Legal
Privacy Policy
Effective date: June 1, 2026 · Last updated: June 1, 2026
Postless ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, share, and protect your personal data when you use the Postless platform, website, and services (collectively, "the Service").
By using Postless, you agree to the collection and use of your data as described in this policy. If you do not agree, please do not use our Service.
This policy applies to all users globally and is designed to comply with applicable privacy laws including the General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA), and other relevant regional data protection regulations.
Our service is intended for adults aged 18 and over. We do not knowingly collect data from children under 13.
1. Who We Are (Data Controller)
For the purposes of applicable data protection laws, the data controller is:
- Postless
- Website: https://postless.app
- Contact: [email protected]
If you are located in the European Economic Area (EEA) or the UK, Postless acts as the data controller for the personal data you provide to us.
2. What Data We Collect
Data You Provide Directly
- Account information: name, email address, password (hashed and encrypted)
- Profile and brand information: your job title, industry, target audience, brand tone, and content goals
- Content inputs: links, articles, ideas, screenshots, and other material you upload to generate posts
- Payment information: billing name, address, and payment card details (processed securely by Stripe — we do not store raw card data)
- Communications: messages and emails you send to our support team
Data We Collect Automatically
- Usage data: pages visited, features used, actions taken within the platform, session duration
- Device and browser data: IP address, browser type, operating system, device identifiers
- Log data: server logs, error reports, performance metrics
- Cookies and similar tracking technologies (see Section 9)
Data from Social Media Platforms
When you connect your social media accounts (such as LinkedIn, X/Twitter, Instagram, Facebook, Threads, TikTok, or Bluesky), we collect:
- OAuth access tokens to post on your behalf (stored securely and encrypted)
- Basic profile information provided by those platforms (e.g. username, profile picture)
- Post performance data where permitted by the platform's API (e.g. engagement metrics)
We only request the minimum permissions needed to provide the Service. You can revoke access to any connected account at any time from within Postless or directly from the social media platform.
Data from AI Processing
When you use our AI content generation features, the inputs you provide (brand goals, article links, ideas, image content) are processed by our AI infrastructure. This processing involves third-party AI providers (see Section 6). We do not use your content to train AI models without your explicit consent.
3. How We Use Your Data
We use your personal data for the following purposes:
- To create and manage your account
- To provide the core features of the Service, including AI content generation, scheduling, and multi-platform publishing
- To process payments and manage your subscription via Stripe
- To send transactional emails (account confirmations, password resets, post approval notifications) via Resend
- To analyse platform usage and improve the Service
- To detect and prevent fraud, abuse, or security incidents
- To comply with legal obligations
- To send you product updates and marketing communications (only where you have opted in, and with an easy opt-out at any time)
Our legal bases for processing your data (under GDPR) are:
- Contract: processing necessary to deliver the Service you've signed up for
- Legitimate interests: improving the platform, preventing fraud, ensuring security
- Consent: marketing communications and certain cookie usage
- Legal obligation: complying with applicable laws and regulations
4. How We Store Your Data
Your data is stored on secure infrastructure hosted on Amazon Web Services (AWS), deployed via Docker containers. Our application database is powered by Supabase Postgres, managed through Prisma ORM.
Data is stored in encrypted form at rest and in transit using industry-standard TLS/SSL encryption. Access to production data is restricted to authorised personnel only, using role-based access controls.
Our static landing page is hosted on Cloudflare Pages. Cloudflare may collect standard web analytics data in accordance with their own privacy policy.
We retain your personal data for as long as your account is active, or as needed to provide the Service. If you close your account, we will delete or anonymise your personal data within 90 days, except where we are required to retain it for legal or compliance reasons.
5. Third-Party Services We Use
To deliver the Service, we share data with the following trusted third-party providers. Each provider is bound by their own privacy policy and applicable data protection agreements.
| Provider | Purpose | Data Shared |
|---|---|---|
| Amazon Web Services (AWS) | Application hosting and infrastructure | All application data |
| Cloudflare Pages | Static landing page hosting | Web traffic and analytics |
| Supabase | Database hosting (Postgres) | All user and application data |
| OpenAI | AI content generation | Content inputs and brand data |
| Anthropic | AI content generation | Content inputs and brand data |
| Google Gemini | Content inbox image analysis | Images uploaded to inbox |
| Post for Me | Multi-platform social media publishing | Approved posts and access tokens |
| Resend | Transactional and notification emails | Email address and message content |
| Stripe | Payment processing and subscription billing | Billing name, address, payment data |
| Meta (Facebook / Instagram) | Social media publishing integration | Access tokens and post content |
We do not sell your personal data to any third party. We only share data with providers as necessary to operate the Service.
