Privacy Policy
Effective date: September 4, 2026
Last updated: September 11, 2026
1. Who We Are
Postelio is an online service for AI-assisted content creation, scheduling, automation, and publishing to connected social networks and communication platforms.
The data controller for Postelio is Dmitry Rannev, trading as Postelio, established in Spain.
Contact: info@postelio.app
Full legal identification and contact details of the service provider are available in our Legal Notice.
2. Personal Data We Process
Depending on how you use Postelio, we may process the following categories of personal data.
Account data
This may include your email address, username, account status, language and timezone preferences, verification information, authentication-related data, and legal-acceptance evidence: the version of the Terms of Service you accepted, the version of this Privacy Policy you acknowledged, the date and time of each act, and the context in which it occurred.
We do not store your account password in readable form. Passwords are stored using secure password hashing.
Customer and workspace data
We process information associated with your Postelio account, customer account, workspaces, memberships, roles, subscription or plan status, usage, and service configuration.
If you use Postelio as an individual or sole trader, some workspace or customer information may itself constitute personal data.
Content and publishing data
We process the information you provide or generate through Postelio, including topics, prompts, generated text, content versions, campaigns, schedules, publication data, publishing results, images, media, and related metadata.
AI processing data
When you request AI generation, relevant prompts, instructions, content, generation settings, and other information required for the request may be sent to the AI provider selected for that operation.
Connected platform data
When you connect a supported social network or communication platform, we may process identifiers, authorization credentials or tokens, account information, channel configuration, publishing status, and information necessary to publish content on your behalf.
Postelio currently provides publishing integrations and does not use connected accounts to import or build general-purpose copies of your social feeds.
Bring Your Own AI data
If you connect your own AI provider account, Postelio processes the credentials and configuration necessary to use that provider on your behalf.
Contact and support data
If you contact us through the website or by email, we may process your name, email address, message, and other information you voluntarily provide.
The website contact form sends the submitted message to our support mailbox. Contact form submissions are not stored as separate support records in the Postelio application database.
Technical, security, and usage data
We may process technical and operational information such as request information, IP addresses where operationally necessary, timestamps, application errors, security events, service usage, generation usage, publication activity, and other information required to operate, secure, troubleshoot, and account for use of the service.
Subscription and payment data
Postelio may process information relating to your plan, subscription status, limits, and usage.
Postelio does not currently process payments through an integrated payment processor. If payment functionality is introduced, this Privacy Policy and related service information will be updated as appropriate.
3. Why We Process Personal Data
We process personal data where necessary to:
- create and manage your account;
- provide and operate Postelio;
- maintain workspaces, memberships, permissions, and service configuration;
- generate content requested by you;
- publish content to services you connect;
- execute campaigns, schedules, and automations;
- provide customer support;
- administer plans, limits, and service usage;
- protect Postelio, its users, and infrastructure against abuse, fraud, and security threats;
- diagnose errors and maintain service reliability;
- comply with applicable legal obligations;
- evidence which version of our Terms you accepted and which version of this Policy you acknowledged, and when; and
- establish, exercise, or defend legal claims where necessary.
Depending on the processing activity, our legal basis may be performance of a contract, steps taken at your request before entering into a contract, compliance with a legal obligation, or our legitimate interests in operating, securing, and improving the reliability of the service.
Where consent is legally required for a particular activity, we will request it separately.
4. AI Processing
Postelio allows content to be generated using AI services.
Depending on your configuration, generation may use AI services provided through Postelio or an AI provider account that you connect yourself.
To perform a generation request, Postelio may transmit the information necessary for that request to the selected AI provider. This can include prompts, topics, existing content, instructions, generation parameters, and other context supplied or selected by you.
Different AI providers operate under their own terms and data-processing arrangements.
Postelio does not require you to use a particular AI provider where alternative supported options are available.
Some optional AI functionality may use additional provider features, such as web or search grounding. When such functionality is used, additional processing by the relevant provider may occur.
