BlastCP

Privacy Policy

Effective September 22, 2026

BlastCP ("BlastCP", "we", "us") provides a posting-queue application at blastcp.com that drafts, schedules, and publishes posts to social platforms — for people and for AI agents acting on their behalf. This policy explains what data we collect from people who use our site and application, how we use it, and the choices you have.

1. Information we collect

Account information. When you sign in with Google or a magic-link email, we receive your name, email address, and profile photo (if provided by Google). We use Supabase Auth to manage sign-in and store session data.

Workspace. We store your workspace's name and slug, and who is a member of it.

Content you create. Posts you draft or schedule — the text, a promoted link, and that link's preview card (title, description, image) — plus your workspace's posting schedule, are stored so the product can function.

Connected channels. When you connect a LinkedIn or Substack account so BlastCP can post on your behalf, we store the credentials needed to do that. See "Connected publishing accounts" below for what each one involves.

Link previews. When a post promotes a URL, we fetch that page's public OpenGraph tags on our server to build the preview card, unless you fill the card in yourself. We don't record what you browse — only the URL you attach to a post.

Contact information. If you email support, we store the email address and message you send.

2. How we use information

3. Connected publishing accounts: LinkedIn and Substack

LinkedIn. Connecting LinkedIn uses OAuth. We receive an access token, valid for 60 days and not automatically renewed, with the scopes openid profile email w_member_social. We store that token encrypted at rest and use it only to publish the posts you or your agent schedule through BlastCP — never to read your LinkedIn activity, and never to post anything you didn't queue. Disconnecting revokes the token at LinkedIn and removes it from our database.

Substack. Substack has no OAuth, so connecting it means pasting your own Substack session cookie. We store that cookie on our server and send it only to substack.com, and we use it only to create draft posts in your publication — BlastCP never publishes to Substack itself, only drafts. This is plainly full access to your Substack account, equivalent to being signed in as you, so treat it with the same care as a password. You can end this access at any time, either by disconnecting in BlastCP or simply by signing out of that session on Substack, which invalidates the cookie. Disconnecting deletes the stored cookie.

Any edit you or your agent makes to a scheduled post is applied before it publishes; nothing is sent to LinkedIn or Substack until the scheduled time.

4. AI agents and MCP access

BlastCP is built to be used by an AI agent on your behalf, over a protocol called MCP. Connecting an AI client issues it an OAuth 2.1 access token scoped to your account. We store only a one-way hash of that token, never the token itself, and you can revoke it at any time from your workspace settings. While connected, the agent acts as you: it can draft and schedule posts, and — if your workspace allows agents to publish without a person's approval — publish them, exactly as if you had done it yourself.

5. AI training

We do not use anything you create or connect in BlastCP — post text, links, or content from a connected account — to train AI models, ours or anyone else's.

6. Third-party services

We rely on the following processors to operate BlastCP:

Each of these providers processes data under its own privacy policy and only to the extent necessary to provide their service to us.

7. Cookies

We use a session cookie to keep you signed in, managed by Supabase Auth. We don't currently run any analytics or advertising cookies.

8. Data retention

We retain account and content data for as long as your account is active. You may request deletion of your account and associated data at any time by contacting us (below); we will delete it within a reasonable period, except where retention is required by law.

9. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to withdraw consent to processing. To exercise any of these rights, contact us at the email below.

10. Security

We use industry-standard measures — encrypted transport (HTTPS), encryption at rest for connected-account credentials, access-controlled databases, and secure session cookies — to protect your data. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

11. Children

BlastCP is not directed at children under 13, and we do not knowingly collect personal information from them.

12. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the effective date above.

13. Contact

Questions about this policy or your data? Email support@blastcp.com.