Post AI Pilot
Home
Creative Tools PlannerPlan your content calendar and create content automatically with AI Generate ImageCreate professional visuals with AI Generate VideoText to video in seconds Product StudioAI-powered studio-quality shoots for ecommerce and social media Catalog StudioTransform apparel, jewelry, and accessories with premium catalog aesthetics
Explore Post AI Pilot StudioExplore Smart Calendar, Media Assets, Ads Center, and Message Center in one flow Credit BalanceTrack your credit spending ServicesProfessional production and web solutions PortfolioExplore sample work
Post AI Pilot Logo
About Pricing
FAQ Contact
Blog
English Türkçe
Log In Start Free
Post AI Pilot
Home
Planner Post AI Pilot Studio Credit Balance Generate Image Generate Video Product Studio Catalog Studio
About Pricing
FAQ Contact
Blog
Log In Start Free
Contact
info@postaipilot.com +90 542 656 07 00
Post AI Pilot

Privacy & Cookie Policy

Review what data we collect on our platform, how we use it, and how your cookie preferences are managed.

Post AI Pilot

Note: This Privacy Policy officially governs the data collection and processing practices of the PostAIPilot application and platform.

1. Introduction and Scope

This Privacy Policy describes the principles regarding the collection, use, storage, and sharing of users' personal data with third parties within the scope of the services offered through the postaipilot.com website and mobile applications ("Platform") operated by the data controller, Furkan Pehlivanoğlu Individual Company ("Company", "PostAIPilot" or "Post ai Pilot").

All natural and legal persons (“Users”) who visit the Platform, become members, purchase plans, log in with Instagram, or use social media integrations are deemed to have been informed about data processing activities in accordance with this Privacy Policy.

2. Types of Data Collected

The following data types can be processed within the Post AI Pilot program:

2.1. Account and Membership Information

  • First name, last name, username
  • Email address
  • Company name (in corporate accounts)
  • Password (in hashed form)
  • Profile picture (if uploaded by the user)

2.2. Plan and Usage Information

  • Type of plan/package purchased
  • Credit balance, number of loans used
  • Posting dates/times entered into the planner
  • Content volumes, production and publication history

2.3. Content and Media Data

  • User-uploaded images, videos, logos
  • Written captions, texts, briefs, and prompts
  • AI-generated content (text/images/video)
  • Drafts, campaign notes, and planned post content.

This data is stored in conjunction with your account as part of your plan; you can request deletion/editing at any time (excluding regulatory retention obligations).

2.4. Data Obtained via Instagram and Meta API

During the Facebook login or Instagram account linking processes, the following types of data may be collected via the Meta API (depending on the scope and API permissions you grant):

Requested Data Scope Intended Use
General Profile Information (Required) public_profile It is used for identity verification and profile creation by reading the user's publicly available profile information (name, surname, profile picture, etc.) from their Facebook account.
Email Address (Required) e-mail The user's primary email address is read and used for communication, account security, and informational purposes.
Profile and Page Information instagram_business_basic This is used to identify and display the Instagram Business/Creative accounts that a user has linked to on our platform.
Content Publishing Authority instagram_business_content_publish This feature is used to automatically publish content created by users on our platform to their Instagram account at a scheduled date and time, with the user's explicit consent. This constitutes the core service of the application.
Insights and Performance instagram_business_manage_insights It is used to analyze the performance of a user's published posts (metrics such as reach, engagement, impressions, etc.) and provide the user with a content analysis service.
Message Management instagram_business_manage_messages The Message Center feature allows users to view and respond to direct messages received on their Instagram account through our platform, as well as to run automated reply streams set up by the user.
Comment Management instagram_business_manage_comments It is used to view and respond to comments on a user's posts, and to run comment-to-DM automation flows set up by the user.

Data Sharing and Storage Commitment:

Limitation: Data collected via Instagram APIs is used solely for content scheduling, publishing, and performance analysis purposes.
Token Security: Access tokens are encrypted in accordance with Meta's required security standards and are stored only for scheduling/automatic sharing functions.
Policy Compliance: All data processing processes are carried out in full compliance with Meta Platform Terms and Policies and the Turkish Republic's Personal Data Protection Law (KVKK) legislation, as the data controller.

