← All legal documents

Privacy Policy

Effective date: 28 April 2026 · Last updated: 2 August 2026

This Privacy Policy explains how PostThing handles personal data. PostThing is operated by JDG Kiryl Anokhin, an individual entrepreneur registered in Poland (NIP 8982272619) ("PostThing," "we," "us," "our"). It applies to the website, web app, and APIs available at post-thing.com.

We act as a data controller for the data described below. If you use PostThing to publish content on social platforms you connect (Instagram, Pinterest, Facebook, TikTok, YouTube), each of those platforms is a separate, independent controller for the data you publish there.

1. Who to contact

  • General data-protection requests: privacy@post-thing.com
  • Legal correspondence: legal@post-thing.com
  • Product support: support@post-thing.com
  • Postal: JDG Kiryl Anokhin, ul. Chorwacka 41B-13, 51-107 Wrocław, Poland

We do not have a statutory Data Protection Officer (we are not required to appoint one), but privacy@post-thing.com is monitored by the controller and is the single point of contact for any data-protection matter.

2. Personal data we collect

We collect only what we need to operate the service.

2.1 Account data

When you sign in with a magic-link email (delivered via Resend), we receive and store:

  • your email address (the identifier you sign in with);
  • a session record so you stay signed in;
  • your role and permissions inside the workspaces you belong to.

We support invite-only registration. If a workspace owner invites you, we store your email and an invitation token until the invite is accepted, declined, or expires.

2.2 Workspace data

For each workspace ("tenant") you create or belong to we store the workspace name, slug, member list with roles (Owner / Admin / Member), and your active workspace selection.

2.3 Connected social-platform data

When you connect a social platform inside PostThing we receive and store, in encrypted form:

  • your platform handle / username (where the platform provides one);
  • platform identifiers needed for publishing (for example, an Instagram professional account ID, a Facebook Page ID, a TikTok Open ID, or a YouTube channel ID);
  • an OAuth access token, an OAuth refresh token (where the platform issues one), the token expiry, and the granted scopes.

For Pinterest we additionally record the ID of the board you choose for a specific pin — that is your publishing instruction, not data imported from Pinterest. Your Pinterest board list is fetched live from the Pinterest API each time you compose a pin and is not stored by us.

Tokens are encrypted at rest with AES-256-GCM. The encryption uses your workspace's tenant ID as additional authenticated data, so a token issued for one workspace cannot be decrypted in the context of another.

2.4 Content you upload or generate

To create a post you provide:

  • images and videos (stored in Cloudflare R2 under a per-workspace key prefix);
  • a source product description ("Etsy description" or similar) used as the creative brief;
  • captions, hashtags, titles and descriptions, and per-platform options;
  • voiceover scripts and the synthesized audio files we produce from them.

2.5 Operational and security data

  • monthly usage counters per workspace (AI tokens used, TTS seconds used, posts published);
  • request logs, including IP address, user agent, and timestamp, used for rate limiting and abuse prevention;
  • short-lived OAuth state nonces (HMAC-signed, ten-minute lifetime) used to protect the platform-connection flow.

2.6 Cookies

See our separate Cookie Policy. Today PostThing uses only strictly-necessary cookies set by our authentication library.

We do not knowingly collect any special-category personal data (health, biometric, political opinions, etc.) through PostThing. Please do not upload such data into the service.

3. How we use personal data

We use the data above to:

  • create your account, sign you in, and keep you signed in;
  • create and manage workspaces and invitations;
  • store the OAuth tokens necessary to publish on the platforms you connect;
  • transcode, resize, and store the media you upload;
  • generate draft captions and voiceovers from the inputs you provide, using the AI sub-processor you select (Anthropic Claude or DeepSeek for captions; Google Gemini for voiceovers), or store the voiceover you record yourself;
  • publish or schedule posts on the platforms you connect, on your behalf;
  • meter your usage against the workspace's monthly quotas;
  • prevent abuse, debug problems, and keep the service secure;
  • respond to your support and data-protection requests;
  • comply with our legal obligations.

We do not use your content, your account data, or data we receive from connected social platforms to train AI models, build advertising profiles, or sell to third parties.

