PulsarPromo — Privacy Policy
Last updated: 23 August 2026
Who we are
PulsarPromo is a social-media publishing console operated by AronKan LLC, 7901 4th St N STE 4702, St. Petersburg, FL 33702, United States.
You can reach us at contact@aronkan.org or at the postal address above.
What this product is
PulsarPromo lets a business plan, publish, moderate and measure its own social-media posts from one place, across Facebook Pages, Instagram, YouTube and TikTok.
A business connects its own accounts to us and tells us what to do with them. We do not obtain accounts on anyone's behalf, we do not post without being told to, and we do not use one business's material for another's.
The two roles we play — read this first
For a business that uses the console, we act on its instruction. The posts, captions, media and connected accounts belong to that business. We hold them so the product can work, and we act only on what that business asks for. If you are a customer or a follower of such a business, we are not the people deciding what happens to your information — they are.
For our own account holders, we decide. The sign-in that reaches the console, and the record of which business it belongs to, are ours.
What we connect to, and what we take
When a business connects an account, the platform shows it a consent screen listing exactly what it is granting, and it grants it — not us. From that point we can do only what it agreed to:
- Read the business's own posts, the comments on them, and the performance figures for them.
- Write posts to the business's own account, edit a caption, reply to a comment, hide or delete a comment, and block a person from the business's Page.
We never read a private message, a follower list, or anything belonging to an account that has not been connected to us.
What we store
This is the complete list.
| What | Why |
|---|---|
| The business's workspace and brands | To keep each business's material separate from every other's |
| Connected accounts — the platform, the account handle, the platform's own id for it, what was granted, and when it expires | To know which account a post goes to, and to warn before access lapses |
| Access tokens, encrypted | The credential that lets us act for the business. See below |
| Publications — the title, caption, notes, the platform's post id, the link to the live post, its status, and when it was scheduled or published | This is the console's record of what was posted and what happened to it |
| Media you upload to post | So it can be attached to a post |
| Performance figures — reach, impressions, likes, comments and similar counts | To show how a post did |
| Who confirmed that a paid-partnership label was switched on, and when | Because publishing paid content for a client without disclosure is not something a checkbox should be able to claim |
| Operational records — publishing attempts, scheduler runs, API usage against the platform's daily allowance, and alerts | To run the service and to diagnose it when something fails |
Access tokens
A token is the thing that can act on a business's account, so it gets its own handling. Tokens are encrypted before they are written down, using a key held in a separate file outside the database and outside our source code. Anyone reading the database alone gets ciphertext.
We keep the metadata — expiry, what was granted, when it was last checked — unencrypted on purpose, so we can warn a business that its access is about to lapse without unwrapping the token to find out.
What we deliberately do not store
We think this list matters as much as the one above.
- Comments and the people who write them. The console reads comments live from the platform, shows them, and does not keep them. There is no comments table in our database. When you close the screen, we are not still holding what somebody wrote or who wrote them.
- IP addresses. We do not record the IP address of anyone who clicks a link or views a post.
- Browser user-agent strings. Where the product records a click on a tracked link at all, it keeps only a coarse classification — broadly, whether the click looked automated — and the instant it happened. Not the raw string, and nothing that identifies a device or a person.
- Anything about a business's own customers. We hold the business's posts, not its client list.
⚠️ The tracked-link feature above is not switched on. The service that would receive a click is not installed and not running, and no click has ever been recorded.
What we use it for
To publish what a business asks us to publish, when it asks, to show it what happened, and to tell it when something is wrong — an expiring credential, a failed post, a daily allowance nearly spent.
What we never use it for
We do not sell anything. We do not build advertising profiles, we run no advertising network inside this product, we do not track anyone across other websites, and we do not use one business's posts, figures or media to serve another business. We do not use what we hold to train anything.
Who else processes it
The social-media platforms themselves — Meta (Facebook and Instagram), Google (YouTube) and TikTok — receive what is published to them and return what the console displays. Each has its own terms with the business that connected the account.
The service runs on infrastructure operated by AronKan LLC in the United States.
How long we keep it
We keep a business's material for as long as its workspace exists. Nothing is deleted merely because time has passed — we would rather say that plainly than publish a retention schedule we do not operate.
A token is deleted when the account is disconnected, or when the business's workspace is deleted.
Disconnecting and deletion
Disconnecting an account removes our stored token for it. We can no longer read or write anything on that account. The posts we already published stay on the platform, because they belong to the account, and our own record of having published them stays in the console.
A business can also revoke our access from the platform's side, without us — in Facebook or Instagram under Settings → Business integrations, and in a Google Account under Security → Third-party access. Doing so stops us immediately.
To have everything deleted, including the workspace, the publication records and the uploaded media, see Data deletion, which sets out exactly what is removed and how long it takes.
Security
Access to the console requires a sign-in, and the console is additionally placed behind an identity check at the network edge. Tokens are encrypted at rest as described above. We do not send credentials in email.
Children
This is a tool for businesses. It is not directed at children and we do not knowingly hold information about them.
Changes to this policy
If we change what we collect or what we do with it, we will change this page and update the date at the top rather than let it go quietly stale.
Contact
Write to contact@aronkan.org, or to AronKan LLC, 7901 4th St N STE 4702, St. Petersburg, FL 33702, United States.