What we do to protect the social accounts you connect, the messages we reply to and your own account, where your data is stored, and what we do not claim. Every point on this page describes how PersonaXpand works today.
Accounts connect through each network's official login, so you sign in with the network itself and we only receive a key you can cancel.
The access keys we hold for your accounts are encrypted with AES-256-GCM before they are saved.
AI replies to DMs, comments and mentions are held for your approval unless you choose to let them send on their own.
Every network connects through its official login (OAuth). You sign in on the network's own page, approve what PersonaXpand may do, and the network gives us a key for those actions. We never see or store your social media password. The one exception is Telegram, where you paste a bot token that you create in Telegram yourself.
When you disconnect an account, PersonaXpand stops posting and replying with it straight away. Where the network offers a way to cancel access, we also ask it to cancel ours, and you can always remove PersonaXpand from the network's own settings as well.
Auto-replies are off for every account until you switch them on. When you do, replies to DMs, comments and mentions wait for your approval by default, and you choose whether any of them may send without you. Daily limits stop a busy post from producing a flood of replies.
PersonaXpand runs on Microsoft Azure, and your data is stored in Azure's India region. We chose that region for its capacity and its cost, which helps keep PersonaXpand affordable. Every service that receives any of your data, and why, is listed in the privacy policy.
AI drafts and replies are written by Google Gemini through Google's paid API. Under Google's terms for paid use, your prompts and the replies are not used to improve Google's products and are logged only for a limited time to detect abuse. If Gemini is unavailable, the same request may go to OpenAI as a backup so the feature keeps working.
Nothing is sent to an AI provider unless you use an AI feature: auto-replies are off until you switch them on, and AI writing tools run only when you press them.
When you delete your account you have seven days to change your mind by signing in again. After that, your account and content are permanently deleted, and we ask Facebook, Instagram, Google, YouTube, X and TikTok to cancel our access. We keep only a small amount of usage and anti-abuse records, for example to stop repeat free-trial sign-ups.
PersonaXpand is not SOC 2 or ISO 27001 certified, and we have not published a third-party penetration test. Sign-in does not offer one-time codes from an authenticator app yet; passkeys are the stronger option we offer today. We would rather tell you this than let you assume otherwise.
If you think you have found a security problem in PersonaXpand, email [email protected] with the details and how to reproduce it. Please do not test against other people's accounts or data. Our contact details are also published in security.txt.
PersonaXpand is built to be simple. You do not need any experience with social media tools to get started.
Connect your accounts through each network's official login and stay in control of every reply.
Get startedOptional analytics cookies help us improve the site. Essential ones always stay on. Privacy Policy