2.5. Data Obtained via TikTok API

During the processes of sharing content on TikTok or connecting your TikTok accounts, the following types of data may be collected via the TikTok API (depending on the scope and API permissions you grant):

Requested Data Scope Intended Use
Basic User Information user.info.basic The user's TikTok username, profile picture, and publicly available profile details are used to display their information on the platform.
Detailed Profile Information user.info.profile User details such as biography and account type are read in order to provide personalized service.
Accounting Statistics user.info.stats The system tracks a user's general metrics, such as follower count and like count, for performance reporting purposes.
Video Publishing Process video.publish It allows users to directly share approved video content on the TikTok platform.
Video Uploads and Drafts video.upload It ensures that videos are securely uploaded to TikTok servers and added to the sharing queue.

Data Sharing and Storage Commitment:

Limitation: Data collected via TikTok APIs is used solely for content planning, publishing, and performance analysis purposes.
Token Security: Access tokens and refresh tokens are encrypted in accordance with TikTok Inc.'s required security standards and are stored only for scheduling/automatic sharing functions.
Policy Compliance: All data processing processes are conducted in full compliance with the TikTok Platform Terms and Policies and the Turkish Republic's Personal Data Protection Law (KVKK) legislation, as the data controller.

2.6. Data Obtained Through Facebook Business and MetaAd APIs

During Facebook page management, Message Center, Ads Center (meta-ad management), or when connecting your Facebook account, the following types of data may be collected via the Meta Graph API and Meta Marketing API (depending on the scope and API permissions you grant):

Requested Data Scope Intended Use
Page List pages_show_list This is used to list the Facebook pages that a user manages and allow them to select them on our platform.
Page Content Management pages_manage_posts It is used to share content (photos, videos, text) approved by the user on their Facebook page. This constitutes the core service of the application.
Page Interactions pages_read_engagement It is used to extract interaction data (number of likes, comments, shares) from page posts and provide users with performance analysis.
Page Analytics read_insights It is used to extract page performance metrics (reach, impressions, follower change) and provide analysis services in statistics.
Page Messages pages_messaging The Message Center feature allows you to view and reply to messages sent to your Facebook page, as well as run automated reply feeds configured by the user, all through our platform.
Page Settings Management pages_manage_metadata This is used to set up and manage the necessary webhook subscriptions for the Message Center to receive page messages; and also to set up the necessary webhook subscription for the immediate delivery of new form responses when a lead generation form is published in the Ads Center.
Reading Advertising Data ads_read Ad Center uses this system to read the campaign list and performance data (spending, reach, conversion, ROAS, etc.) from the user's own ad account, and to provide reporting and optimization suggestions.
Advertising Management ads_management With the user's explicit consent, it is used to create campaigns/ad sets/ads in their own advertising account (each campaign created is set to be paused; no spending occurs until the user activates it) and to perform management operations such as stopping/starting/budget changes.
Business Assets business_management This allows the user to access their advertising accounts and pages under Business Manager and select the correct account/page.
Linked Instagram Account instagram_basic In Ad Center, this is used to identify the Instagram account linked to the selected Facebook page (required for Instagram embedded ads) and to suggest a boost candidate by listing the user's own Instagram posts along with engagement data.
Page Ad Forms pages_manage_ads In the Ad Center, this permission is used to create, edit, and link a lead form (Instant Form/Lead Form) to a generated ad on behalf of the user's Facebook page, upon the user's explicit request. With this permission, the page content cannot be modified, and no posts can be shared on behalf of the page.
Potential Customer Data leads_retrieval The form responses (name, email, phone number, and answers to custom questions added by the user) of individuals who fill out the form on the user's advertisement are retrieved from Meta and used to display in the Leads list and Message Center on the platform. This data is only shown to the business user who owns the form; it is not sold or transferred to advertising networks, data brokers, or other third parties. See the "Lead data" section below for details.
Product Catalog Management catalog_management This permission allows users to create and update their product catalog within their Meta Business Manager account using product information they enter on the platform (product code, name, description, price, stock status, image, and product page link). This enables users to run dynamic product ads. This permission is granted only for the user's own catalog.

