Privacy Policy

Last updated: August 7, 2026

1. Data controller and scope

This Privacy Policy (the "Policy") explains what personal data we, Posthex ("we", "us", "Posthex"), collect when you use our social media management service (the "Service"), why we process it, on what legal basis, and what rights you have. This Policy is designed to meet the standards of the EU/UK General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and other data protection frameworks generally recognized under international law. Our contact details are listed in the "Contact" section below.

2. Who this Policy covers

This Policy covers account holders who register for the Service, team members an account holder invites, and third parties who visit a user's public bio page. Data processing about bio-page visitors is addressed separately in section 3 below.

3. Categories of personal data we process

  • Identity and contact data: your full name, email address, account type (individual/company), and company name if applicable.
  • Account and authentication data: an irreversibly hashed form of your password; your language preference and account settings.
  • Connected social account data: access/refresh tokens and profile information (platform username, profile picture) obtained from the platforms you authorize (X/Twitter, Instagram, Facebook, LinkedIn, TikTok, YouTube, Pinterest, Threads, Bluesky). These tokens are used solely to publish content on your behalf — we never see or store your social media account password.
  • Content data: the post text you create, the images/videos you upload, scheduling information, account groups, and your bio-page content (display name, bio, custom links, avatar).
  • Payment and subscription data: your subscription plan, payment status, and billing period. Your card/bank details never reach our servers — payments are processed directly by our payment provider, Paddle, on Paddle's own infrastructure (see section 7).
  • Usage and technical data: login/session records, IP address, browser/device information, error logs, in-app actions (creating, scheduling, publishing posts), and basic usage statistics.
  • Communications: information you share when you contact us for support, feedback, or otherwise.
  • Bio-page visitor data: we don't collect data from visitors to your public bio page beyond the basic technical data (e.g. IP address, request timestamp) needed to serve the page — visitors aren't account holders and aren't profiled.

4. How we collect your data

We collect your personal data (i) directly from you, through the signup form, account settings, and support requests; (ii) via the OAuth authorization flow of the social media platforms you connect; (iii) from our payment provider Paddle, as subscription/billing status; and (iv) automatically while you use the Service (log records, cookies). Your personal data is processed on the legal bases set out in section 6 below.

5. Purposes of processing

  • Providing the Service: creating and managing your account, connecting your social accounts, publishing your content to the relevant platforms at the scheduled or chosen time, and running the notification features.
  • Billing: managing your subscription plan, processing payments (via Paddle), and meeting our legal invoicing/accounting obligations.
  • AI-assisted suggestions: on Pro/Business plans, when a portion of your post content is sent to our AI provider, Groq, to generate hashtag and caption suggestions, it's used solely to produce that one-off suggestion — never for advertising or profiling.
  • Security and abuse prevention: keeping your account secure, detecting fraud and unauthorized access, and enforcing usage/rate limits.
  • Communication: sending transactional notifications about your account (publish outcomes, approval requests, security alerts) and responding to support requests.
  • Legal obligations: meeting retention, notification, and disclosure obligations under applicable law, and responding to legal requests.
  • Improving the Service: reviewing aggregated, and where possible anonymized, usage statistics for debugging, performance monitoring, and product improvement.

6. Legal bases for processing

Where the GDPR or an equivalent framework applies, we process your personal data on the following legal bases: (a) processing is necessary for the performance of a contract (processing account, content, and connected-platform data so we can provide the Service); (b) compliance with a legal obligation (invoicing/accounting records, responding to legal requests); (c) our legitimate interests, where these don't override your fundamental rights and freedoms (security, abuse prevention, improving the Service); and (d) your explicit consent — obtained separately and specifically, only for optional processing activities the bases above don't cover (e.g. optional marketing communications, if any); you may withdraw consent at any time. In jurisdictions that don't use a "legal basis" framework (for example, under the CCPA/CPRA), we limit our processing to the disclosed business and commercial purposes described in this Policy.