4. Legal bases (GDPR Article 6)

  • Performance of a contract (Art. 6(1)(b)) — most processing is necessary to provide the service you signed up for: storing your account, holding your platform tokens, generating drafts, and publishing on your behalf.
  • Legitimate interests (Art. 6(1)(f)) — request logging, rate limiting, fraud and abuse prevention, and basic operational monitoring.
  • Explicit consent for transfers outside the EEA (Art. 6(1)(a) together with Art. 49(1)(a)) — if you select DeepSeek as your caption provider, the content of your request is transferred to the People's Republic of China, a country with no EU adequacy decision and, for this flow, no Article 46 safeguards. Possible risks of this transfer: your data may be accessed by Chinese public authorities under local law; you may have no enforceable data-protection rights or effective judicial remedy in China; and DeepSeek's terms permit broader use of your inputs than the other providers we offer. DeepSeek is never preselected — it runs only if you (or your workspace admin, for workspace defaults) actively select it, and the selection screen restates this disclosure. You can withdraw consent at any time by switching provider; withdrawal does not affect prior processing. You can always choose Anthropic Claude instead, or not use AI features at all. Note that a provider default set by your workspace admin applies to generations by all workspace members.
  • Legal obligation (Art. 6(1)(c)) — responding to lawful requests from public authorities, complying with tax and accounting rules.

5. Data we receive from social platforms

When you connect a social platform we request only the scopes needed to publish on your behalf, plus the dependency scopes the platform itself requires for those (for example, Meta requires pages_read_engagement to publish as a Page). We never request scopes that would let us read other users' private content or your direct messages. If a future feature ever needs an additional scope, we will update this policy, obtain the platform's approval through its app-review process, and ask you for the new permission explicitly.

| Platform | Data we receive | Why we need it | What we store | |---|---|---|---| | Instagram (Instagram API with Instagram Login) | Your professional (Business or Creator) account ID and username, under the instagram_business_basic and instagram_business_content_publish scopes you authorize | Publish images, carousels, and Reels on your behalf | Encrypted long-lived access token, account ID, username | | Facebook (Meta Graph API) | Your Page ID, Page name, and a Page access token, under the pages_show_list, pages_manage_posts, and pages_read_engagement (a Meta-required dependency for Page publishing) scopes | Publish posts to the Page you choose | Encrypted access token, Page ID, Page name | | Pinterest | Your user ID and an access + refresh token; your board list is read live when you compose a pin | Create pins on the board you select | Encrypted access and refresh tokens, user ID, and the ID of the board you choose for a pin. Your board list and profile details are not stored | | TikTok | Your Open ID, display name, and avatar, under the user.info.basic, video.upload, and video.publish scopes | Upload videos through the Content Posting API; TikTok requires us to show you your account name before posting | Encrypted access and refresh tokens, Open ID, display name | | YouTube (Google) | Your channel ID and channel title under the youtube.upload scope, an access token and a refresh token | Upload videos with the visibility you choose | Encrypted access and refresh tokens, channel ID and channel title |

We store the metadata above only to make the publishing flow work. We do not import, store, or analyze your existing posts, comments, followers, or audience analytics.

We do not sell, rent, or share platform data with any third party for advertising, profiling, or training of machine-learning models. Data we receive from connected platforms (tokens, account and Page identifiers, profile metadata) is processed only on our own EU infrastructure (the database, queue, and object storage listed in §7) and exchanged with the issuing platform itself — it is never sent to any AI caption or voiceover provider.

5.1 YouTube API Services

PostThing uses YouTube API Services to provide the YouTube features described above (connecting your channel and uploading videos on your behalf). By using PostThing's YouTube features you agree to be bound by the YouTube Terms of Service. Google's handling of your data is described in the Google Privacy Policy.

