ConFYI ConFYI Post

On this page

Who we are The service Data we collect How we use data Who we share with Retention Security Your rights Contact
ConFYI Post / privacy

Privacy Policy

Last updated: May 3, 2026

This Privacy Policy explains how ConFYI Post (“ConFYI Post”, “we”, “us”, or “our”) collects, uses, shares, and protects personal data in connection with the ConFYI Post social-media scheduling, publishing, analytics, and team-collaboration service (the “Service”), the website at post.con.fyi and related pages (the “Site”). It applies to visitors, account holders, workspace members, prospects, support contacts, and anyone else who interacts with us. By using the Site or Service, you acknowledge this Policy. Our contractual terms are in the Terms of Service.

1. Who we are

The Service is operated by Open Growth Group INC, a corporation incorporated in Delaware, USA. In this Policy, “ConFYI Post”, “we”, “us”, and “our” mean Open Growth Group INC.

Open Growth Group INC operates this ConFYI Post deployment and its configured integrations. The deployment uses Postiz software and may connect to third-party social platforms, but it is not operated by postiz.com or by any connected platform.

For privacy questions, requests, or complaints, contact hello@opengrowthgroup.co.

2. The Service in brief

ConFYI Post lets approved teams connect social-media and communication channels to centrally schedule, publish, analyse, and collaborate on content. Features include a calendar and scheduling engine, media library, publishing queue, analytics, team and workspace management, and integrations with third-party platforms. Features and supported channels depend on the configuration and platforms you choose to connect.

3. The data we collect

3.1 Account and identity data

We may collect your name, email address, password credential or salted password hash, profile picture, organisation name, role, language, timezone, workspace membership, invitations, and permissions. If you sign in through another provider, we receive the basic profile fields and email that provider returns.

3.2 Connected-platform data

When you connect a third-party social or messaging account, we receive and store data made available through that platform’s API, including OAuth access and refresh tokens, granted scopes, platform usernames and identifiers, profile and page metadata, channel IDs, and content or engagement data needed to provide the Service.

This can include posts you create or schedule, published-post records, comments, replies, direct messages where you explicitly enable that feature, analytics, and audience-level aggregates exposed by the platform. You can revoke access from the connected platform at any time. For YouTube, use of the integration is also subject to the YouTube Terms of Service and Google Privacy Policy.

3.3 Content you provide

We collect text, images, video, audio, captions, links, hashtags, schedules, prompts, comments, approval notes, calendar metadata, and other content you upload to or generate within the Service.

3.4 Billing data

If a paid plan is offered, we collect plan, subscription, invoice, billing-contact, billing-address, and tax information needed to administer it. Payment-card and bank-account details are collected directly by the relevant payment processor. We receive only the tokenised reference and limited payment metadata needed for reconciliation and support.

3.5 Logs, usage, and device data

We may collect IP address, user-agent, browser and operating-system details, device identifiers, referrer URL, language, approximate location derived from IP, pages visited, features used, posts created or published, API calls, error reports, performance metrics, login timestamps, session data, and security events.

3.6 Communications and support data

We collect messages sent by email or support channels, surveys, feedback, feature requests, and engagement information for marketing messages where applicable.

3.7 Cookies and similar technologies

We use cookies, local storage, pixels, and similar technologies for authentication, security, preferences, analytics, and service operation. You can manage non-essential cookies through available controls or your browser settings. Disabling strictly necessary cookies may prevent parts of the Service from working.

4. How we use data and legal bases

We process personal data to:

  • provide the Service, authenticate users, manage workspaces, store and publish content, return analytics, and provide support (performance of contract);
  • administer commercial plans, issue invoices, prevent payment fraud, and comply with tax obligations where applicable (performance of contract; legal obligation);
  • secure the Service, detect abuse and account takeover, investigate incidents, and enforce the Terms (legitimate interests; legal obligation);
  • operate, maintain, debug, monitor, and improve a reliable Service (legitimate interests);
  • send service-related messages and, where permitted or opted into, marketing communications (performance of contract; consent or legitimate interests); and
  • respond to lawful requests, defend claims, and comply with law (legal obligation; legitimate interests).

We do not sell personal data. We do not use the content of scheduled posts, connected-platform content, or private messages to send advertising.

5. AI-assisted features

Optional AI features may generate or rewrite captions, hashtags, image prompts, video scripts, or analytics summaries. To provide them, we may transmit prompts and the inputs you choose to include to third-party model providers acting as service providers. We ask those providers to protect your inputs and not use them to train their models except where you expressly opt in or a separate disclosed provider policy applies. AI output may be inaccurate; you remain responsible for reviewing it before publication.

