Privacy policy
Last updated 4 October 2026
Schedulely is a social media scheduler and comment inbox run by the operator of this service (“we”). Businesses and agencies (“customers”) use it to plan, approve and publish posts on Instagram and X, and to sort and answer the comments and direct messages those posts bring in. This policy explains what we collect, why, and the choices you have.
What we collect
- Your Schedulely account: your name and email address, and how you signed in (email or Google). Sign in is handled by Clerk on our behalf; we never see your Google password.
- From Instagram and X, when an account is connected: the account's id, username, display name and profile picture, an access token that lets us act for it, and the permissions it granted. We never see or store your Instagram or X password.
- Comments and direct messages: the comments on the account's recent posts and its direct message conversations, with the sender's username and the time, so the team can read, label and answer them in one inbox. Labels (complaint, lead, question, praise, spam) are set by simple rules inside Schedulely; nothing is sent to any other service to do this.
- Content you schedule: captions, photos, videos, scheduling times, and the ids and links of posts once they are published.
- Approval feedback: approval decisions and comments left on review pages.
- Technical records: IP addresses and device types of people who sign in or use our links, kept in a security activity log.
We don't use advertising trackers or analytics cookies.
How we use it
Only to provide the service: to publish the posts you scheduled, to show comments and messages in your inbox and send the replies you write, to keep your access working (Instagram tokens are renewed automatically), to keep a record of who did what, and to keep the service secure. We don't sell or rent your data, we don't use it for advertising, and nothing is published or replied to unless a person in your workspace prepared it.
Who can see it
Each customer has a private workspace. Only the people that customer invites can see its clients, accounts, posts, comments and messages. Clients a customer invites see only their own business. Our team accesses a workspace only to support it or when the law requires it.
Who we share it with
Instagram (Meta) and X receive the posts and replies we send on your behalf, as needed to send them. Clerk handles sign in, and our hosting provider stores the data, both on our behalf. We share nothing else unless the law requires it.
How we protect it
Access tokens are encrypted in our database. All connections use HTTPS. Every action is recorded in an activity log that shows if it has been altered.
How long we keep it
Account data and tokens are kept while the account is connected. When you disconnect an account, or remove our app in Instagram's settings, we delete its access tokens straight away. Posts, comments, messages and the activity log are kept while the workspace exists, as the customer's business record, unless you ask us to delete them.
Your choices
- Remove access: in Instagram, go to Settings → Apps and websites and remove our app; on X, go to Settings → Security and account access → Apps and sessions. We stop immediately.
- Delete your data: see Data deletion.
- See or correct your data: contact us.
Contact
Questions or requests: us through the contact link on our website.