Data Sharing and Storage Commitment:

Limitation: Data collected via Facebook and Meta ad APIs is used solely for content scheduling, publishing, message management, ad management, and performance analysis purposes; ad and message data is only shown to the user who owns the relevant account.
Token Security: Access tokens and Page tokens are encrypted in accordance with Meta's required security standards.
Policy Compliance: All data processing processes are carried out in full compliance with Meta Platform Terms and Policies and the Turkish Republic's Personal Data Protection Law (KVKK) legislation, as the data controller.

Social Connection Management:

Users can terminate the links to their Instagram, Facebook, and TikTok accounts at any time via the "Social Connections" section on their profile page, and the links to their Meta and Google Ads advertising accounts via Studio > Ad Center. When a link is terminated, all access permissions, access tokens, and stored data for that platform are deleted from our system. Additionally, when Meta deauthorizes access or submits a data deletion request, all Meta data belonging to that user is automatically deleted via the feedback endpoints called by Meta.

Lead data

For businesses using lead forms on Reklam Merkezi, we retrieve the information provided by those filling out the form from Meta and display it in the business's own dashboard.

  • Which data: The person filling out the form has the following information: full name, email address, phone number, and answers to any specific questions the business adds to the form (e.g., the service they are interested in or their preferred appointment time). This data is collected with the person filling out the form's consent, via the information provided and checkboxes on Meta's form screen.
  • Why: So that the business that owns the form can get back to this person. We don't use this data in our own marketing, nor do we use it to train models.
  • Who it is shared with: Only the business user who owns the form and their authorized team members can see it. It is not sold to data brokers, shared with other clients, or used to train AI models. Our infrastructure service providers (hosting and database) process the data only on our behalf.
  • Retargeting (optional): If the business user explicitly requests it in the panel, we upload the email and phone information from the lead list in encrypted (hashed) form to their custom audience in their Meta ad account; this allows them to reach the same people again. This process is never done without the user pressing a button, and the data only goes to the user's own ad account.
  • How long is it stored: The data of the person filling out the form is stored for as long as the business account is active, for a maximum of 12 months ; after this period, it is automatically deleted. The business user can delete leads from the Leads list individually or in bulk at any time.
  • Deletion: When a business deletes its account or removes its Facebook connection, all associated lead records are deleted. Data deletion requests received via Facebook ( facebook/data-deletion/ ) also include these records.

2.7. Data Obtained via Google API

To provide our services and ensure account security, when a user signs in with Google (Google Sign-In) or grants access to Google APIs, the following types of data may be collected and processed (depending on the scope and API permissions you grant):

Requested Data Scope Intended Use
Google User Information .../auth/userinfo.profile It is used to personalize the user interface (name, surname, profile picture).
Primary Email Address .../auth/userinfo.email Secure authentication is used to send critical system notifications such as account creation and password reset.
Google Ads Account and Campaign Data .../auth/adwords This is only requested when the user explicitly connects their Google Ads account from Ad Center. It is used to list the Google Ads accounts the user can access, read campaign performance data (spending, clicks, conversions, etc.) from the selected account to provide reporting and optimization suggestions, and, with the user's explicit consent, to perform management actions such as creating, pausing/starting campaigns and changing budgets. The refresh token received for this purpose is stored encrypted on our servers and deleted when the connection is terminated.

Data Usage and Security Commitment (Google API Services User Data Policy — Limited Use):

All transactions are conducted through Google's secure OAuth/Token mechanism, and the granted permissions are securely stored and used only for the purposes stated in this clause. Data obtained from Google APIs is not sold or transferred to third parties for advertising purposes, and is not used for any purpose other than providing user-facing features as stated in this clause. Users can revoke their Google access permissions to Post AI Pilot at any time through their Google Account security settings .

Post AI Pilot's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy , including the Limited Use requirements.