6. Controller and processor roles

For account, billing, Site analytics, marketing, and security data, Open Growth Group INC acts as a data controller.

For content you publish through the Service and personal data about your audience, followers, customers, or message contacts that flows through the Service on your instructions, you may be the controller and Open Growth Group INC may act as your processor. You are responsible for having a lawful basis, providing notices, and honouring rights for that processing. Additional data-processing terms may apply where required.

7. Who we share data with

We do not sell or rent personal data. We share it only as needed to provide and protect the Service:

  • Hosting and service providers. Cloud hosting, storage, database, email, monitoring, support, analytics, payment, and AI providers process data under appropriate contractual and security controls.
  • Connected platforms. When you schedule or publish, we transmit the selected content to the platform you chose and receive data when you request analytics. That platform’s policy governs its subsequent use.
  • Workspace members. Content, schedules, comments, and approvals may be visible to members of the workspaces you join, according to their roles and permissions.
  • Professional advisers and authorities. Accountants, lawyers, insurers, regulators, courts, and law-enforcement authorities may receive data where confidential advice, legal compliance, fraud prevention, security, or protection of people requires it.
  • Successor entities. Data may transfer in a merger, acquisition, financing, reorganisation, or sale of assets, subject to continued protection or notice of a changed policy.

8. International data transfers

Open Growth Group INC is incorporated in Delaware, USA, and our providers may process data in the United States, the European Union, the United Kingdom, and other jurisdictions. Your data may therefore be transferred outside your country. Where required by applicable law, we use recognised transfer safeguards such as Standard Contractual Clauses and appropriate technical and organisational measures.

9. Data retention

  • Account data is kept while your account is active and ordinarily for up to 90 days after closure to allow recovery, unless longer retention is required.
  • Unpublished scheduled content is kept until publication or deletion.
  • Published-post records and analytics are kept while the account is active so historical reporting remains available.
  • OAuth tokens are kept while a connection is active; revoked tokens are deleted promptly.
  • Billing records are retained for the period required by tax and accounting law.
  • Operational and security logs are ordinarily retained for up to 12 months, while encrypted backups roll off on their normal schedule.

We may retain data longer where necessary for legal, regulatory, dispute-resolution, security, or fraud-prevention reasons.

10. Security

We maintain administrative, technical, and physical safeguards designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Measures may include TLS, encryption of sensitive credentials, password hashing, role-based access controls, least-privilege access, audit logging, vendor commitments, and incident-response procedures. No system is completely secure, and we cannot guarantee absolute security.

11. Your rights

Depending on where you live, you may have the right to access your personal data, receive a portable copy, request correction or deletion, object to or restrict processing, withdraw consent, and lodge a complaint with your supervisory authority. ConFYI Post does not sell personal data or share it for cross-context behavioural advertising.

Most changes can be made in your account, profile, workspace, or integrations settings. For requests that cannot be handled in-product, email hello@opengrowthgroup.co. We may verify your identity and will respond within the time required by applicable law. We will not discriminate against you for exercising your rights.

12. California privacy rights

If you are a California resident, applicable California privacy laws may provide rights to know, delete, correct, limit certain uses of sensitive personal information, and receive equal treatment when exercising those rights. ConFYI Post does not sell personal information or share it for cross-context behavioural advertising. Contact hello@opengrowthgroup.co to exercise California rights.

13. Children

The Service is intended for business use and is not directed to children. We do not knowingly collect personal data from children under 18. If you believe a child provided personal data, contact us at hello@opengrowthgroup.co and we will investigate and delete it where required.

14. Marketing and cookie choices

You can unsubscribe from marketing emails using the unsubscribe link in the message. This does not stop transactional and account-related messages. You can manage cookie preferences through available Site controls or your browser settings.

15. Third-party sites and services

The Site and Service link to and integrate with third-party services. Their handling of data is governed by their own privacy policies, not this one. Review the privacy policy of each platform you connect to ConFYI Post, including the Google Privacy Policy for YouTube integrations.

16. Changes to this Policy

We may update this Policy from time to time. If a change is material, we will provide reasonable notice before it takes effect. The date at the top of this page shows when the Policy was last updated.

17. Contact us

For privacy questions, requests, or complaints:

Open Growth Group INC
Delaware, USA
hello@opengrowthgroup.co

ConFYI Post information© 2026 Open Growth Group INC