Privacy Policy

Postyn Privacy Policy

How Postly Technologies, Inc. handles personal data when you use Postyn.

Effective and last updated: July 25, 2026https://postyn.appOperated by Postly Technologies, Inc.

1. Scope, Company, and Our Role

This Privacy Policy explains how Postly Technologies, Inc. collects, uses, discloses, and protects personal data when you visit https://postyn.app, create or use a Postyn account, connect third-party services, contact us, or otherwise use the Service.

We generally act as controller or business for account, website, billing, support, security, and product-usage data. For Customer Content and personal data you direct us to process about your audience, contacts, customers, or end users, your organization is generally the controller or business and we act as processor or service provider. Your organization’s privacy notice governs its processing; contact that organization first to exercise rights concerning data it controls.

2. Personal Data We Collect

  • Account and identity: name, email, profile image, authentication provider identifiers, password hash, verification status, roles, organization, workspace, preferences, and account recovery information.
  • Commercial and billing: plan, trial, add-ons, usage, invoices, transaction status, tax and billing details. Payment card data is generally processed directly by our payment providers.
  • Device, usage, and security: IP address, browser, device, operating system, language, time zone, referring URLs, pages and features used, clicks, timestamps, logs, diagnostics, cookies, fraud signals, and approximate location derived from IP.
  • Customer Content: posts, drafts, prompts, generated output, media, links, templates, notes, schedules, files, recipient or audience information, instructions, and other data you submit.
  • Communications: support requests, surveys, feedback, preferences, marketing interactions, call or meeting details, and correspondence.
  • Connected-service data: X account identifiers and profile details, authorization tokens, posts, media, publishing status, audience or engagement metrics, and other data returned under the permissions you grant.

3. Sources of Personal Data

We collect data directly from you, your organization and administrators, your browser or device, connected services you authorize, payment and authentication providers, service providers, integrations, referrals, and publicly available sources where permitted. We may derive insights such as feature adoption, risk indicators, campaign performance, or aggregated usage statistics from those sources.

4. X and OAuth Data

When you connect X, Postyn receives authorization tokens and the account, publishing, media, and analytics data permitted by your approved scopes. Postyn uses that data to perform requested publishing and analytics workflows and does not use it for surveillance or unrelated profiling.

We access only permissions you authorize and use connected-service data to authenticate the connection, display authorized resources, perform actions you request, synchronize status, provide analytics, troubleshoot, secure the integration, and comply with law. We do not sell connected-account content or use it for targeted advertising. Disconnecting stops new access but does not immediately remove data already needed for records, security, backups, or legal compliance.

Where we receive information from Google APIs, our use and transfer of that information adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is not used for advertising, sold to data brokers, or used to train generalized AI or machine-learning models.

5. How We Use Personal Data

  • Provide, configure, authenticate, synchronize, personalize, and support the Service and connected integrations.
  • Process instructions, publish or schedule authorized content, generate requested output, operate collaboration tools, and provide analytics.
  • Administer trials, subscriptions, add-ons, usage limits, invoices, payments, taxes, and account communications.
  • Detect, investigate, and prevent fraud, spam, abuse, security incidents, unlawful conduct, and violations of our Terms.
  • Monitor reliability, debug errors, improve usability and performance, develop features, and create aggregated or de-identified insights.
  • Respond to support and rights requests, send service notices, and—where permitted—send product news or marketing you can opt out of.
  • Comply with law, enforce agreements, establish or defend legal claims, protect rights and safety, and complete corporate transactions.

7. Customer-Controlled Audience and End-User Data

Customers may submit or connect personal data about other people. We process that data under the customer’s instructions to provide the Service. Customers must have a lawful basis, deliver required privacy notices, respect consent and opt-out signals, limit collection, and respond to their data subjects. We do not independently determine the customer’s campaign audience or message content.

Customers remain responsible for their X content, automation frequency, disclosures, replies, audience interactions, and compliance with X rules and applicable communications law.

8. How We Disclose Personal Data

We may disclose data only as reasonably necessary to:

  • Your organization: owners, administrators, workspace members, and collaborators according to roles and settings.
  • Service providers: hosting, databases, content delivery, authentication, payments, email delivery, support, analytics, security, storage, monitoring, and AI providers bound to process data for authorized purposes.
  • Connected services: X and destinations you select, to perform requested actions.
  • Professional and legal recipients: auditors, insurers, advisers, courts, regulators, and authorities where legally required or necessary to protect rights and safety.
  • Corporate transactions: a buyer, investor, lender, affiliate, or successor involved in financing, reorganization, merger, acquisition, or asset sale, subject to appropriate protections.
  • With your direction or consent: other recipients you select or authorize.