  • In addition to disconnecting YouTube inside PostThing (/settings/accounts), you can revoke PostThing's access to your Google/YouTube data at any time via the Google security settings page.
  • We store only your channel ID, channel title and encrypted OAuth tokens. Authorization tokens are kept while your authorization remains active; stored non-token YouTube data (such as your channel ID and title) is refreshed or deleted at least every 30 calendar days.
  • When you disconnect YouTube in the app or ask us to delete your data, we delete stored Google user data immediately, and in every case within 7 calendar days; if you revoke access via Google's security settings, within 30 calendar days.
  • PostThing's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5.2 The platforms are independent controllers

Meta, Pinterest, TikTok, and Google are not our processors: they receive data because you instruct us to publish to them, and each processes it under its own privacy policy as an independent controller. See §7 for the full list of recipients.

6. AI and voiceover providers

When you trigger a feature that uses an external provider, your inputs are sent to that provider:

  • Caption generation: the source description, platform hints, and any context you add are sent to the provider you have selected — either Anthropic (Claude) or DeepSeek. The built-in default is Anthropic Claude; DeepSeek runs only if you or your workspace admin actively select it (see §4 for the consent and transfer-risk disclosure).
  • Voiceover (TTS): when you generate a voiceover, the script you supply is sent to Google Gemini.
  • Recorded voiceover: if you record a voiceover with your own voice, the recording is processed on our own infrastructure (loudness normalization and format conversion) and stored in your workspace's media storage. It is not sent to any AI provider.

Per its published terms, Anthropic does not use API inputs to train its models. For voiceovers we use the paid tier of the Google Gemini API, which — per Google's Gemini API terms — Google does not use to improve its products. DeepSeek's terms permit broader use of inputs and route data through infrastructure in the People's Republic of China; we restate this in the UI where you make the selection so you can decide knowingly.

7. Recipients of personal data and where data is stored

7.1 Sub-processors (process data on our behalf, on our instructions)

| Sub-processor | Purpose | Location | Transfer mechanism | |---|---|---|---| | Cloudflare R2 | Object storage for images and videos | EU jurisdictional buckets | EU storage; EU–US Data Privacy Framework (certified) for support access | | Database hosting | PostgreSQL for accounts, posts, encrypted tokens, sessions | EU | — | | Redis hosting | Job queue and per-workspace rate-limit counters | EU | — | | Resend | Magic-link sign-in and transactional email | United States | Standard Contractual Clauses (2021/914) | | Anthropic | Caption generation when you select Claude | United States | EU–US Data Privacy Framework (certified) | | DeepSeek | Caption generation when you select DeepSeek | People's Republic of China | Explicit consent, GDPR Art. 49(1)(a) — see below | | Google | Voiceover synthesis (Gemini) | United States | EU–US Data Privacy Framework (certified) |

7.2 Independent recipients (platforms you instruct us to publish to — each a separate controller)

| Platform | Purpose | Their privacy policy | |---|---|---| | Meta Platforms (Instagram, Facebook) | Publishing via the Instagram API and Meta Graph API | Meta Privacy Policy | | Pinterest | Publishing via the Pinterest API | Pinterest Privacy Policy | | TikTok | Publishing via the Content Posting API | TikTok Privacy Policy | | Google (YouTube) | Publishing via YouTube API Services | Google Privacy Policy |

Transfers from the EEA to the United States rely on the EU–US Data Privacy Framework where the recipient is certified, otherwise on the European Commission's Standard Contractual Clauses (2021/914). You can request a copy of the Standard Contractual Clauses we rely on by emailing privacy@post-thing.com.

Transfers to DeepSeek (People's Republic of China) are based on your explicit consent under GDPR Article 49(1)(a), given when you select DeepSeek as your provider. There is no EU adequacy decision for China and we have no Standard Contractual Clauses or other Article 46 safeguards in place for this transfer; your data may be accessible to Chinese authorities under local law and your GDPR rights may not be enforceable there. You can avoid this transfer entirely by selecting Anthropic Claude instead.

