Privacy Policy

Your privacy is our priority - understand how we protect your data

Your privacy is our priority. This policy explains how we collect, use, and protect your personal information.

Privacy at a Glance

✅ What We Do

  • • Encrypt your data
  • • Use data only for our services
  • • Give you control over your data
  • • Allow you to delete your account
  • • Comply with GDPR and privacy laws

❌ What We Don't Do

  • • Sell your personal data
  • • Share data with advertisers
  • • Track you across other websites
  • • Use your content for our marketing

1. Information We Collect

Account Information

  • Name and email address
  • Profile picture (if provided)
  • Business information (name, address)
  • Social media account connections
  • Subscription and billing information

Content Data

  • Posts you create, edit, and schedule
  • Images and videos you upload or generate
  • AI prompts and generated content
  • Media library files
  • Scheduled content and publishing history

Usage Information

  • How you interact with our platform
  • Features you use most frequently
  • Performance and error data
  • Device and browser information
  • IP address and location data

Social Media Data

  • Access tokens (encrypted) for Facebook/Instagram, YouTube, TikTok, X, LinkedIn
  • Connected account information
  • Publishing permissions and scope
  • Basic profile information from connected accounts

1.1 International Users and GDPR Compliance

PostPal AI is based in Virginia, USA, and our services are available globally. If you are located in the European Union, European Economic Area, or other regions with data protection laws, the following applies:

  • We process your data based on legitimate business interests and your consent
  • You have additional rights under GDPR including data portability and erasure
  • For EU users, data may be transferred to the US under adequate safeguards
  • You may lodge complaints with your local data protection authority

2. How We Use Your Information

Primary Purposes

  • Service Delivery: Create, schedule, and publish your social media content
  • AI Generation: Process your prompts to generate text, images, and videos
  • Account Management: Maintain your profile and business information
  • Social Media Integration: Connect and publish to your social media accounts
  • Analytics: Provide performance insights and usage statistics

Secondary Purposes

  • Customer Support: Respond to your questions and resolve issues
  • Service Improvement: Analyze usage patterns to enhance our platform
  • Security: Detect and prevent fraud, abuse, and security threats
  • Legal Compliance: Meet legal obligations and enforce our terms
  • Billing: Process payments and manage subscriptions

2.1 Social Media Platform Data

When you connect social media accounts, we collect:

  • Access tokens (encrypted) for Facebook/Instagram, YouTube, TikTok, X, LinkedIn
  • Basic profile information (name, profile picture, follower counts)
  • Publishing permissions and account status
  • Post performance analytics (views, likes, comments, shares)
  • Comments and messages (when you enable this feature)
  • Account insights and demographic data

This data is used solely for providing our services and is subject to each platform's data policies.

3. Information Sharing and Disclosure

We do NOT sell your personal information to third parties.

Service Providers We Use:

  • Stripe (payment processing) - Financial data
  • Railway (video processing) - Content files
  • Bunny CDN (file storage) - Media files
  • OpenAI (AI text and image generation) - Content prompts
  • Runway ML (AI video generation) - Video creation requests
  • Social Media Platforms (Facebook/Instagram, YouTube, TikTok, X, LinkedIn) - Publishing and analytics data

When We May Share Information:

  • Service Providers: Third-party tools that help us operate our platform
  • Social Media Platforms: Content you choose to publish through our platform
  • Legal Requirements: When required by law, court order, or to protect rights and safety
  • Business Transfers: In connection with mergers, acquisitions, or sales of assets
  • With Your Consent: Any other sharing with your explicit permission

3.1 Government and Legal Requests

When we receive requests from government authorities or law enforcement for user data, we follow these procedures:

  • Legal Review: We review all requests to verify they are legally valid, properly authorized, and within the requesting authority's jurisdiction.
  • Challenge Process: We reserve the right to challenge requests we believe are legally insufficient, overly broad, or otherwise unlawful through appropriate legal channels.
  • Data Minimization: We will only disclose the minimum amount of information necessary to comply with valid legal requests, and will object to requests that seek irrelevant or excessive data.
  • Documentation: We maintain records of all government data requests, our responses, and the legal basis for our decisions. These records include the nature of the request, what data (if any) was provided, and our rationale.
  • User Notification: When legally permitted, we will notify affected users about requests for their data, unless prohibited by law or court order.

For questions about these procedures, contact us at legal@postpal-ai.com.

4. Data Security and Protection

Technical Safeguards

  • • End-to-end encryption for sensitive data
  • • Secure HTTPS connections
  • • Regular security audits and updates
  • • Access controls and authentication
  • • Encrypted storage of social media tokens

Organizational Safeguards

  • • Limited employee access to data
  • • Privacy training for staff
  • • Incident response procedures
  • • Data retention policies
  • • Regular compliance reviews

5. Your Privacy Rights and Choices

You Have the Right To:

  • Access your personal data
  • Correct inaccurate information
  • Delete your account and data
  • Export your data
  • Restrict processing
  • Object to processing
  • Withdraw consent
  • Lodge a complaint with supervisory authorities

How to Exercise Your Rights:

Contact us at privacy@postpal-ai.com with your request. We will respond within 30 days.

6. Data Retention and Deletion

Retention Periods:

  • Account Data: Retained while your account is active, deleted within 30 days of account deletion request
  • Content Data: Posted content stored permanently unless you request deletion; scheduled posts stored until published or deleted
  • Social Media Tokens: Encrypted and stored only while connections are active; deleted immediately when you disconnect accounts
  • Usage Analytics: Individual data anonymized after 12 months, aggregated data retained indefinitely
  • Financial Data: Stripe retains payment data per their retention policy; we delete our copies after 7 years
  • Legal Hold: Extended retention only if required by law

7. Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your experience, analyze usage, and provide personalized features.

Essential Cookies

Required for basic functionality and security

Functional Cookies

Remember your preferences and settings

Analytics Cookies

Help us improve our service (optional)

You can control cookie preferences through your browser settings.

8. International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for international transfers, including:

  • Adequacy decisions by regulatory authorities
  • Standard contractual clauses
  • Certification programs and codes of conduct
  • Your explicit consent when required

9. Children's Privacy

Our service is not intended for children under 13.

We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately at privacy@postpal-ai.com.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through our platform. We encourage you to review this Privacy Policy periodically for the latest information.

11. Contact Us About Privacy

If you have any questions about this Privacy Policy or our privacy practices, please contact us:

General Privacy Questions

Email: privacy@postpal-ai.com

Response time: 48 hours

Data Protection Officer

Email: privacy@postpal-ai.com

For GDPR/CCPA requests

Support Team

Email: support@postpal-ai.com

General questions

Legal Team

Email: legal@postpal-ai.com

Compliance matters

Company: Minas Media LLC (dba PostPal AI)
Location: Chantilly, Virginia, USA
Response time: 48 hours for general inquiries, 30 days for formal requests

This Privacy Policy is effective as of 1/15/2026.