Skip to content

Privacy policy

What Postreo collects, why it needs it, and what you can do about it.

Last updated

What we collect

We collect the minimum needed to run a scheduling service, and we try to be specific rather than vague about it.

  • Account details: your email address and, if you give one, your name.
  • Authentication data: a session token, and access tokens for the social accounts you connect.
  • Content you create: posts, drafts, media you upload, and the schedule you set.
  • Usage data: which features you use and when, so we can find what is broken.
  • Technical data: IP address and user agent, recorded with each session for security.

Connected social accounts

When you connect a social account, the network gives us an access token scoped to the permissions you approved. We store that token encrypted and use it only to publish and read back the content you asked us to.

We never ask for your password to a social network, and we do not post anything you have not scheduled or approved. You can revoke a connection from Postreo or from the network itself at any time.

How we use it

To operate the service: publishing your posts, showing your calendar, and reporting on how posts performed.

To keep accounts secure: detecting unusual sign-in activity and rate-limiting abuse.

To improve the product: understanding which features are used, in aggregate.

AI features

When you use the AI assistant, the prompt and the surrounding draft are sent to a third-party model provider to generate the response. Content you send to the AI assistant is processed to produce your result and is not used by us to train models.

If you would rather no content leave the platform this way, do not use the AI features; the rest of the product works without them.

Who we share it with

We do not sell personal data. We share it only with providers that make the service work — hosting, email delivery, payment processing, and the AI provider described above — and only what each needs.

We may disclose data where the law requires it, and we will tell you unless we are prohibited from doing so.

How long we keep it

Account and content data is kept while your account is open. When you delete your account, we delete or anonymise your personal data within a reasonable period, except where we must retain records for legal or accounting reasons.

Session records expire on their own schedule and are removed once expired.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. You can exercise most of these from your account settings.

To make a request we cannot handle in-product, contact us at the address below. We will respond within the period the applicable law allows.

Contact

Questions about this policy can be sent to privacy@quickpost.example. Replace this with your real contact address before publishing.