7. Who we share data with

  • Supabase: our database, authentication, and file storage infrastructure provider — your account, content, and connected-account tokens (accessible only server-side, never sent to the browser) are hosted here.
  • Paddle: our payment processor, acting as "Merchant of Record" for subscription payments — meaning billing, tax collection, and payment disputes are handled directly between you and Paddle, under Paddle's own terms and privacy policy.
  • Post for Me: the third-party unified publishing infrastructure that lets us publish to every connected platform other than X/Twitter (Instagram, Facebook, LinkedIn, TikTok, YouTube, Pinterest, Threads, Bluesky) — only the content you publish and the connected-account credentials needed for that purpose are shared.
  • The relevant social media platforms: only to the extent you explicitly authorize, to publish the content you create, either directly (X/Twitter) or via Post for Me to the platforms listed above.
  • Groq: our AI infrastructure provider, which processes the post text you submit only when you actively use the AI-assisted hashtag/caption suggestion feature.
  • Legal authorities: where required by a court order, legal obligation, or a competent public authority's request, and only to the extent required.

8. International data transfers

Some of the service providers listed above (e.g. Supabase, Paddle, Post for Me, Groq, and the international social media platforms you connect) may host their infrastructure in a country other than yours. Where this involves a transfer out of the EU/EEA or UK, we rely on recognized safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, an applicable adequacy decision, or another legally recognized transfer mechanism. Similar safeguards, consistent with generally accepted international data protection standards, are applied to transfers governed by other jurisdictions' laws.

9. Cookies and similar technologies

The Service uses only cookies that are strictly necessary for it to function: authentication cookies that keep you logged in, and a cookie that remembers your language preference. These cannot be disabled without breaking the Service. As of the date of this Policy, we do not use third-party advertising, tracking, or analytics cookies. If that changes, this section will be updated and you'll be notified.

10. Data retention

We retain your personal data for as long as your account is active and for as long as the purposes above require. When you delete your account, your account and content data is deleted or irreversibly anonymized from our systems within a reasonable period (ordinarily within 30 days). Certain records, such as invoicing and accounting data, may be retained separately for as long as required by the statutory recordkeeping periods applicable in the relevant jurisdiction (commonly up to 10 years for financial records). Connected social account tokens are deleted immediately when you disconnect the account.

11. Data security

We apply technical and organizational measures to protect your data, including row-level access control, encryption in transit (TLS/HTTPS), keeping authorization tokens server-side only, and limiting access to what's strictly needed for authorized operations. That said, no method of transmission or storage over the internet is 100% secure, and absolute security cannot be guaranteed even with reasonable technical measures in place.

12. Your rights

If you're located in the EU/EEA, UK, or a jurisdiction with an equivalent framework, you have the right to: access your personal data; request rectification of inaccurate or incomplete data; request erasure of your data once the purpose for processing it no longer applies; request restriction of processing; object to processing based on our legitimate interests; receive your data in a portable format; and lodge a complaint with your local data protection supervisory authority. If you're a California resident, you have the right under the CCPA/CPRA to: know what personal information we collect, use, and disclose about you; request deletion of your personal information; request correction of inaccurate personal information; opt out of the sale or sharing of personal information (we don't sell or share your personal information for cross-context behavioral advertising); limit the use of sensitive personal information; and not be discriminated against for exercising these rights. If your local law grants you additional or different rights (for example, under Brazil's LGPD, Canada's PIPEDA, South Africa's POPIA, or Singapore's PDPA), those rights apply to the extent they're broader than what's described here. You can access some of your data directly from your account settings in the app, or delete your account there; for other requests, use the Contact section below.

13. How to exercise your rights

To exercise the rights above, send your request, along with information to verify your identity, to the email address in the Contact section. We'll respond free of charge within the timeframe required by applicable law — generally within one month for GDPR-based requests (extendable by up to two further months for complex requests, with notice to you) and within 45 days for CCPA/CPRA requests (extendable by a further 45 days). If a request is manifestly unfounded, excessive, or repetitive, we may charge a reasonable fee or decline to act on it, to the extent permitted by applicable law.

14. Children

The Service isn't directed at anyone under 18, and we don't knowingly collect data from them. If we learn that someone under 18 has provided us with personal data, we'll delete it within a reasonable period.

15. Data breach notification

If we detect a security breach affecting your personal data, we'll notify the competent supervisory or regulatory authority and the affected users without undue delay and within the timeframe required by applicable law — for example, within 72 hours of becoming aware of the breach where the GDPR's notification duty to the supervisory authority applies.

16. Changes to this Policy

We may update this Policy from time to time to reflect legal changes or updates to the Service. We'll notify you of significant changes by email or in the app before they take effect; the "Last updated" date at the top of this page is updated with every revision.

17. Contact

For questions about this Policy or how we process your personal data: Posthex Email: support@posthex.com