasks, save your work, and show community and account checks.
  • Create checkout sessions, confirm orders, and provide paid access.
  • Improve product matching, task planning, risk checks, and service reliability.
  • Prevent abuse, spam, and unsafe requests.
  • Contact waitlist users about product updates or early access.

Service Providers

We use Google for sign-in, Cloudflare for hosting, security, request handling, and site analytics, Neon Postgres for data storage, and Creem or Waffo Pancake for checkout and payment handling. The provider used for a purchase is shown at checkout.

The public Reddit Shadowban Detector may use TikHub as a bounded fallback for public Reddit profile facts when Reddit blocks the direct server-side read. A separate limited internal owner beta may also use TikHub for saved-account profile facts. TikHub processes data under its own terms and privacy notice. Recent account activity checking is currently paused.

When the community-rule guide is approved and enabled, TikHub may provide public subreddit rules and limited moderator-maintained community information, such as the description, posting guidance, available post types, and whether post flair is enabled. The source may be incomplete and does not provide the rules' own update time, so the guide does not replace checking Reddit.

When deeper discussion relevance checking is enabled, WhereToPost may send its configured AI provider your product name, description, target audience, audience tags, and use cases, along with community context and public Reddit discussion excerpts. This relevance check does not send your saved Reddit username, account status, project ID, or task history. AI assessments support discussion selection; they do not confirm Reddit posting eligibility.

A user-triggered public post draft or eligible Workspace promotion draft can be sent to WhereToPost's configured AI provider. The separate free browser extension sends a user-triggered request directly to the provider or custom endpoint selected by that user, as described above.

How We Share Data

  • With service providers that help us host, secure, store, and operate the product.
  • When needed for legal, security, fraud prevention, or abuse investigation reasons.
  • We do not sell personal data.

Data Retention

  • Account and workspace data is kept while you use the service or until it is deleted, subject to records we reasonably need for security, transactions, disputes, or legal obligations.
  • You can permanently delete an individual project from the workspace. This removes the project and its related stored task and readiness records from our application database.
  • Waitlist and legacy report data is kept until you ask us to delete it or it is no longer needed to operate the service.
  • Order, payment, tax, fraud-prevention, and security records may be kept for a reasonable period when needed to complete transactions, protect the service, resolve disputes, or meet legal obligations.
  • Shared community-rule guides may be kept for up to 30 days while their rule-text hash remains unchanged. Older cache entries expire automatically and are not tied to a user's product, Reddit account, post, draft, or API key.

Your Choices

You can delete individual projects in the workspace. You can ask us to delete your WhereToPost account, waitlist email, or legacy report data by contacting support@wheretopost.com. We may need enough information to verify the request and find the relevant records.

You can stop using the service at any time. If we send product emails later, those emails should include a way to unsubscribe.

Cookies And Browser Storage

We use essential cookies to maintain sign-in and security. The app may also use browser storage to cache workspace data and remember interface state so pages load and recover more reliably.

The public Reddit Post Generator uses browser storage for its latest anonymous draft and form values for no more than 24 hours from the latest successful generation. Resetting or deleting the draft removes that copy immediately.

The free browser extension uses extension-local storage for the selected provider, model, endpoint, API key, and saved comment drafts described above. These values remain on that device after browser restarts, extension reloads, and extension updates. Removing the extension or using its clear-data control removes the saved extension data, subject to how your browser handles extension data.

Clearing browser data may remove cached copies or local interface state, but it does not automatically delete records stored in your WhereToPost account.

Children

WhereToPost is not intended for children under 13. Do not use the service if you are under 13.

Changes

We may update this policy as the product changes. The effective date above shows when this version became active.

Contact

Questions or deletion requests: support@wheretopost.com