Legal
Privacy policy
Draft for legal review before publication. Last updated 24 September 2026.
This policy explains what personal data postpeg processes, why, who helps us process it, how long we keep it and what rights you have. It covers the postpeg API, the dashboard, this website and its free tools.
1. Who we are
postpeg is operated by [Company legal name], [Registered address] (“postpeg”, “we”, “us”). For privacy questions and requests, email privacy@postpeg.com. [If required: name and contact details of our EU and UK representatives].
2. Our two roles
We handle personal data in two different roles:
- As a processor for our customers. When a customer connects social accounts, publishes posts, or reads analytics, comments or direct messages through postpeg, the customer decides what is processed and why; we process that data only on their instructions. If you are an end user of a product built on postpeg (for example, your social account was connected through an app that uses postpeg), that app’s owner is responsible for your data, and their privacy notice applies. We will pass any request you send us to them.
- As a controller for our own data: customer account and sign-in details, API key records, billing, security logs, support emails, and visitors to this website and its tools.
Customers who need a data processing agreement can request one at privacy@postpeg.com. Our Terms of Service describe the customer’s obligations towards their end users.
3. Data we process
Your postpeg account (controller)
- Account details: your name and email address, whether the email is verified, and when the account was created. If you sign in with GitHub, we receive your GitHub account id, name, email address and profile picture, and keep the tokens GitHub issues for signing you in.
- Password: stored only as a salted hash by our authentication library (Better Auth), never in readable form.
- Sessions: a session token, its expiry, and the IP address and browser user agent it was created from, so you can stay signed in and we can spot misuse. Sign-in attempts are counted to limit guessing.
- API keys: each key’s name, environment (live or test), prefix, last four characters, and when it was created, last used and revoked. The key itself is stored only as a SHA-256 hash, so nobody at postpeg can read it.
- Billing: your plan, trial end date, subscription status and renewal date, and the customer and subscription ids Polar gives us. Polar, our merchant of record, collects your payment details and billing address; we never see your full card number.
- Support: what you send us by email.
Data processed for customers (processor)
- Profiles: the names and optional external ids customers give to the brands or end users they manage.
- Connected social accounts: the platform, the account’s id on it, username, display name and avatar link, its status, and when it was connected. The credentials that let us act on the account (access tokens, or a Bluesky app password) are encrypted with AES-GCM before they are stored, and are deleted when the account is disconnected.
- Posts: the text, links to media, platform-specific options, the time a post is scheduled for, and any idempotency key sent with it.
- Delivery results: for each account a post goes to, its status, attempts, the platform’s post id and link, publish time, and any error the platform returned.
- Analytics, comments and direct messages: fetched from the platform when the customer asks for them, and returned to the customer. Post analytics are cached for about 15 minutes to avoid repeated calls; we don’t keep copies of comments or messages beyond handling the request. Replies and messages customers send are passed to the platform.
This data can include personal data about people other than our customer: the owners of connected accounts, and anyone who appears in posts, comments or messages.
Logs (controller)
Our servers log requests to the API and dashboard: time, method, path, response status, request id, IP address, user agent and error details. We use them to operate, secure and debug the service. They are kept by our hosting provider for up to [7] days.
4. Our website and free tools
postpeg.com is a static website. It has no analytics or advertising scripts and doesn’t ask you to sign in.
Most free tools (the character counter, text formatter, best-time and image size guides) run entirely in your browser: what you type doesn’t leave your device.
The hashtag generator and post idea generator send the topic or niche you type, and the network you pick, to our tools server on Cloudflare Workers. It passes them to an AI model run on Cloudflare Workers AI and returns the suggestions. We don’t store what you type or the results, and there is no account. To prevent abuse we keep a per-minute rate-limit counter keyed to your IP address, and a daily total of requests with no content or IP address attached. Please don’t enter personal or confidential information into these tools.
5. Cookies and local storage
This website sets no cookies. The documentation remembers the code language you pick (curl or JavaScript) in your browser’s local storage; it never leaves your device and you can clear it in your browser settings.
The dashboard uses one strictly necessary session cookie to keep you signed in, and the cookies our authentication library needs for sign-in security (for example, during GitHub sign-in). We use no advertising or tracking cookies. If we add analytics in future we will update this policy and ask for consent where the law requires.
