Privacy Policy
myna, by Profullstack, Inc. Last updated September 24, 2026.
What myna is
myna is a social media manager that runs on your own computer: a terminal app, a command line tool and a desktop app. You connect your social accounts, write a post once, and myna publishes it to the networks you choose, now or on a schedule. mynaposter.com hosts the website, the installer, the sign-in pages that hand a login back to myna on your machine, and the optional myna cloud service.
What stays on your computer
Almost everything. The accounts you connect, and the access tokens and keys for them, are kept in an encrypted vault in myna's configuration folder on your machine (~/.config/myna). Your drafts, your post queue, your posting history and your contacts are stored there too. We do not receive them.
What reaches us
- Visiting the website. Our hosting provider records standard request logs (IP address, time, the page asked for, browser) for security and troubleshooting, and keeps them for a short time.
- Sign-in pages. When you connect an account, the network sends your browser back to a page on mynaposter.com with a one-time authorization code. The page runs in your browser and hands the code straight to myna on your computer, which exchanges it for a token. The code is single use, expires within minutes, and cannot be used without credentials that stay on your machine. We do not store it.
- myna cloud, only if you sign up. Your email address and a session. If you turn on settings sync, your myna settings, profile and skills (plain text you wrote; never your vault or tokens). If you run
myna cloud push, a copy of your connected accounts sealed with a passphrase only you know; we cannot open it. Features you choose to use, such as hand-off cards, directory listings or newsletter subscriber lists, store what they need to work. - Email from us. Sign-in links and messages you ask for, sent through an email delivery provider.
Third-party services and integrations
When you post, myna sends your content to the networks you picked, under their own terms and privacy policies. Some integrations work through another provider (for example an advertising, analytics, directory or outreach service you connect or turn on). In those cases myna may need to share certain information with that provider so the feature works, such as your public handle, the link to a post, the text of a listing, or the email address you gave it. myna only shares what that integration needs, only when you have connected or enabled it, and tells you in the app what it sends. We use hosting, database and email delivery providers to run mynaposter.com and myna cloud; they process data only on our behalf.
Google user data
myna can connect to Google Calendar, only if you choose to. When you run myna login gcal and approve access, myna asks for:
https://www.googleapis.com/auth/calendar.events: to create events you ask for (myna calendar add, or a post to thegcaltarget), to add an event for each post you schedule and remove it if you cancel the post (myna calendar auto, which you can turn off), to delete an event you name (myna calendar remove), and to show your upcoming events in your terminal when you runmyna calendar list.https://www.googleapis.com/auth/calendar.calendarlist.readonly: to find your primary calendar when you sign in, and to list your calendars (myna calendar calendars) so you can pick which one myna writes to.
myna reads your events only when you run myna calendar list, and then only the upcoming ones, printed on your own screen; it never changes or deletes an event it did not create unless you name that event in myna calendar remove. Event data goes directly between your computer and Google: it is not sent to mynaposter.com or myna cloud and is not stored by us. The Google access and refresh tokens are stored only in the encrypted vault on your computer; they are not sent to mynaposter.com or myna cloud (unless you run myna cloud push, which uploads them sealed with a passphrase we never see). Google user data is not sold, not used for advertising, not used to train AI or machine learning models, and not shared with anyone except as needed to provide the calendar feature you turned on or as required by law.
myna's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
To disconnect, run myna logout gcal:<your address>, which deletes the tokens from your computer, and remove myna at myaccount.google.com/permissions. Events myna already created stay in your calendar until you delete them.
How long we keep things
Data on your computer stays until you delete it or uninstall myna. myna cloud data stays while your account exists; delete your account (or email us) and we delete it within 30 days, apart from what we must keep by law. Request logs are kept for a short time and then discarded.
Your choices and rights
You can use myna without a myna cloud account. You can see, export or delete your myna cloud data, or ask us to, by emailing hello@profullstack.com. Depending on where you live you may have further rights (for example under the GDPR or CCPA); we honour them. We do not sell personal information.
Security
Credentials are encrypted at rest on your machine, connections to us use HTTPS, and sign-ins use OAuth with PKCE so no password passes through myna. No system is perfectly secure; tell us about a problem at hello@profullstack.com.
Children
myna is not meant for children under 13, and we do not knowingly collect their data.
Changes
We will update this page when what myna does changes, and change the date at the top. Significant changes will be announced on this site.
Contact
Profullstack, Inc. · hello@profullstack.com. This policy sits alongside the Profullstack privacy policy; where they differ for myna, this page applies.