5. Connected Social Networks and Platforms
Postelio allows you to connect supported external platforms and authorize Postelio to publish content on your behalf.
Depending on the platform, Postelio may store authorization tokens, account or channel identifiers, configuration, token expiry information, and other data required to maintain the connection and perform requested publishing operations.
When Postelio publishes content, the content and associated media are transmitted to the platform you selected.
Your use of a connected platform remains subject to that platform's own terms and privacy practices.
You can disconnect supported integrations through Postelio where that functionality is available. Certain technical or historical records relating to completed publications may remain where necessary for service history, security, troubleshooting, or legal purposes.
Threads lifecycle deletion processing is currently under verification and mutation is disabled. Postelio does not remove Threads credentials or stored Threads account identity while that verification is incomplete.
Once activated after verification and product/legal sign-off, when Meta sends Postelio a Threads data-deletion request for a connected account, Postelio removes the active Threads OAuth credentials and the stored Threads account identity kept in that connection. Postelio retains the channel row, the channel name you chose, publication history (including provider message identifiers and provider responses), and campaign-target records as customer business and history records. A Threads deletion request does not mean that all Meta or Threads user data has been deleted from Postelio.
6. Third-Party Service Providers
We use third-party service providers where necessary to operate Postelio.
These may include providers of:
- hosting and infrastructure;
- cloud storage and backups;
- email services;
- AI services;
- website analytics;
- connected social and communication platforms; and
- other technical services required to provide Postelio.
Website analytics are provided by Google LLC. How the Google Analytics tag loads and what it may transmit is described in section 9.
Depending on the service and your configuration, these providers may process personal data on our behalf or as independent controllers under their own terms.
Where required by applicable law, we use appropriate contractual or other safeguards for such processing.
Information about the principal external services currently used by Postelio is available on our Third-Party Services page and may be updated as our infrastructure and integrations change.
7. International Data Transfers
Postelio is operated from Spain, while infrastructure and service providers may process data in other countries.
Our primary application infrastructure is hosted in the Netherlands.
Some service providers or backup infrastructure may process or store information outside the European Economic Area.
Where personal data is transferred outside the EEA and applicable law requires transfer safeguards, we rely on appropriate mechanisms such as adequacy decisions, Standard Contractual Clauses, or other legally recognized safeguards, as applicable to the relevant provider and transfer.
The exact locations involved may also depend on the external services and AI providers you choose to connect to Postelio.
Google Analytics may process measurement data on servers outside the European Economic Area, including in the United States. Where required, such transfers rely on the safeguards described above.
8. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes for which it is processed, including providing the service, maintaining security and reliability, resolving disputes, and complying with legal obligations.
Retention periods depend on the type of information and its purpose.
Account and workspace information is generally retained while the relevant account or workspace remains active and for any additional period necessary for legitimate operational or legal purposes.
Content, campaigns, publication history, and related records may be retained while they remain part of your account or are necessary to provide service history and functionality.
Credentials and tokens for connected platforms are generally retained while the relevant connection remains configured, subject to technical and legal requirements.
Credentials for your own AI providers are generally retained while the relevant provider connection remains configured.
Temporary image binaries and publishing media may have shorter technical retention periods and may be removed automatically when no longer required for processing or publication.
Messages sent through the website contact form are delivered to our support email system and are not separately stored in the Postelio application database. Support correspondence may be retained for as long as reasonably necessary to handle the request and related business or legal matters.
Technical anti-abuse information used by the contact form is temporary. The current contact-form rate-limiting data expires after approximately 15 minutes.
Operational application, access, and security logs are maintained as rotating operational logs for security, troubleshooting, and service reliability. They are not maintained as a permanent raw-log archive and are automatically rotated based on configured storage limits. Their actual retention duration therefore depends on log volume and operational conditions and is generally expected to be relatively short.