6. Meta and Social Media Platform Integrations
When you connect Facebook or Instagram through our Meta integration, Postless acts in accordance with Meta's Platform Terms and Developer Policies. Specifically:
- We request only the permissions required to publish content on your behalf
- We do not access your private messages, contacts, or personal timeline without explicit permission
- Access tokens are stored encrypted and are used solely to publish approved content
- You can revoke Postless's access to your Facebook or Instagram account at any time through your Meta account settings (Settings > Security > Apps and Websites)
- Upon revocation, we will delete your stored access token within 48 hours
Postless complies with Meta's data deletion requirements. If you request deletion of your data (see Section 10), we will also remove your Meta-related tokens and any associated data from our systems.
For other social platforms (LinkedIn, X/Twitter, TikTok, Threads, Bluesky), the same principles apply: minimal permissions, encrypted token storage, and immediate deletion on request.
7. International Data Transfers
Postless is a global service and your data may be processed in countries outside your own, including the United States, where some of our third-party providers (such as AWS, OpenAI, Anthropic, and Stripe) operate.
Where we transfer data outside the EEA or UK, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Transfers to providers certified under applicable adequacy frameworks
You can request information about the specific safeguards we use for international transfers by contacting [email protected].
9. Your Rights
Depending on where you are located, you have the following rights regarding your personal data:
For users in the EEA, UK, and similar jurisdictions (GDPR)
- Right of access: request a copy of the personal data we hold about you
- Right to rectification: ask us to correct inaccurate or incomplete data
- Right to erasure ("right to be forgotten"): ask us to delete your data
- Right to restriction: ask us to limit how we use your data
- Right to data portability: receive your data in a structured, machine-readable format
- Right to object: object to processing based on legitimate interests or for direct marketing
- Right to withdraw consent: where processing is based on consent, you can withdraw it at any time
For California residents (CCPA)
- Right to know what personal information we collect, use, and share
- Right to delete your personal information
- Right to opt out of the sale of personal information (we do not sell personal data)
- Right to non-discrimination for exercising your privacy rights
To exercise any of these rights, please contact us at [email protected]. We will respond within 30 days (or sooner where required by law). We may need to verify your identity before processing your request.
10. Data Security
We take the security of your data seriously. Our security measures include:
- Encryption of data at rest and in transit (TLS 1.2+)
- Encrypted storage of all OAuth tokens and sensitive credentials
- Role-based access controls and least-privilege principles for internal access
- Regular security reviews and dependency updates
- Hashed and salted password storage (we never store plain-text passwords)
While we take all reasonable steps to protect your data, no system is completely secure. If you discover a security vulnerability, please report it responsibly to [email protected].
In the event of a data breach that affects your rights and freedoms, we will notify you and the relevant supervisory authority as required by applicable law.
11. Stripe and Payment Data
All payment processing is handled by Stripe, Inc. Postless does not store your full payment card number, CVV, or any raw card data on our servers. Stripe collects and processes this information directly in accordance with their Privacy Policy (https://stripe.com/privacy) and is certified to PCI DSS Level 1 standards.
We receive and store only non-sensitive billing information such as the last four digits of your card, card brand, expiry date, and billing address for account management purposes.
12. Children's Privacy
The Postless Service is not directed at children under the age of 13 (or 16 in some jurisdictions). We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a child under the applicable minimum age, we will delete it immediately.
If you believe a child has provided us with their personal information, please contact us at [email protected].
13. Changes to This Policy
We may update this Privacy Policy from time to time as our Service evolves or legal requirements change. When we make material changes, we will notify you by email or by displaying a prominent notice in the app at least 14 days before the changes take effect.
The "Last Updated" date at the top of this document will always reflect when the most recent changes were made. We encourage you to review this policy periodically.
14. Contact Us
If you have any questions, concerns, or requests related to this Privacy Policy, please contact us:
- Email: [email protected]
- Website: https://postless.app
- Support: [email protected]
If you are located in the EEA and are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority (for example, the ICO in the UK or your national supervisory authority in the EU).