2.8. Payment and Billing Information

In payment transactions:

  • Payment amount, currency
  • Payment date, transaction number
  • Invoice information (name/title, tax number, address)

Your credit card/debit card information is processed and stored by payment institutions such as İyzico Payment Services Inc.; the company does not see or store sensitive data such as card numbers, CVV, etc., in its own systems.

2.9. Technical and Usage Data

  • IP address
  • Device type, operating system, browser information
  • Session duration, page view counts
  • Usage analytics collected through cookies and similar technologies.
  • Error logs, performance and security logs.

This data is processed for system security, performance analysis, and improving user experience.

3. Purposes of Data Use

Your collected personal data may be used for the following purposes in accordance with the KVKK (Personal Data Protection Law) and relevant legislation:

  • Creating, managing, and verifying your user account.
  • Identifying the plans/packages and credits you purchased.
  • Providing AI-powered content creation and scheduling services.
  • Integration with Instagram and other social media accounts, scheduling and automated posting.
  • Processing payments, managing returns and billing processes.
  • System security, error detection, and prevention of attacks and abuse.
  • Improving our products and services, developing new features.
  • Generating usage statistics and anonymized/pseudonym analytical data.
  • With your explicit consent, we can send you commercial electronic messages regarding campaigns and new products.

4. Third-Party Service Providers and Data Sharing

Post ai Pilot may operate its technological infrastructure and some of its features through third-party services. In this context, your personal data may be shared with the following parties only to the extent necessary for the provision of the service and in accordance with the KVKK (Personal Data Protection Law):

4.1. Payment Institutions (Iyzico, etc.)

  • Payment processing
  • Fraud and security checks
  • Return and accounting processes

Your credit card information is processed only by these organizations; it is not stored by the Company.

4.2. Cloud and Infrastructure Providers (e.g., Google Cloud, AWS)

  • Hosting the platform
  • Data backup
  • Providing scalable, high-performance infrastructure.

Your data may be stored in the data centers of these providers (domestic/international).

4.3. Artificial Intelligence Services (OpenAI, etc.)

  • The prompts, texts, and images you enter (with masking/pseudonymization applied as much as possible)
  • Content creation and improvement processes

These services are used to provide Post AI Pilot's AI features. AI features may be disabled without your explicit consent.

4.4. Task Queue and Processing Systems (Celery, Broker, etc.)

  • Task IDs, job parameters, and status information can be accessed via a celery broker (Redis, RabbitMQ, etc.).
  • Metadata relating to content creation/planning/delivery processes running in the background.

Content or personal data may be processed. Wherever possible, this processing is limited to what is necessary for the business.

4.5. Analytics and Cookie Services (Google Analytics, Google Tag Manager, etc.)

  • Analyzing user behavior
  • Measuring site performance
  • Understanding which pages are used more often.

In this context, anonymized/anonymizable data obtained through cookies may be transferred to tools such as Google Analytics.

4.6. Social Media Platforms (Meta/Instagram, etc.)

  • Content scheduling and automated sharing via API.
  • Extraction of key insights and performance data (within permitted scope)

The company processes this data in accordance with Instagram/Meta's terms of use and policies.

5. Data Security

The company takes appropriate technical and administrative measures to protect your personal data against unauthorized access, loss, misuse, or disclosure. These include:

  • Access control mechanisms
  • Encryption techniques (in appropriate fields)
  • Firewalls and intrusion detection systems
  • Logging and monitoring processes

However, no system can be guaranteed to be 100% secure on the internet. Users are also responsible for taking basic security measures, such as not sharing their passwords with third parties and choosing strong passwords.

6. Children's Privacy

The platform is not designed for individuals under the age of 18. It is not intended for individuals under 18 to create accounts and share personal data without the permission of their parent/guardian. If such a situation is detected, the account will be reviewed and appropriate action may be taken.

7. Changes in Policy

The company may update this Privacy Policy at any time. The updated policy becomes effective from the moment it is published on the Platform. Important changes will be notified to the User as soon as possible.

