← back to home

privacy policy

effective date: april 1, 2026

1. data controller

App Studio (SASU) is the data controller for personal data processed through the Service. Our details are:

App Studio — RCS Marseille 917 474 207
BT B, 18 Boulevard Reynaud de Trets, 13010 Marseille, France
legal@getpostai.com

2. data we collect

We collect the following categories of personal data:

  • Account information: name, email address, and password (hashed) when you register.
  • Connected social accounts: OAuth tokens and profile metadata for each platform you connect (e.g. Twitter/X, LinkedIn, Instagram, TikTok).
  • Content you create: posts, captions, media, schedules, and AI-generated drafts saved in your Workspace.
  • Usage analytics: pages visited, features used, session duration, and error logs collected via PostHog.
  • Payment information: billing address and payment method details processed and stored by Stripe. We do not store raw card numbers.

3. how we use your data

We use your personal data to: provide and operate the Service; authenticate your identity and manage your account; process subscription payments and invoices; schedule and publish content to connected social platforms on your behalf; generate AI-powered content suggestions; send transactional emails (account notifications, billing receipts, security alerts) via Resend; analyse usage patterns to improve and develop the product; and detect and prevent fraud, abuse, and security incidents.

4. data storage & security

All user data is stored in Supabase, which operates its EU region within the European Union. Data is encrypted at rest using AES-256 and in transit using TLS 1.2+. We implement role-based access controls so that only authorised PostAI personnel can access production data, and only where strictly necessary for operational support.

5. third-party sub-processors

We share data with the following third-party sub-processors to operate the Service. This list covers every provider that receives personal data or user content, including the AI providers behind text, image, video, audio, and B2B-contact features — not only our core infrastructure. Where we don't have a precise, published figure for retention or a confirmed training policy from a vendor, we say so rather than guess. As a default position, we do not authorize any sub-processor to train their general models on your account content; where a provider's standard API/enterprise terms already exclude training by default, we rely on that.

ProviderFunctionData receivedRegionUsed to train models?Transfer mechanism
SupabaseDatabase, authentication, file storageAll account and content dataEU (Supabase EU project)NoN/A — EU
StripePayment processingBilling details, payment methodNot independently confirmed which processing region Stripe uses for this accountNoSCCs
Trigger.devBackground job execution and schedulingJob payloads, which may include content or tokens in transitNot independently confirmedNoSCCs (assume non-EU pending region confirmation)
ResendTransactional email deliveryEmail address, message contentNot independently confirmedNoSCCs (assume non-EU pending region confirmation)
VercelApplication hostingRequest data, logsGlobal edge network; company is US-basedNoSCCs
PostHogProduct analytics (event tracking only — no session recording is configured)Usage events, device/browser metadataEU cloud instanceNoN/A — EU
Anthropic (Claude)AI text generationPrompts, source content you provide, generated draftsUSNo — API usage is excluded from model training by Anthropic's standard commercial termsSCCs
OpenAIAI text/image generation (GPT, Sora 2)Prompts, source content, generated mediaUSNo — API usage is excluded from training by OpenAI's API termsSCCs
Google (Gemini / Veo 3)AI text/video generationPrompts, source content, generated mediaUS/GlobalNo — API usage is excluded from training by Google's API termsSCCs
xAI (Grok)AI image generationPrompts, generated imagesUSNot independently confirmedSCCs
fal.aiHosted video model inference (e.g. Kling, Wan)Prompts, generated videoUSNot independently confirmedSCCs
ARK (Seedance)AI video generationPrompts, generated videoNot confirmedNot independently confirmedSCCs
RunwayAI video generation (Gen-4)Prompts, generated videoUSNot independently confirmedSCCs
ElevenLabsAI voice/audio generationText input, generated audioUS/EUNot independently confirmedSCCs
CartesiaAI voice/audio generationText input, generated audioUSNot independently confirmedSCCs
MiniMaxAI voice/audio generationText input, generated audioNot confirmedNot independently confirmedSCCs
SunoAI music generationPrompts, generated audioUSNot independently confirmedSCCs
UdioAI music generationPrompts, generated audioUSNot independently confirmedSCCs
Pexels / Pixabay / FreesoundStock media search (b-roll, sound)Search queries only — no user content sentUS/EUNo — search onlySCCs
Apollo.ioB2B contact data enrichmentSearch filters you enter; no PostAI user data is sent to build the underlying datasetUSN/A — PostAI is a data recipient, not a trainer of Apollo's datasetSCCs
Typesense (self-hosted via apps/jobs)Search indexingIndexed content (e.g. viral post corpus)Depends on hosting region — not independently confirmedNoN/A

This table was last reviewed against our codebase on August 11, 2026. "Not independently confirmed" means we have not yet completed a documented review of that vendor's current data-use terms — we are not asserting a policy we haven't checked. This same table is shared by the DPA and GDPR pages so the three can't drift out of sync with each other again.

6. data retention

We retain personal data for as long as your account is active. If you cancel your subscription, your data is retained for 90 days to allow reactivation, after which it is permanently deleted from production systems. Anonymised analytics data may be retained indefinitely. Stripe retains payment records for the period required by applicable tax and financial regulations.

7. your rights

Under GDPR you have the following rights regarding your personal data:

  • Right of access: obtain a copy of the data we hold about you.
  • Right to rectification: correct inaccurate or incomplete data.
  • Right to erasure: request deletion of your personal data.
  • Right to data portability: receive your data in a structured, machine-readable format.
  • Right to restriction: request that we limit processing of your data.
  • Right to object: object to processing based on legitimate interests.

To exercise any of these rights, email legal@getpostai.com. We will respond within 30 days.

8. cookies

We use the following cookies:

  • Auth session cookie (Supabase) — strictly necessary to keep you logged in.
  • PostHog analytics cookies — used to understand how users interact with the product. You can opt out via our cookie banner.
  • Stripe cookies — used during the checkout flow for fraud prevention.

9. children's privacy

The Service is a business tool and is not directed at minors. You must be at least 18 years old, or a duly authorized agent of a business acting on its behalf, to create an account. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, please contact us and we will delete it promptly.

10. international transfers

We process and store data within the EU wherever possible. Where data is transferred outside the EU (e.g. to a sub-processor without an EU region), we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure an adequate level of protection.

11. contact & dpo

For any privacy-related enquiries or to exercise your rights, contact us at legal@getpostai.com. You also have the right to lodge a complaint with the French data protection authority, the CNIL (www.cnil.fr).