Privacy Policy
Last updated: August 9, 2026
1. Introduction
PostFlow ("we", "us", "our") respects your privacy. This Privacy Policy explains what data we collect, why we collect it, and how we handle it when you use our Service.
2. Data We Collect
- Account data: email, name, password hash
- Workspace data: posts, drafts, schedules, element approvals
- Connected accounts: OAuth tokens for social platforms you link
- Usage data: actions within the app, error logs
- Billing data: handled by our Merchant of Record — we never see your card
3. How We Use Your Data
We use your data solely to:
- Provide the Service (generate, review, schedule, publish content)
- Authenticate you and secure your account
- Send transactional emails (confirmations, alerts)
- Improve the Service based on aggregated, anonymized usage
We do not sell, rent, or share your personal data with advertisers.
4. Data Residency and Transfers
Your data is stored on servers in the European Union (Germany) and processed in the United States (for AI generation and payment processing). By using the Service, you consent to these transfers. We apply appropriate safeguards (encryption in transit and at rest, RLS, access controls) to protect your data across jurisdictions.
5. Third-Party Services
We integrate with:
- Social platforms you explicitly connect (Instagram, Facebook, X, LinkedIn)
- AI providers (for content generation — your prompts only)
- Payment processor (Merchant of Record)
- Email delivery (transactional only)
Each is bound by its own privacy policy and our data processing terms.
6. Your Rights (GDPR / CCPA)
You have the right to:
- Access a copy of your data
- Correct inaccurate data
- Request deletion of your account and data
- Export your data in a portable format
- Withdraw consent at any time
Exercise these rights via Settings → Delete Account, or email privacy@postflow-aiagency.com.
7. Data Retention
We retain your data for the lifetime of your account. Upon deletion, all personal data and content are permanently removed within 30 days. Backups are purged within 90 days. Aggregated, anonymized analytics may be retained.
8. Security
We apply industry-standard security: TLS everywhere, encrypted secrets (AES-256-GCM), row-level security on every table, isolated execution environments, and regular audits. No system is 100% secure — but we treat your data as if it were our own.
9. Children's Privacy
The Service is not intended for users under 16. We do not knowingly collect data from children.
10. Changes to This Policy
Material changes will be notified via email or in-app notice at least 30 days before taking effect.
11. Contact
Privacy questions or requests? Email privacy@postflow-aiagency.com.