1. Scope and our role
This policy applies when PostBod determines why and how personal data is processed, including account administration, billing, website operation, product improvement, and direct customer relationships.
For content, contacts, assets, social account data, and other information a customer submits or connects for its own business purposes, the customer may be the controller or business and PostBod may act as its processor or service provider. Workspace owners are responsible for providing required notices and having a lawful basis for that data.
2. Data we collect
- Account and identity data: name, email, avatar, organization, role, authentication identifiers, and account status.
- Workspace and brand data: brand guidance, audiences, company information, proof points, documents, prompts, drafts, campaigns, approvals, comments, schedules, and uploaded assets.
- Connected-service data: authorized account identifiers, profile and page metadata, permissions, tokens, published-post identifiers, content, engagement, audience insights, and connection health, limited by provider permissions.
- Usage and device data: product actions, request identifiers, diagnostics, browser and device information, IP address, logs, security events, and cookie choices.
- Commercial data: plan, credit usage, transaction status, billing contact, and payment-provider references. PostBod does not need to store full payment card numbers when payment is handled by a payment provider.
- Communications: support, sales, privacy, and security correspondence and related attachments.
3. Sources of personal data
We receive data from you, workspace administrators, people you collaborate with, connected social networks and storage providers you authorize, authentication and payment providers, your device and browser, and service providers that help operate and secure PostBod. We may also receive public business information that a user intentionally asks the service to use.
4. How we use personal data
- Provide, authenticate, secure, support, and administer the service.
- Create and manage brand context, content, campaigns, approvals, schedules, publishing, and analytics.
- Operate authorized connections, refresh credentials, diagnose failures, and import requested data.
- Process subscriptions, enforce plan limits, prevent abuse, and maintain business records.
- Communicate about the service, requests, security, material changes, and relevant product information as permitted by law.
- Measure and improve reliability, accessibility, workflows, and AI quality using appropriate safeguards.
- Comply with law, enforce agreements, and protect users, PostBod, and the public.
5. AI and automated processing
PostBod sends the context needed for a requested AI operation to configured model providers. That context may include prompts, brand guidance, selected documents or assets, and previous output. Do not submit sensitive personal data unless it is necessary, authorized, and appropriate for the task.
AI output can be inaccurate or unsuitable. Users must review material claims, rights, disclosures, and platform suitability before publishing. PostBod does not make legal or similarly significant decisions about people solely through automated processing.
7. Legal bases
Where a legal basis is required, we rely on performance of a contract, steps requested before entering a contract, legitimate interests such as securing and improving the service, consent where required, and compliance with legal obligations. You may withdraw consent for future processing without affecting prior lawful processing.
8. Retention
We keep personal data only as long as reasonably necessary for the purpose collected, including providing the service, maintaining security and audit records, resolving disputes, and meeting legal, tax, accounting, or regulatory requirements. Retention depends on data type, sensitivity, workspace instructions, active connections, legal obligations, and risk. Deleted data may remain in access-restricted backups until normal rotation completes.
9. International transfers
PostBod and its providers may process data in countries other than yours. Where required, we use recognized transfer mechanisms, contractual safeguards, adequacy decisions, or another lawful basis. Customers may request relevant transfer information or a data processing agreement by contacting privacy@postbod.app.
10. Your privacy rights
Depending on your location and the circumstances, you may have rights to access, know, correct, delete, restrict, object, withdraw consent, receive a portable copy, opt out of sale, sharing, targeted advertising or certain profiling, limit some uses of sensitive data, and complain to a regulator. We do not discriminate for exercising applicable rights.
Email privacy@postbod.app. We may verify identity, authority, and the workspace concerned. If PostBod processes data only on behalf of a customer, we may direct the request to that customer. See our Data Deletion, GDPR, and Global Compliance pages.
11. Security
We use technical and organizational safeguards appropriate to the service, including authenticated access, tenant-aware authorization, encrypted credential storage when configured, security headers, request limits, signed sessions, provider authorization controls, and operational logging. No system is risk-free. Review implemented controls and reporting instructions on our Security page.
12. Children
PostBod is a business service and is not directed to children under 13 or the higher minimum age required by local law. We do not knowingly collect personal data from a child who cannot legally consent to the service. Contact us if you believe this has occurred.
13. Changes and contact
We may update this policy as the service or law changes. We will publish the revised date and provide additional notice where required. Privacy questions and rights requests may be sent to privacy@postbod.app. Security reports should go to security@postbod.app.