8. How long we keep data

| Category | Retention | |---|---| | Account profile, workspace memberships | While the account exists; deleted on request within 30 days | | Sessions | Valid for up to 30 days of inactivity; expired session records are purged periodically | | Connected-platform tokens and platform identifiers/metadata (account IDs, Page names, handles) | Until you disconnect the platform or delete your account. Disconnecting deletes them from our live systems immediately; Google/YouTube data is always deleted from our live systems within 7 days of an in-app disconnect or deletion request. Residual copies inside encrypted database backups age out on the backup rotation cycle, at most 90 days; backups exist only for disaster recovery, and if one is ever restored, deletions are re-applied | | Posts and media (drafts and published) | While the workspace exists; you can delete individual items at any time. Platform-issued identifiers embedded in publishing history are deleted or anonymized within 30 days of disconnecting that platform | | Quota counters | Stored as monthly per-workspace totals (no per-request detail); retained while the workspace exists | | Request and security logs | Kept in fixed-size rolling buffers, purged on rotation and at most 90 days after collection | | Email communications with us | Up to 24 months from last reply |

Stored non-token YouTube data is additionally refreshed or deleted at least every 30 calendar days, per the YouTube API Services Developer Policies (see §5.1).

When you delete your account we delete or irreversibly anonymize your personal data in our live systems within 30 days, except where we are required by law to keep it longer (for example, tax records linked to paid subscriptions, when those launch). Residual copies inside encrypted database backups age out within at most 90 days, as described above.

9. Your rights

If you are in the European Economic Area, the United Kingdom, Switzerland, or another jurisdiction with comparable laws, you have the right to:

  • access the personal data we hold about you;
  • ask us to correct inaccurate data;
  • ask us to delete your data ("right to be forgotten");
  • ask us to restrict or stop processing your data;
  • receive your data in a portable format;
  • object to processing based on our legitimate interests;
  • withdraw consent at any time, where we rely on consent;
  • lodge a complaint with the Polish data-protection authority UODO (uodo.gov.pl), or with the supervisory authority of your habitual residence.

If you are a California resident, you have the rights described in the California Consumer Privacy Act and CPRA, including the right to know, delete, correct, and limit. We do not sell or share personal data for cross-context behavioral advertising.

If you are in Australia, you have the rights set out in the Australian Privacy Principles. Complaints can also be made to the Office of the Australian Information Commissioner (OAIC).

You can exercise most rights yourself in the app: disconnect a platform from /settings/accounts (which immediately deletes our copy of that platform's tokens and identifiers), delete posts and media, and — as a workspace owner — download an export of your workspace's data. For YouTube/Google you can additionally revoke access via the Google security settings page. For anything else, email privacy@post-thing.com and we will respond within 30 days.

Step-by-step deletion instructions — including how to delete data we received from a connected platform (Facebook, Instagram, Pinterest, TikTok, YouTube) — are on our dedicated How to delete your data page.

10. Security

  • OAuth tokens are encrypted at rest with AES-256-GCM, with key rotation supported and the workspace tenant ID bound as additional authenticated data.
  • Database queries are tenant-scoped at the ORM layer, and object-storage keys are prefixed and verified per tenant, so one workspace cannot access another's data.
  • The OAuth connect flow uses an HMAC-signed state with a ten-minute lifetime to prevent CSRF and replay.
  • We rate-limit authenticated traffic and OAuth callbacks.
  • All traffic is served over HTTPS.

No system is perfectly secure. If you believe you have found a security issue, please email security@post-thing.com.

11. Children

PostThing is for adults. The service is not directed to anyone under 18, and we do not knowingly collect personal data from anyone under 18. If you believe a minor has given us personal data, contact us and we will delete it.

12. Automated decision-making

We do not make decisions that produce legal or similarly significant effects about you using only automated processing. The AI features generate draft text and audio, which you review and approve before any post is published.

13. Changes to this policy

If we make material changes, we will notify you by email and inside the app at least 30 days before they take effect. Non-material changes (typos, clarifications) take effect on publication. Exceptionally, a change may take effect immediately or on shorter notice where it is required by law, by an order of a court or authority, by a connected platform or sub-processor as a condition of continued service, or to address an urgent security or abuse risk — we will still notify you as soon as reasonably possible. The "Last updated" date at the top of this page always reflects the latest revision.

14. Disclosures we may have to make

We may disclose personal data when required by law, court order, or a binding request from a public authority with jurisdiction over us, and when we need to enforce our Terms of Service or protect the rights, safety, or property of users or third parties. Where the law permits, we will notify the affected user before disclosing.


If anything in this policy is unclear, write to privacy@post-thing.com and we will get back to you.