Draft Privacy Policy
Draft dated 2026-08-21
1. Who controls your data
UAB Gildium is the data controller for Postsie. Company code 307192563; registered address Polocko g. 17-113, LT-01205 Vilnius, Lithuania.
Privacy questions and requests may be sent to privacy@postsie.com.
2. Data we collect now
Currently collected: data needed for the account, authentication, security, support, and operation of the pre-launch service.
- Account identity, email address, and hashed password.
- For optional Google sign-in, Google
openid,email, andprofileidentity data. - Sessions and security records used to authenticate and protect accounts.
- Support messages, operational logs, product events, and audit records used for support, security, and service reliability.
3. Data planned for Postsie V1
Collected only when the corresponding V1 feature becomes available and you use it: the categories below are planned and are not described as currently collected merely because they appear in this policy.
- Encrypted Meta OAuth credentials.
- Facebook Page and Instagram professional account metadata, content, media, and insights.
- Customer captions, drafts, uploads, schedules, and preferences.
- Page Guides, suggestions, AI outputs, AI usage records, and basic analytics.
- Subscription and invoice references without card details. Stripe, not Postsie, handles card details.
4. How we use data
We use the relevant data to:
- Authenticate accounts and maintain sessions.
- Connect and publish through services you request, when those planned functions become available.
- Provide requested AI features and billing when those planned functions become available.
- Provide support, secure, and keep Postsie reliable.
- Meet legal obligations and maintain required records.
The expected legal bases include steps requested before or under a contract for core account and requested service operations, legitimate interests for proportionate security, reliability, and support, consent where applicable law requires it, and compliance with legal obligations.
The final legal bases are pending professional review.
5. AI processing
Relevant customer content and social-profile data can be sent to Anthropic only when you request an AI-assisted feature. Anthropic processes that information to return the requested AI result. AI features are not required for optional Google identity sign-in.
6. Providers and sharing
Data is shared only as needed for the requested service, security, support, billing, legal obligations, or the limited provider purposes below. Provider names do not imply endorsement.
- Meta: planned authorised access to Facebook Pages and Instagram professional accounts, including relevant metadata, content, media, insights, credentials, and publishing activity directed by the customer.
- Google: optional identity sign-in. Google identity data is accessed only after optional sign-in authorisation, used to authenticate and maintain your account, stored with your account record, shared only with infrastructure and security providers needed to operate that account, and deleted through the account-deletion process subject to the retention rules below.
- Anthropic: relevant customer content and social-profile data for AI features the customer requests.
- Stripe: planned subscription and payment processing, including subscription and invoice references; card details remain with Stripe.
- Amazon SES: transactional account and service email delivery.
- Laravel Cloud: application infrastructure used to host and operate the service.
- Laravel Nightwatch: operational monitoring using relevant service events and logs.
7. International transfers
Most listed providers can process data in the United States and other countries outside your country. Provider locations and access paths can therefore involve international transfers.
The final transfer safeguards and mechanism are pending professional review before launch.
8. Retention
When applicable data exists and a verified deletion request is approved, the technical deletion sequence is:
- Access is disabled, sessions are invalidated, Meta credentials are revoked, subscription cancellation is initiated, and queued work is stopped immediately. Connected-provider OAuth tokens are included in that immediate revocation step.
- The process removes active database rows and media within 24 hours.
- It removes object-storage remnants within 7 days.
- It expires encrypted backups within 30 days.
- Postsie may retain anonymised product and audit data for 13 months.
- Postsie retains financial records for the legally required period.
- It expires export archives within 7 days.
9. Your rights
Depending on applicable law, you may have rights of access, correction, portability, deletion, restriction, objection, and consent withdrawal where consent applies. You may also complain to the competent data-protection regulator. Available rights and any lawful exceptions depend on applicable law.
10. Requests and identity verification
Send a rights request to privacy@postsie.com. We aim to acknowledge emailed privacy requests within five business days and to respond to verified requests within one month, unless applicable law permits an extension and we tell you.
We may use proportionate identity verification to protect the requester and other customers. We will never ask for your password, OAuth token, or card number as verification.
11. Cookies and security
Postsie currently uses essential cookies and security technologies only. The Cookie Policy describes their purposes and scope.
Security practices include encryption, access controls, and sensitive-value redaction where appropriate. No security measure eliminates every risk, and we do not promise absolute security.
12. Children, changes, and contact
Postsie is for people aged 18 or over and is not directed to children. We will provide appropriate notice of material policy changes.
Draft dated 2026-08-21; this policy remains pending professional review. Contact privacy@postsie.com with privacy questions.