← PulsarPromo

PulsarPromo — Privacy Policy

Last updated: 23 August 2026

Who we are

PulsarPromo is a social-media publishing console operated by AronKan LLC, 7901 4th St N STE 4702, St. Petersburg, FL 33702, United States.

You can reach us at contact@aronkan.org or at the postal address above.

What this product is

PulsarPromo lets a business plan, publish, moderate and measure its own social-media posts from one place, across Facebook Pages, Instagram, YouTube and TikTok.

A business connects its own accounts to us and tells us what to do with them. We do not obtain accounts on anyone's behalf, we do not post without being told to, and we do not use one business's material for another's.

The two roles we play — read this first

For a business that uses the console, we act on its instruction. The posts, captions, media and connected accounts belong to that business. We hold them so the product can work, and we act only on what that business asks for. If you are a customer or a follower of such a business, we are not the people deciding what happens to your information — they are.

For our own account holders, we decide. The sign-in that reaches the console, and the record of which business it belongs to, are ours.

What we connect to, and what we take

When a business connects an account, the platform shows it a consent screen listing exactly what it is granting, and it grants it — not us. From that point we can do only what it agreed to:

We never read a private message, a follower list, or anything belonging to an account that has not been connected to us.

What we store

This is the complete list.

What Why
The business's workspace and brands To keep each business's material separate from every other's
Connected accounts — the platform, the account handle, the platform's own id for it, what was granted, and when it expires To know which account a post goes to, and to warn before access lapses
Access tokens, encrypted The credential that lets us act for the business. See below
Publications — the title, caption, notes, the platform's post id, the link to the live post, its status, and when it was scheduled or published This is the console's record of what was posted and what happened to it
Media you upload to post So it can be attached to a post
Performance figures — reach, impressions, likes, comments and similar counts To show how a post did
Who confirmed that a paid-partnership label was switched on, and when Because publishing paid content for a client without disclosure is not something a checkbox should be able to claim
Operational records — publishing attempts, scheduler runs, API usage against the platform's daily allowance, and alerts To run the service and to diagnose it when something fails

Access tokens

A token is the thing that can act on a business's account, so it gets its own handling. Tokens are encrypted before they are written down, using a key held in a separate file outside the database and outside our source code. Anyone reading the database alone gets ciphertext.

We keep the metadata — expiry, what was granted, when it was last checked — unencrypted on purpose, so we can warn a business that its access is about to lapse without unwrapping the token to find out.

What we deliberately do not store

We think this list matters as much as the one above.

⚠️ The tracked-link feature above is not switched on. The service that would receive a click is not installed and not running, and no click has ever been recorded.

What we use it for

To publish what a business asks us to publish, when it asks, to show it what happened, and to tell it when something is wrong — an expiring credential, a failed post, a daily allowance nearly spent.

What we never use it for

We do not sell anything. We do not build advertising profiles, we run no advertising network inside this product, we do not track anyone across other websites, and we do not use one business's posts, figures or media to serve another business. We do not use what we hold to train anything.

Who else processes it

The social-media platforms themselves — Meta (Facebook and Instagram), Google (YouTube) and TikTok — receive what is published to them and return what the console displays. Each has its own terms with the business that connected the account.

The service runs on infrastructure operated by AronKan LLC in the United States.

How long we keep it

We keep a business's material for as long as its workspace exists. Nothing is deleted merely because time has passed — we would rather say that plainly than publish a retention schedule we do not operate.

A token is deleted when the account is disconnected, or when the business's workspace is deleted.

Disconnecting and deletion

Disconnecting an account removes our stored token for it. We can no longer read or write anything on that account. The posts we already published stay on the platform, because they belong to the account, and our own record of having published them stays in the console.

A business can also revoke our access from the platform's side, without us — in Facebook or Instagram under Settings → Business integrations, and in a Google Account under Security → Third-party access. Doing so stops us immediately.

To have everything deleted, including the workspace, the publication records and the uploaded media, see Data deletion, which sets out exactly what is removed and how long it takes.

Security

Access to the console requires a sign-in, and the console is additionally placed behind an identity check at the network edge. Tokens are encrypted at rest as described above. We do not send credentials in email.

Children

This is a tool for businesses. It is not directed at children and we do not knowingly hold information about them.

Changes to this policy

If we change what we collect or what we do with it, we will change this page and update the date at the top rather than let it go quietly stale.

Contact

Write to contact@aronkan.org, or to AronKan LLC, 7901 4th St N STE 4702, St. Petersburg, FL 33702, United States.