gdpr compliance
effective date: april 1, 2026
1. our commitment
App Studio is committed to complying with the General Data Protection Regulation (EU) 2016/679 (“GDPR”). We act as a data controller when we process your personal data to provide our Service, and as a data processor when we handle personal data on behalf of our customers. This page explains how we fulfil our GDPR obligations and how you can exercise your rights.
2. legal bases for processing
We rely on the following legal bases under GDPR Article 6:
- Contract performance (Art. 6(1)(b)): processing necessary to provide the Service you subscribed to, including account management, content scheduling, and payment processing.
- Legitimate interests (Art. 6(1)(f)): product analytics, fraud prevention, security monitoring, and improving the platform, where these interests are not overridden by your rights.
- Consent (Art. 6(1)(a)): optional analytics cookies and marketing communications where you have given explicit consent.
3. your rights under gdpr
Under GDPR you have the right to:
- Access the personal data we hold about you (Art. 15).
- Rectification of inaccurate or incomplete data (Art. 16).
- Erasure (“right to be forgotten”) of your data where no overriding legal basis applies (Art. 17).
- Restriction of processing in certain circumstances (Art. 18).
- Data portability in a structured, machine-readable format (Art. 20).
- Objection to processing based on legitimate interests (Art. 21).
- Withdraw consent at any time without affecting the lawfulness of prior processing.
To exercise any right, contact legal@getpostai.com. We will respond within 30 days.
4. data portability
There is no self-serve export button in the dashboard yet. To request a copy of your personal data and content, email legal@getpostai.com with the subject “Data Export Request”. We'll send it to you within 30 days, covering your account information, connected social account metadata, scheduled and published posts, and AI-generated drafts.
5. right to erasure
You can delete your account yourself from Settings, in the Danger zone section — or submit an erasure request by emailing legal@getpostai.com with the subject “Erasure Request”. Requests are processed within 30 days. Deletion is permanent and irreversible. We will retain minimal data where required by law (e.g. financial records for tax compliance).
6. sub-processors list
We use the following sub-processors to operate the Service, under our own data-processing terms with each provider (either a standard DPA/enterprise terms the provider publishes, or Standard Contractual Clauses). The full table — including what data each provider receives and whether it's used for model training — is published on the Privacy Policy.
| Sub-processor | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication, file storage | EU (Supabase EU project) |
| Stripe | Payment processing | Not independently confirmed which processing region Stripe uses for this account |
| Trigger.dev | Background job execution and scheduling | Not independently confirmed |
| Resend | Transactional email delivery | Not independently confirmed |
| Vercel | Application hosting | Global edge network; company is US-based |
| PostHog | Product analytics (event tracking only — no session recording is configured) | EU cloud instance |
| Anthropic (Claude) | AI text generation | US |
| OpenAI | AI text/image generation (GPT, Sora 2) | US |
| Google (Gemini / Veo 3) | AI text/video generation | US/Global |
| xAI (Grok) | AI image generation | US |
| fal.ai | Hosted video model inference (e.g. Kling, Wan) | US |
| ARK (Seedance) | AI video generation | Not confirmed |
| Runway | AI video generation (Gen-4) | US |
| ElevenLabs | AI voice/audio generation | US/EU |
| Cartesia | AI voice/audio generation | US |
| MiniMax | AI voice/audio generation | Not confirmed |
| Suno | AI music generation | US |
| Udio | AI music generation | US |
| Pexels / Pixabay / Freesound | Stock media search (b-roll, sound) | US/EU |
| Apollo.io | B2B contact data enrichment | US |
| Typesense (self-hosted via apps/jobs) | Search indexing | Depends on hosting region — not independently confirmed |
7. data transfers
We store and process data within the EU wherever possible. For sub-processors that transfer data outside the EU, we rely on adequacy decisions issued by the European Commission (where applicable) or on Standard Contractual Clauses (SCCs) to ensure an equivalent level of data protection.
8. data breach notification
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the relevant supervisory authority (CNIL) within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33. Where the breach is likely to result in a high risk, we will also notify affected individuals without undue delay, as required by GDPR Article 34.
9. contact & complaints
For any GDPR-related enquiries, contact our data protection contact at legal@getpostai.com. You also have the right to lodge a complaint with the French supervisory authority:
Commission Nationale de l'Informatique et des Libertés (CNIL)
3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07
www.cnil.fr