The questions we are actually asked, answered plainly.
Can I sign up for MyPostiz?
No. MyPostiz is an internal application operated by Banto Inc. for the social media accounts Banto
Inc. owns. There is no public registration, no paid plan and no distribution of the software. This
website exists to document what the application does and how it treats data, not to sell it.
Why does the dashboard ask for a login?
Because it holds the access tokens for our own social media accounts. Anyone who reached it without
a login could publish to those accounts. The dashboard is at
postiz.banto-works.com; this documentation site is public
and needs no login.
Does MyPostiz store my social media password?
No, and it cannot. Accounts are connected through each platform's own authorisation screen. The
platform returns an access token, which is what MyPostiz stores. Passwords are never sent to, seen by, or
stored in the application.
What TikTok data does it read?
Only data belonging to the connected account: its display name, handle and avatar; its follower,
like and video counts; and its own list of posts, used to confirm that a scheduled post was really
published. It never reads other creators' content, direct messages, follower lists or comments. The
full breakdown is on the TikTok integration page.
Can it post to somebody else's account?
No. The only accounts it can publish to are accounts that were connected through the platform's
authorisation screen by the person who controls them. There is no feature for posting on behalf of a
third party, and no feature for accepting an account someone else connected.
Does it post automatically, without a person?
No. Every post is written and scheduled by a person before anything is sent. The automatic part is
only the timing: the application waits for the time that person chose and then publishes what that
person wrote. There is no mode that generates or publishes content on its own.
What happens when a publish fails?
The post is marked as an error and the platform's own message is stored and displayed — an expired
token, a rejected media file, a rate limit, or a policy refusal. It is not retried indefinitely and it is
never shown as published. The operator fixes the cause and reschedules it.
How do I disconnect an account?
Open the channel in the dashboard and remove it. The stored access token is deleted at that point and
the application can no longer publish to that account. Access can also be revoked from the platform's own
settings, which has the same effect.
How long is data kept?
Access tokens are kept only while the account is connected. Posts and their publish results are kept
while they are operationally useful and then deleted. Details and the deletion request address are in the
Privacy Policy.
Is any of this shared with third parties?
No. Nothing is sold, rented or shared, and none of it is used for advertising, profiling or training
machine-learning models. The only disclosure we would make is one required by law.