Last Updated:

You're right to ask. Handing an AI assistant access to your Instagram, your TikTok, or your business's entire social presence is not a small decision, and it deserves a direct answer, not a reassurance. Here is the real risk, and exactly what Planoly's connector does about each part of it. For the full underlying reference, see Planoly's MCP hub.
Three problems show up across the MCP ecosystem broadly, and they are worth naming plainly.
On scopes. Every tool Planoly's connector exposes is published and labeled, marked clearly as read-only or as a destructive action. Nothing hides behind a vague permission grant.
On steering. Tool descriptions state what an action does in plain terms. They do not instruct the model to take additional actions beyond what you asked for.
On credentials. Authorization runs through per-user OAuth, tied to your Planoly login. No password is stored in a config file, on your computer, or anywhere Claude, ChatGPT, or any other client can read it directly.
Read-only tools: viewing scheduled posts, reading performance data, listing connected channels, browsing the media library.
Write tools requiring confirmation: creating a draft post, scheduling a post, editing a caption, uploading media.
Destructive tools requiring explicit confirmation: deleting a scheduled post, removing a media library item.
Tools that do not exist in this connector at all: connecting a new social account, disconnecting an existing one, changing account-level settings, publishing without landing in a draft or scheduled slot first.
Nothing publishes without a review step. Every post the assistant creates lands as a draft or a scheduled item, not a live post. Connecting and disconnecting accounts stays entirely in your hands, inside Planoly's own settings, not something an assistant can trigger. That boundary is intentional, and it stays in place regardless of which AI client you connect.
Apply the same three questions to any MCP server before you connect it: does it publish a clear, scoped tool list, does it require per-user authorization instead of a shared credential, and does it require your explicit confirmation before a destructive or public-facing action. A connector that fails any of the three deserves more scrutiny before it touches a real account. We hold Planoly's own connector to that same bar, and we will say so plainly if that ever changes.
If you've already reviewed this and want the setup steps themselves, Planoly's connection walkthrough covers Claude, ChatGPT, Claude Code, and the Gemini CLI. If you're already set up with Claude, you can find Planoly directly in the Claude Connector Directory.
Does Planoly's connector store my social media passwords?
No. Authorization runs through your Planoly login, not a stored password.
Can the assistant connect or disconnect my accounts on its own?
No. That action does not exist in the connector at all. It happens only inside Planoly's own settings, by you.
Can a post publish without my approval?
No. Every post lands as a draft or a scheduled item first.
What should I check before connecting any MCP server, not just Planoly's?
A clear, scoped tool list, per-user authorization, and required confirmation before any destructive or public action.
The honest answer is that risk in this category is real, and it comes from vague scopes and stored credentials, not from AI assistants generally. Ask any connector to show you its boundaries. If it can't, that's your answer.