Usage, accounting, security-relevant, and other structured service records may be retained for longer where necessary for service operation, abuse prevention, dispute resolution, accounting, or legal compliance.
Minimal legal-acceptance evidence — an internal account identifier, the document version, the type of act (acceptance or acknowledgement), the timestamp, and the context — may survive deletion of the account. This record does not retain your email address. It is retained for five years after account termination or deletion, after which it is deleted or anonymised unless a legal claim or another legal obligation requires longer retention.
Production backups are maintained on a rotating basis and are generally retained for approximately 30 days. Information deleted from active systems may therefore remain temporarily in backups until the relevant backup expires.
Where information must be retained to comply with law or to establish, exercise, or defend legal claims, access may be restricted and the information retained only for the applicable purpose and period.
9. Cookies and Similar Technologies
Postelio uses cookies that are necessary for core website and application functionality, including authentication sessions, protection against cross-site request forgery, and remembering your language preference.
Postelio uses Google Analytics 4 to understand how the public website and
application are used. Postelio stores your analytics choice in a first-party
cookie named postelio_consent.
The Google Analytics tag loads on measured pages regardless of your choice, in a mode where storage is denied. While storage is denied, Google Analytics does not read or write first-party Analytics cookies, and the resulting measurement events are not associated with a persistent Google Analytics user identifier.
In that state, one or more cookieless measurement requests may still be sent to Google as you use the page, and may transmit technical and event data: a random value generated for the page load, the IP address inherent to the connection, the browser user-agent, screen and device information, the page path in a normalized form that excludes account identifiers and query parameters, a sanitized referrer or no referrer, and a page title derived from that same normalized path.
After you accept, Analytics cookies such as _ga are set and
measurement continues with a persistent identifier. Advertising storage,
advertising user data, and advertising personalization remain denied at all
times, and no advertising or remarketing cookies or pixels are used.
You can change or withdraw your analytics choice at any time by using Cookie settings, which are available in the website footer.
10. Security
We use technical and organizational measures intended to protect personal data against unauthorized access, disclosure, alteration, loss, or misuse.
These measures include access controls, secure transport, restricted production access, credential protection, operational monitoring, and other safeguards appropriate to the nature of the service.
Credentials for user-configured AI provider connections are protected using application-level encryption.
No internet-based service can guarantee absolute security. Users are responsible for protecting their own account credentials and for maintaining appropriate security over external accounts and services they connect to Postelio.
11. Your Data Protection Rights
Subject to applicable law, you may have the right to:
- request access to your personal data;
- request correction of inaccurate personal data;
- request deletion of personal data;
- request restriction of processing;
- object to certain processing based on legitimate interests;
- receive certain personal data in a portable format;
- withdraw consent where processing is based on consent; and
- lodge a complaint with a competent data protection supervisory authority.
These rights may be subject to legal conditions, limitations, and exceptions.
To exercise your rights, contact us at info@postelio.app.
We may need to verify your identity before fulfilling a request.
If you are in Spain, you also have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD).
12. Automated Decision-Making
Postelio uses AI and automation to generate, adapt, schedule, and publish content according to user instructions and configuration.
Postelio does not currently use automated processing to make decisions about users that produce legal effects or similarly significant effects within the meaning of applicable data protection law.
13. Children
Postelio is not intended for children.
You must have the legal capacity required under applicable law to create an account and use the service.
We do not knowingly design Postelio to collect personal data from children.
14. Data Relating to Other People
You are responsible for ensuring that you have an appropriate legal basis or other lawful authority to provide personal data relating to other people through Postelio.
This may apply, for example, where prompts, uploaded content, media, publication material, or support requests contain personal data about third parties.
15. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes to Postelio, our data-processing practices, service providers, or applicable legal requirements.
When we make material changes, we will update the “Last updated” date and provide additional notice where required by law.
16. Contact
For privacy questions or requests relating to your personal data, contact:
Full legal identification and service-provider contact details are available in our Legal Notice.