1. Subprocessors and independent providers
A subprocessor handles personal data on PostBod's behalf. A connected social network or storage platform may instead process data independently under its own terms when a customer directs PostBod to connect or publish. Listing a provider does not mean every workspace sends data to it.
2. Core and optional providers
| Provider | Purpose | Data involved | When used |
|---|---|---|---|
| Gemini AI generation; Google authentication; Google Drive assets | Prompt and selected brand context for AI; identity data for sign-in; authorized Drive metadata and files | Only for the relevant configured feature | |
| Paddle | Subscription checkout, billing status, and payment events | Billing contact, plan, transaction references, and payment status | When Paddle billing is enabled |
| Google Analytics | Aggregate website usage measurement | Online identifiers and usage events configured by PostBod | Only when configured and after analytics consent where required |
AI inputs should be minimized to what is needed for the requested output. Connected credentials are held server-side and encrypted when production secret encryption is configured.
3. Customer-connected services
At a customer's direction, PostBod can interact with Meta (Facebook and Instagram), LinkedIn, X, TikTok, Pinterest, YouTube, and Google Drive. These providers receive publishing, media, or API requests and return authorized account, post, engagement, audience, or file data. Their own privacy terms apply to their independent processing.
4. Deployment-specific infrastructure
Hosting, managed database, email delivery, observability, backup, and support providers depend on the production deployment selected for the customer or PostBod environment. The applicable order form, data processing agreement, or deployment notice must identify those providers before production customer data is processed. PostBod will not represent an unselected vendor as an active subprocessor.
5. Changes, notice, and objections
We may add or replace providers as the service changes. Eligible customers with a data processing agreement will receive notice and an opportunity to object on reasonable data-protection grounds as provided in that agreement. Questions or requests for the deployment-specific list: privacy@postbod.app.