8. Communication

For questions regarding our Privacy Policy and requests concerning your rights under the Turkish Personal Data Protection Law (KVKK):

Email: info@postaipilot.com

Address: Cevizli Mahallesi, Zuhal Caddesi, Ritim İstanbul Sitesi, A4 Blok, No: 46 D, Floor: 3, Apartment: 34, Maltepe / ISTANBUL

You can contact us through [email address].

Cookie Policy

(PostAIPilot – Post ai Pilot)

1. What are cookies?

Cookies are small text files that are saved to your device (computer, tablet, phone, etc.) via your browser when you visit a website. Thanks to cookies:

  • To keep your session on the site,
  • Remembering your preferences,
  • Measuring site performance,
  • Extracting usage statistics

It is possible.

2. Types of Cookies Used

The following types of cookies may be used on the platform:

2.1. Mandatory Cookies

These cookies are necessary for the site to perform its basic functions. Functions such as login, security, and form completion cannot work without these cookies. Explicit consent is not required for these cookies.

2.2. Performance and Analytical Cookies

It is used to generate anonymized statistics on how users use the site. For example:

  • Most visited pages
  • Click and browser errors
  • Session durations

These cookies are used to improve the site and enhance the user experience.

2.3. Functional Cookies

It can be used to remember your personal preferences such as language preference and theme selection. The aim is to provide the user with a more personalized experience.

2.4. Targeting/Advertising Cookies (If Used)

If remarketing or targeted advertising campaigns are planned for the future, these cookies may be used in conjunction with advertising partners. You can add a short description if you are currently using them or plan to use them; you can remove this section if you are not using them.

3. Third-Party Cookies

The following third-party cookies may be used on the platform:

  • Google Analytics: Used to collect visitor statistics and analyze site usage. For details on Google's cookie and data processing processes, please refer to Google's relevant documentation.
  • Meta Pixel: Can be used for measuring ad performance, tracking conversions, and remarketing activities. Data shared via Meta Pixel is processed by Meta as a data processor in accordance with relevant legislation.
  • (If available) Analytical/thermal mapping tools such as Hotjar, Mixpanel, etc.

Data collected through these cookies is generally anonymous/anonymizable, and no direct attempt is made to identify you. However, profiling based on data such as IP address may be technically possible; in this case, actions will be taken in accordance with the Personal Data Protection Law (KVKK) and relevant legislation.

4. How can you manage cookies?

You can control cookies using your browser settings.

  • It can completely block it,
  • You can only grant permission for specific sites.
  • You can delete previously saved cookies.

For popular browsers, cookie management is usually done under the "Settings / Privacy / Cookies" menu.

Please note that if you disable some or all cookies, some functions of the Platform may not work properly (e.g., login, planner, cart/plan selection, etc.).

Additionally, if you use a “Cookie Preferences” section/banner on the Platform: it's a good idea to always have “Mandatory cookies” active, and to offer “Accept / Reject / Customize Preferences” options for analytical and targeting cookies.

5. Changes to the Cookie Policy

This Cookie Policy may be updated from time to time. The most current version will always be available via postaipilot.com. Additional notifications may be provided as needed in case of significant changes.

Let AI Pilot Your Marketing

From content creation and social media to ad optimization and customer engagement — manage it all from one place.

Contact info@postaipilot.com
Post AI Pilot

A hybrid marketing platform that brings AI-powered content production, advertising, and messaging together in a single panel.

Solutions

  • Planner
  • Generate Image
  • Generate Video
  • Product Studio
  • Catalog Studio
  • Post AI Pilot Studio

Explore

  • Pricing
  • Credit Balance
  • Services
  • Portfolio
  • Blog

Company

  • About
  • Frequently Asked Questions
  • Contact
  • info@postaipilot.com
  • +90 542 656 07 00

Legal

  • KVKK Privacy Notice
  • Privacy & Cookie Policy
  • Distance Sales Agreement
  • Transaction and Terms of Use
  • Data Processing Agreement
  • Social Media Authorization Consent

© 2026 Post AI Pilot. All rights reserved.

iyzico Mastercard Troy
Supported by Google & AWS
Cookie Preferences
We use cookies to personalize your experience and improve our service quality. For details, Privacy and Cookie Policy you can review it.