1. Introduction
PostInstantly ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
2. Information We Collect
2.1 Information You Provide
- Account Information: Name, email address, password, and profile information
- Content: Posts, templates, and other content you create
- AI Training Data: Profile information and preferences you provide to train your AI brain
- Payment Information: Billing details processed by our payment provider
2.2 Information from Connected Accounts
When you connect LinkedIn, X (Twitter), or Reddit accounts, we collect:
- Public profile information (name, handle, profile picture)
- OAuth access and refresh tokens (used to publish on your behalf)
- Post engagement metrics for content you publish through us
- Follower / connection counts
We use OAuth 2.0 authentication and never receive or store your social media passwords. OAuth tokens are encrypted at rest using AES-256-GCM before being stored in our database. You can disconnect any account at any time from your dashboard settings, which immediately revokes our access.
2.3 Automatically Collected Information
- Device and browser information
- IP address and location data
- Usage patterns and feature interactions
- Cookies and similar technologies
3. How We Use Your Information
We use collected information to:
- Provide and improve the Service
- Train your personalized AI model
- Process transactions and send related information
- Send administrative and promotional communications
- Respond to inquiries and provide customer support
- Monitor and analyze usage patterns
- Detect and prevent fraud and abuse
4. AI and Your Data
Your content is used to personalize your AI experience. Important points:
- Your content is NOT used to train our general AI models
- Your AI brain is private to your account
- You can delete your AI training data at any time
- We use industry-leading AI providers with strict data handling agreements
5. Information Sharing
We do not sell your personal information. We may share information with:
- Service Providers: Third parties that help us operate the Service
- Connected Platforms: When you authorize publishing to LinkedIn, X (Twitter), or Reddit
- Legal Requirements: When required by law or to protect rights
- Business Transfers: In connection with mergers or acquisitions
6. Data Security
We implement industry-standard security measures including:
- Encryption in transit using TLS
- OAuth tokens encrypted at rest using AES-256-GCM
- Row-level security (RLS) on our Postgres database so users can only access their own data
- Strict access controls and authentication requirements for internal systems
- Regular dependency and security audits
No method of electronic transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.
7. Data Retention
We retain your information for as long as your account is active or as needed to provide services. You can request deletion of your data at any time.
8. Your Rights
Depending on your location, you may have rights to:
- Access your personal information
- Correct inaccurate data
- Delete your data
- Export your data (data portability)
- Opt out of marketing communications
- Withdraw consent
9. Cookies
We use cookies and similar technologies for:
- Authentication and security
- Preferences and settings
- Analytics and performance
- Marketing (with consent)
You can control cookies through your browser settings.
10. International Transfers
We may transfer data to countries outside your residence. We ensure appropriate safeguards are in place, including Standard Contractual Clauses for EU data transfers.
11. Children's Privacy
The Service is not intended for users under 16. We do not knowingly collect information from children.
12. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes via email or through the Service.
13. Contact Us
For privacy-related questions or to exercise your rights:
Email: [email protected]
Data Protection Officer: [email protected]
General support: [email protected]
14. California Privacy Rights (CCPA)
California residents have additional rights including the right to know what personal information is collected, the right to delete, and the right to opt-out of sale (we do not sell personal information).
15. European Privacy Rights (GDPR)
If you are in the EEA, you have rights under GDPR including access, rectification, erasure, restriction, portability, and objection. Our legal bases for processing include consent, contract performance, and legitimate interests.