6. Why we use it, and our legal bases
| Purpose | Data | Legal basis (GDPR / UK GDPR) |
|---|---|---|
| Provide the service: accounts, keys, publishing, scheduling, engagement | Account, API key and customer data | Contract with the customer; for customer data, the customer’s instructions |
| Billing and invoicing | Billing data | Contract; legal obligations (tax and accounting) |
| Service emails: verification, security, billing and service notices | Email address, name | Contract |
| Security, abuse prevention, rate limiting and debugging | Sessions, logs, IP addresses, tool rate-limit counters | Legitimate interests in keeping the service secure and available |
| Free AI tools | The text you enter, IP address for rate limiting | Legitimate interests in offering and protecting free tools |
| Enforcing our terms, responding to platforms and legal claims | Any relevant data | Legitimate interests; legal obligations |
We don’t sell personal data, use it for advertising, or use customer content to train AI models. We don’t send marketing email without your consent.
7. How long we keep it
- Account, key and customer data: while your account is open. When you ask us to close your account, we disconnect your social accounts and delete your data within [30] days, except what we must keep by law.
- Ended trials: connected social accounts are disconnected, and their credentials deleted, 3 days after a trial ends without a paid plan. The rest of the account is kept so you can subscribe later, until you ask us to delete it or after [12 months] of inactivity.
- Disconnected social accounts: their credentials are deleted immediately; the account record and past posts stay in your history until you delete your account.
- Deletion on request: customers can ask us to delete specific data at any time by emailing privacy@postpeg.com.
- Billing records: invoices and payment records are kept by Polar, and by us, for as long as tax and accounting law requires.
- Logs: up to [7] days. Cached analytics: about 15 minutes. Free tool input: not stored.
- Backups: our database provider keeps point-in-time recovery data for up to 30 days, after which deleted data is gone from backups too.
8. Service providers and sharing
We use a small number of service providers, each bound by contract to process data only to provide their service to us:
| Category | Provider | What they process |
|---|---|---|
| Hosting, database, queues, logs and email delivery | Cloudflare | All service data, request logs, transactional emails |
| AI model for the free tools | Cloudflare (Workers AI) | Text entered into the AI tools |
| Payments, tax and invoicing (merchant of record) | Polar | Billing contact and payment details, subscription status |
| Social publishing | A contracted social publishing API provider that connects to the networks’ official APIs on our behalf | Connected account identifiers and credentials, posts, media links, analytics, comments and messages |
| Sign-in (optional) | GitHub | Your GitHub identity, if you choose to sign in with it |
The social networks themselves (Meta for Facebook, Instagram and Threads, X, LinkedIn, TikTok, Google for YouTube and Business Profile, Pinterest and Bluesky) receive what customers publish or send through them, and return analytics, comments and messages. They process that data under their own terms and privacy policies, as independent controllers.
The current list of sub-processors, with their locations, is available on request at privacy@postpeg.com. We will notify customers who have a data processing agreement before adding a new sub-processor.
We may also disclose data when the law requires it, to protect the rights and safety of people or of postpeg, or to a successor if our business is sold or merged, in which case this policy continues to apply.
9. International transfers
Our providers operate globally, so data may be processed outside your country, including in the United States. Where data leaves the EEA, the UK or Switzerland for a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, or on a provider’s certification under the EU-US Data Privacy Framework where that applies. Ask us at privacy@postpeg.com for details.
10. Security
- All traffic to postpeg is encrypted in transit with TLS.
- API keys are stored as SHA-256 hashes and passwords as salted hashes; neither can be read back.
- Social account credentials are encrypted at rest with AES-GCM.
- Access is rate limited, sessions expire, and access to production systems is restricted to the people who need it.
No system is perfectly secure. If we learn of a personal data breach that affects you, we will tell you, and the relevant authorities, as the law requires.
11. Your rights
If you are in the EEA, the UK or Switzerland, you have the right to access your personal data, correct it, have it deleted, restrict or object to how we use it, and receive it in a portable format. Where we rely on consent you can withdraw it at any time. You can also complain to your data protection authority (in the UK, the Information Commissioner’s Office), though we’d appreciate the chance to help first.
To exercise a right, email privacy@postpeg.com from the address on your account, or tell us enough to identify you. We reply within one month. For data we process as a processor, contact the customer (the app that connected your account); we will forward requests we receive and help the customer answer them.
Other regions. Residents of California and other US states with privacy laws have similar rights to know, access, correct and delete personal information, and not to be discriminated against for using them. We do not sell personal information or share it for cross-context behavioural advertising. Wherever you live, you can use the rights above by emailing us.
12. Children
postpeg is a business service for people aged 18 or over. It is not directed at children, and we don’t knowingly collect personal data from them for our own purposes. Customers must not use postpeg in ways that break the law or platform rules on children’s data.
13. Changes to this policy
We will update this policy when what we do with data changes, and change the date at the top. For material changes we will email account owners before they take effect.
14. Contact
Email privacy@postpeg.com, or write to [Company legal name], [Registered address].