We may use and disclose aggregated or de-identified information that cannot reasonably identify an individual, and we will not attempt to re-identify it except to test safeguards or as allowed by law.

9. AI Features and Model Providers

When you use AI features, we process prompts, selected Customer Content, settings, and outputs to provide the requested feature, enforce safety controls, troubleshoot, and measure performance. Authorized AI providers may process this data as our service providers under contractual restrictions. Do not submit unnecessary sensitive personal data. Unless we clearly disclose otherwise and obtain any required permission, we do not use Customer Content or connected-service user data to train general-purpose models for unrelated customers.

10. Cookies, Analytics, and Preference Signals

We use necessary cookies and similar technologies for login, security, preferences, load balancing, and core functionality. With consent where required, we may use analytics technologies to understand site and feature usage. You can use the cookie controls offered on the site and browser settings; disabling necessary storage may prevent parts of the Service from working.

We do not sell personal data for money. We do not use Customer Content or connected-service content for cross-context behavioral advertising. Where applicable law requires recognition of supported opt-out preference signals, we process them as legally required.

11. Data Retention and Deletion

We retain personal data only as long as reasonably necessary for the purposes described, including while an account is active and afterward for account recovery, customer-directed retention, backups, security, fraud prevention, billing, tax and audit records, dispute resolution, enforcement, and legal obligations. Retention depends on data type, sensitivity, contractual requirements, connected-service rules, and applicable limitation periods.

When retention is no longer justified, we delete, aggregate, or de-identify data. Deletion from encrypted backups and distributed systems may occur on a delayed cycle. Disconnect integrations and export needed content before closing an account.

12. Security

We use administrative, technical, and organizational safeguards designed to protect personal data, such as access controls, encryption in transit, credential protections, logging, monitoring, backups, and incident response appropriate to risk. No method is completely secure. You are responsible for strong credentials, appropriate roles, endpoint security, safe API-key handling, and promptly reporting suspected compromise to [email protected].

13. International Data Transfers

We and our service providers may process data in the United States and other countries that may have different data-protection laws. Where required, we use recognized safeguards such as adequacy decisions, standard contractual clauses, the UK addendum, or another lawful transfer mechanism, together with supplementary measures where appropriate.

14. Your Privacy Rights

Depending on your location and our role, you may have rights to:

  • Know or access personal data and receive information about categories, sources, purposes, and recipients.
  • Correct inaccurate data, delete data, or restrict processing.
  • Receive portable data and object to processing based on legitimate interests or direct marketing.
  • Withdraw consent without affecting prior lawful processing.
  • Opt out of qualifying sale, sharing, targeted advertising, or profiling, where applicable.
  • Appeal a denied request and complain to a competent privacy regulator.

Submit requests to [email protected]. We may verify identity and authority and may deny or limit requests where law permits. Authorized agents may submit requests with legally sufficient authorization. We will not discriminate against you for exercising rights.

15. Regional Disclosures

EEA, UK, and Switzerland: You may contact your local supervisory authority and may object to direct marketing at any time. Where we process data for a customer, that customer is normally responsible for your request.

United States: The categories collected are described in Section 2; sources in Section 3; purposes in Section 5; and recipients in Section 8. We may collect identifiers, commercial information, internet activity, approximate geolocation, professional information, customer content, and inferences. We do not knowingly sell or share personal data of people under 18. We use sensitive information, such as account credentials, only for permitted operational purposes and do not use it to infer characteristics.

16. Service Messages and Marketing Preferences

We send transactional messages necessary for security, authentication, billing, requested workflows, policy updates, and support. You cannot opt out of essential service messages while maintaining an account. You may opt out of marketing using the unsubscribe or “Manage preferences” link in product emails or by contacting us. We may retain a suppression record so we can honor the choice.

17. Children’s Privacy

The Service is not directed to children under 18, and we do not knowingly collect their personal data for our own purposes. If you believe a child provided personal data, contact us. Customers must not use the Service to process children’s data unless they have all legally required authority, notices, consents, and safeguards.

18. Automated Processing

We may use automated systems for security, spam and abuse detection, feature recommendations, scheduling suggestions, and AI output. We do not use account data to make solely automated decisions that produce legal or similarly significant effects about you. Customers are responsible for any decisions they make using Service output.

19. Third-Party Sites and Services

The Service may link to or integrate with third parties. Their privacy practices apply once you interact directly with them. Review their notices and permission screens. We are not responsible for third-party privacy, security, content, or availability.

20. Changes and Contact

We may update this Policy to reflect product, legal, or operational changes. We will post the updated date and provide additional notice or request consent where required. Material changes apply prospectively from their effective date.

Privacy questions and requests may be sent to [email protected]. Identify Postyn, your account or organization, your country or state, and the request. Website: https://postyn.app.